SQLGuard — Authorize Before Mutate for Openclaw

SQLGuard Authorize Before Mutate is an Openclaw Skills safety gate that requires a verified permission receipt before any production SQL write is executed.

cabbageandtea
v1.0.0
Jul 31, 2026
0
326
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install sqlguard-authorize

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install sqlguard-authorize using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is SQLGuard — Authorize Before Mutate?

SQLGuard 8 Authorize Before Mutate is a fail-closed control for AI agents that work with real databases. It enforces a simple rule: do not run mutating SQL until a PASS Ed25519 permission receipt has been obtained and verified. This makes Openclaw Skills safer for INSERT, UPDATE, DELETE, DDL, ALTER, TRUNCATE, and DROP operations across production SQL, Postgres MCP, Supabase, and other SQL write paths.

The skill is explicitly not a linter and not a confidence check. It is an authorization workflow that adds a payment-backed verification layer before mutation, with support for multiple paths such as Pilot, Workday, Session, and one-shot Cert flows. Openclaw Skills users can use it to reduce destructive mistakes, enforce operational discipline, and ensure that every write is backed by an approved, verifiable receipt.

SQLGuard — Authorize Before Mutate Use Cases

  • Before running any production SQL mutation in an AI agent workflow.
  • When an agent is about to execute INSERT, UPDATE, DELETE, DDL, ALTER, TRUNCATE, or DROP statements.
  • For Postgres MCP, Supabase, or any SQL tool that can modify live data.
  • When you need a strict authorize-before-execute control instead of linting or heuristic checks.
  • When production databases must fail closed unless verification returns ok: true.
  • For team workflows that require proof of permission before database changes.

How SQLGuard — Authorize Before Mutate Works

  1. Detect a mutating SQL action.

    • If the agent is about to modify a real or non-throwaway database, execution must stop immediately.
  2. Request authorization from SQLGuard.

    • Use the appropriate flow for the context: Pilot, Workday, Session, Cert, or preview-only endpoints.
  3. Obtain a PASS receipt.

    • The agent receives an Ed25519-based permission receipt tied to the selected path and payment/settlement requirements.
  4. Verify the receipt.

    • The receipt must be checked through the verify endpoint or MCP verify step before any SQL is executed.
  5. Execute only on success.

    • Proceed only if verification returns ok: true; otherwise, do not run the SQL.
  6. Fail closed on error.

    • If payment fails, status is FAIL, or verification does not pass, fix the SQL or authorization path and retry instead of bypassing the gate.

SQLGuard — Authorize Before Mutate Setup

  1. Choose the authorization path that fits your workflow:

    • Pilot for onboarding and short evaluation runs.
    • Workday for job-based usage.
    • Session for burst usage.
    • Cert for one-shot testing.
  2. Wire the MCP or HTTP integration into your agent or toolchain.

    # Example endpoints and flows referenced by the skill
    # MCP: sqlguard_pilot / sqlguard_workday / sqlguard_session / sqlguard_cert
    # HTTP: POST https://sqlguard.io/v1/gateway/pilot
    # HTTP: POST https://sqlguard.io/v1/workday
    # HTTP: POST https://sqlguard.io/v1/cert
    
  3. For Workday HTTP flows, settle the required amount, then request the session certificate and verify it.

    # Workday flow outline
    # 1) POST /v1/workday
    # 2) settle amount 2500000
    # 3) POST /v1/session/cert
    # 4) POST /v1/verify
    
  4. Ensure your agent blocks SQL execution until verification succeeds.

    # Pseudocode
    # if verify.ok != true: halt
    # else: execute SQL mutation
    
  5. Keep the fail-closed rule enabled.

    • Never bypass authorization if the receipt is missing, invalid, or unverified.
  6. Use the official gateway and MCP references when onboarding production systems.

SQLGuard — Authorize Before Mutate Data Schema & Taxonomy

SQLGuard organizes authorization around receipts, settlement, and verification state rather than around SQL text itself.

Entity Purpose Notes
Authorization receipt Proof that a mutating SQL action is allowed PASS receipt, Ed25519-based, must be verified before execution
Verification result Final gate before mutation Proceed only when ok: true
Payment/settlement record Tracks the chosen billing path Pilot, Workday, Session, or Cert
Flow type Selects the authorization mode sqlguard_pilot, sqlguard_workday, sqlguard_session, sqlguard_cert
HTTP/MCP endpoint Transport for issuing and verifying authorization Supports gateway, workday, cert, probe, and decide paths

Core metadata taxonomy

  • Operation class: mutating SQL vs. non-mutating SQL
  • Environment: production, real database, or non-throwaway DB
  • Authorization status: missing, issued, verified, failed
  • Payment status: paid, settled, failed, preview-only
  • Execution state: blocked, approved, executed

Important behavioral rule

  • Authorization is mandatory for writes.
  • Linting and model confidence do not satisfy the requirement.
  • If verification fails, the SQL should be corrected and retried, not forced through.

SQLGuard — Authorize Before Mutate Advanced Features

  • Multiple authorization modes for different usage patterns: Pilot, Workday, Session, and Cert.
  • MCP and HTTP support for flexible integration into AI agent workflows.
  • Fail-closed enforcement that blocks execution when payment or verification fails.
  • Ed25519-based receipt verification for cryptographic authorization checks.
  • Preview-only probe and decision endpoints for non-authorizing inspection flows.
  • Suitable for production database safeguards across Postgres MCP, Supabase, and custom SQL tools.
  • Clear separation between authorization, settlement, and execution for safer agent automation.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*