A comprehensive security framework designed to protect OpenClaw agents from supply chain attacks, malicious skills, and unauthorized file modifications.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install openclaw-defender
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install openclaw-defender using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
OpenClaw Defender is a robust security layer for the OpenClaw ecosystem, specifically engineered to mitigate risks identified in recent AI security research like ToxicSkills. It addresses critical vulnerabilities including prompt injection, credential theft, and memory poisoning by implementing a zero-trust model for skill installation and execution. By integrating this skill, developers ensure their Openclaw Skills operate within a hardened environment where every file change, network request, and command execution is monitored and validated against a secure baseline.
The framework provides a multi-layered defense strategy, ranging from pre-installation auditing to real-time runtime protection. It is designed for developers who need to maintain high-integrity agents while navigating a landscape of potentially malicious third-party contributions. By automating the detection of obfuscated code and unauthorized modifications to core agent files like SOUL.md and MEMORY.md, OpenClaw Defender maintains the operational safety of your Openclaw Skills.
To secure your Openclaw Skills, first establish the initial security baseline for your workspace:
cd ~/.openclaw/workspace
./skills/openclaw-defender/scripts/generate-baseline.sh
Enable automated monitoring by adding the integrity check to your crontab:
crontab -e
# Add the following line to check every 10 minutes:
*/10 * * * * ~/.openclaw/workspace/bin/check-integrity.sh >> ~/.openclaw/logs/integrity.log 2>&1
Verify that the protection is active by running a manual integrity check:
~/.openclaw/workspace/bin/check-integrity.sh
OpenClaw Defender organizes its security data and metadata using the following structure:
| Directory/File | Purpose | Format |
|---|---|---|
.integrity/ |
Stores SHA256 baselines and the master manifest for file monitoring. | Binary/Text |
logs/runtime-security.jsonl |
Structured stream of security events and runtime interceptions. | JSON Lines |
memory/security-incidents.md |
Human-readable log of detected threats and policy violations. | Markdown |
references/blocklist.conf |
Single source of truth for blocked authors, skills, and infrastructure. | Config |
memory/security-report-*.md |
Automated daily and weekly analysis reports for Openclaw Skills. | Markdown |
Loading
An autonomous economic AI entity that earns Bitcoin and Solana by selling storage, compute, and bandwidth while managing its own hosting and replication.

A powerful CLI tool to batch export Feishu documents and folders into clean Markdown or PDF files while maintaining original hierarchy.

A powerful utility for consolidating data from multiple Feishu Bitable sources into a single target table with field mapping and deduplication.

A powerful automation tool for Feishu that handles incoming messages using custom keyword and regex matching rules.

Automate X (Twitter) content creation and posting via browser automation to bypass expensive API fees.

A professional cognitive writing assistant that deconstructs complex phenomena into deep business logic and impactful aphorisms.








































