ClawProof Security for Openclaw

A comprehensive security scanner designed to protect OpenClaw agents from malicious skills, hallucinated packages, and prompt injection attacks.

sinewaveai
v3.10.3
Feb 22, 2026
0
1.1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install clawproof-security

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install clawproof-security using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is ClawProof Security?

ClawProof Security provides a robust defense layer for autonomous AI agents. As Openclaw Skills can execute code and manage dependencies, they introduce unique risks such as supply chain attacks and data exfiltration. This tool acts as a gatekeeper, analyzing every action before execution.

By integrating deep skill scanning and real-time behavioral analysis, it ensures that your Openclaw Skills remain safe and compliant with enterprise security standards. It specifically targets threats like the ClawHavoc malware and prevents the common LLM issue of package name hallucination.

ClawProof Security Use Cases

  • Scan third-party Openclaw Skills before installation to identify hidden malware, backdoors, or crypto miners.
  • Verify package names suggested by LLMs to prevent installing hallucinated or malicious dependencies that don't exist in official registries.
  • Block prompt injection attempts that try to bypass safety rules or exfiltrate sensitive data via webhooks.
  • Integrate security audits into CI/CD pipelines to ensure all AI-generated code is free from vulnerabilities like SQL injection or XSS.

How ClawProof Security Works

  1. The user triggers a scan request through the CLI or an integrated MCP server for a specific skill, code file, or action.
  2. ClawProof performs a 6-layer deep scan, covering malware signatures, prompt injection patterns, and AST-based code analysis.
  3. The tool verifies package existence against a massive database of 4.3 million verified registry entries to catch AI hallucinations.
  4. A security grade from A to F is generated, along with specific recommendations to allow, warn, or block the action based on 1700+ security rules.
  5. For identified vulnerabilities in code, the tool can optionally apply one of 165 auto-fix templates to secure the file automatically.

ClawProof Security Setup

To secure your environment for Openclaw Skills, install the scanner globally using npm:

npm install -g agent-security-scanner-mcp

To initialize the MCP server for automatic protection in your AI-powered IDE (like Cursor or Claude Code), run:

npx agent-security-scanner-mcp init openclaw

You can also verify the installation by running the doctor command:

npx agent-security-scanner-mcp doctor

ClawProof Security Data Schema & Taxonomy

ClawProof organizes its security intelligence using several metadata layers and export formats to ensure transparency and compatibility:

Component Description
Threat Rules 1700+ security rules covering 12 programming languages including Python and JS
Malware Signatures 121 specific patterns targeting the ClawHavoc malware family and OpenClaw exfiltration
Package Registry A verified local cache of 4.3M+ packages from npm, PyPI, Go, and Ruby
SARIF Output Standardized JSON format for integration with enterprise security tabs in GitHub or GitLab

ClawProof Security Advanced Features

  • Automated Git hooks to scan code diffs and Openclaw Skills before every commit.
  • Real-time pre-execution interception that blocks dangerous bash commands like destructive file system operations.
  • 165 built-in security fix templates for automatic vulnerability remediation in generated code.
  • Multi-language support covering 12 different environments including Docker, Kubernetes, and Terraform.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Bins npx
Github Stars: 0
forks: 0

Featured*