Arc-shield Secret Sanitizer for Openclaw

Arc-shield is an advanced output filtering skill designed to scan and sanitize AI agent responses, ensuring sensitive credentials and PII never leak to external channels.

arc-claw-bot
v1.0.0
Feb 9, 2026
0
1.8k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install arc-shield

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install arc-shield using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Arc-shield Secret Sanitizer?

Arc-shield provides a critical safety layer for AI agents by acting as a dedicated output filter. While other tools focus on input validation, this skill specifically monitors outbound communications to prevent the accidental disclosure of sensitive information like 1Password tokens, GitHub PATs, and private keys. By integrating this into your Openclaw Skills workflow, you ensure that even if an agent accesses a secret during its task, that secret is redacted or blocked before reaching Discord, Slack, or any public-facing API.

The skill combines high-speed pattern matching with sophisticated entropy analysis to catch both known secret formats and novel high-entropy strings that might represent undocumented tokens or credentials. This is an essential component for any production-grade deployment of Openclaw Skills where security and privacy are paramount.

Arc-shield Secret Sanitizer Use Cases

  • Prevent agents from leaking environment variables or config files during debugging sessions.
  • Redact credit card numbers and Social Security Numbers from customer support agent transcripts.
  • Block outbound messages containing 12 or 24-word wallet recovery phrases in crypto-related workflows.
  • Sanitize log files before storage to ensure compliance with privacy regulations.
  • Audit historical agent conversations to identify potential security vulnerabilities within your Openclaw Skills ecosystem.

How Arc-shield Secret Sanitizer Works

  1. The outbound message is intercepted via a pre-send hook or pipe within the agent's communication wrapper.
  2. The text is passed through the bash-based scanner for rapid regex pattern matching against a predefined list of critical, high, and warning-level threats.
  3. For deep analysis, the Python-based output-guard utility calculates the Shannon entropy of various strings to identify potential secrets that don't follow standard patterns.
  4. Depending on the configuration (e.g., --strict), the skill either blocks the message entirely, redacts the sensitive portions, or allows it to pass through with a warning.
  5. The sanitized output is then handed back to the primary messaging skill for final transmission to the destination channel.

Arc-shield Secret Sanitizer Setup

To install Arc-shield within your environment, use the following commands:

cd ~/.openclaw/workspace/skills
git clone <arc-shield-repo> arc-shield
chmod +x arc-shield/scripts/*.sh arc-shield/scripts/*.py

To integrate it as a pre-send hook for your Openclaw Skills, wrap your messaging command like this:

#!/bin/bash
# Sanitize output before sending
SANITIZED=$(echo "$MESSAGE" | arc-shield.sh --strict --redact)
EXIT_CODE=$?

if [[ $EXIT_CODE -eq 1 ]]; then
    echo "ERROR: Message contains critical secrets and was blocked." >&2
    exit 1
fi

# Send sanitized message
openclaw message send --channel "$CHANNEL" "$SANITIZED"

Arc-shield Secret Sanitizer Data Schema & Taxonomy

The skill utilizes a centralized configuration file to manage detection logic and provides structured output for audits.

Component Description
config/patterns.conf Defines the regex patterns and severity levels (CRITICAL, HIGH, WARN) for secret matching.
--report output Generates a detailed analysis log of detected patterns and entropy scores for auditing Openclaw Skills.
--redact output Produces a sanitized version of the input text with sensitive strings replaced by [REDACTED:TYPE] labels.
entropy-threshold A configurable float value (default 4.5) used by the Python engine to flag high-entropy strings.

Arc-shield Secret Sanitizer Advanced Features

  • Customizable entropy thresholding to balance between high-security detection and false-positive prevention.
  • Support for custom regex patterns in the configuration file to catch internal company secrets or specific token formats.
  • Dual-engine processing using both Bash for speed and Python for Shannon entropy algorithmic accuracy.
  • Multi-mode execution including strict blocking for production and redaction-only for development logs.
  • Seamless integration compatibility with any Openclaw Skills that utilize standard Unix pipes for communication.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*