ClawShield is a specialized security utility that audits local OpenClaw installations for vulnerabilities and prompt injection patterns.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install clawshield
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install clawshield using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
ClawShield is an essential security layer designed to audit the posture of local OpenClaw environments. It serves as a comprehensive detector for prompt injection (PI) patterns, gateway vulnerabilities, and unauthorized cron modifications. By providing a structured way to monitor and harden your AI setups, it ensures that your automated workflows remain secure and resilient against malicious inputs. As a standout entry among Openclaw Skills, it focuses on local-only scanning to maintain data privacy while providing actionable security insights.
The tool is designed for developers and system administrators who need to frenzy-proof their installs. Whether you are running a single agent or a complex multi-agent system, ClawShield offers the peace of mind required to deploy AI solutions in production-like environments without exposing hidden vulnerabilities.
To integrate this security tool into your collection of Openclaw Skills, follow these steps:
1. Launch the Management Panel
node scripts/panel-server.js
Navigate to http://localhost:8133 to manage scans and view logs.
2. Configure Scan Parameters Adjust your sensitivity and alert settings via the CLI:
node scripts/config.js set Scan_freq daily alerts telegram sensitivity high
3. Execute a Manual Security Audit Run the audit script to generate an immediate report:
bash scripts/audit.sh > report.json
ClawShield organizes its security data and configurations into a predictable file structure to support easy integration with other Openclaw Skills.
| Data Component | Location | Description |
|---|---|---|
| Configuration | config.yaml |
Stores user-defined settings for frequency, alerts, and sensitivity. |
| Audit Reports | logs/last-report.json |
The most recent security scan results in a structured JSON format. |
| Audit Logic | scripts/audit.sh |
The core bash script responsible for scanning the local environment. |
| UI State | scripts/panel-server.js |
Manages the local web server for the security dashboard. |
Loading
Query live data from the Renzo liquid restaking protocol, including ezETH metrics, vault performance, and user portfolio balances.

A compliance-focused tool for capturing and verifying tamper-proof TCPA consent sessions during the lead generation process.

ClawShell provides a robust security layer for Openclaw Skills by intercepting shell commands and requiring manual human approval for high-risk operations.

A standardized framework for AI agents to track and guide humans through complex, multi-day real-world processes.

A specialized security auditing tool designed to detect prompt injection patterns and audit the security posture of local agent environments.

A professional B2B intelligence skill for company firmographics, validated contact discovery, and account list management.








































