8.5
/ 10
1 evaluations
14.7k Downloads
Overview
Security guardrails plugin for OpenClaw that routes agent activity to OpenGuardrails Core for detection of prompt injection, malicious behaviors, and data leakage.
Key Advantages
1.Simple one-command installation with automatic activation and a guided test that proves protection is working.
2.Covers multiple risk surfaces: prompt/instruction attacks, dangerous commands/behaviors, and data/secret/PII leakage.
3.Centralized SaaS Core service with free daily quota (500 detections) and higher paid tiers for heavier workloads.
4.Provides operational tooling: status, dashboard, API key configuration, and account/agent claiming to share quotas across agents.
5.Supports enterprise scenarios via enrollment scripts that point MoltGuard at a private Core deployment instead of the public service, plus unenroll and uninstall scripts for lifecycle management.
Use Cases
- Protecting autonomous OpenClaw agents that can execute shell commands, modify files, or call external APIs from carrying out hidden malicious instructions in content.
- Scanning untrusted inputs such as emails, documents, and web pages for embedded prompt injection or malicious instructions before allowing the agent to act on them.
- Reducing the risk of data exfiltration and unintentional secret or PII exposure when agents read and transmit local files or contextual data to LLMs.
- Standardizing security controls for teams or organizations by linking multiple agents to a shared OpenGuardrails Core account and quota.
- Enterprise deployments that require a private, self-managed Core backend for policy enforcement and detection, instead of relying on the public SaaS service.
Evaluation Scores
8.5
/ 10
Reliability
7.8
Functionality
8.5
Usability
9.0
Safety
9.0
Performance
7.5
Compatibility
8.8
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.5/103/19/2026▼
OS: darwin-x64LLM: z-ai/glm-4.5-air
**Judgment:** MoltGuard is a mature, high-value security and guardrails layer for OpenClaw agents, particularly those exposed to untrusted content or with powerful system access. It integrates tightly with OpenClaw workflows and offers both individual and enterprise deployment modes.
**Strengths:**
- One-command install with automatic activation and a built-in test flow that clearly demonstrates protection.
- Multi-surface detection (prompt injection, behavioral risks, and data/secret leakage) backed by a centralized Core service.
- Operational tools (status, dashboard, config, claim-agent) that make it manageable at scale, plus enterprise enrollment for private Core instances.
**Risks / Limitations:**
- Detection quality, false-positive rate, and latency characteristics are not quantified in the description and depend on the external Core service.
- Reliance on a remote SaaS backend (unless using a private Core) introduces network and service-dependency risks; if Core is unavailable or quotas are exhausted, protection may degrade or block actions.
- Security scanning implies sending relevant content/metadata to OpenGuardrails Core; users handling highly sensitive data must ensure this aligns with their compliance and privacy requirements.
**Recommended Scenarios:**
- Autonomous or semi-autonomous OpenClaw agents that can run commands, modify the filesystem, or access sensitive data.
- Workflows that routinely process untrusted emails, documents, or web content where prompt injection and malicious instructions are realistic threats.
- Teams and organizations wanting standardized, centrally managed guardrails, especially when combined with a private Core deployment for stricter governance.
Comments (0)
No comments yet. Be the first!