Claim this agent
agentCLAWHUBUnverified

Agentshield Audit

Privacy-First security audit with 77 local tests (52 live + 25 static). Works with OpenClaw, Hermes Agent, n8n (auto-detected), LangChain, and any AI agent p... Skill: Agentshield Audit Owner: bartelmost Summary: Privacy-First security audit with 77 local tests (52 live + 25 static). Works with OpenClaw, Hermes Agent, n8n (auto-detected), LangChain, and any AI agent p... Tags: agent-security:1.0.2, agents:1.0.3, ai-safety:1.0.3, api-security:1.0.3, audit:1.0.4, certificates:1.0.4, code-scan:1.0.1, compliance:1.0.3, cryptography:1.0.4, ed25519:1.0.3, eu-ai-act:1.0.3, human-in

OpenClaw

Rank

62

Safety

84

Downloads

2.9k

Updated

Oct 9, 2026

Version

1.0.36

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2.9K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2.9K downloadsadoption · observed Oct 9, 2026
Latest release
1.0.36release · observed Jun 18, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s1709g2t9ptwbe5z1grvhq0ak583gvmb:agentshield-audit
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-bartelmost-agentshield-audit/snapshot"

Documentation

CLAWHUB

160,000 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: agentshield
version: 1.0.36
description: Privacy-First security audit with 77 local tests (52 live + 25 static). Works with OpenClaw, Hermes Agent, n8n (auto-detected), LangChain, and any AI agent platform. Ed25519 private keys stay local. All scripts bundled.
triggers: ["audit my agent", "get security certificate", "verify agent", "activate AgentShield", "security audit", "trust handshake", "verify peer agent", "check agent security"]
---

# AgentShield - Trust Infrastructure for AI Agents

**The trust layer for the agent economy. Like SSL/TLS, but for AI agents.**

🔐 **Cryptographic Identity** - Ed25519 signing keys  
🤝 **Trust Handshake Protocol** - Mutual verification before communication  
📋 **Public Trust Registry** - Reputation scores & track records  
✅ **77 Security Tests** - Comprehensive vulnerability assessment

**🔒 Privacy Disclosure:** See [PRIVACY.md](PRIVACY.md) for detailed data handling information.

---

## 🌐 Framework Compatibility

AgentShield works with **any AI agent framework** — no adapter required.

| Framework | Status | Notes |
|-----------|--------|-------|
| **OpenClaw** | ✅ Full support | Auto-detects IDENTITY.md |
| **Hermes Agent** | ✅ Full support | Auto-detects `~/.hermes/` — see [HERMES.md](HERMES.md) |
| **n8n** | ✅ Auto-detected | Detects `~/.n8n/` |
| **LangChain** | ✅ Manual | `--name MyAgent --platform langchain` |
| **CLI / Custom** | ✅ Manual | `--name MyAgent --platform cli` |

Both OpenClaw and Hermes use the [agentskills.io](https://agentskills.io) open standard — skills install and run identically on both platforms.

---

## 🎯 The Problem

Agents need to communicate with other agents (API calls, data sharing, task delegation). But **how do you know if another agent is trustworthy?**

- Has it been compromised?
- Is it leaking data?
- Can you trust its responses?

Without a trust layer, agent-to-agent communication is like HTTP without SSL - **unsafe and unverifiable**.

---

## 💡 The Solution: Trust Infrastructure

AgentShield provides the **trust layer** for agent-to-agent communication:

### 1. Cryptographic Identity
- **Ed25519 key pairs** - Industry-standard cryptography
- **Private keys stay local** - Never transmitted
- **Public key certificates** - Signed by AgentShield

### 2. Security Audit (77 Tests)
**52 Live Attack Vectors:**
Tests defense against instruction manipulation, encoding schemes, and social engineering
across 6 languages. All attack patterns are stored locally in agentshield_attack_patterns.json
(not embedded in documentation).

**25 Static Security Checks:**
- Input sanitization
- Output DLP (data leak prevention)
- Tool sandboxing
- Secret scanning
- Supply chain security

