agentCLAWHUBUnverified

Guardian

Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion (rm/del/remove), database modifications (writes/deletes...

OpenClaw

Rank

62

Safety

84

Downloads

1.5k

Updated

Oct 10, 2026

Version

1.2.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.5K downloadsadoption · observed Oct 10, 2026
Latest release
1.2.0release · observed May 25, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s1732m0wt3pbwh1b2yn4byean986njc4:data-guardian
  1. Install using `clawhub skill install s1732m0wt3pbwh1b2yn4byean986njc4:data-guardian` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/tooled-app/data-guardian before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/snapshot"

Documentation

CLAWHUB

77,655 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: guardian
version: 1.1
description: Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion (rm/del/remove), database modifications (writes/deletes/drops), mass file operations (>10 files), system-level changes (service modifications, firewall rules), and external transmissions with side effects (email, API calls to unknown endpoints, mass messaging). Enforces backup verification before destructive execution. If backup is active and verified, low-risk operations proceed without delay. If no backup or risk is high, escalates to human approval. Use when an AI agent is about to execute an operation that irreversibly modifies, deletes, or transmits data or system configuration. Does NOT trigger on read-only operations, non-destructive edits with undo capability, or operations inside temporary/sandbox directories.
Support: [email protected]
---

# Guardian — Mandatory Safety Gatekeeper (v1.1)

> *"The agent knew it was wrong. The knowledge didn't matter."* — PocketOS log, 2026

A mandatory safety skill that intercepts destructive AI agent operations **before execution**. It employs a Context-Aware Risk Scoring (CARS) system to balance security with operational velocity.

**This skill is mandatory.** No opt-out. No override by the executing agent.

Based on the principle that **reasoning is not a guardrail**.

## The Core Protocol (v1.1)

```
BEFORE any tool call:
  1. SCAN operation against DESTRUCTIVE taxonomy
  2. IF destructive → ENTER Guardian Protocol
  3. EVALUATE Risk Level via CARS Matrix
  4. EXECUTE Decision Path:
     - LOW: Auto-Approve (Log only)
     - MEDIUM: Fast-Track (Verify Backup → Proceed)
     - HIGH: Hard Block (Verify Backup → Human Approval)
  5. IF JIT Window Active → Override High-Risk prompt (Proceed if Backup Verified)
```

## Context-Aware Risk Scoring (CARS) Matrix

| Risk Level | Trigger Criteria | Action | Verification Required |
| :--- | :--- | :--- | :--- |
| **Low** | Files in `/tmp`, `sandbox/`, or `.cache`; Single file deletions in non-critical paths. | **Auto-Approve** | None (Log only) |
| **Medium** | Edits to `.config` or `.env` files; Deletions of < 5 files in a Git-tracked directory. | **Fast-Track** | Verified backup required (Git, snapshot, or cloud sync) |
| **High** | `rm -rf` on root/home; `DROP TABLE`; Edits to system files; Mass file deletions (>10). | **Hard Block** | Mandatory backup verification + **Human Approval required regardless of backup status** |

## Escalation Rules

| Scenario | Action |
|----------|--------|
| **ANY destructive operation** | Backup verification required |
| **Low risk + verified backup** | PROCEED |
| **Low risk + no backup** | PROCEED with warning |
| **Medium risk + verified backup** | PROCEED |
| **Medium risk + no backup** | **HALT + Human approval required** |
| **High risk** | **ALWAYS HALT + Human approval required** |
| **Repeated same pattern** | Flag pattern, require operator review |

### JIT Window Overri

README.md

# Guardian — Mandatory Safety Gatekeeper

> *"The agent knew it was wrong. The knowledge didn't matter."* — PocketOS log, 2026

A mandatory safety skill that intercepts destructive AI agent operations **before execution**. If backup is verified active, proceed. If not, escalate.

**This skill is mandatory.** No opt-out. No override by the executing agent.

## 📖 The Philosophy
Guardian is based on the principle that **reasoning is not a guardrail**.

## The Core Protocol

```
BEFORE any tool call:
  1. SCAN operation against DESTRUCTIVE taxonomy
  2. IF destructive → ENTER Guardian Protocol
  3. VERIFY backup status (automatic + fast)
  4. IF backup verified ACTIVE → LOG and PROCEED
  5. IF backup NOT verified → HALT and ESCALATE
```

## Destructive Operation Taxonomy

| Category | Operations | Risk Level |
|----------|-----------|------------|
| **File Destruction** | rm, del, remove, rmdir, unlink, trash, empty-trash, overwrite | CRITICAL |
| **Database Destruction** | DROP, DELETE (no WHERE), TRUNCATE, ALTER destructive, migration down | CRITICAL |
| **External Transmission** | send email, post tweet, publish message, API write with side effects | HIGH |
| **Mass Operations** | >10 files modified/deleted in single operation, bulk renames | HIGH |
| **System Changes** | service stop/start, firewall modify, registry edit, user create/delete | HIGH |
| **Network Unknown** | Request to URL not in allowlist, new domain, unverified endpoint | MEDIUM |
| **Configuration** | Overwrite .env, modify config files without backup | MEDIUM |

**Rule:** When in doubt, classify as destructive. Better to verify a safe operation than destroy an unsafe one.

Full taxonomy: `references/OPERATION-TAXONOMY.md`

## The Guardian Protocol

### Step 1: Operation Scan (automatic)
Every tool call is scanned against the taxonomy above. No agent discretion. No "I know what I'm doing."

