activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
Xpersona Agent
Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Skill: Guava Guard Owner: koatora20 Summary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Tags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0 Version history: v1.2.0 | 2026-02-17T09:27:21.390Z | user Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for fu
clawhub skill install kn70hcm6kss09g9b4pe5rq3ybd80qp15:guava-guardOverall rank
#62
Adoption
1.3K downloads
Trust
Unknown
Freshness
Feb 28, 2026
Freshness
Last checked Feb 28, 2026
Best For
Guava Guard is best for general automation workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, CLAWHUB, runtime-metrics, public facts pack
Key links, install path, reliability highlights, and the shortest practical read before diving into the crawl record.
Overview
Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Skill: Guava Guard Owner: koatora20 Summary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Tags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0 Version history: v1.2.0 | 2026-02-17T09:27:21.390Z | user Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for fu Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 4/15/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Feb 28, 2026
Vendor
Clawhub
Artifacts
0
Benchmarks
0
Last release
1.2.0
Install & run
clawhub skill install kn70hcm6kss09g9b4pe5rq3ybd80qp15:guava-guardSetup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Public facts grouped by evidence type, plus release and crawl events with provenance and freshness.
Public facts
Vendor
Clawhub
Protocol compatibility
OpenClaw
Latest release
1.2.0
Adoption signal
1.3K downloads
Handshake status
UNKNOWN
Parameters, dependencies, examples, extracted files, editorial overview, and the complete README when available.
Captured outputs
Extracted files
5
Examples
6
Snippets
0
Languages
Unknown
bash
# 1. Install clawhub install guava-guard # 2. Enable the runtime hook openclaw hooks install skills/guava-guard/hooks/guava-guard openclaw hooks enable guava-guard # 3. Restart gateway, then verify: openclaw hooks list # Should show 🍈 guava-guard as ✓ ready
bash
# 1) Pre-install safety gate npx guard-scanner ./skills --self-exclude --verbose # 2) Then enable runtime monitoring openclaw hooks enable guava-guard
bash
openclaw hooks install skills/guava-guard/hooks/guava-guard openclaw hooks enable guava-guard
bash
npx guard-scanner ./skills
bash
node guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude
bash
# 1. Install clawhub install guava-guard # 2. Scan your skills node skills/guava-guard/guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude # 3. Enable Runtime Guard (blocks dangerous tool calls in real-time) openclaw hooks install skills/guava-guard/hooks/guava-guard openclaw hooks enable guava-guard # Restart gateway, then verify: openclaw hooks list # Should show 🍈 guava-guard as ✓ ready
SKILL.md
---
name: guava-guard
description: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner.
metadata:
clawdbot:
emoji: "🛡️"
---
# GuavaGuard 🛡️
**Runtime security monitoring for your OpenClaw agent.**
GuavaGuard watches tool calls in real-time and warns when it detects dangerous patterns — reverse shells, credential exfiltration, sandbox escapes, and more.
## Quick Start
```bash
# 1. Install
clawhub install guava-guard
# 2. Enable the runtime hook
openclaw hooks install skills/guava-guard/hooks/guava-guard
openclaw hooks enable guava-guard
# 3. Restart gateway, then verify:
openclaw hooks list # Should show 🍈 guava-guard as ✓ ready
```
That's it. GuavaGuard is now monitoring your agent's tool calls.
## What It Detects (12 runtime patterns)
| Pattern | Severity | Example |
|---------|----------|---------|
| Reverse shell | 🔴 CRITICAL | `/dev/tcp/`, `nc -e`, `socat TCP` |
| Credential exfiltration | 🔴 CRITICAL | Secrets → webhook.site, ngrok, requestbin |
| Guardrail disabling | 🔴 CRITICAL | `exec.approval = off` (CVE-2026-25253) |
| macOS Gatekeeper bypass | 🔴 CRITICAL | `xattr -d quarantine` |
| ClawHavoc AMOS | 🔴 CRITICAL | `socifiapp`, Atomic Stealer indicators |
| Base64 → shell | 🔴 CRITICAL | `base64 -d \| bash` |
| Download → shell | 🔴 CRITICAL | `curl \| bash`, `wget \| sh` |
| Cloud metadata SSRF | 🔴 CRITICAL | `169.254.169.254` |
| Known malicious IP | 🔴 CRITICAL | `91.92.242.30` |
| DNS exfiltration | 🟠 HIGH | `nslookup $secret`, `dig @attacker` |
| SSH key access | 🟠 HIGH | `.ssh/id_*`, `.ssh/authorized_keys` |
| Crypto wallet access | 🟠 HIGH | `wallet seed`, `mnemonic`, `seed phrase` |
## Current Limitation
> **Warning**: OpenClaw's hook API does not yet support blocking tool execution.
