agentCLAWHUBUnverified

ai-guardian

Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts). Always use this skill for "what local models are installed", "find shadow / unsanctioned AI models", "which model is loaded in VRAM", "scan this prompt for secrets/PII before sending", "stop secrets leaking into a local model", "block a prompt with an API key", "detect a jailbreak / prompt injection", "set a model allowlist / denylist", "detect a tampered / re-pulled model", "audit local LLM usage", "guard my llama.cpp / LM Studio / local vLLM endpoint", or "the complement to IGEL AI Armor". Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices. Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.

OpenClaw

Rank

62

Safety

84

Downloads

1.6k

Updated

Oct 10, 2026

Version

0.11.3

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.6K downloadsadoption · observed Oct 10, 2026
Latest release
0.11.3release · observed Sep 15, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:ai-guardian
  1. Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:ai-guardian` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/ai-guardian before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/snapshot"

Documentation

CLAWHUB

150,180 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: ai-guardian
slug: ai-guardian
displayName: "AI Guardian"
summary: "Governed local-LLM observability: model policy, prompt scanner, capture proxy, 21 tools."
license: MIT
homepage: https://github.com/AIops-tools/AI-Guardian
tags: [aiops, mcp, governance, ai-guardian]
description: >
  Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts).
  Always use this skill for "what local models are installed", "find shadow / unsanctioned AI models", "which model is loaded in VRAM", "scan this prompt for secrets/PII before sending", "stop secrets leaking into a local model", "block a prompt with an API key", "detect a jailbreak / prompt injection", "set a model allowlist / denylist", "detect a tampered / re-pulled model", "audit local LLM usage", "guard my llama.cpp / LM Studio / local vLLM endpoint", or "the complement to IGEL AI Armor".
  Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices.
  Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.
installer:
  kind: uv
  package: ai-guardian
argument-hint: "[model name, a prompt to scan, or describe your local-LLM task]"
allowed-tools:
  - Bash
metadata: {"openclaw":{"requires":{"anyBins":["ai-guardian","uvx"]},"optional":{"env":["AI_GUARDIAN_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/AI-Guardian","emoji":"🛡️","os":["macos","linux"]}}
compatibility: >
  Standalone, self-governed local-LLM (Ollama) observability + content governance. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
  Every tool call is audited to a local SQLite DB at ~/.ai-guardian/audit.db (relocatable via AI_GUARDIAN_AIOPS_HOME); the OBSERVED local-LLM usage log is a SEPARATE DB at ~/.ai-guardian/usage.db.
  Zero-config: ai-guardian defaults to the local Ollama at http://localhost:11434 with no token. Ollama endpoints usua

_meta.json

{
  "ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
  "slug": "ai-guardian",
  "version": "0.11.3",
  "publishedAt": 1789451141277
}

references/agent-guardrails.md

# Agent guardrails — running ai-guardian with a smaller / local model

There is a pleasing recursion here: ai-guardian governs local LLMs, and this page
is about driving ai-guardian *with* one. The same weaknesses this tool exists to
observe — a model that answers confidently without checking, that cannot tell
"unknown" from "none", that reports a truncated view as complete — are the ones
you will hit while operating it.

If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.

The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.

## Authorization is not this tool's job — decide it where it belongs

Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:

- **The host and account you run under.** Point the tool at a runtime the account
  cannot administer — an Ollama daemon whose model store the user can't modify —
  so a `remove_model` or `pull_model` fails at the runtime, the only place the
  permission actually lives. A revoked permission cannot be argued around by a
  model; a skill-side flag can.
- **Your agent's system prompt.** If you want an observe-only session, tell the
  model not to call the write tools (they are clearly tagged `[WRITE]`), or hand
  it only the scan/observe tools.

Content governance is different, and it stays: `guarded_generate` still scans and
gates each prompt against the allow/deny model policy and the block threshold
before the model runs. That is a product control over *what a model is asked to
do*, not an authorization gate over *which tools an agent may call*.

What the tool *does* guarantee is that you can always see what happened:

## What the tool enforces — do not waste prompt budget on these

| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Log everything you do, over both MCP and the CLI" | Every call is audited to `~/.ai-guardian/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. Observed local-LLM usage lives in a separate `~/.ai-guardian/usage.db`. |
| "Don't invent a digest / version / license" | A field the runtime cannot report comes back as `null`, never as `""`. This is load-bearing: Ollama and llama.cpp expose a pinnable identity, while LM Studio and vLLM expose only a model id. |
| "Don't call it tampering when you just can't tell" | `model_provenance` reports 

references/capabilities.md

# ai-guardian capabilities

> 21 MCP tools (11 read, 8 write, 2 undo) over Ollama's REST API
> (default `http://localhost:11434`, usually no auth). The scanner / policy /
> risk-band are pure deterministic offline logic; the Ollama paths need live
> verification.

## Read tools (10)

| Tool | Ollama endpoint / pure | Returns |
|------|------------------------|---------|
| `list_models` | `GET /api/tags` | per-model: name, digest, sizeBytes, family, parameterSize, quantization, modifiedAt, **allowed** (allow/deny verdict — shadow → `false`) |
| `running_models` | `GET /api/ps` | per-loaded-model: name, digest, sizeVramBytes, expiresAt, allowed |
| `model_details` | `POST /api/show` | model, license, family, parameterSize, quantization, capabilities[] |
| `server_status` | `GET /api/version` | reachable, version (or error) |
| `vram_usage` | `GET /api/ps` | loadedModels, totalVramBytes, budgetBytes, overBudget, models[] |
| `policy_view` | pure (reads config) | allowedModels, deniedModels, pinnedDigests, note |
| `model_provenance` | `GET /api/tags` + config | driftCount, pinnedCount, models[]{model, currentDigest, pinnedDigest, status: ok/DRIFT/unpinned} |
| `scan_prompt` | **pure** (no model call) | riskBand, findingCount, byCategory, findings[]{category, kind, severity, preview(redacted)} |
| `usage_events` | reads `usage.db` | count, events[] (filter by model / risk_level / allowed / since / limit) |
| `anomaly_report` | `GET /api/tags` + `usage.db` | shadowModels[], digestDrift[], highRiskPrompts, blockedPrompts, totalObserved |

