A runtime security shell that hardens AI agents against prompt injection, data exfiltration, and unauthorized operations.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install eridian
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install eridian using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Carapace, also known as Pistolclaw, acts as a hardened outer shell for your AI agents, providing a critical layer of defense that complements pre-installation scanners. While other tools check skills before they are added, Carapace reinforces the agent's behavior at runtime to ensure it can identify and block malicious intent from external content. It is designed to prevent scenarios like the ClawHavoc incident by strictly governing how agents handle sensitive data and configuration changes.
This skill is indispensable for developers building robust Openclaw Skills that need to interact with untrusted web content or manage sensitive credentials. By implementing these security patterns, you ensure your agent remains under your control and protects your private information from sophisticated injection attacks and exfiltration attempts.
To secure your Openclaw Skills, follow these implementation steps:
security/browser-allowlist.json to define trusted domains:{
"allowlist": [
"docs.openclaw.ai",
"github.com"
],
"requireApproval": true
}
Carapace uses a structured approach to manage security policies and audit trails across these key files:
| File Path | Description | Format |
|---|---|---|
security/browser-allowlist.json |
Defines trusted domains and navigation requirements | JSON |
references/security-patterns.md |
Reusable markdown snippets for agent instruction hardening | Markdown |
references/audit-template.md |
A standardized checklist for evaluating agent security posture | Markdown |
AGENTS.md |
The primary configuration file where runtime rules are enforced | Markdown |
Loading
A comprehensive security hardening layer that protects OpenClaw agents from prompt injection, data exfiltration, and unauthorized operations at runtime.

Automate the creation of professional social media carousel posts from text, articles, or social media threads using AI.

A comprehensive toolkit for Indian language processing including speech-to-text, text-to-speech, translation, and chat capabilities.

A professional Node.js client and CLI tool for querying, analyzing, and exporting energy data from iammeter smart meters via their official API.

A powerful CLI-based skill to manage Home Assistant entities, services, and automations with a built-in multi-level safety system.

A powerful AI image generation skill integrating Midjourney, Flux, and video creation via a streamlined API wrapper.








