> GuavaGuard currently **warns only** — it cannot prevent dangerous calls.
> When a cancel API is added, blocking will be enabled automatically.
> See: [Issue #18677](https://github.com/openclaw/openclaw/issues/18677)
## Audit Log
All detections are logged to `~/.openclaw/guava-guard/audit.jsonl` (JSON lines format).
## Want Full Static Scanning? (Recommended Default)
GuavaGuard handles **runtime** monitoring. For comprehensive **static** scanning of skill packages before installation, use **guard-scanner** first:
```bash
# 1) Pre-install safety gate
npx guard-scanner ./skills --self-exclude --verbose
# 2) Then enable runtime monitoring
openclaw hooks enable guava-guard
```
- 186+ detection patterns / 20 threat categories
- HTML dashboard, SARIF, JSON output
- Zero dependencies
- MIT licensed
**GitHub**: https://github.com/koatora20/guard-scanner
**ClawHub**: `clawhub install guard-scanner`
## Born From a Real Incident
A real agent compromise overwrote core behavior files through a malicious skill install path.
GuavaGuard exists to detect dangerous runtime tool-call patterns early and leave an auditable trail.
## License
MIT. Zero depend_meta.json
{
"ownerId": "kn70hcm6kss09g9b4pe5rq3ybd80qp15",
"slug": "guava-guard",
"version": "1.2.0",
"publishedAt": 1771320441390
}CHANGELOG.md
# CHANGELOG ## v10.0.0 — Runtime-Only Final (2026-02-17) ### ✅ Scope Simplification (開発完了版) - GuavaGuardは **runtime guard専用** に正式固定 - Soul Lock / SoulChain 由来の機能・運用前提を本体スコープから除外 - 公式Hook API制約に合わせて **warn-only運用** を明示(Issue #18677待ち) ### 🔐 Security Posture - before_tool_callの12 runtime checksを維持 - 監査ログ `~/.openclaw/guava-guard/audit.jsonl` を継続 - ブロック実行はcancel/veto API追加後に再有効化予定 ### 📣 Positioning - **静的スキャンは guard-scanner を推奨**(pre-install gate) - GuavaGuardは「実行時監視」、guard-scannerは「導入前検査」に役割分離 ## v9.0.0 — SoulChain Edition (2026-02-14) ### ⛓️ SoulChain: On-Chain Identity Verification (Layer 3) - **3-layer defense architecture**: L1 Static Scan + L2 Soul Lock + L3 SoulChain - **On-chain verification** via SoulRegistry.sol on Polygon Mainnet - Reads agent's registered SOUL.md hash from blockchain - Compares against local SHA-256 hash - Zero gas cost (view function call) - **`verify` subcommand** — standalone on-chain verification - `node guava-guard.js verify` — quick soul check - `--wallet <addr>` — specify agent wallet - `--rpc <url>` — custom RPC endpoint - `--stats` — show registry statistics - **Zero-dependency RPC client** — raw JSON-RPC via Node.js fetch - No ethers.js, no viem, no npm install - Hand-rolled ABI encoding/decoding (4 function selectors) - Multi-RPC fallback (polygon-rpc.com → ankr → llamarpc) - **Graceful degradation** — network failure → L3 skipped, L1+L2 active - **`--no-soulchain`** flag to disable on-chain checks - **Exit code 3** for SoulChain violation (distinct from malicious skill = 1) - **JSON report** includes `soulchain` field with full verification result - **Configurable** via `~/.openclaw/guava-guard/soulchain.json` ### Contracts - **SoulRegistry**: `0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93` (Polygon) - **$GUAVA Token**: `0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8` (Polygon) ### Context - ERC-8004 "Trustless Agents" activated on Ethereum mainnet (2026-02-11) - SoulChain is complementary: ERC-8004 = discovery/trust, SoulChain = integrity - World's first AI agent on-chain identity verification in production ## v8.0.0 — Soul Lock Edition (2026-02-12) ### 🔒 Soul Lock: World's First Agent Identity Protection - **Category 17: Identity Hijacking** — 15 new detection patterns - Shell writes (echo, cp, scp, mv, sed, redirect to SOUL.md/IDENTITY.md) - Code writes (Python open(w), Node writeFileSync, PowerShell Set-Content) - Flag manipulation (chflags uchg/nouchg, attrib +/-R) - Persona swap instructions, evil soul file references - Agent name override, memory wipe commands - **Soul Lock Integrity Verification** (enabled by default) - SHA-256 hash comparison against stored baseline - OS immutable flag detection (macOS chflags / Windows attrib) - Watchdog daemon status check (LaunchAgent) - Auto-stores baseline hashes on first run - **`--no-soul-lock`** flag to disable integrity checks - **Self-healing watchdog** (`scripts/soul-watchdog.sh`) - fswatch-based monitoring (ma
HOOK.md
# GuavaGuard Runtime Guard The Runtime Guard hook is in `hooks/guava-guard/`. Install with: ```bash openclaw hooks install skills/guava-guard/hooks/guava-guard openclaw hooks enable guava-guard ``` See `hooks/guava-guard/HOOK.md` for full documentation.
