Claw Permission Firewall for Openclaw

A runtime least-privilege firewall that evaluates AI agent actions to prevent data exfiltration and unauthorized system access.

bharathjanumpally
v1.0.0
Feb 5, 2026
1
2.4k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install claw-permission-firewall

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install claw-permission-firewall using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Claw Permission Firewall?

Claw Permission Firewall serves as a critical security layer for autonomous agents, providing runtime evaluation of requested actions. It operates on a least-privilege model, analyzing every intent—such as file reads, HTTP requests, or shell commands—to determine if they are safe to execute. As a vital component for developers building with Openclaw Skills, it acts as a gatekeeper that mitigates risks associated with prompt injection and unauthorized data access.

Beyond simple blocking, this skill provides intelligent mediation. It can redact sensitive information like API keys or cookies before an action is performed and can trigger human-in-the-loop confirmation for high-risk operations. By integrating this into your agentic workflows, you ensure that your Openclaw Skills remain compliant with local security policies without sacrificing the autonomy of the AI.

Claw Permission Firewall Use Cases

  • Preventing data exfiltration by blocking outgoing HTTP requests to untrusted or non-TLS domains.
  • Shielding sensitive local files such as SSH keys, AWS credentials, and .env files from agent access.
  • Mitigating prompt-injection attacks that attempt to trick agents into executing destructive shell commands like rm -rf.
  • Implementing human-in-the-loop workflows for risky actions that require explicit user approval before execution.

How Claw Permission Firewall Works

  1. The host application or primary agent generates an action object representing the intended operation.
  2. This action object is passed to the Claw Permission Firewall for security analysis.
  3. The firewall evaluates the action against the rules defined in policy.yaml and calculates a risk score.
  4. The skill returns a decision: ALLOW, DENY, or NEED_CONFIRMATION, along with a sanitized version of the action.
  5. If the decision is ALLOW, the system executes the sanitized action; if NEED_CONFIRMATION, it pauses for user input.

Claw Permission Firewall Setup

To get started, ensure you have your policy configurations defined. The firewall relies on a local configuration file to manage rule sets.

# Navigate to your skill directory
cd skills/claw-permission-firewall

# Edit the policy file to match your security requirements
nano policy.yaml

Integrate the firewall into your agent's decision loop by calling the evaluation endpoint before any external side-effect is triggered.

Claw Permission Firewall Data Schema & Taxonomy

The skill utilizes a structured JSON schema for both inputs and outputs to ensure compatibility across Openclaw Skills.

Property Type Description
decision String The verdict: ALLOW, DENY, or NEED_CONFIRMATION.
riskScore Number A float representing the calculated threat level of the action.
sanitizedAction Object The original action payload with secrets and headers redacted.
reasons Array A list of specific policy rules that triggered the decision.
audit Object Metadata including traceId and policyVersion for compliance tracking.

Claw Permission Firewall Advanced Features

  • Dynamic secret redaction that automatically identifies and masks Authorization headers, Cookies, and X-API-Keys.
  • Workspace jailing that restricts all file system operations to a designated root directory.
  • Flexible security modes including strict, balanced, and permissive to suit different development stages.
  • Fingerprinting of actions to provide a consistent audit trail across multiple sessions in Openclaw Skills.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*