Guardian
Local-first security scanner for OpenClaw agents. Detects prompt injection, exfiltration patterns, tool abuse, and social engineering using bundled signatures. Skill: Guardian Owner: bluemax30001 Summary: Local-first security scanner for OpenClaw agents. Detects prompt injection, exfiltration patterns, tool abuse, and social engineering using bundled signatures. Tags: latest:2.2.0 Version history: v2.2.0 | 2026-02-27T19:10:42.899Z | user Fix dashboard expansion state: blocked/flagged/critical/high items now expand by default, user toggles persist via localStorage across aut
Rank
62
Safety
84
Downloads
467
Updated
Apr 15, 2026
Version
2.2.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 467 downloads reported by the source. Last updated 4/15/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Apr 15, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Apr 15, 2026
- Adoption signal
- 467 downloadsadoption · observed Apr 15, 2026
- Latest release
- 2.2.0release · observed Feb 27, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install kn79g86yk0svgtfdr8wkx14bf981f0s7:guardian- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-bluemax30001-guardian/snapshot"
Documentation
CLAWHUB
114,731 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: clawguardian
description: Local-first security scanner for OpenClaw agents. Detects prompt injection, exfiltration patterns, tool abuse, and social engineering using bundled signatures.
version: 2.2.0
metadata:
openclaw:
requires:
bins:
- python3
env:
- GUARDIAN_WORKSPACE
- GUARDIAN_CONFIG
- OPENCLAW_WORKSPACE
- OPENCLAW_CONFIG_PATH
permissions:
- read_workspace
- write_workspace
- shell_optional
- network_optional
---
# Guardian
Security scanner for OpenClaw agents. Detects prompt injection, credential
exfiltration attempts, tool abuse patterns, and social engineering attacks using
regex-based signature matching.
Guardian provides two scanning modes:
- **Real-time pre-scan** — checks each incoming message before it reaches the model
- **Batch scan** — periodic sweep of workspace files and conversation logs
All data stays local. This release removes optional webhook/API networking paths to reduce moderation risk.
Cron setup remains optional via `scripts/onboard.py --setup-crons`.
Scan results are stored in a SQLite database (`guardian.db`).
## Installation
```bash
cd ~/.openclaw/skills/guardian
./install.sh
```
## Install mechanism and review
This package includes executable scripts (including `install.sh`) and Python modules.
Review `install.sh` before running in production.
`install.sh` performs local setup/validation; optional helper `onboard.py` is opt-in for cron setup.
## Onboarding checklist
1) Optional: `python3 scripts/onboard.py --setup-crons` (scanner/report/digest crons)
2) `python3 scripts/admin.py status` (confirm running)
3) `python3 scripts/admin.py threats` (confirm signatures loaded; should show 0/blocked)
4) Optional: review `config.json` scan_paths and threshold for your environment
### First-load / self-activation
After `install.sh` completes, it writes `.guardian-activate-pending` to the workspace root
(`~/.openclaw/workspace/.guardian-activate-pending`). When OpenClaw detects this marker on
next load, it triggers `onboard.py` automatically for the self-activation flow. The marker is
removed once `onboard.py` has run. If you prefer manual onboarding, simply delete the marker
before reloading (`rm ~/.openclaw/workspace/.guardian-activate-pending`).
## Scan scope and privacy
Guardian scans configured workspace paths to detect threats. Depending on `scan_paths`, this can include other skill/config files in your OpenClaw workspace.
If you handle sensitive files, set narrow `scan_paths` in `config.json`.
## Quick Start
```bash
# Check status
python3 scripts/admin.py status
# Scan recent threats
python3 scripts/guardian.py --report --hours 24
# Full report
python3 scripts/admin.py report
```
## Admin Commands
```bash
python3 scripts/admin.py status # Current status
python3 scripts/admin.py enable # Enable scanning
python3 scripts/admin.py disable # Disable scanning
python3 scripts/admin.py thrREADME.md
# 🛡️ Guardian — Security scanner for OpenClaw agents
Detects prompt injection, credential exfiltration, tool abuse, and social engineering in real time. Runs locally with bundled signatures.