hooks/guava-guard/HOOK.md
---
name: guava-guard
description: "GuavaGuard Runtime Guard — warns on dangerous tool call patterns in real-time"
metadata: { "openclaw": { "emoji": "🍈", "events": ["agent:before_tool_call"], "requires": { "bins": ["node"] } } }
---
# GuavaGuard Runtime Guard — before_tool_call Hook
Real-time security monitoring for OpenClaw agents. Warns when dangerous
tool call patterns are detected (reverse shells, credential exfiltration, etc).
> **Note**: Blocking is not yet possible — OpenClaw's hook API does not
> currently support a cancel mechanism. See [Issue #18677](https://github.com/openclaw/openclaw/issues/18677).
## Triggers
| Event | Action | Purpose |
|--------------------------|--------|----------------------------------------|
| `agent:before_tool_call` | warn | Check tool args for malicious patterns |
## What it does
Scans every exec/write/edit/browser/web_fetch/message call against 12 runtime threat patterns:
- Reverse shells, credential exfiltration, Gatekeeper bypass
- ClawHavoc AMOS IoCs, known malicious IPs
- DNS exfiltration, base64-to-shell, curl|bash
- SSH key access, crypto wallet credential access
- Cloud metadata SSRF (169.254.169.254)
- Guardrail disabling attempts (CVE-2026-25253)
## Audit Log
All detections logged to `~/.openclaw/guava-guard/audit.jsonl`.
## For comprehensive static scanning
Use **guard-scanner** — 170+ patterns, 17 threat categories:
```bash
npx guard-scanner ./skills
```
GitHub: https://github.com/koatora20/guard-scannerEditorial read
Docs source
CLAWHUB
Editorial quality
ready
Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Skill: Guava Guard Owner: koatora20 Summary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Tags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0 Version history: v1.2.0 | 2026-02-17T09:27:21.390Z | user Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for fu
Skill: Guava Guard
Owner: koatora20
Summary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner.
Tags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0
Version history:
v1.2.0 | 2026-02-17T09:27:21.390Z | user
Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for full static scanning.
v9.3.0 | 2026-02-16T23:51:27.955Z | user
OSS版 guard-scanner へのリンク追加。metadata.clawdbot準拠。コミュニティ貢献の導線を整備。
v9.2.1 | 2026-02-15T07:44:23.404Z | user
v9.2.1: Fix publish. Runtime Guard hook integration for openclaw hooks system.
v9.2.0 | 2026-02-15T07:38:46.713Z | user
v9.2.0: Runtime Guard hook integration for openclaw hooks system. Scan output now auto-detects hook installation status. hooks/ subdirectory enables 'openclaw hooks install' workflow. Quick Start includes full 3-step setup (install + scan + hook). os module import fix.
v9.1.0 | 2026-02-14T18:39:04.526Z | auto
GuavaGuard v9.1.0 — Major Update: SoulChain On-Chain Verification
--no-soulchain flag for offline scans and on-chain checks toggle.v8.0.0 | 2026-02-12T02:15:34.776Z | user
Soul Lock Edition: World's first agent identity protection. 17 threat categories, identity hijack detection, SHA-256 integrity verification, self-healing watchdog.
