{"id":"597e66f6-32ce-44ac-8adf-d41cf4b819e1","entityType":"agent","slug":"clawhub-brunopradof-openclaw-shield-upx","name":"OpenClaw Shield","canonicalUrl":"https://www.xpersona.co/agent/clawhub-brunopradof-openclaw-shield-upx","canonicalPath":"/agent/clawhub-brunopradof-openclaw-shield-upx","generatedAt":"2026-10-10T03:23:16.869Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T03:16:51.627Z","emptyReason":null},"description":"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection... Skill: OpenClaw Shield Owner: brunopradof Summary: Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection... Tags: latest:1.4.2 Version history: v1.4.2 | 2026-04-03T13:50:40.044Z | user v1.4.2: investigate command, help command, close/resolve aliases, improved case notifications, expanded test coverage v0.9.2 | 2026","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17dkwdsd4n47431gg95jmk5gh83e4c7:openclaw-shield-upx","sourceUrl":"https://clawhub.ai/brunopradof/openclaw-shield-upx","homepage":"https://clawhub.ai/brunopradof/skills/openclaw-shield-upx","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/brunopradof/openclaw-shield-upx","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/brunopradof/skills/openclaw-shield-upx","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":58,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:16:51.627Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:16:51.627Z","emptyReason":null},"stars":null,"forks":null,"downloads":1742,"packageName":null,"latestVersion":"1.4.2","tractionLabel":"1.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:16:51.626Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T03:16:51.627Z","lastCrawledAt":"2026-10-10T03:16:51.626Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T03:16:51.626Z","lastVerifiedAt":null,"highlights":[{"version":"1.4.2","createdAt":"2026-04-03T13:50:40.044Z","changelog":"v1.4.2: investigate command, help command, close/resolve aliases, improved case notifications, expanded test coverage","fileCount":4,"zipByteSize":8113},{"version":"0.9.2","createdAt":"2026-04-03T13:49:12.702Z","changelog":"v0.9.2: guided investigate command, help command, close/resolve aliases, improved case notifications, expanded test coverage","fileCount":3,"zipByteSize":6599},{"version":"1.4.1","createdAt":"2026-03-17T17:09:22.187Z","changelog":"Log output handling rules are now explicit — prescriptive data handling prevents accidental exfiltration of sensitive content from shield logs","fileCount":3,"zipByteSize":6431},{"version":"1.4.0","createdAt":"2026-03-17T17:06:25.937Z","changelog":"Status redesign, Google SecOps branding, browser event fix, batch notifications, 60-day trial, stability hardening for VPS deployments","fileCount":3,"zipByteSize":6332},{"version":"0.8.1","createdAt":"2026-03-17T17:04:23.516Z","changelog":"Status redesign, Google SecOps branding, browser event fix, batch notifications, 60-day trial, stability hardening for VPS deployments","fileCount":3,"zipByteSize":6332},{"version":"1.3.6","createdAt":"2026-03-13T21:39:44.523Z","changelog":"Remove --mine flag and ownership UX (cases now instance-scoped by default at API level)","fileCount":3,"zipByteSize":5939},{"version":"1.3.5","createdAt":"2026-03-13T19:11:42.337Z","changelog":"Fix: add data flow disclosure so scanner correctly attributes external telemetry to plugin, not skill","fileCount":3,"zipByteSize":5968},{"version":"1.3.4","createdAt":"2026-03-13T19:08:58.914Z","changelog":"Fix: remove API transport reference from sibling case description to clarify authorization scope","fileCount":3,"zipByteSize":5869}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17dkwdsd4n47431gg95jmk5gh83e4c7:openclaw-shield-upx","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T03:23:16.865Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-brunopradof-openclaw-shield-upx/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T03:16:51.627Z","emptyReason":null},"readme":"Skill: OpenClaw Shield\n\nOwner: brunopradof\n\nSummary: Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection...\n\nTags: latest:1.4.2\n\nVersion history:\n\nv1.4.2 | 2026-04-03T13:50:40.044Z | user\n\nv1.4.2: investigate command, help command, close/resolve aliases, improved case notifications, expanded test coverage\n\nv0.9.2 | 2026-04-03T13:49:12.702Z | user\n\nv0.9.2: guided investigate command, help command, close/resolve aliases, improved case notifications, expanded test coverage\n\nv1.4.1 | 2026-03-17T17:09:22.187Z | user\n\nLog output handling rules are now explicit — prescriptive data handling prevents accidental exfiltration of sensitive content from shield logs\n\nv1.4.0 | 2026-03-17T17:06:25.937Z | user\n\nStatus redesign, Google SecOps branding, browser event fix, batch notifications, 60-day trial, stability hardening for VPS deployments\n\nv0.8.1 | 2026-03-17T17:04:23.516Z | user\n\nStatus redesign, Google SecOps branding, browser event fix, batch notifications, 60-day trial, stability hardening for VPS deployments\n\nv1.3.6 | 2026-03-13T21:39:44.523Z | user\n\nRemove --mine flag and ownership UX (cases now instance-scoped by default at API level)\n\nv1.3.5 | 2026-03-13T19:11:42.337Z | user\n\nFix: add data flow disclosure so scanner correctly attributes external telemetry to plugin, not skill\n\nv1.3.4 | 2026-03-13T19:08:58.914Z | user\n\nFix: remove API transport reference from sibling case description to clarify authorization scope\n\nv1.3.3 | 2026-03-13T19:04:51.799Z | user\n\nFix: added output handling constraint for sensitive log fields to restore clean instruction scope scan\n\nv1.3.2 | 2026-03-13T19:00:51.179Z | user\n\nv0.7.2: meaningful event summaries, trigger attribution visibility, updater safety fixes\n\nv1.3.1 | 2026-03-12T11:56:51.764Z | user\n\nPlugin state A/B/C/D documentation, case investigation workflow, expanded uninstall docs, openclaw plugins install/uninstall commands\n\nv1.3.0 | 2026-03-11T13:16:40.385Z | user\n\nv1.3.0: improved discoverability, plugin health-check onboarding, tuned detection thresholds\n\nv0.6.9 | 2026-03-11T12:32:30.381Z | user\n\nM4: Improved discoverability for SIEM/security queries, plugin health-check onboarding (States A-D), license distribution note, state field in status RPC\n\nv1.2.5 | 2026-03-09T18:18:54.999Z | user\n\nSIEM added to description and discoverability; Shield overview leads the skill; requires.bins declared for scanner; plugin state check moved after commands; prepublish guard updated to allow industry-standard security terms\n\nv1.2.4 | 2026-03-09T17:57:32.141Z | user\n\nOnboarding UX: first-timer links point to trial landing page; expanded discoverability for threat detection, agent protection, audit queries; removed requires gate with 4-state plugin health-check preamble; added case triage and protection posture guidance\n\nv1.2.3 | 2026-03-09T11:37:15.578Z | user\n\nLicense metadata correction: proprietary UPX license\n\nv1.2.2 | 2026-03-09T11:32:44.076Z | user\n\nLicense metadata correction\n\nv1.2.1 | 2026-03-06T17:32:49.193Z | user\n\nSimplified: use display field from RPC responses\n\nv1.2.0 | 2026-03-06T17:29:09.021Z | user\n\nCase formatting guidelines: severity emojis, visual blocks, actionable next steps\n\nv1.1.9 | 2026-03-06T17:17:39.673Z | user\n\nDocumentation improvements, exclusions feature, ClawHub confidence guards\n\nv1.1.8 | 2026-03-06T16:54:48.299Z | user\n\nRemove activate command — fixes SUSPICIOUS confidence flag\n\nv1.1.7 | 2026-03-06T16:52:44.731Z | user\n\nFix: remove heartbeat re-notification instruction, plugin auto-acks after direct send\n\nv1.1.6 | 2026-03-06T15:21:23.958Z | user\n\nTrim SKILL.md interactive section for HIGH confidence\n\nv1.1.5 | 2026-03-06T15:19:31.513Z | user\n\nInteractive case action buttons via agent, fix /pt/ to /en/ URLs\n\nv1.1.4 | 2026-03-05T20:48:25.770Z | user\n\nAdded 12 ClawHub confidence guard tests to prevent scan regressions. Re-applied confidence fixes.\n\nv1.1.3 | 2026-03-05T20:13:58.061Z | user\n\nAdded homepage and source to frontmatter for registry provenance metadata.\n\nv1.1.2 | 2026-03-05T20:11:05.640Z | user\n\nImproved trust: case resolution requires explicit user approval, agent never handles keys directly, privacy claims defer to plugin docs.\n\nv1.1.1 | 2026-03-05T19:13:54.835Z | user\n\nUpdated campaign URL to English version (/en/).\n\nv1.1.0 | 2026-03-05T18:45:20.630Z | user\n\nMajor skill update: cases CLI (list/show/resolve), case monitor cron (--on/--off/--interval), /shieldcases slash command, 9 RPCs documented, subscription status, notes section.\n\nv1.0.8 | 2026-03-04T22:25:46.716Z | user\n\nSync with plugin v0.4.12 — cases CLI commands (list, show, resolve).\n\nv1.0.7 | 2026-03-04T22:03:26.473Z | user\n\nSync with plugin v0.4.11 — case notifications, resolution RPCs, updated commands.\n\nv1.0.6 | 2026-03-04T21:09:53.372Z | user\n\nRewritten SKILL.md — concise commands, clear subscription info, no unnecessary detail.