Tophant Clawvault Installer
Install, configure, test, and uninstall ClawVault AI security proxy
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
0.2.13
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 0.2.13release · observed May 19, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17570btgfthte5n8w72wxen8d83gzm4:tophant-clawvault-installer- Install using `clawhub skill install s17570btgfthte5n8w72wxen8d83gzm4:tophant-clawvault-installer` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/martin2877/tophant-clawvault-installer before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/snapshot"
Documentation
CLAWHUB
149,780 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: tophant-clawvault-installer version: 0.2.13 description: Install, configure, test, and uninstall ClawVault AI security proxy homepage: https://github.com/tophant-ai/ClawVault user-invocable: true disable-model-invocation: false --- # ClawVault Installer Install, configure, test, and uninstall ClawVault — the AI security proxy that protects agents from prompt injection, data leakage, and dangerous commands. **Protection Against:** - Prompt injection attacks - Data leakage (PII, credentials, API keys) - Dangerous command execution - Jailbreak attempts ## What This Skill Does Installs ClawVault into a dedicated venv at `~/.clawvault-env/` and writes config under `~/.ClawVault/`. See `SECURITY.md` for the full capability, risk, and design-intent disclosure. ## How to Run **IMPORTANT: All commands MUST be executed using the Python script bundled with this skill.** Do NOT run `pip install`, `clawvault`, or any other command directly. Always use: ```bash python3 SKILL_DIR/clawvault_manager.py <command> [options] ``` Where `SKILL_DIR` is the directory containing this SKILL.md file (typically `~/.openclaw/workspace/skills/tophant-clawvault-installer/` or `~/.openclaw/skills/tophant-clawvault-installer/`). Add `--json` to any command for machine-readable JSON output. ## Commands ### /tophant-clawvault-installer install Install ClawVault. The script creates a Python virtual environment, temporarily installs the latest GitHub repository code from `main` instead of PyPI or a fixed tag, generates config, writes OpenClaw gateway proxy config when the gateway service exists, and starts ClawVault services. By default it does **not** restart `openclaw-gateway`, because recent OpenClaw versions may disconnect or hang after a gateway restart. **No pip or system package manager needed.** ```bash # Default: write OpenClaw gateway proxy config and start ClawVault web dashboard, # but do not restart openclaw-gateway. # ClawVault web dashboard starts at http://localhost:8766. # To activate OpenClaw proxy later, manually run: # systemctl --user restart openclaw-gateway python3 SKILL_DIR/clawvault_manager.py install --mode quick --install-plugin --json # Interactive setup python3 SKILL_DIR/clawvault_manager.py install --mode standard --json # Full control (strict mode) python3 SKILL_DIR/clawvault_manager.py install --mode advanced --json # Install without starting services python3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json # Deprecated compatibility flag: proxy config is already written by default python3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --json # Dangerous: restart gateway immediately; may disconnect or hang OpenClaw python3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --restart-gateway --json # Skip OpenClaw proxy integration explicitly python3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json ``` ### OpenClaw plugi
README.md
# ClawVault Installer Skill AI security system for OpenClaw — protect your AI agents from prompt injection, data leakage, and dangerous commands. ## Before Installing This skill installs and operates a local HTTPS-inspection proxy. Capabilities, defaults, and risks are documented in [SECURITY.md](./SECURITY.md) — please review it before installing. ## Quick Start ### Installation **Option 1: Install from ClawHub (Recommended)** ```bash # Install from ClawHub openclaw skills install tophant-clawvault-installer # Or use clawhub CLI clawhub install tophant-clawvault-installer ``` **ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault-installer **Option 2: Install from Local Repository** ```bash # Copy to OpenClaw skills directory cp -r skills/tophant-clawvault-installer ~/.openclaw/skills/ # Or create symbolic link ln -s /path/to/ClawVault/skills/tophant-clawvault-installer ~/.openclaw/skills/tophant-clawvault-installer # Restart OpenClaw openclaw restart ``` ### Basic Usage ```bash # Install ClawVault and link the OpenClaw file-guard plugin /tophant-clawvault-installer install --mode quick --install-plugin # Check health /tophant-clawvault-installer health # Generate security rule /tophant-clawvault-installer generate-rule "Block all AWS credentials" --apply # Run tests /tophant-clawvault-installer test --category all ``` ## Features - **AI-guided installation** - Quick, standard, or advanced setup modes - **Dedicated virtualenv** - Installs into `~/.clawvault-env` instead of the system Python - **Latest GitHub install source** - Temporarily installs from the latest GitHub `main` code instead of PyPI or a fixed tag - **Failure-aware setup** - Reports configuration initialization failures as installation failures - **Secure dashboard defaults** - Binds the dashboard to `127.0.0.1` by default - **OpenClaw proxy integration and validation** - Can configure OpenClaw gateway proxy settings and verify the normal prompt path that triggers file-guard plugin interception - **Rule generation** - Create security rules from natural language - **Scenario templates** - Pre-configured policies (customer_service, development, production, finance) - **Detection testing** - Built-in test suites for validation - **Health monitoring** - Real-time service status ## Documentation - **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first** - **Skill Reference**: [SKILL.md](./SKILL.md) - **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md) - **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md) ## Requirements - Python 3.10+ - OpenClaw installed - Ports 8765, 8766 available ## Support - **Repository**: https://github.com/tophant-ai/ClawVault - **Issues**: https://github.com/tophant-ai/ClawVault/issues - **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc ## License MIT © 2
_meta.json
{
"ownerId": "kn70av3n6bs6dqfaajr8drm90d82v5tt",
"slug": "tophant-clawvault-installer",
"version": "0.2.13",
"publishedAt": 1779184574409
}SECURITY.md
# Security Documentation
## Overview
ClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.