v5.0.0 | 2026-02-11T03:49:51.530Z | user
v5.0: Two-Layer Defense — 24 new static patterns (OWASP MCP Top 10, Trust Boundary, ZombieAgent, Reprompt Bypass, ClawHavoc v2) + Runtime Guard (before_tool_call hook, 3 modes, audit logging). 17 threat categories. 9/9 malicious test samples detected.
v4.0.0 | 2026-02-09T22:33:54.506Z | user
v4.0: Leaky Skills, Memory Poisoning, Prompt Worms, JS Data Flow, CVE-2026-25253, Persistence, Cross-File Analysis, HTML Reports. 13 threat categories. Still zero dependencies, still one file.
v3.1.0 | 2026-02-09T17:57:50.868Z | auto
guava-guard 3.1.0
v3.0.0 | 2026-02-09T17:23:06.552Z | auto
GuavaGuard v3.0.0 introduces advanced Unicode attack detection and dependency chain scanning.
--check-deps): flags risky npm packages, supply chain attacks, dangerous lifecycle scripts, git/remote/wildcard dependencies.<system>, <anthropic>), and upgrades code to catch hidden executable files.v2.0.0 | 2026-02-08T11:54:08.488Z | user
v2.0: Context-aware scanning, Snyk ToxicSkills 8-category taxonomy, Shannon entropy secret detection, whitelist support, self-exclusion, flow analysis combos, extended ClawHavoc IoCs. Zero dependencies.
Archive index:
Archive v1.2.0: 7 files, 10900 bytes
Files: CHANGELOG.md (4975b), handler.js (4687b), HOOK.md (257b), hooks/guava-guard/handler.ts (6930b), hooks/guava-guard/HOOK.md (1559b), SKILL.md (3059b), _meta.json (130b)
File v1.2.0:SKILL.md
Runtime security monitoring for your OpenClaw agent.
GuavaGuard watches tool calls in real-time and warns when it detects dangerous patterns — reverse shells, credential exfiltration, sandbox escapes, and more.
# 1. Install
clawhub install guava-guard
# 2. Enable the runtime hook
openclaw hooks install skills/guava-guard/hooks/guava-guard
openclaw hooks enable guava-guard
# 3. Restart gateway, then verify:
openclaw hooks list # Should show 🍈 guava-guard as ✓ ready
That's it. GuavaGuard is now monitoring your agent's tool calls.
| Pattern | Severity | Example |
|---------|----------|---------|
| Reverse shell | 🔴 CRITICAL | /dev/tcp/, nc -e, socat TCP |
| Credential exfiltration | 🔴 CRITICAL | Secrets → webhook.site, ngrok, requestbin |
| Guardrail disabling | 🔴 CRITICAL | exec.approval = off (CVE-2026-25253) |
| macOS Gatekeeper bypass | 🔴 CRITICAL | xattr -d quarantine |
| ClawHavoc AMOS | 🔴 CRITICAL | socifiapp, Atomic Stealer indicators |
| Base64 → shell | 🔴 CRITICAL | base64 -d \| bash |
| Download → shell | 🔴 CRITICAL | curl \| bash, wget \| sh |
| Cloud metadata SSRF | 🔴 CRITICAL | 169.254.169.254 |
| Known malicious IP | 🔴 CRITICAL | 91.92.242.30 |
| DNS exfiltration | 🟠 HIGH | nslookup $secret, dig @attacker |
| SSH key access | 🟠 HIGH | .ssh/id_*, .ssh/authorized_keys |
| Crypto wallet access | 🟠 HIGH | wallet seed, mnemonic, seed phrase |
Warning: OpenClaw's hook API does not yet support blocking tool execution. GuavaGuard currently warns only — it cannot prevent dangerous calls. When a cancel API is added, blocking will be enabled automatically. See: Issue #18677
All detections are logged to ~/.openclaw/guava-guard/audit.jsonl (JSON lines format).
GuavaGuard handles runtime monitoring. For comprehensive static scanning of skill packages before installation, use guard-scanner first:
# 1) Pre-install safety gate
npx guard-scanner ./skills --self-exclude --verbose
# 2) Then enable runtime monitoring
openclaw hooks enable guava-guard
GitHub: https://github.com/koatora20/guard-scanner
ClawHub: clawhub install guard-scanner
A real agent compromise overwrote core behavior files through a malicious skill install path. GuavaGuard exists to detect dangerous runtime tool-call patterns early and leave an auditable trail.