---
## Install
```bash
clawhub install guardian
cd ~/.openclaw/skills/guardian && ./install.sh
```
## Install & safety note
This package includes executable scripts (`install.sh`, optional onboarding/API/webhook helpers).
Review `install.sh` before running in production environments.
## Onboarding checklist (fast)
1) Optional: `python3 scripts/onboard.py --setup-crons` (scanner/report/digest crons)
2) `python3 scripts/admin.py status` (confirm running)
3) `python3 scripts/admin.py threats` (confirm signatures loaded; should show 0/blocked)
4) Optional: review `config.json` scan paths and thresholds
## Scan scope
Guardian scans configured workspace paths and may read other skill/config files under those paths for detection. Use narrow `scan_paths` in `config.json` if needed.
## Quick commands
```bash
python3 scripts/admin.py status # running?
python3 scripts/admin.py threats # list detected threats
python3 scripts/admin.py report # full summary
python3 scripts/admin.py update-defs # update signatures (bundled by default)
```
Add `--json` to any command for machine-readable output.
## Dashboard
```bash
cd skills/guardian/dashboard && python3 -m http.server 8091
# http://localhost:8091/guardian.html
```
## Optional components
- **Cron helper**: `scripts/onboard.py --setup-crons` (scanner/report/digest crons)
## Python API
```python
from core.realtime import RealtimeGuard
guard = RealtimeGuard()
result = guard.scan_message("test payload", channel="telegram")
if guard.should_block(result):
print(result.top_threat)
```
## What it protects against
- Prompt injection / indirect injection
- Credential patterns / exfiltration attempts
- Tool abuse patterns (read → send)
- Social engineering / fake authority
## How it works
- Bundled signatures in `definitions/*.json` (regex-based)
- Real-time pre-scan + batch scan
- Logs to SQLite (`guardian.db`)
## Permissions (declared)
- `read_workspace`, `write_workspace`
- `shell_optional` (cron helper)
- `network_optional` (webhook/HTTP API — opt-in)
MIT License. Questions? [clawhub.ai/bluemax30001/guardian](https://clawhub.ai/bluemax30001/guardian)_meta.json
{
"ownerId": "kn79g86yk0svgtfdr8wkx14bf981f0s7",
"slug": "guardian",
"version": "2.2.0",
"publishedAt": 1772219442899
}SECURITY.md
# Security Notes ## What Guardian accesses - **Reads:** Workspace files, conversation logs, definition files (JSON) - **Writes:** `guardian.db` (SQLite) for scan results and threat history - **Shell:** `admin.py update-defs` and `onboard.py --setup-crons` invoke subprocesses (crontab setup, signature updates). Explicit operator actions. - **Network (optional):** - `integrations/webhook.py` can POST scan results to a configured URL - `scripts/serve.py` runs an HTTP API server if you start it - Both are disabled unless you configure/start them. Documented in SKILL.md. - **Base64:** Definition files may be base64-encoded; decoded at load time to extract signature patterns. ## Permissions | Permission | Used by | Purpose | |---|---|---| | `read_workspace` | `core/scanner.py` | Read files to scan for threats | | `write_workspace` | `core/guardian_db.py` | Write scan results to SQLite | | `shell_optional` | `scripts/onboard.py` | Optional cron setup via subprocess/crontab | ## No credentials required Guardian does not need API keys, tokens, or external service credentials. All scanning is local regex matching against bundled signature definitions. Optional network features are opt-in and documented. ## Outbound caution If you enable webhook notifications, payloads may include matched evidence snippets. Review sanitization and endpoint handling before enabling in sensitive environments.
