ClawGuard for Openclaw

ClawGuard is a specialized security scanner that identifies malicious code and suspicious patterns within Openclaw Skills to ensure safe installations.

devinfloyd1
v1.0.0
Feb 19, 2026
0
1.1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install clawguarddevin

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install clawguarddevin using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is ClawGuard?

ClawGuard serves as a critical security layer for developers and users within the AI agent ecosystem. By analyzing Openclaw Skills for dangerous behaviors such as reverse shells, data exfiltration, and credential harvesting, it prevents the installation of compromised tools. It is particularly effective against the ClawHavoc campaign, incorporating research-backed indicators of compromise to maintain a secure development environment.

The tool is designed to be lightweight and dependency-free, making it easy to integrate into any workflow where Openclaw Skills are being developed or deployed. By providing a clear risk score and detailed category breakdowns, it empowers users to make informed decisions about the code they run in their agent environments.

ClawGuard Use Cases

  • Pre-installation vetting of new Openclaw Skills to ensure environment safety.
  • Auditing currently installed Openclaw Skills for hidden malicious patterns or obfuscated code.
  • Automating security checks within CI/CD pipelines using JSON output for Openclaw Skills deployments.
  • Identifying specific indicators of compromise related to the ClawHavoc security threat.

How ClawGuard Works

  1. The user triggers a scan by targeting a specific skill name, a file path, or all installed Openclaw Skills.
  2. ClawGuard analyzes the source code for predefined malicious patterns including socket connections, suspicious TLDs, and credential file access.
  3. The tool cross-references findings against an IOC database containing over 70 indicators, including real-world threats from the ClawHavoc campaign.
  4. A risk score (0-100) is calculated based on the severity of detected patterns and behaviors.
  5. A report is generated in the requested format (Console, JSON, or Markdown) providing actionable security insights for your Openclaw Skills.

ClawGuard Setup

To begin using this tool for your Openclaw Skills, ensure you have Python 3.8+ installed. No external dependencies are required as the scanner relies on the Python standard library.

# Scan a specific skill by name
python scan.py --skill <skill-name>

# Scan a skill by local directory path
python scan.py --path /path/to/skill

# Audit all installed Openclaw Skills
python scan.py --all

ClawGuard Data Schema & Taxonomy

ClawGuard evaluates Openclaw Skills and generates structured risk reports. It categorizes threats based on severity levels and generates data according to the following taxonomy:

Category Examples Severity
Reverse Shells socket.connect(), pty.spawn() Critical
Data Exfiltration Post requests to suspicious TLDs Critical
Credential Harvest Reading .ssh/id_rsa or AWS keys Critical
Obfuscation base64.b64decode, chr() chains Critical
Code Execution exec(), eval(), subprocess High
Suspicious Network URL shorteners, non-standard ports Medium

Reports can be exported as JSON for programmatic processing or Markdown for documentation within your Openclaw Skills project repository.

ClawGuard Advanced Features

  • Automated discovery of all installed Openclaw Skills for bulk security auditing.
  • Integration with CI/CD systems via machine-readable JSON formatting for automated gatekeeping.
  • Real-time updates based on ClawHavoc campaign indicators provided by security researchers at Koi Security.
  • Multi-platform support ensuring consistent security scanning on Darwin, Linux, and Win32 environments.
  • Flexible output formatting including colored console logs for humans and Markdown for Openclaw Skills documentation.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*