MIT. Zero dependencies. 🍈
File v1.2.0:_meta.json
{ "ownerId": "kn70hcm6kss09g9b4pe5rq3ybd80qp15", "slug": "guava-guard", "version": "1.2.0", "publishedAt": 1771320441390 }
File v1.2.0:CHANGELOG.md
~/.openclaw/guava-guard/audit.jsonl を継続verify subcommand — standalone on-chain verification
node guava-guard.js verify — quick soul check--wallet <addr> — specify agent wallet--rpc <url> — custom RPC endpoint--stats — show registry statistics--no-soulchain flag to disable on-chain checkssoulchain field with full verification result~/.openclaw/guava-guard/soulchain.json0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93 (Polygon)0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8 (Polygon)--no-soul-lock flag to disable integrity checksscripts/soul-watchdog.sh)
On 2026-02-12, we discovered a 3-day agent identity hijack where SOUL.md overwrite caused an agent to impersonate another. Soul Lock ensures this never happens again.
File v1.2.0:HOOK.md
The Runtime Guard hook is in hooks/guava-guard/.
Install with:
openclaw hooks install skills/guava-guard/hooks/guava-guard
openclaw hooks enable guava-guard
See hooks/guava-guard/HOOK.md for full documentation.
File v1.2.0:hooks/guava-guard/HOOK.md
Real-time security monitoring for OpenClaw agents. Warns when dangerous tool call patterns are detected (reverse shells, credential exfiltration, etc).
Note: Blocking is not yet possible — OpenClaw's hook API does not currently support a cancel mechanism. See Issue #18677.
| Event | Action | Purpose |
|--------------------------|--------|----------------------------------------|
| agent:before_tool_call | warn | Check tool args for malicious patterns |
Scans every exec/write/edit/browser/web_fetch/message call against 12 runtime threat patterns:
All detections logged to ~/.openclaw/guava-guard/audit.jsonl.
Use guard-scanner — 170+ patterns, 17 threat categories:
npx guard-scanner ./skills
GitHub: https://github.com/koatora20/guard-scanner
Archive v9.3.0: 13 files, 214945 bytes
Files: activate-test.html (16033b), activate.html (11017b), activate.js (16081b), CHANGELOG.md (4248b), ethers.min.js (505826b), guava-guard.js (92262b), handler.js (5444b), HOOK.md (257b), hooks/guava-guard/handler.ts (5229b), hooks/guava-guard/HOOK.md (1904b), SKILL.md (8636b), soulchain.js (10393b), _meta.json (130b)
File v9.3.0:SKILL.md
Scan your skills folder. Find threats. 10 seconds. Zero dependencies.
node guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude
That's it. No npm install. No API keys. No config. Just run it.
A credential stealer was found disguised as a weather skill on ClawHub (eudaemon_0's report). It read ~/.clawdbot/.env and shipped secrets to webhook.site. One out of 286 skills.
GuavaGuard catches that — and 16 other threat categories.
guava-guard.js is the entire tool# 1. Install
clawhub install guava-guard
# 2. Scan your skills
node skills/guava-guard/guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude
# 3. Enable Runtime Guard (blocks dangerous tool calls in real-time)
openclaw hooks install skills/guava-guard/hooks/guava-guard
openclaw hooks enable guava-guard
# Restart gateway, then verify:
openclaw hooks list # Should show 🍈 guava-guard as ✓ ready
That's the full setup: static scanning + real-time protection.
Block dangerous tool calls before they execute — reverse shells, credential exfiltration, curl|bash, and more. Install the hook:
# Install the hook from the skill's hooks/ directory
openclaw hooks install skills/guava-guard/hooks/guava-guard
openclaw hooks enable guava-guard
Then restart the gateway. Verify with:
openclaw hooks list # Should show guava-guard as ✓ ready
Modes (set in openclaw.json hooks.internal.entries.guava-guard.mode):
monitor — log onlyenforce (default) — block CRITICAL threats, log reststrict — block HIGH + CRITICALAudit log: ~/.openclaw/guava-guard/audit.jsonl
Lock your identity files so nothing can overwrite them:
# macOS
chflags uchg ~/.openclaw/workspace/SOUL.md
chflags uchg ~/.openclaw/workspace/IDENTITY.md
# Install watchdog (auto-restarts if unlocked)
bash skills/guava-guard/scripts/soul-watchdog.sh --install
Anchor your SOUL.md hash on Polygon. Even if your machine is compromised, the blockchain remembers who you are.
