Carapace Runtime Security for Openclaw

A runtime security shell that hardens AI agents against prompt injection, data exfiltration, and unauthorized operations.

iampaulpatterson-boop
v1.0.0
Feb 13, 2026
0
1.8k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install eridian

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install eridian using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Carapace Runtime Security?

Carapace, also known as Pistolclaw, acts as a hardened outer shell for your AI agents, providing a critical layer of defense that complements pre-installation scanners. While other tools check skills before they are added, Carapace reinforces the agent's behavior at runtime to ensure it can identify and block malicious intent from external content. It is designed to prevent scenarios like the ClawHavoc incident by strictly governing how agents handle sensitive data and configuration changes.

This skill is indispensable for developers building robust Openclaw Skills that need to interact with untrusted web content or manage sensitive credentials. By implementing these security patterns, you ensure your agent remains under your control and protects your private information from sophisticated injection attacks and exfiltration attempts.

Carapace Runtime Security Use Cases

  • Protecting agents from indirect prompt injection when browsing untrusted websites or processing external emails.
  • Preventing accidental credential leaks and unauthorized access to environment variables or secret keys.
  • Implementing a secure 'Ask-Before-Executing' workflow for sensitive CLI commands or file operations.
  • Hardening agent configurations to prevent malicious skills from hijacking authentication settings.
  • Establishing a browser allowlist to restrict agent navigation to verified and safe domains.

How Carapace Runtime Security Works

  1. The agent core instructions are updated with security patterns from Carapace to prioritize safety over external suggestions.
  2. When processing external content, the agent treats all instructions as untrusted and flags potential takeover red flags.
  3. Every sensitive operation, such as writing files or sending data to external APIs, triggers a mandatory approval flow.
  4. Access to restricted files like .env or config files is blocked by default, even if requested via a complex prompt injection.
  5. The agent consults a browser allowlist before navigating to any new URL, ensuring a secure perimeter for Openclaw Skills.

Carapace Runtime Security Setup

To secure your Openclaw Skills, follow these implementation steps:

  1. Copy the security rules from the provided security patterns into your AGENTS.md file, placing them at the top for maximum priority.
  2. Create a browser allowlist in your workspace at security/browser-allowlist.json to define trusted domains:
{
  "allowlist": [
    "docs.openclaw.ai",
    "github.com"
  ],
  "requireApproval": true
}
  1. Perform an initial security audit using the provided audit template checklist to verify your agent's defensive posture.

Carapace Runtime Security Data Schema & Taxonomy

Carapace uses a structured approach to manage security policies and audit trails across these key files:

File Path Description Format
security/browser-allowlist.json Defines trusted domains and navigation requirements JSON
references/security-patterns.md Reusable markdown snippets for agent instruction hardening Markdown
references/audit-template.md A standardized checklist for evaluating agent security posture Markdown
AGENTS.md The primary configuration file where runtime rules are enforced Markdown

Carapace Runtime Security Advanced Features

  • Integrated Anti-Takeover defense specifically designed to neutralize indirect prompt injection attacks from web content.
  • Automated Data Exfiltration Prevention that blocks sensitive file sharing across non-approved channels.
  • Granular File Access Restrictions that hardcode forbidden zones for sensitive files like .env and .git config.
  • Multi-step Sensitive Operation Approval flows that require explicit human-in-the-loop confirmation for high-risk actions.
  • Comprehensive security audit templates to maintain long-term compliance for all your Openclaw Skills.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*