SecureClaw for Openclaw

A comprehensive security and auditing framework designed to protect AI agents from prompt injections, data leaks, and unauthorized commands.

adversa-ai
v2.2.0
Feb 20, 2026
4
3.2k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install secureclaw-skill

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install secureclaw-skill using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is SecureClaw?

SecureClaw is a robust security skill designed for Openclaw Skills that aligns with industry-leading frameworks like OWASP ASI Top 10, MITRE ATLAS, and NIST AI 100-2. It establishes a set of 15 core rules that govern agent behavior, ensuring that external content is treated as hostile and sensitive operations require explicit human approval. By integrating this skill, developers can fortify their agents against complex threats such as memory poisoning and credential harvesting.

The skill provides a suite of automated scripts for privacy checking, skill scanning, and daily security audits. It acts as a cognitive safety net, monitoring file integrity and identifying dangerous tool chains where sensitive data might be leaked. With SecureClaw, Openclaw Skills become significantly more resilient in production environments, providing peace of mind through transparent reasoning and emergency kill switches.

SecureClaw Use Cases

  • Auditing external content for hidden prompt injection instructions.
  • Preventing accidental exposure of API keys and credentials in public logs.
  • Scanning third-party plugins or MCP servers for malicious patterns before installation.
  • Running daily security audits to identify critical infrastructure vulnerabilities.
  • Enforcing human-in-the-loop approvals for destructive terminal commands.
  • Detecting and responding to suspected agent compromises using emergency protocols.

How SecureClaw Works

  1. The agent evaluates every external input against a zero-trust model to detect malicious instructions.
  2. Sensitive commands are intercepted, requiring the agent to present a clear justification and impact report to the human user.
  3. Automated scripts perform periodic integrity checks on core identity and configuration files.
  4. Privacy filters scan all outgoing communications to redact personally identifiable information (PII).
  5. In the event of a suspected breach, the emergency response protocol triggers to suspend operations and alert the owner.

SecureClaw Setup

Direct Script Usage

Ensure you replace SKILL_DIR with your actual installation path (e.g., ~/.openclaw/skills/secureclaw).

# Run a quick security audit
bash SKILL_DIR/scripts/quick-audit.sh

# Scan a new skill before installation
bash SKILL_DIR/scripts/scan-skills.sh [path-to-skill]

Plugin Integration

If using the SecureClaw plugin, use the simplified CLI for Openclaw Skills management:

npx openclaw secureclaw audit
npx openclaw secureclaw harden
npx openclaw secureclaw emergency

SecureClaw Data Schema & Taxonomy

Component Description
~/.openclaw/.secureclaw/killswitch A trigger file that stops all agent operations immediately when present.
scripts/check-privacy.sh Logic for identifying PII and sensitive infrastructure details in drafts.
SECURITY.md Core framework mapping and rule definitions for the agent's logic.
SOUL.md / IDENTITY.md Monitored files used for cognitive integrity checks to prevent poisoning.

SecureClaw Advanced Features

  • Multi-framework alignment with NIST AI 100-2, MITRE ATLAS, and CSA MAESTRO.
  • Automated cognitive file integrity monitoring every 12 hours.
  • Dangerous tool-chain detection to prevent data exfiltration patterns.
  • Physical kill switch mechanism for immediate suspension of all agent actions.
  • Reasoning telemetry that forces agents to log plans before multi-step operations.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*