ClawGateSecure for Openclaw

A mandatory, immutable security protocol designed to protect LLM agents from prompt injections, malicious code execution, and data exfiltration.

thestormshadow
v3.1.0
Feb 3, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install clawgatesecure

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install clawgatesecure using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is ClawGateSecure?

ClawGateSecure is a sophisticated security framework that serves as the immutable core for AI agents. It establishes a zero-trust environment where all incoming data is treated as potentially malicious until verified. By incorporating this into your library of Openclaw Skills, you ensure your agents are resilient against narrative-based overrides, emotional manipulation, and unauthorized authority claims.

The protocol provides a robust shield for developers looking to deploy agents in production environments where security is non-negotiable. It integrates deeply with the agent's workflow, acting as both a sieve for input and a muzzle for output, ensuring that sensitive data like API keys and PII never leave the controlled environment.

ClawGateSecure Use Cases

  • Hardening AI agents against complex prompt injection and jailbreak attempts.
  • Automated line-by-line auditing of external files or third-party skills before activation.
  • Preventing accidental leakage of sensitive credentials, tokens, or personal identifiable information.
  • Implementing a zero-trust network policy by whitelisting approved domains for agent communication.

How ClawGateSecure Works

  1. The Zero-Trust Ingestion phase triggers a scrubber to sanitize input and isolate analysis within a zero-memory sandbox.
  2. A Mandatory Pipeline scan, powered by ClawDefender, performs a line-by-line audit to detect fragmentation attacks and hidden backdoors.
  3. Resource Guarding monitors for background activity spikes and restricts network traffic to pre-approved domain lists.
  4. Egress Filtering intercepts all outgoing messages to scan for PII, secrets, or internal encryption keys before delivery.
  5. The Unified Audit Report generates a risk score and identifies anomalies across all active security modules.
  6. An Execution Lock freezes the workflow, requiring explicit human consent before the agent can proceed with high-risk actions.

ClawGateSecure Setup

To deploy this security protocol, follow these steps to integrate it with your Openclaw Skills environment:

  1. Create the persistent audit log file:
touch ~/.openclaw/SecurityAudit.log
  1. Update your openclaw.json config with the following structure:
"skills": {
  "entries": {
    "clawgatesecure": {
      "enabled": true,
      "config": {
        "audit_enabled": true,
        "scrubber_enabled": true,
        "encryption_enabled": true,
        "fragmentation_check": true,
        "keys": {
          "encryption_key": "YOUR_SECURE_KEY",
          "bypass_key": "YOUR_BYPASS_KEY"
        }
      }
    }
  }
}
  1. Reference ClawGateSecure in your SOUL.md and AGENTS.md files as the primary operational constraint.

ClawGateSecure Data Schema & Taxonomy

ClawGateSecure organizes its security data and metadata using the following taxonomy:

Component Path / Location Description
Audit Trail ~/.openclaw/SecurityAudit.log Immutable record of all security scans, findings, and verdicts.
Media Sandbox ~/openclaw/skills/clawgatesecurity/media/ Isolated directory for multimedia storage with restricted permissions.
Risk Scoring Metadata Object A weighted average (1-10) based on consensus from active security modules.
Memory Store Encrypted at-rest High-sensitivity memories secured via the configured encryption key.
Dependency Map Audit Report Identification of affected files, environment variables, and network sockets.

ClawGateSecure Advanced Features

  • Fragmentation Check: Detects malicious instructions split across multiple sources to bypass standard filters.
  • Context Immunity: Forces the agent to ignore situational contexts like "emergency" or "life-threat" scenarios intended to bypass rules.
  • Multi-Skill Consensus: Aggregates security verdicts from multiple Openclaw Skills to generate a global risk score.
  • Stop-by-Design Workflow: Automatically aborts execution if a risk score exceeds 8 or if commands remain ambiguous.
  • Canary Traps: Monitors internal data for unauthorized access or breach attempts within the agent's memory.

SKILL.md


Loading

Related Openclaw Skills

Featured*