OpenClaw Defender for Openclaw

A comprehensive security framework designed to protect OpenClaw agents from supply chain attacks, malicious skills, and unauthorized file modifications.

nightfullstar
v0.1.0
Feb 8, 2026
2
1.6k
5

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install openclaw-defender

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install openclaw-defender using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is OpenClaw Defender?

OpenClaw Defender is a robust security layer for the OpenClaw ecosystem, specifically engineered to mitigate risks identified in recent AI security research like ToxicSkills. It addresses critical vulnerabilities including prompt injection, credential theft, and memory poisoning by implementing a zero-trust model for skill installation and execution. By integrating this skill, developers ensure their Openclaw Skills operate within a hardened environment where every file change, network request, and command execution is monitored and validated against a secure baseline.

The framework provides a multi-layered defense strategy, ranging from pre-installation auditing to real-time runtime protection. It is designed for developers who need to maintain high-integrity agents while navigating a landscape of potentially malicious third-party contributions. By automating the detection of obfuscated code and unauthorized modifications to core agent files like SOUL.md and MEMORY.md, OpenClaw Defender maintains the operational safety of your Openclaw Skills.

OpenClaw Defender Use Cases

  • Protecting agent memory and identity files from unauthorized poisoning or tampering.
  • Auditing third-party Openclaw Skills before installation to detect obfuscated malware and credential theft patterns.
  • Implementing an emergency kill switch to immediately halt all agent operations during a detected security breach.
  • Monitoring real-time network requests and system command executions for suspicious activity.
  • Generating daily forensic security reports and incident logs for compliance and auditing.

How OpenClaw Defender Works

  1. The system establishes a cryptographic baseline of all critical agent files using SHA256 hashes to create a secure manifest.
  2. A background cron job executes scheduled integrity checks to detect any unauthorized modifications to the core identity or workspace files.
  3. New Openclaw Skills are audited against a curated blocklist of known malicious actors and infrastructure before they are permitted to run.
  4. During execution, the runtime monitor intercepts network calls, file access requests, and RAG operations to enforce strict security policies.
  5. If a threat is detected, the framework can automatically trigger a kill switch or quarantine the suspicious skill while logging the incident for human review.
  6. Security event analysis tools parse structured JSON logs to identify complex attack patterns such as multi-skill collusion.

OpenClaw Defender Setup

To secure your Openclaw Skills, first establish the initial security baseline for your workspace:

cd ~/.openclaw/workspace
./skills/openclaw-defender/scripts/generate-baseline.sh

Enable automated monitoring by adding the integrity check to your crontab:

crontab -e
# Add the following line to check every 10 minutes:
*/10 * * * * ~/.openclaw/workspace/bin/check-integrity.sh >> ~/.openclaw/logs/integrity.log 2>&1

Verify that the protection is active by running a manual integrity check:

~/.openclaw/workspace/bin/check-integrity.sh

OpenClaw Defender Data Schema & Taxonomy

OpenClaw Defender organizes its security data and metadata using the following structure:

Directory/File Purpose Format
.integrity/ Stores SHA256 baselines and the master manifest for file monitoring. Binary/Text
logs/runtime-security.jsonl Structured stream of security events and runtime interceptions. JSON Lines
memory/security-incidents.md Human-readable log of detected threats and policy violations. Markdown
references/blocklist.conf Single source of truth for blocked authors, skills, and infrastructure. Config
memory/security-report-*.md Automated daily and weekly analysis reports for Openclaw Skills. Markdown

OpenClaw Defender Advanced Features

  • Collusion Detection: Monitors concurrent execution to detect Sybil networks or multi-skill coordination attacks.
  • Emergency Kill Switch: Provides a manual and automated mechanism to shut down all agent operations during active threats.
  • Quarantine System: Isolates compromised or suspicious Openclaw Skills by moving them to a restricted state.
  • Protected Configuration: Uses file integrity monitoring to prevent skills from tampering with their own security whitelists.
  • Author Reputation Verification: Automatically checks GitHub account age and contributor history during skill audits.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*