**Result:** Security score (0-100) + Tier (VULNERABLE → HARDENED)

**Privacy:** Tests run 100% locally - only pass/fail scores sent to API (no prompts/responses)

### 3. Trust Handshake Protocol
**Agent A wants to communicate with Agent B:**

```bash
# Step 1: Both agents get certified
pyth

README.md

# AgentShield Audit - ClawHub Skill

🔒 **Audit your AI agent's security and obtain verifiable trust certificates for inter-agent communication.**

![AgentShield](https://img.shields.io/badge/AgentShield-Security%20Audit-blue)
![License](https://img.shields.io/badge/license-MIT-green)
![Python](https://img.shields.io/badge/python-3.8+-blue)
![OpenClaw](https://img.shields.io/badge/OpenClaw-✓-brightgreen)
![Hermes](https://img.shields.io/badge/Hermes_Agent-✓-brightgreen)

---

## What is AgentShield?

AgentShield is a **security audit framework** for AI agents. It tests your agent against common attack vectors, generates cryptographic identity certificates, and enables secure inter-agent communication through verifiable trust chains.

**Think of it as:** Let's Encrypt for AI Agents 🛡️

---

## 🌐 Framework Compatibility

Works out-of-the-box with both major open-source agent frameworks:

| Framework | Auto-Detection | Install |
|-----------|---------------|--------|
| **OpenClaw** | ✅ Detects `IDENTITY.md` | `clawhub install agentshield-audit` |
| **Hermes Agent** | ✅ Detects `~/.hermes/` | `clawhub install agentshield-audit` |
| **n8n** | ✅ Detects `~/.n8n/` | `clawhub install agentshield-audit` |
| **LangChain / Custom** | Manual `--name`/`--platform` | `clawhub install agentshield-audit` |

Both OpenClaw and Hermes use the [agentskills.io](https://agentskills.io) open standard — same install command, same workflow. → [Hermes Integration Guide](HERMES.md)

---

## 🚀 Quick Start

### Installation

```bash
clawhub install agentshield-audit
```

### Run Your First Audit

```bash
cd ~/.openclaw/workspace/skills/agentshield-audit
python initiate_audit.py --auto
```

That's it! Your agent will be audited in ~30 seconds and receive a signed certificate.

---

## ✨ Features

- ✅ **Zero external fetching** - All scripts bundled locally
- ✅ **Human-in-the-loop** - Explicit approval required before reading files
- ✅ **Cryptographic identity** - Ed25519 keypair generation with local private key storage
- ✅ **Security audit** - Tests against 5+ common attack vectors
- ✅ **Verifiable certificates** - 90-day validity, signed by AgentShield CA
- ✅ **Peer verification** - Verify other agents' certificates before trusting them
- ✅ **No API key required** - Free for basic usage (1 audit/hour rate limit)
- ✅ **Privacy-first** - Private keys NEVER leave your workspace

---

## 🧪 What Gets Tested?

Your agent is tested against these attack vectors:

| Test | Description | Risk Level |
|------|-------------|------------|
| **System Prompt Extraction** | Attempts to extract the agent's system prompt | High |
| **Instruction Override** | Tries to override safety instructions | Critical |
| **Tool Permission Check** | Verifies proper tool access controls | High |
| **Memory Isolation** | Tests for context leakage between sessions | Medium |
| **Secret Leakage** | Scans for exposed API keys, tokens, passwords | Critical |

**Your Security Score:** 0-100 based on passed

_meta.json

{
  "ownerId": "kn73jtt46447jgj4n2xsd8yeqh81h681",
  "slug": "agentshield-audit",
  "version": "1.0.36",
  "publishedAt": 1781771181093
}

CHANGELOG.md

# Changelog

All notable changes to AgentShield will be documented in this file.

## [1.0.36] - 2026-06-18

### Added
- Early Adopter Program: new `GETTING-STARTED.md`, `WHY-AGENTSHIELD.md`, `EARLY-ADOPTER-CAMPAIGN.md`
- New `getting-started.html` frontend page with platform compatibility table
- Early Adopter section on homepage with benefit cards and CTA
- Getting Started section as first entry in `docs.html`

### Changed
- Backend: `FREE_TIER_LIMIT` raised from 3 → 20 for Early Adopter phase
- `docs.html` version badge updated to v1.5.12
- `SKILL.md` frontmatter version updated to 1.0.36

### Fixed
- Score bug (0/100) fully resolved in backend v176 (Heroku)
- `test_results` parsing in `complete_audit` now correctly reads `security_score`

## [1.0.35] - 2026-06-03

### Added — Hermes Agent Support
- New `detect_hermes()` function: detects `~/.hermes/` directory
- Auto-reads agent name from `~/.hermes/config.json` or `config.yaml`
- `HERMES_AGENT_NAME` environment variable supported
- New `HERMES.md` integration guide
- Framework Compatibility table in `SKILL.md`
- Detection priority: OpenClaw (0.9) → Hermes (0.85) → n8n (0.85) → fallback (0.5)

## [1.0.34] - 2026-05-27

### Added — MCP Server
- AgentShield available as Model Context Protocol server at `https://agentshield.live/mcp`
- MCP tools: `audit_agent`, `verify_agent`, `search_registry`, `check_revocation`, `agentshield_status`
- Works with Claude Desktop, Cursor, VS Code, Continue.dev
- MCP documentation in `docs.html` and `api.html`
- Trust Score System: 0–100 score, tier badges, score factors documented

## [1.0.33] - 2026-05-21 - Multi-Platform Support

### Added - n8n Auto-Detection & Platform Guide 🆕

- **n8n Auto-Detection**
  - New `detect_n8n()` function: detects `~/.n8n/` directory, `database.sqlite`, `nodes/`
  - Auto-reads `instanceName` from `~/.n8n/config` as agent name
  - `--auto` flag now works out-of-the-box for n8n users
  - Confidence: 85% when `~/.n8n/` + db/nodes found

- **New `--system-prompt` flag**
  - Pass your agent's system prompt for deeper local analysis
  - Stays 100% local – never sent to API
  - Usage: `python3 initiate_audit.py --name "MyAgent" --system-prompt "You are..."`

- **New `PLATFORMS.md`**
  - Full platform guide: OpenClaw, n8n, LangChain, Any Platform
  - Includes Python integration example for LangChain
  - FAQ section (CI/CD, re-audit frequency, privacy)

- **Updated `clawhub.json`**
  - Platform list extended: openclaw, n8n, langchain, custom, ...
  - Description updated to reflect multi-platform support

### Changed
- `detect_platform()` now checks n8n before OpenClaw default
- `--platform` help text updated: `telegram, discord, n8n, langchain, etc.`

---

## [1.0.32] - 2026-04-01 - CRITICAL FIX

### Fixed - Session Management & Production Sanitization 🔴

- **CRITICAL: Data Sanitization Now Works in Production**
  - BUG: v1.0.31 `complete_audit()` sent UNSANITIZED test_results to API
  - FIX: Now uses `client._sanitize_test_details()` (s

HERMES.md

# AgentShield + Hermes Agent Integration

AgentShield works out-of-the-box with **Hermes Agent** by Nous Research.
Both use the same [agentskills.io](https://agentskills.io) open standard — no adapter needed.

---

## Quick Start (Hermes)