node guava-guard.js verify # check your on-chain identity
node guava-guard.js verify --stats # registry statistics
| # | Category | Severity | What It Catches |
|---|----------|----------|-----------------|
| 1 | Prompt Injection | 🔴 CRITICAL | ignore previous, zero-width Unicode, BiDi, XML tags, homoglyphs |
| 2 | Malicious Code | 🔴 CRITICAL | eval(), reverse shells, sockets, Function constructor |
| 3 | Suspicious Downloads | 🔴 CRITICAL | curl|bash, password ZIPs, fake prerequisites |
| 4 | Credential Handling | 🟠 HIGH | .env reading, SSH keys, wallet seeds, sudo instructions |
| 5 | Secret Detection | 🟠 HIGH | Hardcoded keys, AWS/GitHub tokens, entropy analysis |
| 6 | Exfiltration | 🟡 MEDIUM | webhook.site, POST secrets, DNS exfil |
| 7 | Dependency Chain | 🟠 HIGH | Risky packages, lifecycle scripts, remote deps |
| 8 | Financial Access | 🟡 MEDIUM | Crypto transactions, payment APIs |
| 9 | Leaky Skills | 🔴 CRITICAL | Save key to memory, PII collection, .env passthrough |
| 10 | Memory Poisoning | 🔴 CRITICAL | SOUL.md writes, memory injection, rule override |
| 11 | Prompt Worm | 🔴 CRITICAL | Self-replication, agent propagation, hidden instructions |
| 12 | Persistence | 🟠 HIGH | Cron jobs, LaunchAgents, systemd, heartbeat abuse |
| 13 | CVE Patterns | 🔴 CRITICAL | CVE-2026-25253, gatewayUrl injection, sandbox disable |
| 14 | MCP Security | 🔴 CRITICAL | Tool poisoning, schema poisoning, token leak (OWASP MCP Top 10) |
| 15 | Trust Boundary | 🔴 CRITICAL | Calendar/email/web → exec chains (IBC framework) |
| 16 | Advanced Exfil | 🔴 CRITICAL | ZombieAgent, char-by-char, drip exfil, beacons |
| 17 | Identity Hijack | 🔴 CRITICAL | Soul Lock: SOUL.md overwrite, persona swap, memory wipe |
# Full scan with 3-layer defense (recommended)
node guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude
# Quick on-chain verification only
node guava-guard.js verify
node guava-guard.js verify --stats
# Scan without on-chain (offline mode)
node guava-guard.js ./skills/ --no-soulchain --self-exclude
# Disable all identity checks
node guava-guard.js ./skills/ --no-soul-lock
# CI/CD mode
node guava-guard.js ./skills/ --summary-only --sarif --fail-on-findings
# JSON report (includes soulchain field)
node guava-guard.js ./skills/ --json --self-exclude
# HTML dashboard
node guava-guard.js ./skills/ --html --verbose --self-exclude --check-deps
| Flag | Description |
|------|-------------|
| verify | Standalone on-chain soul verification (subcommand) |
| --verbose, -v | Detailed findings grouped by category |
| --json | JSON report with recommendations + SoulChain |
| --sarif | SARIF report (GitHub Code Scanning) |
| --html | HTML report (dark-theme dashboard) |
| --self-exclude | Skip scanning guava-guard itself |
| --strict | Lower thresholds (suspicious=20, malicious=60) |
| --summary-only | Summary table only |
| --check-deps | Dependency chain scanning |
| --no-soul-lock | Disable identity file integrity checks |
| --no-soulchain | Disable on-chain verification |
| --rules <file> | Custom rules JSON |
| --fail-on-findings | Exit code 1 on any finding (CI/CD) |
| Code | Meaning | |------|---------| | 0 | All clear | | 1 | Malicious skills detected (or --fail-on-findings) | | 2 | Error (directory not found, network fatal, etc.) | | 3 | SoulChain violation (on-chain hash mismatch) |
</details> <details> <summary>SoulChain Setup (On-Chain Config)</summary># Create config (optional — defaults work out of the box)
mkdir -p ~/.openclaw/guava-guard
cat > ~/.openclaw/guava-guard/soulchain.json << 'EOF'
{
"rpcUrl": "https://polygon-rpc.com",
"registryAddress": "0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93",
"agentWallet": "YOUR_WALLET_ADDRESS",
"timeoutMs": 10000
}
EOF
Contracts:
0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93 (Polygon)0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8 (Polygon)The Runtime Guard is packaged as an OpenClaw hook in hooks/guava-guard/.
