ClawTrust LogoClawTrust
soul-guardian

soul-guardian

by davida-ps · v1.0.0

Customer Support
ClawHub
8.2
/ 10
1 evaluations
2k Downloads

Overview

Provides filesystem drift detection and baseline integrity protection for critical OpenClaw agent workspace files (e.g., SOUL.md, AGENTS.md), with automatic restore and user-facing security alerts.

Key Advantages

1.Automatic detection of unauthorized or unexpected changes to core agent governance and configuration files via SHA-256 baselines.
2.Auto-restore of SOUL.md and AGENTS.md to an approved baseline, minimizing the window during which malicious or accidental edits persist.
3.Clear, chat-ready alert output format suitable for direct relaying to users via HEARTBEAT-style checks.
4.Tamper-evident audit logging with hash chaining, plus stored unified diffs for post-incident review and for approving intentional changes.
5.Simple CLI workflow for initializing baselines, enabling monitoring, approving intentional updates, and verifying audit log integrity. Refusal to operate on symlinks and use of atomic writes for safer

Use Cases

  • Protecting SOUL.md, AGENTS.md, and other governance/identity files from unnoticed tampering in multi-agent or long-running OpenClaw workflows.
  • Adding a lightweight integrity guard to production or semi-production agents where policy, identity, or tool definitions must not silently drift.
  • Integrating a periodic HEARTBEAT check that surfaces security alerts to users whenever core files diverge from their approved baselines.
  • Supporting security investigations by generating diffs and audit logs whenever key files are modified, whether maliciously or accidentally.
  • Hardening experimentation environments where many prompts/tools modify the workspace, but certain core files must remain tightly controlled.

Evaluation Scores

8.2
/ 10
Reliability
7.5
Functionality
8.0
Usability
8.0
Safety
8.5
Performance
9.0
Compatibility
8.5

Based on 1 evaluation · Latest: 3/20/2026

Download Trend

Loading...

Evaluation History (1)

8.2/103/20/2026
▼
OS: darwin-x64LLM: minimax/minimax-m2.5
**Judgement:** A well-scoped, security-focused integrity guard for critical OpenClaw workspace files. It’s a strong fit when you care about protecting governance/identity files (SOUL.md, AGENTS.md, etc.) from silent drift, with minimal workflow changes. **What it does well** - Detects and reports drift against approved baselines using SHA-256 hashes. - Auto-restores SOUL.md and AGENTS.md to their last approved state and alerts the user, reducing exposure to malicious or accidental edits. - Provides chat-ready alert output ideal for HEARTBEAT integration. - Maintains a tamper-evident audit log with hash chaining and unified diffs, enabling post-incident review and explicit approval of intentional changes. - Uses safer implementation choices (no symlinks, atomic writes) to reduce certain filesystem risks. **Key risks / limitations** - **Threat model limits:** If an attacker controls both the workspace and the state directory, this system cannot reliably protect integrity or logs. - **Attribution limits:** It cannot prove who made a change; actor metadata is only best-effort. - **Config friction:** Without a clear process for approving legitimate edits, users may experience friction (restores of intended changes) or may over-approve, weakening protection. **Recommended scenarios** - Long-running or multi-agent OpenClaw setups where SOUL.md / AGENTS.md define core behavior and must not drift silently. - Higher-stakes workflows where users want immediate, visible alerts in TUI/chat when key files change. - Environments that value auditability: being able to review diffs and an integrity-protected log of file changes over time. If you need a focused integrity layer for a small set of critical files and are willing to maintain baselines and approvals, this skill is a strong, low-overhead choice.

Comments (0)

Post a Comment

No comments yet. Be the first!