## Design Intent — Why Several Defaults Look Permissive
ClawVault is a **man-in-the-middle (MITM) inspection proxy for AI traffic**. To do its job, it necessarily exhibits behaviors that automated security scanners flag as high-risk. Every one of these is intentional. This section documents them up-front so there is no ambiguity between "intentional capability" and "bug."
| Behavior | Why it's required | How to constrain it |
|---|---|---|
| `ssl_verify: false` in default config | Decrypts HTTPS so detectors can scan request/response bodies. Without this, ClawVault cannot see the AI traffic it is meant to protect. | MITM only applies to hosts listed in `proxy.intercept_hosts`. Non-AI traffic passes through untouched. Limit the list if you only want specific providers inspected. |
| Dashboard has no authentication by default | Default bind is `127.0.0.1` (localhost only); anyone with a shell on the machine already has more access than the dashboard exposes. | **Never** start with `--dashboard-host 0.0.0.0` on untrusted networks. Use SSH port-forwarding for remote viewing. |
| The skill sees your API keys and prompts | API keys travel inside the HTTPS requests being inspected. A proxy that inspects requests will see them. | All traffic stays on `localhost`. Nothing is uploaded. Audit logs in `~/.ClawVault/audit.db` are local-only. |
| Installer writes `HTTP_PROXY`/`HTTPS_PROXY` into `openclaw-gateway.service` | Routes OpenClaw traffic through ClawVault when the gateway is restarted later. The installer does not restart the gateway by default because recent OpenClaw versions may disconnect or hang after gateway restart. | Pass `--no-proxy` to skip the unit-file change. Restart `openclaw-gateway` manually only when safe to reconnect. Use `unconfigure-proxy` to remove the injected env lines. |
| Installs from latest GitHub source | Temporary behavior: PyPI and fixed-tag installs are disabled so users get the newest repository code. | Review the repository before installing or run in a disposable VM for higher assurance. See "Package Sources" below. |
If any of these trade-offs are unacceptable for your threat model, **do not install this skill.**
## How ClawVault Works
### Proxy Architecture
ClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:
```
AI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs
↓
Detection Engine
↓
Dashboard (localhost:8766)
```
**What This Means:**
- All API requests pass through ClawVault for inspection
- ClawVault can see request/response content including API keys
- This is intentional and necesskill-card.md
## Description: Install, configure, test, and uninstall ClawVault AI security proxy. This skill is ready for commercial/non-commercial use. ## Publisher: [martin2877](https://clawhub.ai/user/martin2877) ### License/Terms of Use: MIT-0 ## Use Case: Developers and OpenClaw operators use this skill to install and manage ClawVault as a local AI security proxy, generate security rules, run detection tests, and remove proxy configuration when needed. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Default setup can inspect API prompts, responses, and credentials through a local HTTPS inspection proxy. Mitigation: Review before installing on a machine with real credentials and prefer a disposable VM or container for initial evaluation. Risk: The installer uses mutable remote code from the ClawVault main branch rather than a pinned release. Mitigation: Install only from an audited pinned ClawVault commit for sensitive environments. Risk: Proxy integration can make persistent OpenClaw gateway changes and gateway restart may affect active sessions. Mitigation: Use --no-proxy and --no-start unless proxy activation is intentional, and avoid --restart-gateway until the TLS and connectivity impact is understood. ## Reference(s): - [ClawVault repository](https://github.com/tophant-ai/ClawVault) - [ClawVault OpenClaw skill guide](https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md) - [ClawVault documentation](https://github.com/tophant-ai/ClawVault/tree/main/doc) - [ClawHub skill page](https://clawhub.ai/martin2877/skills/tophant-clawvault-installer) ## Skill Output: **Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] **Output Format:** [Markdown instructions with bash command examples and JSON-capable command output.] **Output Parameters:** [1D] **Other Properties Related to Output:** [Commands support --json for machine-readable output.] ## Skill Version(s): 0.2.13 (source: server release, SKILL.md frontmatter, skill.json) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/martin2877/skills/tophant-clawvault-installer",
"sourceUrl": "https://clawhub.ai/martin2877/skills/tophant-clawvault-installer",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T03:28:29.472Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T03:28:29.472Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/martin2877/tophant-clawvault-installer",
"sourceUrl": "https://clawhub.ai/martin2877/tophant-clawvault-installer",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T03:28:29.472Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.2.13",
"href": "https://clawhub.ai/martin2877/tophant-clawvault-installer",
"sourceUrl": "https://clawhub.ai/martin2877/tophant-clawvault-installer",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-19T09:56:14.409Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.2.13",
"description": "Add OpenClaw plugin installation and acceptance flow",
"href": "https://clawhub.ai/martin2877/tophant-clawvault-installer",
"sourceUrl": "https://clawhub.ai/martin2877/tophant-clawvault-installer",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-19T09:56:14.409Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
