ai-guardian
Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts). Always use this skill for "what local models are installed", "find shadow / unsanctioned AI models", "which model is loaded in VRAM", "scan this prompt for secrets/PII before sending", "stop secrets leaking into a local model", "block a prompt with an API key", "detect a jailbreak / prompt injection", "set a model allowlist / denylist", "detect a tampered / re-pulled model", "audit local LLM usage", "guard my llama.cpp / LM Studio / local vLLM endpoint", or "the complement to IGEL AI Armor". Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices. Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.11.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.11.3release · observed Sep 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:ai-guardian- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:ai-guardian` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/ai-guardian before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/snapshot"
Documentation
CLAWHUB
150,180 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: ai-guardian
slug: ai-guardian
displayName: "AI Guardian"
summary: "Governed local-LLM observability: model policy, prompt scanner, capture proxy, 21 tools."
license: MIT
homepage: https://github.com/AIops-tools/AI-Guardian
tags: [aiops, mcp, governance, ai-guardian]
description: >
Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts).
Always use this skill for "what local models are installed", "find shadow / unsanctioned AI models", "which model is loaded in VRAM", "scan this prompt for secrets/PII before sending", "stop secrets leaking into a local model", "block a prompt with an API key", "detect a jailbreak / prompt injection", "set a model allowlist / denylist", "detect a tampered / re-pulled model", "audit local LLM usage", "guard my llama.cpp / LM Studio / local vLLM endpoint", or "the complement to IGEL AI Armor".
Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices.
Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.
installer:
kind: uv
package: ai-guardian
argument-hint: "[model name, a prompt to scan, or describe your local-LLM task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["ai-guardian","uvx"]},"optional":{"env":["AI_GUARDIAN_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/AI-Guardian","emoji":"🛡️","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed local-LLM (Ollama) observability + content governance. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
Every tool call is audited to a local SQLite DB at ~/.ai-guardian/audit.db (relocatable via AI_GUARDIAN_AIOPS_HOME); the OBSERVED local-LLM usage log is a SEPARATE DB at ~/.ai-guardian/usage.db.
Zero-config: ai-guardian defaults to the local Ollama at http://localhost:11434 with no token. Ollama endpoints usua_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "ai-guardian",
"version": "0.11.3",
"publishedAt": 1789451141277
}references/agent-guardrails.md
# Agent guardrails — running ai-guardian with a smaller / local model There is a pleasing recursion here: ai-guardian governs local LLMs, and this page is about driving ai-guardian *with* one. The same weaknesses this tool exists to observe — a model that answers confidently without checking, that cannot tell "unknown" from "none", that reports a truncated view as complete — are the ones you will hit while operating it. If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose, Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably better results with a short system prompt. This page gives you one, and — more importantly — tells you which guardrails you **no longer need to write**, because the tool now enforces them itself. The distinction matters. A guardrail in a prompt is a request. A guardrail in the harness is a guarantee. Anything below that we could move into the harness, we did. ## Authorization is not this tool's job — decide it where it belongs Whether a write should happen is your decision, or the account's. The tool does not gate it — there is no read-only switch and no approval prompt to configure. The two right places to control read vs write: - **The host and account you run under.** Point the tool at a runtime the account cannot administer — an Ollama daemon whose model store the user can't modify — so a `remove_model` or `pull_model` fails at the runtime, the only place the permission actually lives. A revoked permission cannot be argued around by a model; a skill-side flag can. - **Your agent's system prompt.** If you want an observe-only session, tell the model not to call the write tools (they are clearly tagged `[WRITE]`), or hand it only the scan/observe tools. Content governance is different, and it stays: `guarded_generate` still scans and gates each prompt against the allow/deny model policy and the block threshold before the model runs. That is a product control over *what a model is asked to do*, not an authorization gate over *which tools an agent may call*. What the tool *does* guarantee is that you can always see what happened: ## What the tool enforces — do not waste prompt budget on these | You might be tempted to prompt | Why you don't need to | |---|---| | "Log everything you do, over both MCP and the CLI" | Every call is audited to `~/.ai-guardian/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. Observed local-LLM usage lives in a separate `~/.ai-guardian/usage.db`. | | "Don't invent a digest / version / license" | A field the runtime cannot report comes back as `null`, never as `""`. This is load-bearing: Ollama and llama.cpp expose a pinnable identity, while LM Studio and vLLM expose only a model id. | | "Don't call it tampering when you just can't tell" | `model_provenance` reports
references/capabilities.md
# ai-guardian capabilities
> 21 MCP tools (11 read, 8 write, 2 undo) over Ollama's REST API
> (default `http://localhost:11434`, usually no auth). The scanner / policy /
> risk-band are pure deterministic offline logic; the Ollama paths need live
> verification.