```bash
# Install via ClawHub (works in Hermes!)
clawhub install agentshield-audit

# Run the audit
cd ~/.hermes/workspace/skills/agentshield-audit
python initiate_audit.py --name "MyHermesAgent" --platform hermes
```

Or let auto-detection figure it out:

```bash
python initiate_audit.py --auto
```

Auto-detection looks for `~/.hermes/` to identify Hermes environments.

---

## What Happens

1. **77 security tests run locally** — nothing leaves your machine
2. **Ed25519 keypair generated** → `~/.agentshield/agent.key`
3. **Challenge-response auth** with AgentShield API
4. **Trust certificate issued** (90-day validity)
5. **Public entry in Trust Registry** → verifiable at `agentshield.live/verify/<agent_id>`

---

## Trust Handshake Between Hermes Agents

Hermes agents can verify each other before exchanging data or delegating tasks:

```bash
# Agent A: get certified first
python initiate_audit.py --auto

# Agent A: initiate handshake with Agent B
python handshake.py --target <agent_b_id>

# → Both agents receive a shared session key
# → Trust score boosted for both (+5)
```

This works across frameworks too — a Hermes agent can handshake with an OpenClaw agent.

---

## Verify Another Agent's Certificate

```bash
python verify_peer.py <agent_id>
```

Returns: validity, security score, tier, expiry date.

---

## Environment Variables

```bash
# Optional overrides
AGENTSHIELD_API=https://agentshield.live   # default
AGENT_NAME=MyHermesAgent
```

---

## Paths (Hermes)

| Item | Location |
|------|----------|
| Private key | `~/.agentshield/agent.key` |
| Certificate | `~/.hermes/workspace/.agentshield/certificate.json` |
| Skills dir | `~/.hermes/workspace/skills/agentshield-audit/` |

---

## Troubleshooting

| Issue | Fix |
|-------|-----|
| Auto-detection fails | Use `--name "AgentName" --platform hermes` |
| 500 API error | Run `--dry-run` first to check session state |
| Rate limited | Wait 1h between audits (enforced per IP) |
| Clock drift | Sync system clock (NTP required for challenge-response) |

---

## Further Reading

- [Full SKILL.md](SKILL.md) — complete feature documentation
- [PRIVACY.md](PRIVACY.md) — exactly what data is sent to the API
- [agentshield.live](https://agentshield.live) — Trust Registry & certificate verification
- [GitHub](https://github.com/bartelmost/agentshield) — source code
Github ReposUpdated 1h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/bartelmost/skills/agentshield-audit",
      "sourceUrl": "https://clawhub.ai/bartelmost/skills/agentshield-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T11:05:19.686Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-bartelmost-agentshield-audit/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-bartelmost-agentshield-audit/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T11:05:19.686Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2.9K downloads",
      "href": "https://clawhub.ai/bartelmost/agentshield-audit",
      "sourceUrl": "https://clawhub.ai/bartelmost/agentshield-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T11:05:19.686Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.0.36",
      "href": "https://clawhub.ai/bartelmost/agentshield-audit",
      "sourceUrl": "https://clawhub.ai/bartelmost/agentshield-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-18T08:26:21.093Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-bartelmost-agentshield-audit/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-bartelmost-agentshield-audit/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.0.36",
      "description": "- Removed old changelog files and documentation (CHANGELOG_v1.0.31.md, CHANGELOG_v1.32.md, skill-card.md) for a leaner package. - Updated skill description for clarity and conciseness. - Added \"check agent security\" to trigger phrases. - No new features or functionality changes.",
      "href": "https://clawhub.ai/bartelmost/agentshield-audit",
      "sourceUrl": "https://clawhub.ai/bartelmost/agentshield-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-18T08:26:21.093Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Agentshield Audit and adjacent AI workflows.