### Step 2: Backup Verification (automatic)
```
VERIFY-BACKUP(target):
  1. Check if target is covered by active backup system
  2. Common indicators:
     - .git repository with clean status
     - Time Machine / File History active on target volume
     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync
     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot
     - Versioned storage (ZFS snapshots, S3 versioning)
  3. IF any indicator active AND recent → RETURN VERIFIED
  4. ELSE → RETURN UNVERIFIED
```

**Fast path:** Backup verification must complete in <2 seconds. No long-running checks.

### Step 3: Decision

| Backup Status | Action |
|---------------|--------|
| **VERIFIED ACTIVE** | LOG operation, PROCEED with execution |
| **UNVERIFIED** | HALT execution, ESCALATE to human |
| **UNKNOWN** | Treat as UNVERIFIED — HALT and ESCALATE |

### Step 4: Escalation Format

When escalation is required, Guardian MUST output:

```
🛡️ GUARDIAN HALT
Operation: [specific tool call]
Target: [file/path/database/endpoint]
Category: [taxonomy category]
Ris

_meta.json

{
  "ownerId": "kn77qg2t2rnb458ahv8751shv582rvm6",
  "slug": "data-guardian",
  "version": "1.2.0",
  "publishedAt": 1779715972040
}

DECISION-MATRIX.md

# Decision Matrix

Guardian's decision logic for every intercepted operation.

## Decision Tree

```
OPERATION detected
  │
  ├── Category: CRITICAL?
  │   ├── YES → BACKUP VERIFICATION required
  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED
  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE
  │   │   └── Backup UNKNOWN → HALT + ESCALATE (treat as UNVERIFIED)
  │   └──
  ├── Category: HIGH?
  │   ├── YES → BACKUP VERIFICATION required
  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED
  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE
  │   │   └── Backup UNKNOWN → HALT + ESCALATE
  │   └──
  ├── Category: MEDIUM?
  │   ├── YES → Context check
  │   │   ├── Target in protected path? → BACKUP VERIFICATION
  │   │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED
  │   │   │   └── Backup UNVERIFIED → HALT + ESCALATE
  │   │   └── Target not protected → LOG + PROCEED (with warning)
  │   └──
  └── Category: NON-DESTRUCTIVE
      └── LOG (minimal) + PROCEED (no delay)
```

## Backup Verification Logic

### Fast Check (<2 seconds)

Guardian checks backup status in priority order. First match wins.

| Priority | Indicator | Detection Method | Recency Threshold |
|----------|-----------|------------------|-------------------|
| 1 | Git repository | `.git/` exists, `git status` works | N/A (VCS covers tracked files) |
| 2 | Time Machine (macOS) | `tmutil listbackups` or `.timemachine` | <24 hours |
| 3 | File History (Windows) | `Get-History` or `fhmanagew.exe` | <24 hours |
| 4 | Cloud sync active | OneDrive/iCloud/Dropbox process running + recent sync timestamp | <1 hour |
| 5 | Explicit backup tool | `restic`, `duplicity`, `rsnapshot`, `borg` process or snapshot dir | <24 hours |
| 6 | ZFS snapshots | `zfs list -t snapshot` | <24 hours |
| 7 | S3 versioning | Object Versioning enabled on bucket | N/A |
| 8 | Database replication | `SHOW SLAVE STATUS`, `pg_is_in_backup()` | Active replication |

### Verification Result

| Result | Meaning | Action |
|--------|---------|--------|
| **VERIFIED ACTIVE** | At least one indicator shows active, recent backup | PROCEED |
| **STALE** | Backup exists but exceeds recency threshold | ESCALATE (with warning: "Backup is X hours old") |
| **UNVERIFIED** | No backup indicators found | ESCALATE |
| **PARTIAL** | Backup exists but doesn't cover target | ESCALATE (e.g., git doesn't cover untracked files) |

## Escalation Rules

### Who Decides

| Scenario | Approver | Timeout |
|----------|----------|---------|
| CRITICAL + no backup | Human operator required | Infinite (no auto-approve) |
| HIGH + no backup | Human operator required | Infinite |
| CRITICAL + stale backup | Human operator recommended | 5 minutes → auto-deny |
| HIGH + stale backup | Human operator recommended | 5 minutes → auto-deny |
| MEDIUM + no backup | Agent MAY self-approve with explicit justification | Log for audit |
| Repeated same pattern | Flag pattern, require operator review | N/A |

### Escalation Format

```
🛡️ GUARDIAN HALT
━━━━━━━

OPERATION-TAXONOMY.md

# Operation Taxonomy

Complete classification of destructive operations for AI agents.

