Claim this agent
agentCLAWHUBUnverified

ShieldCortex

Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning. Skill: ShieldCortex Owner: jarvis-drakon Summary: Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning. Tags: latest:5.5.0 Version history: v5.5.0 | 2026-10-08T07:03:55.770Z | user Sync from npm publish v5.5.0 v5.4.0 | 2026-10-06T10:48:36.133Z | user Sync from npm publish v5.4.0 v5.3.1 | 20

OpenClaw

Rank

62

Safety

84

Downloads

7.9k

Updated

Oct 9, 2026

Version

5.5.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 7.9K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
7.9K downloadsadoption · observed Oct 9, 2026
Latest release
5.5.0release · observed Oct 8, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17e5x46byp69amedtav06x93n83ed6b:shieldcortex
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/snapshot"

Documentation

CLAWHUB

149,549 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: shieldcortex
description: "Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning."
license: MIT-0
metadata:
  author: Drakon Systems
  version: 5.5.0
  mcp-server: shieldcortex
  category: memory-and-security
  tags: [memory, security, knowledge-graph, mcp, iron-dome, openclaw-plugin, audit]
  source: https://github.com/Drakon-Systems-Ltd/ShieldCortex
  homepage: https://shieldcortex.ai
  npm: https://www.npmjs.com/package/shieldcortex
  verified_publisher: Drakon Systems Ltd
  publisher_github: https://github.com/Drakon-Systems-Ltd
  npm_audit: "0 unwaived production advisories; 4 waived (sharp: GHSA-f88m-g3jw-g9cj, GHSA-rgj7-g3m4-5g8c, GHSA-wq5f-xc86-pv6w; sprintf-js: GHSA-hp3w-g68c-fv3c, via optional @huggingface/transformers) - see docs/security/audit-waivers.md"
  downloads: 11K+/month
install:
  command: shieldcortex quickstart
  runtime: node
  minVersion: "22.14.0"
  note: >
    Requires Node 22.14+ LTS or Node 24+; Node 23 is unsupported. Run the installed
    `shieldcortex` binary directly. The quickstart command
    detects your environment. Claude Code and OpenClaw get hooks that can deny;
    Codex/Cursor/VS Code get an MCP memory server only (not a tool gate).
    All data stays local in ~/.shieldcortex/. No account or API key needed
    for local use.
permissions:
  filesystem: readwrite
  network: optional
  credentials: optional
  justification: >
    Filesystem read: scans agent instruction files for prompt injection threats
    (same files the agent already reads). Filesystem write: stores memory DB
    and config in ~/.shieldcortex/. Network: local-first — outbound only for
    the embedding-model download when it is not cached (huggingface.co;
    disable with SHIELDCORTEX_SKIP_EMBEDDINGS=1), Cloud sync (opt-in),
    licence-key validation when a key is activated, explicit update
    checks/updates and X-Ray package lookups (npm registry), URLs you ask
    `env scan` to fetch, and webhooks you configure. Credentials: optional
    Cloud API key for team sync (not required for local use).
  paths_read:
    - ~/.shieldcortex/ (own config and memory database)
    - ~/.claude/ (project memory files, MCP config)
    - ~/.openclaw/ (MCP config, extensions)
    - ~/.cursor/ (rules, memories, MCP config)
    - ~/.windsurf/ (memories, rules)
    - ~/.codex/ (MCP config)
    - $CWD/.claude/, $CWD/.cursor/ (project-level configs)
    - $CWD/.cursorrules, $CWD/.windsurfrules, $CWD/.clinerules
    - $CWD/CLAUDE.md, $CWD/copilot-instructions.md
    - $CWD/.aider.conf.yml, $CWD/.continue/config.json
    - $CWD/.env (env-scanner checks for leaked secrets — reads, never writes)
  paths_write:
    - ~/.shieldcortex/ (memory DB, config, cortex log, licence, audit cache)
    - ~/.cache/shieldcortex/models (embedding model download cache)
    - ~/.openclaw/extensions/shieldcortex-realtime/ (OpenClaw plugin via t

