clawsec-nanoclaw
Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Skill: clawsec-nanoclaw Summary: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Tags: latest:0.0.10 Version history: v0.0.10 | 2026-06-23T08:22:27.400Z | user Release 0.0.10 via CI v0.0.8 | 2026-06-10T14:59:12.174Z | user Release 0.0.8 via CI v0.0.7 | 2026-06-07T10:06:18.365Z | user Release 0.0.7 via CI v0.0.6
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
0.0.10
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.0.10release · observed Jun 23, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install unknown:clawsec-nanoclaw- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/snapshot"
Documentation
CLAWHUB
148,209 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: clawsec-nanoclaw
version: 0.0.10
description: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
---
# ClawSec for NanoClaw
Security advisory monitoring that protects your WhatsApp bot from known vulnerabilities in skills and dependencies.
## Vercel Skills Installation
Install with the Vercel Skills CLI for this harness:
```bash
npx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y
```
## Overview
ClawSec provides MCP tools that check installed skills against a curated feed of security advisories. It prevents installation of vulnerable skills, includes exploitability context for triage, and alerts you to issues in existing ones.
**Core principle:** Check before you install. Monitor what's running.
## When to Use
Use ClawSec tools when:
- Installing a new skill (check safety first)
- User asks "are my skills secure?"
- Investigating suspicious behavior
- Regular security audits
- After receiving security notifications
Do NOT use for:
- Code review (use other tools)
- Performance issues (different concern)
- General debugging
## MCP Tools Available
### Pre-Installation Check
```typescript
// Before installing any skill
const safety = await tools.clawsec_check_skill_safety({
skillName: 'new-skill',
skillVersion: '1.0.0' // optional
});
if (!safety.safe) {
// Show user the risks before proceeding
console.warn(`Security issues: ${safety.advisories.map(a => a.id)}`);
}
```
### Security Audit
```typescript
// Check all installed skills (defaults to ~/.claude/skills in the container)
const result = await tools.clawsec_check_advisories({
installRoot: '/home/node/.claude/skills' // optional
});
if (result.matches.some((m) =>
m.advisory.severity === 'critical' || m.advisory.exploitability_score === 'high'
)) {
// Alert user immediately
console.error('Urgent advisories found!');
}
```
### Browse Advisories
```typescript
// List advisories with filters
const advisories = await tools.clawsec_list_advisories({
severity: 'high', // optional
exploitabilityScore: 'high' // optional
});
```
## Quick Reference
| Task | Tool | Key Parameter |
|------|------|---------------|
| Pre-install check | `clawsec_check_skill_safety` | `skillName` |
| Audit all skills | `clawsec_check_advisories` | `installRoot` (optional) |
| Browse feed | `clawsec_list_advisories` | `severity`, `type`, `exploitabilityScore` (optional) |
| Verify package signature | `clawsec_verify_skill_package` | `packagePath` |
| Refresh advisory cache | `clawsec_refresh_cache` | (none) |
| Check file integrity | `clawsec_check_integrity` | `mode`, `autoRestore` (optional) |
| Approve file change | `clawsec_approve_change` | `path` |
| View baseline status | `clawsec_integrity_status` | `path` (optional) |
| Verify audit log | `clawsec_verify_audit` | (none) |
## Common Patterns
### Pattern 1: Safe Skill InREADME.md
# ClawSec for NanoClaw
ClawSec now supports NanoClaw, a containerized WhatsApp bot powered by Claude agents.