## Read tools (10)
| Tool | Ollama endpoint / pure | Returns |
|------|------------------------|---------|
| `list_models` | `GET /api/tags` | per-model: name, digest, sizeBytes, family, parameterSize, quantization, modifiedAt, **allowed** (allow/deny verdict — shadow → `false`) |
| `running_models` | `GET /api/ps` | per-loaded-model: name, digest, sizeVramBytes, expiresAt, allowed |
| `model_details` | `POST /api/show` | model, license, family, parameterSize, quantization, capabilities[] |
| `server_status` | `GET /api/version` | reachable, version (or error) |
| `vram_usage` | `GET /api/ps` | loadedModels, totalVramBytes, budgetBytes, overBudget, models[] |
| `policy_view` | pure (reads config) | allowedModels, deniedModels, pinnedDigests, note |
| `model_provenance` | `GET /api/tags` + config | driftCount, pinnedCount, models[]{model, currentDigest, pinnedDigest, status: ok/DRIFT/unpinned} |
| `scan_prompt` | **pure** (no model call) | riskBand, findingCount, byCategory, findings[]{category, kind, severity, preview(redacted)} |
| `usage_events` | reads `usage.db` | count, events[] (filter by model / risk_level / allowed / since / limit) |
| `anomaly_report` | `GET /api/tags` + `usage.db` | shadowModels[], digestDrift[], highRiskPrompts, blockedPrompts, totalObserved |
## Write tools (8)
| Tool | Risk | Ollama endpoint / effect | Undo / safety |
|------|------|--------------------------|---------------|
| `pull_model` | medium | `POST /api/pull` | **refused if it violates the deny/allow policy** |
| `remove_model` | **high** | `DELETE /api/delete` | captures the model manifest; records an undo (`pull_model` re-pull); CLI `--dry-run` + double confirm |
| `unload_model` | medium | `POST /api/generate` `keep_alive:0` | evict from VRAM; no undo |
| `set_model_allowlist` | medium | writes `config.yaml` | undo → prior allowlist (immutable replace, not append) |
| `set_model_denylist` | medium | writes `config.yaml` | undo → prior denylist (deny patterns always win) |
| `pin_model_digest` | medium | writes `config.yaml` | pin a model's expected provenance digest; undo → prior pin |
| `guarded_generate` | medium | scan → policy-gate → record → `POST /api/generate` if allowed | blocks when risk band `>= block_threshold` (default `high`) OR model disallowed; blocked never reaches Ollama; raw prompt never stored |
| `observe_chat` | medium | scan → policy-gate → record → `POST /api/chat` if allowed | same, for OpenAI-style `[{role,content}]` messages |
## The deterministic scanner (behind `scan_prompt` / the route-through guards)
Pure, offline, no network. Categories and weighted risk band:
- **secrets** — AWS access key (`AKIA…`, critical), private-key blocks (critical),
GitHub token (creferences/cli-reference.md
# ai-guardian CLI reference > The CLI is a convenience subset; the full 21-tool surface > is via MCP (`ai-guardian mcp`). Works zero-config against a local Ollama > (`http://localhost:11434`). ## Setup & diagnostics ```bash ai-guardian init # interactive wizard: Ollama endpoint(s) + optional token + model allowlist ai-guardian doctor [--skip-auth] # config + policy summary + Ollama reachability (/api/version) ai-guardian mcp # start the MCP server (stdio transport) ``` ## Overview ```bash ai-guardian overview [--target <t>] # models installed/running, shadow count, observed-usage stats ``` ## Models (inventory + guarded lifecycle) ```bash ai-guardian model list [--target <t>] # installed models with allow/deny verdicts ai-guardian model running [--target <t>] # loaded models (VRAM + expiry) ai-guardian model details <model> # license / parameters / capabilities ai-guardian model pull <model> # pull a model (refused if it violates policy) ai-guardian model remove <model> [--dry-run] # (high) delete a local model; dry-run + double confirm; undo re-pull ai-guardian model unload <model> # (medium) evict from VRAM (keep_alive:0) ``` ## Guard (policy, provenance, prompt scanning, usage, anomalies) ```bash ai-guardian guard policy # current model allow/deny policy + digest pins ai-guardian guard provenance [--target <t>] # installed digests vs their pins (drift detection) ai-guardian guard scan "<text>" # deterministic scan → findings + risk band (no model call) ai-guardian guard usage [--limit 50] # query the observed-usage log ai-guardian guard anomalies [--target <t>] # rollup: shadow models, digest drift, high-risk + blocked prompts ``` ## Secrets (encrypted store ~/.ai-guardian/secrets.enc) A bearer token is optional (rare for local Ollama). ```bash ai-guardian secret set <target> [--value <token>] # store a token (hidden prompt if no --value) ai-guardian secret list # names only — values never shown ai-guardian secret rm <target> ai-guardian secret migrate # import legacy plaintext .env (AI_GUARDIAN_<T>_TOKEN) ai-guardian secret rotate-password # re-encrypt under a new master password ``` ## Common options & notes - `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target, i.e. the local Ollama) - `--dry-run` (on `model remove`) — print the API call that would be made, change nothing - `model remove` requires two confirmations; set `AI_GUARDIAN_AUDIT_APPROVED_BY` (+ `AI_GUARDIAN_AUDIT_RATIONALE`) to record who/why on the audit row (optional) - The route-through guards (`guarded_generate` / `observe_chat`) are MCP-only; use `guard scan` on the CLI to pre-check text without a model call
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/ai-guardian",
"sourceUrl": "https://clawhub.ai/zw008/skills/ai-guardian",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:04:33.876Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T08:04:33.876Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/zw008/ai-guardian",
"sourceUrl": "https://clawhub.ai/zw008/ai-guardian",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:04:33.876Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.11.3",
"href": "https://clawhub.ai/zw008/ai-guardian",
"sourceUrl": "https://clawhub.ai/zw008/ai-guardian",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:45:41.277Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.11.3",
"description": "ai-guardian v0.11.3 - Removed the file: skill-card.md - No added features or functional changes in this release - The skill continues to provide local LLM observability and governance for Ollama, llama.cpp, LM Studio, and local vLLM environments",
"href": "https://clawhub.ai/zw008/ai-guardian",
"sourceUrl": "https://clawhub.ai/zw008/ai-guardian",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:45:41.277Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