## Write tools (8)

| Tool | Risk | Ollama endpoint / effect | Undo / safety |
|------|------|--------------------------|---------------|
| `pull_model` | medium | `POST /api/pull` | **refused if it violates the deny/allow policy** |
| `remove_model` | **high** | `DELETE /api/delete` | captures the model manifest; records an undo (`pull_model` re-pull); CLI `--dry-run` + double confirm |
| `unload_model` | medium | `POST /api/generate` `keep_alive:0` | evict from VRAM; no undo |
| `set_model_allowlist` | medium | writes `config.yaml` | undo → prior allowlist (immutable replace, not append) |
| `set_model_denylist` | medium | writes `config.yaml` | undo → prior denylist (deny patterns always win) |
| `pin_model_digest` | medium | writes `config.yaml` | pin a model's expected provenance digest; undo → prior pin |
| `guarded_generate` | medium | scan → policy-gate → record → `POST /api/generate` if allowed | blocks when risk band `>= block_threshold` (default `high`) OR model disallowed; blocked never reaches Ollama; raw prompt never stored |
| `observe_chat` | medium | scan → policy-gate → record → `POST /api/chat` if allowed | same, for OpenAI-style `[{role,content}]` messages |

## The deterministic scanner (behind `scan_prompt` / the route-through guards)

Pure, offline, no network. Categories and weighted risk band:

- **secrets** — AWS access key (`AKIA…`, critical), private-key blocks (critical),
  GitHub token (c

references/cli-reference.md

# ai-guardian CLI reference

> The CLI is a convenience subset; the full 21-tool surface
> is via MCP (`ai-guardian mcp`). Works zero-config against a local Ollama
> (`http://localhost:11434`).

## Setup & diagnostics

```bash
ai-guardian init                      # interactive wizard: Ollama endpoint(s) + optional token + model allowlist
ai-guardian doctor [--skip-auth]      # config + policy summary + Ollama reachability (/api/version)
ai-guardian mcp                       # start the MCP server (stdio transport)
```

## Overview

```bash
ai-guardian overview [--target <t>]   # models installed/running, shadow count, observed-usage stats
```

## Models (inventory + guarded lifecycle)

```bash
ai-guardian model list [--target <t>]         # installed models with allow/deny verdicts
ai-guardian model running [--target <t>]      # loaded models (VRAM + expiry)
ai-guardian model details <model>             # license / parameters / capabilities
ai-guardian model pull <model>                # pull a model (refused if it violates policy)
ai-guardian model remove <model> [--dry-run]  # (high) delete a local model; dry-run + double confirm; undo re-pull
ai-guardian model unload <model>              # (medium) evict from VRAM (keep_alive:0)
```

## Guard (policy, provenance, prompt scanning, usage, anomalies)

```bash
ai-guardian guard policy                      # current model allow/deny policy + digest pins
ai-guardian guard provenance [--target <t>]   # installed digests vs their pins (drift detection)
ai-guardian guard scan "<text>"               # deterministic scan → findings + risk band (no model call)
ai-guardian guard usage [--limit 50]          # query the observed-usage log
ai-guardian guard anomalies [--target <t>]    # rollup: shadow models, digest drift, high-risk + blocked prompts
```

## Secrets (encrypted store ~/.ai-guardian/secrets.enc)

A bearer token is optional (rare for local Ollama).

```bash
ai-guardian secret set <target> [--value <token>]  # store a token (hidden prompt if no --value)
ai-guardian secret list                            # names only — values never shown
ai-guardian secret rm <target>
ai-guardian secret migrate                         # import legacy plaintext .env (AI_GUARDIAN_<T>_TOKEN)
ai-guardian secret rotate-password                 # re-encrypt under a new master password
```

## Common options & notes

- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target, i.e. the local Ollama)
- `--dry-run` (on `model remove`) — print the API call that would be made, change nothing
- `model remove` requires two confirmations; set `AI_GUARDIAN_AUDIT_APPROVED_BY` (+ `AI_GUARDIAN_AUDIT_RATIONALE`) to record who/why on the audit row (optional)
- The route-through guards (`guarded_generate` / `observe_chat`) are MCP-only; use `guard scan` on the CLI to pre-check text without a model call
Github ReposUpdated 15h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/zw008/skills/ai-guardian",
      "sourceUrl": "https://clawhub.ai/zw008/skills/ai-guardian",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T08:04:33.876Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T08:04:33.876Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.6K downloads",
      "href": "https://clawhub.ai/zw008/ai-guardian",
      "sourceUrl": "https://clawhub.ai/zw008/ai-guardian",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T08:04:33.876Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.11.3",
      "href": "https://clawhub.ai/zw008/ai-guardian",
      "sourceUrl": "https://clawhub.ai/zw008/ai-guardian",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-15T05:45:41.277Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.11.3",
      "description": "ai-guardian v0.11.3 - Removed the file: skill-card.md - No added features or functional changes in this release - The skill continues to provide local LLM observability and governance for Ollama, llama.cpp, LM Studio, and local vLLM environments",
      "href": "https://clawhub.ai/zw008/ai-guardian",
      "sourceUrl": "https://clawhub.ai/zw008/ai-guardian",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-15T05:45:41.277Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to ai-guardian and adjacent AI workflows.