ClawWall for Openclaw

ClawWall provides outbound Data Loss Prevention for Openclaw Skills by intercepting tool calls to block or redact secrets and PII using hard regex matching.

stanxy
v0.3.0
Feb 22, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install clawguard-skill

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install clawguard-skill using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is ClawWall?

ClawWall is a dedicated security layer designed to sit between your AI agent and the outside world. It serves as an outbound Data Loss Prevention (DLP) service specifically optimized for Openclaw Skills. Unlike traditional filters that rely on LLMs, ClawWall utilizes 60+ hard-coded regex patterns and entropy analysis to ensure that sensitive data like API keys, credentials, and PII never leave your local environment.

By operating entirely on-device, this skill ensures that no telemetry or sensitive content is ever transmitted to external servers. It provides developers using Openclaw Skills with a reliable, high-performance way to enforce security policies and prevent accidental data leakage during automated tool executions.

ClawWall Use Cases

  • Preventing the accidental transmission of cloud provider secrets like AWS or GCP keys.
  • Automatically redacting PII such as credit card numbers or SSNs from outbound tool calls.
  • Implementing custom regex patterns to enforce organization-specific security protocols.
  • Auditing outbound data patterns through a local, privacy-focused metadata dashboard.

How ClawWall Works

  1. The OpenClaw plugin intercepts every outbound tool call using the before_tool_call event.
  2. Intercepted content is sent to a local Python service running on port 8642.
  3. The service scans the payload against a library of 60+ patterns and performs entropy analysis for unknown secrets.
  4. The system applies the defined policy action: ALLOW, REDACT, or BLOCK.
  5. Scan metadata is logged to a local SQLite database for auditing while the actual content is discarded.

ClawWall Setup

To install ClawWall and integrate it with your Openclaw Skills, execute the following command:

bash setup.sh

This script handles the Python service installation, builds the necessary hooks, and registers the plugin in your OpenClaw configuration. To verify the installation, you can run a health check:

curl -s http://127.0.0.1:8642/api/v1/health

ClawWall Data Schema & Taxonomy

ClawWall maintains a local SQLite database to track security findings. It is important to note that the system never stores raw content or actual secret values.

Table Column Description
finding_type The category of secret or PII detected (e.g., JWT, SSN)
severity The risk level assigned to the specific finding
action The outcome of the scan (ALLOWED, REDACTED, BLOCKED)
duration The time in milliseconds taken to complete the scan

ClawWall Advanced Features

  • Entropy Analysis: Detects high-entropy strings that may be proprietary secrets not covered by standard regex.
  • Custom Policy YAML: Allows users to define specific allowlists, blocklists, and custom regex patterns.
  • Local Dashboard: Provides a web interface at port 8642 to monitor scan history and manage security settings.
  • Automated Service Management: Utilizes systemd or launchd to ensure the DLP service is always running alongside Openclaw Skills.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*