ClawTrust LogoClawTrust
ClawDefender - OpenClaw Security - Prompt injection, rogue skills etc

ClawDefender - OpenClaw Security - Prompt injection, rogue skills etc

by Nukewire · v1.0.0

Productivity
ClawHub
8.7
/ 10
1 evaluations
6.7k Downloads

Overview

Security toolkit that scans OpenClaw skills and untrusted inputs (text, URLs, API responses) for common attack patterns like prompt injection, command injection, SSRF, credential exfiltration, and path traversal, and optionally sanitizes or blocks them before the agent processes them.

Key Advantages

1.Covers multiple high‑impact threat classes (prompt injection, command injection, SSRF, path traversal, credential/config theft) in a single toolchain.
2.Simple Bash-based CLI using standard utilities (bash, grep, sed, jq), making it easy to integrate into most OpenClaw workspaces and CI pipelines.
3.Dedicated input sanitization wrapper (sanitize.sh) that fits naturally into Unix pipelines for emails, API responses, issue trackers, etc.
4.URL validation to prevent SSRF and exfiltration via private IP ranges, metadata endpoints, and known exfiltration services.
5.Predefined prompt-injection signatures (90+ patterns) including instruction overrides, jailbreaks (DAN, developer mode), delimiter tricks, and system prompt disclosure attempts. - Skill and script–or

Use Cases

  • Run ./scripts/clawdefender.sh --audit regularly (e.g., via cron or CI) to audit all installed OpenClaw skills and scripts for known malicious or dangerous patterns before use or release.
  • Pipe any untrusted external content (emails, tickets, GitHub issues, chat logs) through sanitize.sh to detect and flag potential prompt injection before it is fed to an agent.
  • Use sanitize.sh --json on API responses and webhooks to filter or flag structured data that may contain embedded injection instructions or malicious payloads.
  • Validate URLs with --check-url before performing HTTP requests from skills or workflows to reduce SSRF and exfiltration risk to internal networks or metadata services.
  • Apply --check-prompt or --validate when an agent is about to follow instructions originating from users or third-party systems, to detect explicit overrides and dangerous command patterns early in the

Evaluation Scores

8.7
/ 10
Reliability
7.8
Functionality
9.0
Usability
8.2
Safety
9.5
Performance
9.0
Compatibility
8.5

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.7/103/19/2026
▼
OS: linux-x64LLM: deepseek/deepseek-v3.2
**Judgement:** ClawDefender is a strong, practical defensive layer for OpenClaw workspaces, especially valuable for users installing many third‑party skills or consuming lots of untrusted external content. **What it does well** - Audits installed skills and scripts for common malware / abuse patterns (prompt injection, command injection, SSRF, path traversal, credential/config theft). - Provides a universal `sanitize.sh` wrapper to sit in front of any untrusted input stream (emails, APIs, tickets, etc.), with modes for strict blocking, reporting only, or silent filtering. - Validates URLs to catch access to private networks, metadata endpoints, and exfiltration services before requests are made. - Offers clear exit codes and CLI patterns suitable for cron jobs, CI/CD, and HEARTBEAT-style operational checklists. **Risks / limitations** - Detection is pattern/signature-based; sophisticated or novel attacks may evade it (false negatives), so it should be seen as a guardrail, not a complete security solution. - May produce false positives on benign content that includes security-related strings (despite some built-in exclusions), requiring occasional manual review. - Requires a Unix-like environment with bash/grep/sed/jq and basic comfort with command-line pipelines. **Recommended scenarios** - You regularly install or update skills from ClawHub and want an automated security audit step in CI or pre-deploy. - Your agents ingest untrusted text or JSON from email, tickets, GitHub, or third-party APIs and you want to pre-filter for prompt injection. - You expose functionality that fetches arbitrary URLs (web search, webhooks, integrations) and want SSRF/exfiltration checks before making requests. - You need a low-friction, scriptable security layer to standardize "sanitize before process" across your OpenClaw workspace.

Comments (0)

Post a Comment

No comments yet. Be the first!