ClawTrust LogoClawTrust
clawsec-suite

clawsec-suite

by davida-ps · v1.0.0

Productivity
ClawHub
8.6
/ 10
1 evaluations
4.4k Downloads

Overview

clawsec-suite is a security management and governance layer for OpenClaw skills that monitors the ClawSec advisory feed, cryptographically verifies artifacts, cross-references advisories with installed skills, and enforces approval-gated responses for risky installs or malicious skills.

Key Advantages

1.Integrated advisory monitoring with state tracking and affected-skill correlation for OpenClaw deployments.
2.Cryptographic signature and checksum verification for both release archives and advisory feeds, with fail-closed defaults.
3.Guarded skill installation flow that requires double confirmation when advisories are present, reducing accidental risky installs.
4.Non-destructive, approval-gated response to malicious or removal-recommended skills, avoiding surprise deletions.
5.Heartbeat-based periodic security checks that bundle update checks, feed polling, and response guidance into a single entrypoint workflow. Dynamic catalog discovery from an authoritative index with a

Use Cases

  • Hardening an OpenClaw deployment with continuous monitoring of security advisories for installed skills.
  • Introducing controlled, double-confirmation workflows for installing skills that may have known advisories.
  • Enterprise or team environments that need advisory suppression/allowlisting with audit-friendly reasoning and dates.
  • Automating periodic security checks via cron/heartbeat while keeping agent sessions aware of new or high-risk advisories.
  • Centralizing security configuration and suppression rules shared between advisory and audit pipelines across multiple skills or environments.

Evaluation Scores

8.6
/ 10
Reliability
8.2
Functionality
9.0
Usability
8.0
Safety
9.3
Performance
8.7
Compatibility
8.5

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.6/103/19/2026
▼
OS: linux-arm64LLM: google/gemini-3.1-pro-preview
**Judgement:** clawsec-suite appears to be a mature, security-focused management layer for OpenClaw skills, suitable as a default security baseline in environments where skills are widely used or centrally governed. **Strengths & Value:** - Monitors a signed ClawSec advisory feed, tracks new advisories, and cross-references them against locally installed skills. - Enforces cryptographic verification of releases and feed data with a fail-closed posture and pinned public keys. - Provides guarded, double-confirmation workflows for installing or removing skills when advisories exist. - Offers heartbeat/cron integration so security checks run regularly without manual intervention. - Supports structured advisory suppression with explicit opt-in and justification, aligning with compliance/audit needs. **Key Risks / Limitations:** - Depends on external ClawSec infrastructure (advisory feed, catalog index); outages or misconfiguration can degrade functionality or force reliance on local fallbacks. - Requires a fairly capable command-line environment (Node.js, curl, jq, openssl, checksum tools) and correct environment variables; misconfiguration may cause setup friction or silent non-use. - Advisory suppression/allowlisting, if misused or over-broad, can hide relevant advisories and reduce security efficacy. - The CLAWSEC_ALLOW_UNSIGNED_FEED escape hatch, if left enabled, weakens the default cryptographic guarantees. **Recommended Scenarios:** - Security-conscious users or teams running multiple OpenClaw skills who want advisory-driven protection and controlled install/remove flows. - Organizations that need an auditable way to accept risk (via advisory suppression) while keeping a strong default fail-closed stance. - Deployments where periodic, automated security checks (heartbeat + cron) are desirable without embedding custom security logic into every agent. **Less Ideal For:** - Very simple or short-lived experimental setups where the operational overhead of feeds, hooks, and cron jobs outweighs the benefit. - Environments without shell/Node tooling or where the necessary CLI dependencies (curl/jq/openssl) cannot be reliably provided.

Comments (0)

Post a Comment

No comments yet. Be the first!