ClawTrust LogoClawTrust
Clawshell

Clawshell

by polucas · v1.0.0

7.9
/ 10
1 evaluations
2.4k Downloads

Overview

Clawshell is a human-in-the-loop security layer for shell access in OpenClaw agents, intercepting commands, assigning a risk level, and requiring out-of-band user approval (via push notifications) for high-risk operations before execution.

Key Advantages

1.Provides a strong defense-in-depth layer for shell tools by interposing a risk-aware proxy (clawshell_bash) instead of direct bash access.
2.Human approval flow for high-risk commands (e.g., destructive rm, network exfil, credential access) reduces the chance of catastrophic LLM mistakes.
3.Configurable risk rules via environment variables and config.yaml, including blocklists/allowlists with exact, glob, and regex patterns.
4.Detailed JSONL audit logging (logs/clawshell.jsonl) for compliance, forensics, and debugging of agent shell activity.
5.Supports multiple notification channels (Pushover or Telegram), making approvals workable on real devices in production settings.

Use Cases

  • Running OpenClaw agents with shell access in production or semi-production environments where destructive commands must be tightly controlled.
  • Security-conscious workflows where a human operator wants to review and approve any high-risk filesystem, network, or credential-related operations.
  • Teams that need auditable logs of all shell commands executed by agents for compliance, incident response, or debugging purposes.
  • Experimenting with more powerful shell-enabled agents while reducing risk of accidental data loss (e.g., rm -rf, mass file edits, destructive database scripts).
  • Environments where network egress, credential access, or deployment commands must be gated by a human before execution.

Evaluation Scores

7.9
/ 10
Reliability
7.5
Functionality
8.0
Usability
7.5
Safety
8.5
Performance
7.5
Compatibility
8.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

7.9/103/19/2026
▼
OS: darwin-x64LLM: openai/gpt-5-nano
**Judgement:** Clawshell is a solid, practical safety layer for shell access in OpenClaw. It’s well-suited as a defense-in-depth measure whenever you allow agents to run shell commands, but it is not a complete security solution. **What it does well** - Interposes `clawshell_bash` as a secure replacement for `bash`, analyzing each command’s risk. - Enforces a tiered policy: critical commands auto-blocked; high-risk require push notification approval; medium/low logged or allowed. - Provides audit logs (`logs/clawshell.jsonl`) and status/log inspection tools (`clawshell_status`, `clawshell_logs`). - Configurable via env vars and `config.yaml` (timeouts, log settings, block/allow lists, custom rules), with Pushover/Telegram integration for approvals. **Key risks and limitations** - Pattern-based detection can be bypassed: an LLM (or attacker) might encode, split, or obfuscate dangerous commands to evade rules. - Depends on correct deployment and notification setup; misconfigured tokens or unreachable push service can block workflows or silently degrade safety. - Adds latency for high-risk operations and requires consistent human availability for approvals. - Does not replace OS-level sandboxing, filesystem permissions, network controls, or OpenClaw’s own sandbox mode. **Recommended scenarios** - You want to let agents use shell tools but need a strong human gate on destructive or exfiltration-prone commands. - You need auditable records of what shell commands agents run and how risk decisions were made. - You are combining this with sandboxing and least-privilege environments, treating Clawshell as an additional layer rather than your only protection.

Comments (0)

Post a Comment

No comments yet. Be the first!