GoPlus AgentGuard for Openclaw

An AI agent security framework that automatically blocks dangerous commands, prevents data exfiltration, and audits skills for vulnerabilities.

0xbeekeeper
v1.1.0
Mar 10, 2026
4
4.8k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install goplus-agentguard

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install goplus-agentguard using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is GoPlus AgentGuard?

GoPlus AgentGuard serves as a comprehensive security layer designed specifically for AI coding agents and the Openclaw Skills ecosystem. It acts as both an automated security auditor and a runtime guard, ensuring that AI-driven operations do not lead to system compromise, sensitive data leakage, or unauthorized financial transactions. By intercepting shell commands, network requests, and file system interactions, it provides a robust defense against both accidental errors and malicious prompt injection attacks.

The framework operates by evaluating actions against a sophisticated set of detection rules and a trust registry. It enables developers to run agents with confidence, knowing that a security-first layer is monitoring for patterns such as shell injection, hardcoded private keys, and suspicious network exfiltration. Whether you are reviewing third-party code or automating complex workflows, GoPlus AgentGuard provides the transparency and control needed to maintain a secure development environment.

GoPlus AgentGuard Use Cases

  • Auditing third-party Openclaw Skills for hidden backdoors, prompt injection, or malicious code before execution.
  • Preventing the accidental execution of destructive shell commands or unauthorized system modifications during autonomous agent sessions.
  • Protecting sensitive environment variables, SSH keys, and system keychains from being accessed or exfiltrated to remote servers.
  • Running automated daily security patrols to detect configuration drift, unauthorized file changes, or dangerous network exposure.
  • Evaluating Web3 transactions and message signing requests to identify wallet-draining patterns and high-risk contract interactions.

How GoPlus AgentGuard Works

  1. The skill analyzes the target codebase or environment using 24+ specialized detection rules to identify critical security risks and vulnerabilities.
  2. At runtime, the framework intercepts agent actions such as command execution and network requests, evaluating them against the current protection level.
  3. It references a local trust registry to determine the specific capabilities and permissions granted to the initiating skill.
  4. For Web3 operations, the system integrates with the GoPlus API to perform transaction simulation and identify malicious addresses in real-time.
  5. Based on the risk assessment, the framework makes an automated decision to allow, deny, or require manual user confirmation for the action.
  6. Every security event, decision, and risk tag is recorded in a centralized audit log for forensic analysis and reporting.

GoPlus AgentGuard Setup

To get started with this security framework for your Openclaw Skills, ensure you have Node.js 18+ installed. Follow these steps for installation:

# Navigate to the skill directory
cd skills/agentguard/scripts

# Install necessary dependencies
npm install

# (Optional) Configure environment variables for Web3 simulation
export GOPLUS_API_KEY="your_api_key"
export GOPLUS_API_SECRET="your_api_secret"

# Set your desired protection level (strict, balanced, or permissive)
/agentguard config balanced

GoPlus AgentGuard Data Schema & Taxonomy

The skill organizes security data and configuration across several key files to maintain a clear audit trail and policy structure:

File Path Description Format
~/.agentguard/audit.jsonl A continuous log of all security events, intercepted actions, and decisions. JSONL
~/.agentguard/config.json Stores global settings, including the active protection level (Strict/Balanced/Permissive). JSON
data/registry.json The trust registry mapping skill identities to their attested hashes and specific capability allowlists. JSON
scan-rules.md Contains the regex patterns and logic used for codebase vulnerability scanning. Markdown
action-policies.md Defines the logic for runtime decision-making across network, exec, and file IO. Markdown

GoPlus AgentGuard Advanced Features

  • OpenClaw-specific security patrol involving 8 automated checks for integrity, secrets exposure, and network misconfigurations.
  • Capability-based security model that allows granular allowlisting of domains, file paths, and environment variables on a per-skill basis.
  • Proactive integrity monitoring that detects tampered or unregistered skill packages by comparing file hashes against the trust registry.
  • Automated audit log analysis that identifies attack patterns, such as repeated denials or high-risk exfiltration attempts.
  • Configurable protection levels that allow users to balance between high-friction security and seamless developer experience.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*