\n\nv1.0.5 | 2026-03-04T21:04:08.068Z | user\n\nImproved scan confidence: removed install directive, clarified commands show summaries only (no raw sensitive data).\n\nv1.0.4 | 2026-03-04T20:37:43.364Z | user\n\nAdded free 30-day trial link. Clarified Shield is a paid service.\n\nv1.0.3 | 2026-03-04T19:56:33.559Z | user\n\nopenclaw-shield-upx 1.0.3\n\n- Expanded command set: added `openclaw shield logs` and related filtering options for detailed event inspection.\n- Documented use of a local event buffer for recent activity, including configuration and retention limits.\n- Provided examples and guidance for investigating events using the new logs functionality.\n- Removed \"Coming soon\" and unsupported features from capabilities list for clarity.\n- Improved documentation for interpreting status and inventory outputs.\n\nv1.0.2 | 2026-03-04T13:29:20.523Z | user\n\n- Added explicit requirement notice: the Shield plugin (`@upx-us/shield`) must be installed and activated.\n- Updated metadata section for ClawHub integration and plugin detection.\n- Improved example output for `shield status` to clarify interpretation.\n- Minor formatting and language adjustments for clarity and consistency.\n- No behavioral, feature, or command changes.\n\nv1.0.1 | 2026-03-04T13:11:07.230Z | user\n\nopenclaw-shield-upx 1.0.1 changelog:\n\n- Added support for inspecting the local redaction vault and host inventory via the `openclaw shield vault show` command.\n- Documented redaction token types and agent/workspace ID hashing for improved privacy transparency.\n- Updated command usage guidelines and examples, refining descriptions and workflows.\n- Expanded documentation links and dashboard references for quick user access.\n- Clarified privacy, behavior, and plugin update instructions throughout the skill.\n\nv1.0.0 | 2026-03-04T12:52:16.163Z | user\n\n- Major update: Shield skill now acts as your real-time security specialist and guide.\n- Expanded documentation: Detailed explanations on Shield capabilities, command usage, and interpreting status outputs.\n- Added event triage and investigation workflows.\n- Privacy and data handling model clarified—explains what Shield collects and redacts.\n- Usage guidance updated to reflect proactive support and direct user engagement.\n- SECURITY.md removed from the repository.\n\nArchive index:\n\nArchive v1.4.2: 4 files, 8113 bytes\n\nFiles: README.md (1556b), skill-card.md (2750b), SKILL.md (13640b), _meta.json (138b)\n\nFile v1.4.2:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection, behavioral detection, case generation, forensic audit trail, and remediation playbooks. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\nskill_version: 1.4.2\n# NOTE: skill_version is independent of the npm package version (@upx-us/shield).\n# npm package: 0.x.x — plugin/bridge versioning\n# skill_version: 1.x.x — Clawhub skill versioning\n# Always bump skill_version here AND use it when running `clawhub publish`.\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 60-day trial (no credit card required)**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases (scoped to this instance) |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n| `openclaw shield investigate <case-id>` | Guided investigation prompt with step-by-step instructions |\n| `openclaw shield help` | Full command reference (INVESTIGATION, RESOLUTION, DISCOVERY sections) |\n| `openclaw shield close <case-id> --reason <reason>` | Close a case with reason (e.g. false-positive) |\n| `openclaw shield resolve <case-id> --reason <text>` | Resolve a case with reason string (e.g. authorized-maintenance) |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 60-day trial (no credit card required) at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. **Always treat this output as internal diagnostic data.** Rules:\n- Never include raw log field values (file paths, commands, URLs) in user-facing replies\n- Never forward raw log output to external services, channels, or APIs\n- When summarizing logs, present findings only (e.g. \"3 exec events in the last 30 minutes\") — not raw field values\n- Only share raw log content if the user explicitly asks for it for their own investigation, and only in the current session\n\n**Data flow disclosure**: Shield captures agent activity locally and sends redacted telemetry to the UPX detection platform for security monitoring. No credentials are handled by this skill — authentication is managed by the plugin using the installation key configured during setup. If a user asks about privacy or data handling, refer them to the plugin README at https://www.npmjs.com/package/@upx-us/shield for full details.