PromptDome for Openclaw

A security integration for OpenClaw that provides automated screening against prompt injections, jailbreaks, and PII exfiltration.

tschew72
v1.3.1
Feb 26, 2026
1
990
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install promptdome

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install promptdome using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is PromptDome?

PromptDome is a specialized security layer designed to protect AI agents from malicious inputs. By incorporating these Openclaw Skills into your environment, you establish a proactive defense mechanism that scans every incoming message before it reaches your LLM. It functions as both a transparent gateway hook and an explicit tool that agents can use to verify untrusted content from external sources.

The integration ensures that your AI remains within its operational boundaries by identifying and neutralizing threats like system prompt overrides, social engineering, and data leaks. Whether you are running a customer-facing bot or a private research assistant, these Openclaw Skills provide the necessary hardening to prevent common LLM vulnerabilities.

PromptDome Use Cases

  • Automating the detection of prompt injection and jailbreak attempts in real-time.
  • Protecting sensitive information by screening for PII and credential exfiltration.
  • Hardening Openclaw Skills against social engineering and fake system events.
  • Scanning web search results or uploaded files for hidden malicious instructions before processing.

How PromptDome Works

  1. The promptdome-gate hook intercepts every message received by the OpenClaw gateway.
  2. The content is sent to the PromptDome engine, which analyzes it across 32 distinct attack categories.
  3. A security score is generated; scores of 70 or higher trigger an immediate block warning in the conversation.
  4. Moderate risks (scores between 40 and 69) result in a soft warning being injected to alert the agent and user.
  5. The promptdome_scan tool allows agents to manually trigger scans on specific data buffers, such as file contents or API responses.

PromptDome Setup

Quick Setup

Run the following command to install the necessary hooks and plugins automatically:

bash skills/promptdome/scripts/setup.sh --api-key sk_shield_live_YOUR_KEY

Manual Installation

  1. Copy the hook files to ~/.openclaw/hooks/promptdome-gate/.
  2. Copy the plugin files to ~/.openclaw/extensions/promptdome/.
  3. Add your API key to the openclaw.json environment block:
{
  "env": {
    "PROMPTDOME_API_KEY": "your_key_here"
  }
}
  1. Enable the hook using openclaw hooks enable promptdome-gate and restart the gateway.

PromptDome Data Schema & Taxonomy

The skill manages security configuration and logging through the following structures:

Data Point Location / Format Description
API Key PROMPTDOME_API_KEY Environment variable for authentication
Scan Logs ~/.openclaw/logs/promptdome-gate.log Local record of all scan results and scores
Hook State openclaw.json Configuration for active hooks and tools
Block Threshold JSON Value (70) The score at which a message is considered a high-risk injection

PromptDome Advanced Features

  • Self-hosted API support by overriding the PROMPTDOME_API_URL environment variable.
  • Fail-open architecture ensures that agent availability is maintained even if the security API is unreachable.
  • Multilingual evasion detection covering 18 different languages.
  • Comprehensive coverage for 32 attack categories, including HTML/DOM injection and agentic chain poisoning.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*