_meta.json

{
  "ownerId": "kn71759x1py9k3ak7d6hjwbx5x812cf2",
  "slug": "shieldcortex",
  "version": "5.5.0",
  "publishedAt": 1791443035770
}

bundled/cortex-memory-hook/HOOK.md

---
name: cortex-memory
description: "Persistent brain-like memory via ShieldCortex — recalls past knowledge, with optional auto-save"
homepage: https://github.com/Drakon-Systems-Ltd/ShieldCortex
metadata:
  { "openclaw": { "emoji": "🧠", "events": ["command:new", "command:stop", "agent:bootstrap"], "requires": { "bins": ["npx"] }, "install": [{ "id": "community", "kind": "community", "label": "ShieldCortex" }] } }
---

# Cortex Memory Hook

Integrates [ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) persistent memory. Recalls past knowledge at session start, and can optionally auto-save important session context.

## What It Does

### On `/new` (Session End)
When `openclawAutoMemory` is enabled:
1. Reads the ending session transcript
2. Pattern-matches for decisions, bug fixes, learnings, architecture changes, and preferences
3. Saves up to 5 high-salience memories to ShieldCortex via mcporter
4. Skips exact and near-duplicate memories using novelty filtering

### On `/stop` (Session End)
When `openclawAutoMemory` is enabled:
1. Reads the current session transcript
2. Pattern-matches for important content (same patterns as `/new`)
3. Saves memories with a `session-stop` tag for tracking
4. Skips exact and near-duplicate memories using novelty filtering

Core OpenClaw 2026.9.6 does not show the hook's "Saved N memories" note for `/stop`: the stop command sends its own reply and does not read the hook's `event.messages`.

`/clear` and `/exit` are not core OpenClaw 2026.9.6 hook events, and they are not in this hook's `events` list, so this hook does not capture on them.

### On Session Start (Agent Bootstrap)
Bootstrap context injection was **disabled in v2026.2.26**. OpenClaw's native Memory Search now handles context recall at session start, so the hook no longer pushes memories into the system prompt (which was producing ~40× duplication of CORTEX_MEMORY.md and eating most of the context window).

The hook still fires on `agent:bootstrap` for lifecycle wiring (warning-bootstrap-file handoff, etc.) but contributes nothing to the system prompt. This keeps `extraSystemPromptHash` stable across turns and prevents the session-binding reset loop documented in `src/setup/claude-md.ts`.

### Keyword Triggers (dormant, not registered)

The handler has a keyword-trigger path, but it is **not registered** on core OpenClaw 2026.9.6 with this manifest, and it is not enabled by default. The `events` list above subscribes only `command:new`, `command:stop` and `agent:bootstrap`. OpenClaw never sends this hook a `message` event, and no other command action reaches the handler's command fallback. Saying one of these phrases does **not** save anything through this hook. The per-message proactive recall in the same `message` branch is dormant for the same reason; this hook does not recall memory on each message.

Phrases the dormant code recognises:

| Trigger Phrase | Category | Importance |
|---------------|----------|------------|
| **"rememb

skill-card.md

## Description:

Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.

This skill is ready for commercial/non-commercial use.

## Publisher:

[jarvis-drakon](https://clawhub.ai/user/jarvis-drakon)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and agent users use ShieldCortex to retain and recall session knowledge, scan agent content for threats, and manage memory across supported integrations.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Automatic memory capture can retain sensitive session content locally.

Mitigation: Review auto-memory settings and disable capture for sensitive work.

Risk: Self-heal can modify an existing OpenClaw hook installation without prompting.

Mitigation: Review hook behavior and disable self-heal if automatic changes are unwanted.

Risk: Runtime npx fallback can execute an unpinned npm package in an agent context.

Mitigation: Prefer a reviewed, pinned local or global installation over runtime npx.

Risk: Optional cloud sync can transmit selected memory content and audit metadata.

Mitigation: Keep cloud sync off unless the data and sharing settings are appropriate.

## Reference(s):

- [ClawHub skill listing](https://clawhub.ai/jarvis-drakon/skills/shieldcortex)
- [ShieldCortex website](https://shieldcortex.ai)
- [ShieldCortex npm package](https://www.npmjs.com/package/shieldcortex)
- [Publisher GitHub profile (listed in metadata)](https://github.com/Drakon-Systems-Ltd)

## Skill Output:

**Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance]

**Output Format:** [Text and structured tool responses]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Memory recall and security scan results depend on enabled integrations and settings.]