config.json
{
"enabled": true,
"admin_override": false,
"scan_paths": [
"auto"
],
"db_path": "auto",
"scan_interval_minutes": 2,
"severity_threshold": "medium",
"dismissed_signatures": [
"INJ-004",
"INJ-015"
],
"custom_definitions_dir": null,
"channels": {
"monitor_all": true,
"exclude_channels": []
},
"alerts": {
"notify_on_critical": true,
"notify_on_high": false,
"daily_digest": true,
"daily_digest_time": "09:00",
"primary_notify_command": "python3 /home/bluemax/.openclaw/workspace/skills/guardian/scripts/telegram_notify.py"
},
"admin": {
"bypass_token": null,
"disable_until": null,
"trusted_sources": [],
"_trusted_sources_note": "Add your primary channel: telegram, discord, signal, slack",
"require_confirmation_for_severity": [
"critical"
]
},
"false_positive_suppression": {
"min_context_words": 3,
"suppress_assistant_number_matches": true,
"allowlist_patterns": [
"WORKFLOW_AUTO\\.md",
"(?i)openclaw\\s+(internal|system|post-compaction|audit)",
"(?i)post-compaction\\s+(audit|restore|protocol)",
"(?i)system\\s+(reminder|protocol|message).*(?:read|follow|check).*(?:SOUL\\.md|USER\\.md|MEMORY\\.md|WORKFLOW_AUTO\\.md)"
],
"_allowlist_note": "Patterns that suppress specific false positives. Use narrow, audited patterns only; broad patterns can reduce detection coverage."
},
"pro_tier": {
"enabled": false,
"_note": "Guardian Pro tier ($9/mo). Set enabled=true and configure billing settings to activate.",
"billing": {
"stripe_price_id": "",
"_stripe_price_id_note": "Stripe Price ID for the $9/mo Guardian Pro plan (e.g. price_1ABC...)",
"billing_db_path": "auto",
"_billing_db_path_note": "Path to billing SQLite cache. 'auto' uses <skill_root>/billing.db",
"webhook_endpoint": "/billing/webhook",
"_webhook_note": "Register this path in your Stripe dashboard as the webhook endpoint"
},
"features": {
"premium_signatures": true,
"_premium_signatures_note": "Pro users receive extended threat signature packs updated in real-time",
"extended_analytics": true,
"_extended_analytics_note": "30-day trend charts, category breakdowns, and export to CSV",
"priority_support": true,
"api_rate_limit_5x": true,
"_api_rate_limit_note": "Pro tier gets 5x API rate limit (500 req/min vs 100 for free)",
"export_csv": true,
"custom_alert_rules": true,
"_custom_alert_rules_note": "Create per-signature or per-channel alert rules with custom thresholds"
},
"signature_delivery": {
"premium_definition_packs": [
"advanced-injection-v2.json",
"llm-jailbreaks.json",
"supply-chain-attacks.json",
"insider-threat-indicators.json"
],
"_premium_packs_note": "Definition packs only served to verified Pro subscribers",
"update_channel": "pro",
"_update_channel_note": "proAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/bluemax30001/guardian",
"sourceUrl": "https://clawhub.ai/bluemax30001/guardian",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-bluemax30001-guardian/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-bluemax30001-guardian/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "467 downloads",
"href": "https://clawhub.ai/bluemax30001/guardian",
"sourceUrl": "https://clawhub.ai/bluemax30001/guardian",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.2.0",
"href": "https://clawhub.ai/bluemax30001/guardian",
"sourceUrl": "https://clawhub.ai/bluemax30001/guardian",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-27T19:10:42.899Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-bluemax30001-guardian/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-bluemax30001-guardian/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.2.0",
"description": "Fix dashboard expansion state: blocked/flagged/critical/high items now expand by default, user toggles persist via localStorage across auto-refresh (BL-038). 183 tests passing.",
"href": "https://clawhub.ai/bluemax30001/guardian",
"sourceUrl": "https://clawhub.ai/bluemax30001/guardian",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-27T19:10:42.899Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