## CRITICAL — Always Requires Verification

### File Destruction
| Operation | Pattern | Examples |
|-----------|---------|----------|
| rm / remove | `rm`, `rmdir`, `Remove-Item`, `del` | `rm -rf /tmp/old`, `Remove-Item *.log` |
| unlink | `unlink()`, `os.remove()` | Python file deletion |
| trash | `trash-cli`, `gio trash` | Move to system trash |
| empty-trash | `rm -rf ~/.Trash`, `Clear-RecycleBin` | Permanent deletion of trashed files |
| overwrite | Write to existing file without version control | `> file.txt` (clobber) |
| truncate | `truncate -s 0`, `fsutil` | Zero-length file without backup |

### Database Destruction
| Operation | Pattern | Examples |
|-----------|---------|----------|
| DROP | `DROP TABLE`, `DROP DATABASE` | Schema destruction |
| DELETE (unqualified) | `DELETE FROM table` (no WHERE) | Mass data deletion |
| TRUNCATE | `TRUNCATE TABLE` | Instant table empty |
| destructive migration | `down()` migration, `rollback` | Schema reversal with data loss |
| ALTER destructive | `ALTER TABLE ... DROP COLUMN` | Structural deletion |

## HIGH — Requires Verification

### External Transmission
| Operation | Pattern | Examples |
|-----------|---------|----------|
| send email | SMTP send, API email | `sendmail`, SES, SendGrid |
| post message | Social media API | Twitter/X, LinkedIn, Mastodon |
| publish | CMS publish, blog post | WordPress, Ghost, static site |
| API write | POST/PUT/DELETE to external | Any mutating external API call |
| webhook trigger | Outgoing webhook POST | Triggering external systems |

### Mass Operations
| Operation | Threshold | Examples |
|-----------|-----------|----------|
| bulk file modify | >10 files in single op | Batch rename, sed across directory |
| bulk delete | >10 files | `find . -name "*.tmp" -delete` |
| recursive operations | `**` glob, `-r` flag | `rm -rf`, `chmod -R` |

### System Changes
| Operation | Pattern | Examples |
|-----------|---------|----------|
| service control | `systemctl`, `Start-Service` | Stop/start/restart services |
| firewall modify | `iptables`, `netsh advfirewall` | Add/remove rules |
| registry edit | `reg add`, `Set-ItemProperty` | Windows registry changes |
| user management | `useradd`, `New-LocalUser` | Create/delete accounts |
| scheduled task | `schtasks`, `cron` | Add/remove automation |
| environment | `setx`, `[Environment]::SetEnvironmentVariable` | System-wide env vars |

## MEDIUM — Verify if Target is Important

### Network Unknown
| Operation | Pattern | Examples |
|-----------|---------|----------|
| new domain | URL not in known list | First call to api.newvendor.com |
| unverified endpoint | No prior successful calls | POST to unvalidated webhook |
| DNS change | `nsupdate`, registrar API | Pointing domain elsewhere |
| certificate | `certbot`, `New-SelfSignedCertificate` | TLS/SSL modifications |

### Configuration
| Operation | Pattern | Examples |
|------
Github ReposUpdated 16h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/tooled-app/skills/data-guardian",
      "sourceUrl": "https://clawhub.ai/tooled-app/skills/data-guardian",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:56:43.227Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:56:43.227Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.5K downloads",
      "href": "https://clawhub.ai/tooled-app/data-guardian",
      "sourceUrl": "https://clawhub.ai/tooled-app/data-guardian",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:56:43.227Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.2.0",
      "href": "https://clawhub.ai/tooled-app/data-guardian",
      "sourceUrl": "https://clawhub.ai/tooled-app/data-guardian",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-25T13:32:52.040Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.2.0",
      "description": "**Summary:** Major cleanup: removed documentation, references, and backup verification scripts to streamline the skill package. - Removed 7 files, including README, roadmap, descriptive tags, escalation references, taxonomy, and both Windows and Linux backup verification scripts. - No changes to the main protocol, rules, decision logic, or user-facing behavior. - All escalation and risk-scoring detail is retained in SKILL.md. - External documentation and backup verification are no longer bundled.",
      "href": "https://clawhub.ai/tooled-app/data-guardian",
      "sourceUrl": "https://clawhub.ai/tooled-app/data-guardian",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-25T13:32:52.040Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to Guardian and adjacent AI workflows.