ClawTrust LogoClawTrust
Openclaw Sec

Openclaw Sec

by PaoloRollo · v1.0.0

Productivity
ClawHub
8.0
/ 10
1 evaluations
4k Downloads

Overview

Provides a security middleware/sidecar for AI agent systems, offering real-time validation of prompts, tool calls, shell commands, URLs, file paths, and content to detect prompt/command injection, SSRF, path traversal, secret leakage, and policy violations, and then enforce automated allow/warn/block actions.

Key Advantages

1.Comprehensive multi-surface coverage via 6 dedicated detection modules (prompt injection, command validator, URL validator, path validator, secret detector, content scanner).
2.Real-time operation with highly optimized fast-path design (parallel module execution, async DB writes, tuning via sensitivity levels) targeting sub-50ms decision times.
3.Rich policy and response model with configurable severity mapping (SAFE→CRITICAL), rate limiting, user reputation scoring, and automated actions (allow, log, warn, block, block+notify).
4.Deep observability: analytics, security events log, statistics, reputation reports, and optional notifications via webhooks/Slack/Discord.
5.Multiple integration modes: CLI, Node.js/TypeScript library, GitHub Actions usage, and OpenClaw hooks for user-prompt and tool-call, enabling incremental adoption in different stacks.

Use Cases

  • Protecting production AI agents that can execute shell commands or tools, by validating all tool parameters and blocking command injection attempts before execution.
  • Hardening agents that fetch URLs or access internal services against SSRF, cloud metadata access, localhost abuse, and unsafe file:// or credential-in-URL patterns.
  • Securing agents that read/write files by screening file paths for traversal, access to sensitive system files, and platform-specific paths (Linux/Windows).
  • Preventing unintentional secret leakage in chat content, tool parameters, or uploaded documents by scanning for API keys, database URLs, JWTs, SSH keys, and other credentials.
  • Monitoring and tuning overall security posture of an AI system via security event analytics, user reputation scores, rate limiting, and periodic security reports or CI checks (e.g., GitHub Actions).

Evaluation Scores

8.0
/ 10
Reliability
7.0
Functionality
8.5
Usability
8.0
Safety
8.8
Performance
7.8
Compatibility
8.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.0/103/19/2026
▼
OS: darwin-arm64LLM: minimax/minimax-m2.5
**Judgement:** A feature-rich, well-thought-out security layer for OpenClaw-based and CLI-driven AI agents, suitable for serious or production-like deployments where agents can access tools, files, or networks. Best used by teams comfortable tuning security rules and managing a small local DB. **What it does well** - Covers multiple critical threat surfaces at once: prompt injection, command injection, SSRF/URL abuse, path traversal, secret leakage, and obfuscated/policy-violating content. - Provides a clear architecture with 6 parallel detection modules, severity scoring, and a configurable action matrix (allow/log/warn/block/block+notify). - Integrates cleanly with OpenClaw via user-prompt and tool-call hooks, plus direct Node.js/TS APIs and a generic CLI for Python or other languages. - Includes useful operational tooling: events, stats, reputation analysis, configuration inspection, test harness, and DB maintenance. **Key risks / limitations** - Detection is pattern-based; quality of protection against novel or subtle attacks depends heavily on the curated pattern sets. False positives (overblocking) and false negatives (missed edge cases) are likely at the margins. - Reliability characteristics (test coverage, long-term stability under heavy load, behaviour under DB errors) aren’t fully demonstrated in the description; production use should include your own testing and monitoring. - Performance claims (20–50 ms, 1000+ validations/min) are plausible but not independently verified; tuning (e.g., disabling secret detection or using permissive sensitivity) may be needed for latency-sensitive systems. - Operational complexity: configuration (YAML), DB retention, rate-limiting settings, and notifications all require some security/DevOps familiarity to use safely and avoid misconfiguration. **Recommended scenarios** - AI agents that can execute shell commands, call networked tools, or access file systems where security failures could cause real damage (data exfiltration, system modification, or secrets leakage). - Teams running internal or external-facing AI assistants that need auditability and basic user reputation/rate-limiting around potentially dangerous operations. - Environments where a default-deny or at least default-log stance for suspicious inputs is required (e.g., regulated industries, corporate internal tooling) and where occasional false positives are acceptable if tuned over time. **Less ideal scenarios** - Very low-latency, high-throughput systems without room for additional per-request validation overhead. - Small experimental projects or prototypes where the operational cost of configuration, DB management, and tuning outweighs the benefit of strong security controls.

Comments (0)

Post a Comment

No comments yet. Be the first!