2.4k Downloads
Overview
Clawshell is a human-in-the-loop security layer for shell access in OpenClaw agents, intercepting commands, assigning a risk level, and requiring out-of-band user approval (via push notifications) for high-risk operations before execution.
Key Advantages
1.Provides a strong defense-in-depth layer for shell tools by interposing a risk-aware proxy (clawshell_bash) instead of direct bash access.
2.Human approval flow for high-risk commands (e.g., destructive rm, network exfil, credential access) reduces the chance of catastrophic LLM mistakes.
3.Configurable risk rules via environment variables and config.yaml, including blocklists/allowlists with exact, glob, and regex patterns.
4.Detailed JSONL audit logging (logs/clawshell.jsonl) for compliance, forensics, and debugging of agent shell activity.
5.Supports multiple notification channels (Pushover or Telegram), making approvals workable on real devices in production settings.
Use Cases
- Running OpenClaw agents with shell access in production or semi-production environments where destructive commands must be tightly controlled.
- Security-conscious workflows where a human operator wants to review and approve any high-risk filesystem, network, or credential-related operations.
- Teams that need auditable logs of all shell commands executed by agents for compliance, incident response, or debugging purposes.
- Experimenting with more powerful shell-enabled agents while reducing risk of accidental data loss (e.g., rm -rf, mass file edits, destructive database scripts).
- Environments where network egress, credential access, or deployment commands must be gated by a human before execution.
Evaluation Scores
7.9
/ 10
Reliability
7.5
Functionality
8.0
Usability
7.5
Safety
8.5
Performance
7.5
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
7.9/103/19/2026▼
OS: darwin-x64LLM: openai/gpt-5-nano
**Judgement:** Clawshell is a solid, practical safety layer for shell access in OpenClaw. It’s well-suited as a defense-in-depth measure whenever you allow agents to run shell commands, but it is not a complete security solution.
**What it does well**
- Interposes `clawshell_bash` as a secure replacement for `bash`, analyzing each command’s risk.
- Enforces a tiered policy: critical commands auto-blocked; high-risk require push notification approval; medium/low logged or allowed.
- Provides audit logs (`logs/clawshell.jsonl`) and status/log inspection tools (`clawshell_status`, `clawshell_logs`).
- Configurable via env vars and `config.yaml` (timeouts, log settings, block/allow lists, custom rules), with Pushover/Telegram integration for approvals.
**Key risks and limitations**
- Pattern-based detection can be bypassed: an LLM (or attacker) might encode, split, or obfuscate dangerous commands to evade rules.
- Depends on correct deployment and notification setup; misconfigured tokens or unreachable push service can block workflows or silently degrade safety.
- Adds latency for high-risk operations and requires consistent human availability for approvals.
- Does not replace OS-level sandboxing, filesystem permissions, network controls, or OpenClaw’s own sandbox mode.
**Recommended scenarios**
- You want to let agents use shell tools but need a strong human gate on destructive or exfiltration-prone commands.
- You need auditable records of what shell commands agents run and how risk decisions were made.
- You are combining this with sandboxing and least-privilege environments, treating Clawshell as an additional layer rather than your only protection.
Comments (0)
No comments yet. Be the first!