Agent Passport for Openclaw

Agent Passport is a comprehensive security framework providing OAuth-style consent-gating, behavioral contracts, and threat-shielding for autonomous AI agents.

markneville
v2.4.2
Feb 27, 2026
3
2.6k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install agent-passport

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install agent-passport using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Agent Passport?

Agent Passport serves as the essential security firewall for the agentic era, introducing a sophisticated consent layer between AI agents and sensitive system resources. By implementing this within your Openclaw Skills environment, you transition from risky, all-access permissions to granular, time-bound mandates. This ensures that every action—whether it involves shell execution, financial transactions, or communication—is governed by a strict behavioral contract.

The skill incorporates advanced protection mechanisms, including an Injection Shield, SSRF Shield, and Path Traversal Guard. With over 75 data-driven threat definitions, Agent Passport provides the governance necessary for scaling agent autonomy safely. It allows users to define exactly what an agent can do, for how long, and under what specific constraints, providing an immutable audit trail for complete accountability.

Agent Passport Use Cases

  • Restricting shell commands to specific development tools or safe directories.
  • Implementing spending caps and merchant allowlists for autonomous agent purchasing.
  • Gating communication channels like email or social media to prevent unauthorized messaging.
  • Protecting sensitive data by defining specific path allowlists and requiring backups.
  • Managing temporary access for third-party agents using TTL-based mandates.

How Agent Passport Works

  1. The user initializes the local ledger and registers the agent's identity using the KYA (Know Your Agent) protocol.
  2. Permission mandates are established using pre-defined templates or custom JSON configurations to define the scope of authorized actions.
  3. Before performing a sensitive operation, the agent must call the check-action function to verify its authorization against the ledger.
  4. If authorized, the agent proceeds with the task and logs the completion; if denied, the agent is programmed to stop and request explicit user consent.
  5. The system continuously evaluates actions against active threat definitions and spending limits to prevent malicious behavior.

Agent Passport Setup

To deploy Agent Passport in your Openclaw Skills setup, run the following initialization commands:

# Initialize the ledger and register your primary agent
./mandate-ledger.sh init agent:my-assistant "Your Name" "personal assistant" "openclaw"

# Apply a standard development tools template
./mandate-ledger.sh create-from-template dev-tools

# Initialize the threat signature database
./mandate-ledger.sh init-definitions

Ensure the AGENT_PASSPORT_LEDGER_DIR environment variable is defined in your environment configuration.

Agent Passport Data Schema & Taxonomy

Agent Passport maintains a structured local database within ~/.openclaw/agent-passport/ to manage security states:

File Purpose
mandates.json Stores active permission scopes, TTLs, and usage limits.
agents.json Contains the Know Your Agent (KYA) registry and agent metadata.
audit.json A chronological log of all authorized and unauthorized agent attempts.
threat-definitions.json A library of security patterns used to identify and block malicious activities.
.threat-meta.json Metadata regarding definition versions and update history.

Agent Passport Advanced Features

  • Multi-vector protection including Skill Scanner and Injection Shield to mitigate prompt-based attacks.
  • Flexible wildcard pattern matching for allowlists, including prefix, suffix, and domain-based rules.
  • Automated behavioral contracts that force agents to stop and ask for permission when scope is exceeded.
  • Global Kill Switch functionality to immediately freeze all sensitive operations across the Openclaw Skills ecosystem.
  • Detailed audit reporting and export capabilities for regulatory compliance and usage analysis.
  • Pro-tier support for real-time threat definition updates every 6 hours.

SKILL.md


Loading

Related Openclaw Skills

Featured*