## Vercel Skills Installation
Install with the Vercel Skills CLI for this harness:
```bash
npx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y
```
## What Changed
### Advisory Feed Monitoring
- **NVD CVE Pipeline**: Now monitors for NanoClaw-specific keywords
- "NanoClaw", "WhatsApp-bot", "baileys" (WhatsApp library)
- Container-related vulnerabilities
- **Platform Targeting**: Advisories can specify `platforms: ["nanoclaw"]` for NanoClaw-specific issues
### Keywords Added
The CVE monitoring now includes:
- `NanoClaw` - Direct product name
- `WhatsApp-bot` - Core functionality
- `baileys` - WhatsApp client library dependency
## Advisory Schema
Advisories now support optional `platforms` field:
```json
{
"id": "CVE-2026-XXXXX",
"platforms": ["openclaw", "nanoclaw"],
"severity": "critical",
"type": "prompt_injection",
"affected": ["[email protected]"],
"action": "Update to version 1.0.1"
}
```
**Platform values:**
- `"openclaw"` - Affects OpenClaw/ClawdBot/MoltBot only
- `"nanoclaw"` - Affects NanoClaw only
- `["openclaw", "nanoclaw"]` - Affects both platforms
- (empty/missing) - Applies to all platforms (backward compatible)
## ClawSec NanoClaw Skill
ClawSec provides a complete security skill for NanoClaw deployments:
**Location**: `skills/clawsec-nanoclaw/`
### Features
- **9 MCP Tools** for agents to manage security:
- `clawsec_check_advisories` - Scan installed skills for vulnerabilities
- `clawsec_check_skill_safety` - Pre-installation safety checks
- `clawsec_list_advisories` - Browse advisory feed with filtering
- `clawsec_refresh_cache` - Request immediate advisory cache refresh
- `clawsec_verify_skill_package` - Verify Ed25519 signatures on skill packages
- `clawsec_check_integrity` - Check protected files for unauthorized changes
- `clawsec_approve_change` - Approve intentional file modifications
- `clawsec_integrity_status` - View file baseline status
- `clawsec_verify_audit` - Verify audit log hash chain
- **Advisory Cache Service**: Host-managed feed fetching with signature validation
- **Signature Verification**: Ed25519-signed feeds ensure integrity
- **Exploitability Context**: Surfaces `exploitability_score` and rationale to reduce alert fatigue
- **IPC Communication**: Container-safe host communication
### Installation
1. Copy the skill to your NanoClaw deployment:
```bash
cp -r skills/clawsec-nanoclaw /path/to/nanoclaw/skills/
```
2. Follow the detailed guide at `skills/clawsec-nanoclaw/INSTALL.md`
### Quick Integration
The skill integrates into three places:
**1. MCP Tools** (container):
```typescript
// container/agent-runner/src/ipc-mcp-stdio.ts
import '../../../skills/clawsec-nanoclaw/mcp-tools/advisory-tools.js';
```
**2. IPC Handlers** (host):
```typescript
// src/ipc.ts
import { handleAdvisoryIpc } from '../skills/clawsec-na_meta.json
{
"ownerId": "kn76m78f01hqrtpgm895s0jsax80jd8v",
"slug": "clawsec-nanoclaw",
"version": "0.0.10",
"publishedAt": 1782202947400
}CHANGELOG.md
# Changelog ## [0.0.10] - 2026-06-23 ### Changed - Re-released skill metadata to run through the corrected normal tag publish pipeline without runtime changes. ## [0.0.9] - 2026-06-22 ### Changed - Re-released skill metadata to publish through the updated ClawHub pipeline without runtime changes. ## [0.0.8] - 2026-06-10 ### Changed - Re-released skill package with updated marketplace grouping and signed release trust artifacts for Vercel-compatible skill installation. ## [0.0.7] - 2026-06-07 ### Security - Added comparator range support for NanoClaw advisory matching and fail-closed handling for malformed affected specifiers. - Added strict integrity IPC request ID validation and result path containment before host-side result writes. ## [0.0.6] - 2026-05-24 ### Changed - Documented that NanoClaw consumes the consolidated signed advisory feed containing NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records. - Added advisory metadata typing for GHSA lifecycle fields used by the consolidated feed. ## [0.0.5] - 2026-05-14 ### Security - Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks. All notable changes to the ClawSec NanoClaw compatibility skill will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). ## [0.0.4] - 2026-04-16 ### Changed - Moved signature-related local file reads into `lib/local_file_io.ts` and kept network fetch logic isolated in `lib/signatures.ts`. ### Security - Reduced static false-positive exfiltration signals by separating local file I/O and remote fetch code paths. ## [0.0.3] - 2026-03-09 ### Security - Removed runtime public-key override from host-side package signature verification; verification now always uses the pinned ClawSec key. - Removed unsigned-package override path in host-side verification flow. - Added strict package/signature path policy for signature verification (`/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`) with absolute-path, extension, symlink, and realpath boundary checks. - Added policy-bound path enforcement for integrity approvals: approvals now require normalized paths that are explicitly present in non-ignored integrity policy targets. ### Changed - Updated MCP signature verification tool docs and behavior to align with bounded path policy and pinned-key-only verification. - Added regression tests for signature-verification and integrity-approval hardening invariants. ## [0.0.2] - 2026-02-28 ### Added - Exploitability-aware advisory output in NanoClaw MCP tools (`exploitability_score`, `exploitability_rationale`). - Exploitability filtering (`expl
docs/INTEGRITY.md
# File Integrity Monitoring for NanoClaw
ClawSec's file integrity monitoring protects critical NanoClaw configuration files from unauthorized modification.
