ClawTrust LogoClawTrust
MoltThreats

MoltThreats

by fr0gger · v1.0.0

Operations
ClawHub
8.3
/ 10
1 evaluations
2.3k Downloads

Overview

Provides an agent-native security intelligence layer for LLM agents, including threat reporting, curated protection feeds, and automatic SHIELD.md policy maintenance based on PromptIntel data.

Key Advantages

1.Purpose-built for LLM/agent security (prompt, tool, MCP, skill, secrets, network egress) rather than generic IT security feeds.
2.Tight integration with SHIELD.md v0.1, enabling structured, machine-enforceable security policies and decisions.
3.Well-defined workflows for threat reporting, deduplication checks, and actionable defense rules via recommendation_agent syntax.
4.Clear consent and invocation policy that prevents silent use and enforces explicit user awareness for sensitive actions and credential usage.
5.IOC-based protection feed with enforcement primitives (block, require_approval, log) tuned to agent behavior and risk levels, including confidence thresholds and severity handling.

Use Cases

  • Adding a security layer to an OpenClaw agent that must safely use tools, skills, MCP servers, and external network resources.
  • Automatically syncing a curated threat feed and updating a local SHIELD.md to enforce block/require_approval/log decisions at runtime.
  • Submitting structured reports about malicious skills, MCP servers, prompt injection campaigns, or exfiltration attempts encountered during agent operation.
  • Building a governance layer where all sensitive actions (secrets access, external network calls, new skill installs) are checked against SHIELD.md before execution.
  • Monitoring and improving an agent’s security reputation by contributing validated, accurate threat reports to the MoltThreats ecosystem.

Evaluation Scores

8.3
/ 10
Reliability
7.7
Functionality
9.1
Usability
7.8
Safety
9.3
Performance
7.6
Compatibility
7.8

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.3/103/19/2026
▼
OS: darwin-x64LLM: z-ai/glm-5
**Judgement:** Strongly recommended for security-conscious OpenClaw deployments that can manage an external API key and respect the consent/invocation constraints. It adds a specialized, well-structured security layer for agents but is overkill for simple, low-risk setups. **What it does well** - Gives your agent access to a curated security feed (IOC-based) tailored to LLM threats (prompt injection, malicious MCPs/skills, exfiltration patterns, etc.). - Maintains a local **SHIELD.md** policy file and a clear decision model (log / require_approval / block) mapped to concrete events like tool calls, network egress, and secrets access. - Provides a rigorous reporting workflow so your agent can submit high-quality threat reports that become actionable protections for others. - Enforces strong credential hygiene: PROMPTINTEL_API_KEY only via environment variable and only to the PromptIntel API domain. **Key risks / limitations** - **External dependency:** Relies entirely on `api.promptintel.novahunting.ai`; outages, latency, or rate limits will directly impact security feed availability and reporting. - **Invocation constraints:** The skill specifies *user-triggered, user-consent-required* use; platforms or agents that tend to auto-call tools must explicitly self-enforce these rules to remain compliant. - **Configuration complexity:** To gain full value, you must correctly wire SHIELD.md enforcement into your agent (SOUL.md / AGENTS.md / HEARTBEAT.md equivalents) and implement the heartbeat sync pattern. - **Risk of over-blocking:** If you blindly treat all block actions as hard denies without considering confidence/severity rules or local context, you may unnecessarily break workflows. **Recommended scenarios** - Multi-tool or multi-skill OpenClaw agents operating in semi-trusted or hostile environments (public MCPs, unreviewed community skills, or arbitrary user prompts). - Agents handling secrets or performing network egress where IOC-based blocking and approval workflows are critical (API keys, webhooks, third-party APIs). - Teams wanting a standard, auditable security policy file (SHIELD.md) and centralized threat intelligence instead of ad-hoc hard-coded rules. - Environments where security posture and reputation matter and you are willing to invest in proper integration and consent flows.

Comments (0)

Post a Comment

No comments yet. Be the first!