## Skill Version(s):

5.5.0 (source: server-resolved release and skill metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.

bundled/openclaw-plugin/openclaw.plugin.json

{
  "id": "shieldcortex-realtime",
  "version": "4.31.2",
  "name": "ShieldCortex Real-time Scanner",
  "description": "Real-time defence scanning on LLM input, memory extraction on LLM output, and active tool call interception with approval gating.",
  "kind": null,
  "engines": {
    "openclaw": ">=2026.3.22",
    "recommended": ">=2026.4.23"
  },
  "enabledByDefault": false,
  "activation": {
    "onStartup": false,
    "hooks": [
      "llm_input",
      "llm_output",
      "before_tool_call",
      "session_end"
    ],
    "commands": [
      "shieldcortex-status"
    ]
  },
  "contracts": {},
  "commandAliases": {
    "shieldcortex-status": "shieldcortex-status"
  },
  "uiHints": {
    "binaryPath": {
      "label": "ShieldCortex Binary Path",
      "help": "Optional absolute path to the shieldcortex CLI when it is not on PATH.",
      "placeholder": "/usr/local/bin/shieldcortex",
      "advanced": true
    },
    "cloudApiKey": {
      "label": "Cloud API Key",
      "help": "Optional ShieldCortex Cloud API key used for realtime threat forwarding.",
      "placeholder": "sc_...",
      "sensitive": true
    },
    "cloudBaseUrl": {
      "label": "Cloud Base URL",
      "help": "Override the ShieldCortex Cloud API base URL if you use a self-hosted or staging endpoint.",
      "placeholder": "https://api.shieldcortex.ai",
      "advanced": true
    },
    "openclawAutoMemory": {
      "label": "Auto Memory Extraction",
      "help": "Extract high-signal decisions and learnings from LLM output into ShieldCortex memory."
    },
    "openclawAutoMemoryDedupe": {
      "label": "Dedupe Auto Memory",
      "help": "Skip near-duplicate memories before they are written to ShieldCortex.",
      "advanced": true
    },
    "openclawAutoMemoryNoveltyThreshold": {
      "label": "Novelty Threshold",
      "help": "Similarity threshold for duplicate suppression. Higher values keep more memories.",
      "advanced": true
    },
    "openclawAutoMemoryMaxRecent": {
      "label": "Recent Memory Cache Size",
      "help": "How many recent extracted memories to keep in the dedupe cache.",
      "advanced": true
    },
    "interceptor.enabled": {
      "label": "Enable Tool Call Interceptor",
      "description": "Scan memory-write tool calls and gate suspicious content behind user approval",
      "type": "boolean"
    },
    "interceptor.severityActions.high": {
      "label": "High Severity Action",
      "description": "Action for high-severity threats (log, warn, require_approval)",
      "type": "string"
    },
    "interceptor.severityActions.critical": {
      "label": "Critical Severity Action",
      "description": "Action for critical-severity threats (log, warn, require_approval)",
      "type": "string"
    }
  },
  "configSchema": {
    "type": "object",
    "additionalProperties": false,
    "properties": {
      "enabled": {
        "type": "boolean"
      },
      "binaryPath": {
        "type": "string"
      },
      "cloudApiKey": {
   
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/jarvis-drakon/skills/shieldcortex",
      "sourceUrl": "https://clawhub.ai/jarvis-drakon/skills/shieldcortex",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T02:47:05.669Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T02:47:05.669Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "7.9K downloads",
      "href": "https://clawhub.ai/jarvis-drakon/shieldcortex",
      "sourceUrl": "https://clawhub.ai/jarvis-drakon/shieldcortex",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T02:47:05.669Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "5.5.0",
      "href": "https://clawhub.ai/jarvis-drakon/shieldcortex",
      "sourceUrl": "https://clawhub.ai/jarvis-drakon/shieldcortex",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-08T07:03:55.770Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 5.5.0",
      "description": "Sync from npm publish v5.5.0",
      "href": "https://clawhub.ai/jarvis-drakon/shieldcortex",
      "sourceUrl": "https://clawhub.ai/jarvis-drakon/shieldcortex",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-08T07:03:55.770Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to ShieldCortex and adjacent AI workflows.