## What It Does
**Protects Critical Files:**
- `registered_groups.json` - Prevents unauthorized group access
- `CLAUDE.md` files - Protects agent instructions
- Container/host code - Alerts on unexpected changes
**How It Works:**
1. **Baseline**: Stores SHA-256 hashes of approved file states
2. **Monitoring**: Periodically checks files for changes (drift)
3. **Restore**: Automatically reverts critical files to approved versions
4. **Audit**: Maintains tamper-evident log of all operations
## Quick Start
### Step 1: Verify Installation
Check that integrity monitoring is available:
```bash
# From container
ls /workspace/project/skills/clawsec-nanoclaw/guardian/
# Should show: policy.json, integrity-monitor.ts
```
### Step 2: Initialize Baselines
The first time integrity monitoring runs, it creates baselines automatically:
```typescript
// Agent calls this (happens automatically on first integrity check)
await tools.clawsec_check_integrity();
```
This creates:
```
/workspace/project/data/soul-guardian/
├── baselines.json # SHA-256 hashes
├── approved/ # File snapshots
│ ├── registered_groups.json
│ └── CLAUDE.md
├── patches/ # Diffs (empty initially)
├── quarantine/ # Tampered files (empty initially)
└── audit.jsonl # Event log
```
### Step 3: Enable Scheduled Monitoring
Add to main group's scheduled tasks:
```typescript
schedule_task({
prompt: `
Check file integrity with clawsec_check_integrity.
If drift detected and files restored, send WhatsApp message:
"⚠️ SECURITY ALERT
Unauthorized changes detected and automatically reverted:
[list files that were restored]
Review details: /workspace/project/data/soul-guardian/patches/"
`,
schedule_type: 'cron',
schedule_value: '*/30 * * * *', // Every 30 minutes
context_mode: 'isolated'
});
```
That's it! Integrity monitoring is now active.
## MCP Tools Reference
### 1. `clawsec_check_integrity`
Check all protected files for unauthorized changes.
**Parameters:**
- `mode` (optional): `'check'` (default) or `'status'`
- `check`: Detect drift and auto-restore
- `status`: View baselines only (no drift detection)
- `autoRestore` (optional): `true` (default) or `false`
- If `false`, drift is detected but not auto-fixed
**Output:**
```json
{
"success": true,
"timestamp": "2026-02-25T12:00:00Z",
"drift_detected": false,
"files": [
{
"path": "/workspace/project/data/registered_groups.json",
"status": "ok",
"mode": "restore",
"expected_sha": "abc123...",
"found_sha": "abc123..."
}
],
"summary": {
"total": 3,
"ok": 3,
"drifted": 0,
"restored": 0,
"alerted": 0,
"errors": 0
}
}
```
**Example:**
```typescript
const result = await tools.clawsec_check_integrity();
if (result.drift_deAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/unknown/skills/clawsec-nanoclaw",
"sourceUrl": "https://clawhub.ai/unknown/skills/clawsec-nanoclaw",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T22:38:56.374Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T22:38:56.374Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/unknown/clawsec-nanoclaw",
"sourceUrl": "https://clawhub.ai/unknown/clawsec-nanoclaw",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T22:38:56.374Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.0.10",
"href": "https://clawhub.ai/unknown/clawsec-nanoclaw",
"sourceUrl": "https://clawhub.ai/unknown/clawsec-nanoclaw",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-23T08:22:27.400Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.0.10",
"description": "Release 0.0.10 via CI",
"href": "https://clawhub.ai/unknown/clawsec-nanoclaw",
"sourceUrl": "https://clawhub.ai/unknown/clawsec-nanoclaw",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-23T08:22:27.400Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