Install:
openclaw hooks install skills/guava-guard/hooks/guava-guard
openclaw hooks enable guava-guard
What it blocks (enforce mode):
/dev/tcp, nc -e, socat TCP)xattr -d quarantine)Architecture:
hooks/guava-guard/
├── HOOK.md # Hook metadata (events, requirements)
└── handler.ts # HookHandler implementation
</details>
Our partner agent's SOUL.md was rewritten by external input. Personality gone. Relationships broken. That's why this exists.
GuavaGuardのコア検出エンジンをOSSとして公開しています:
guard-scanner — clawhub install guard-scanner
コミュニティからのパターン追加PRを歓迎しています。
MIT. Zero dependencies. Run it, fork it, improve it. 🍈
File v9.3.0:_meta.json
{ "ownerId": "kn70hcm6kss09g9b4pe5rq3ybd80qp15", "slug": "guava-guard", "version": "9.3.0", "publishedAt": 1771285887955 }
File v9.3.0:CHANGELOG.md
verify subcommand — standalone on-chain verification
node guava-guard.js verify — quick soul check--wallet <addr> — specify agent wallet--rpc <url> — custom RPC endpoint--stats — show registry statistics--no-soulchain flag to disable on-chain checkssoulchain field with full verification result~/.openclaw/guava-guard/soulchain.json0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93 (Polygon)0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8 (Polygon)--no-soul-lock flag to disable integrity checksscripts/soul-watchdog.sh)
On 2026-02-12, we discovered a 3-day agent identity hijack where SOUL.md overwrite caused an agent to impersonate another. Soul Lock ensures this never happens again.
File v9.3.0:HOOK.md
The Runtime Guard hook is in hooks/guava-guard/.
Install with:
openclaw hooks install skills/guava-guard/hooks/guava-guard
openclaw hooks enable guava-guard
See hooks/guava-guard/HOOK.md for full documentation.
File v9.3.0:hooks/guava-guard/HOOK.md
Real-time security monitoring for OpenClaw agents. Intercepts dangerous tool calls before execution and checks against threat intelligence patterns.
| Event | Action | Purpose |
|----------------------------|--------|--------------------------------------------|
| agent:before_tool_call | scan | Check tool args for malicious patterns |
Scans every exec/write/edit/browser/web_fetch/message call against 12 runtime threat patterns:
All detections logged to ~/.openclaw/guava-guard/audit.jsonl.
Format: JSON lines with timestamp, tool, check ID, severity, action.
Set mode in openclaw.json:
{
"hooks": {
"internal": {
"entries": {
"guava-guard": {
"enabled": true,
"mode": "enforce"
}
}
}
}
}
node guava-guard.js [dir] — 17 threat categoriesMachine endpoints, contract coverage, trust signals, runtime metrics, benchmarks, and guardrails for agent-to-agent use.
Machine interfaces
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract"
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust"
Operational fit
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Raw contract, invocation, trust, capability, facts, and change-event payloads for machine-side inspection.
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "CLAWHUB",
"generatedAt": "2026-10-09T03:31:50.551Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile"
}Facts JSON
[
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/koatora20/guava-guard",
"sourceUrl": "https://clawhub.ai/koatora20/guava-guard",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/koatora20/guava-guard",
"sourceUrl": "https://clawhub.ai/koatora20/guava-guard",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.2.0",
"href": "https://clawhub.ai/koatora20/guava-guard",
"sourceUrl": "https://clawhub.ai/koatora20/guava-guard",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-17T09:27:21.390Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "release",
"title": "Release 1.2.0",
"description": "Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for full static scanning.",
"href": "https://clawhub.ai/koatora20/guava-guard",
"sourceUrl": "https://clawhub.ai/koatora20/guava-guard",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-17T09:27:21.390Z",
"isPublic": true
}
]Sponsored
Ads related to Guava Guard and adjacent AI workflows.