Hook Guard for Openclaw

Hook Guard is a comprehensive security and safety layer for AI agents that provides real-time operation monitoring, automated file backups, and risk-based command interception.

wavmson
v1.0.0
Apr 2, 2026
0
742
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install hook-guard

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install hook-guard using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Hook Guard?

Hook Guard serves as a vital safety net for Openclaw Skills, ensuring that every action taken by an AI agent is audited and protected. By implementing a three-tier hook system (Red, Yellow, and Green), it balances high-security requirements with seamless productivity. It acts as a middleware that watches over file modifications, system commands, and external communications to prevent irreversible mistakes or unauthorized actions.

This skill is particularly essential for developers managing complex environments where agents have significant tool permissions. Whether it is preventing a catastrophic rm -rf command or keeping a history of configuration changes, Hook Guard ensures that the power of AI automation is always coupled with professional-grade safety protocols.

Hook Guard Use Cases

  • Enforcing a default safety mode for all agent interactions within Openclaw Skills.
  • Intercepting high-risk system commands like sudo, docker prune, or service shutdowns for manual confirmation.
  • Automatically backing up critical configuration files such as .env or nginx.conf before an agent applies edits.
  • Maintaining a tamper-evident audit log of all file reads, searches, and network activities.
  • Protecting production environments by requiring explicit user approval for any external messaging or deployment actions.

How Hook Guard Works

  1. Operation Classification: Every requested action is analyzed and categorized into Red (Dangerous), Yellow (Sensitive), or Green (Routine) levels.
  2. Pre-hook Interception (Red): For high-risk tasks, the system halts execution and generates a detailed risk report, waiting for the user to reply with "continue" or "cancel."
  3. Guard Execution (Yellow): For sensitive modifications, the system creates a timestamped backup in a dedicated directory before allowing the operation to proceed.
  4. Post-hook Notification: After Yellow operations, the user is notified of the specific changes made and the location of the backup file.
  5. Audit Logging (Green): Routine operations are recorded asynchronously to an audit log to maintain a complete history without impacting performance.
  6. Maintenance: The system automatically rotates backups and logs to manage disk space, keeping only the most recent data.

Hook Guard Setup

To enable Hook Guard as a permanent security rule for your agents, add the following configuration to your AGENTS.md file:

## Security Rules (Hook Guard)
- Check impact scope before executing rm/trash; confirmation required for >5 files.
- Auto-backup config files to .hook-guard/backups/ before modification.
- Sudo commands must be confirmed by the user.
- Confirm recipient and content before sending external messages.
- Prefer trash over rm for recoverability.

You can also trigger it manually by telling the agent "enable safety mode" or "hook guard."

Hook Guard Data Schema & Taxonomy

Hook Guard organizes its data within the workspace directory using a structured taxonomy for backups and auditing:

Type Path Retention
Backups ~/.openclaw/workspace-main/.hook-guard/backups/YYYY-MM-DD/ 7 Days
Audit Logs ~/.openclaw/workspace-main/.hook-guard/audit.log 30 Days
File Naming {original_name}.{HHmmss}.bak N/A

Logs use a standard format: [Timestamp] ACTION /path/to/resource.

Hook Guard Advanced Features

  • Granular Escalation: Users can customize security levels, promoting specific Yellow actions to Red for mandatory confirmation.
  • Guard Reports: Generate on-demand statistical summaries of interceptions, backups, and logs by asking for a "guard report."
  • Multi-Agent Protection: Fully compatible with Swarm Coord, ensuring sub-agents are also bound by the same safety hooks.
  • Non-Bypassable Hooks: Red Hook protections cannot be disabled through conversational prompts, ensuring permanent safety for critical operations.
  • Intelligent Recovery: Seamlessly integrates with Session Resume to maintain the state of intercepted operations across different sessions.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*