Arc-shield is an advanced output filtering skill designed to scan and sanitize AI agent responses, ensuring sensitive credentials and PII never leak to external channels.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install arc-shield
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install arc-shield using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Arc-shield provides a critical safety layer for AI agents by acting as a dedicated output filter. While other tools focus on input validation, this skill specifically monitors outbound communications to prevent the accidental disclosure of sensitive information like 1Password tokens, GitHub PATs, and private keys. By integrating this into your Openclaw Skills workflow, you ensure that even if an agent accesses a secret during its task, that secret is redacted or blocked before reaching Discord, Slack, or any public-facing API.
The skill combines high-speed pattern matching with sophisticated entropy analysis to catch both known secret formats and novel high-entropy strings that might represent undocumented tokens or credentials. This is an essential component for any production-grade deployment of Openclaw Skills where security and privacy are paramount.
To install Arc-shield within your environment, use the following commands:
cd ~/.openclaw/workspace/skills
git clone <arc-shield-repo> arc-shield
chmod +x arc-shield/scripts/*.sh arc-shield/scripts/*.py
To integrate it as a pre-send hook for your Openclaw Skills, wrap your messaging command like this:
#!/bin/bash
# Sanitize output before sending
SANITIZED=$(echo "$MESSAGE" | arc-shield.sh --strict --redact)
EXIT_CODE=$?
if [[ $EXIT_CODE -eq 1 ]]; then
echo "ERROR: Message contains critical secrets and was blocked." >&2
exit 1
fi
# Send sanitized message
openclaw message send --channel "$CHANNEL" "$SANITIZED"
The skill utilizes a centralized configuration file to manage detection logic and provides structured output for audits.
| Component | Description |
|---|---|
| config/patterns.conf | Defines the regex patterns and severity levels (CRITICAL, HIGH, WARN) for secret matching. |
| --report output | Generates a detailed analysis log of detected patterns and entropy scores for auditing Openclaw Skills. |
| --redact output | Produces a sanitized version of the input text with sensitive strings replaced by [REDACTED:TYPE] labels. |
| entropy-threshold | A configurable float value (default 4.5) used by the Python engine to flag high-entropy strings. |
Loading
A comprehensive security monitoring and infrastructure health toolkit designed for Openclaw Skills agents.

An AI-driven search assistant that generates optimized Mixcache ebook discovery links based on user topics, authors, or genres.

A proactive shopping assistant that generates direct Contaya coupon links based on detected store domains and shopping intent.

An automated audit tool that verifies marketing content against 208 global regulations including FTC, GDPR, and HIPAA.

A specialized briefing tool that aggregates releases, security advisories, and community trends across the OpenClaw ecosystem.

A comprehensive tool for the lifecycle management of AI agents within the OpenClaw ecosystem, from workspace initialization to Telegram routing.








