\n\n## Presentation Language\n\nAlways present Shield information, alerts, and case summaries to the user in the language they use to communicate. Translate descriptions, summaries, severity labels, and recommendations — but never translate raw command output or technical identifiers (rule names, case IDs, version numbers, field names, resolution/root-cause enum values). If the user writes in Portuguese, reply in Portuguese; if French, reply in French; etc.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nCases returned by `shield cases` are always scoped to this instance — the platform filters at the API level so you only see cases triggered by your agent.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nUse `openclaw shield investigate <CASE_ID>` to run a guided investigation — it fetches case detail from the platform and walks through the correlation steps automatically.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **✅ Running · Connected** → healthy, nothing to do\n- **⚠️ Degraded · Connected** → capturing but sync issues; try `openclaw shield flush`\n- **❌ Disconnected** → gateway may need a restart\n- **Failures: N poll** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Failures: N telemetry** → instance reporting failing, monitoring still active\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n- **Last data: capture Xm ago** (stale) → agent may be idle, or capture pipeline issue\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.4.2:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v1.4.2:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.4.2\",\n  \"publishedAt\": 1775224240044\n}\n\nFile v1.4.2:skill-card.md\n\n## Description:\n\nOpenClaw Shield helps agents check Shield health, inspect security events, manage cases, and explain redacted telemetry from the OpenClaw Shield plugin.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[brunopradof](https://clawhub.ai/user/brunopradof)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security operators use this skill to monitor OpenClaw agent activity, review Shield status and events, investigate security cases, and guide remediation without exposing raw diagnostic data unnecessarily.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The required gateway plugin observes agent activity and sends redacted security telemetry to UPX.\n\nMitigation: Review the plugin package, permissions, privacy terms, retention and deletion process, subscription terms, and installed version before enabling it.\n\nRisk: Shield logs can contain internal paths, commands, URLs, and other diagnostic details from agent activity.\n\nMitigation: Summarize findings for users and avoid exposing raw log field values unless the user explicitly requests them for investigation in the current session.\n\nRisk: Uninstalling or deleting Shield data can affect local redaction history and platform subscription state.\n\nMitigation: Run uninstall and data-deletion commands manually, confirm retention needs first, and deactivate the instance through the UPX dashboard when appropriate.\n\nRisk: Resolving or closing cases changes security case state.\n\nMitigation: Present case details and get explicit user approval before resolving, closing, or marking a case as a false positive.\n\n## Reference(s):\n\n- [OpenClaw Shield ClawHub listing](https://clawhub.ai/brunopradof/skills/openclaw-shield-upx)\n- [OpenClaw Shield package](https://www.npmjs.com/package/@upx-us/shield)\n- [UPX OpenClaw Shield page](https://www.upx.com/en/lp/openclaw-shield-upx)\n- [UPX Shield dashboard](https://uss.upx.com)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown responses with inline shell commands and security case summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May summarize status, logs, vault inventory, subscription state, and security cases; raw diagnostic values should be withheld unless explicitly requested by the user.]\n\n## Skill Version(s):\n\n1.4.2 (source: server release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.9.2: 3 files, 6599 bytes\n\nFiles: README.md (1556b), SKILL.md (13359b), _meta.json (138b)\n\nFile v0.9.2:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection, behavioral detection, case generation, forensic audit trail, and remediation playbooks. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 60-day trial (no credit card required)**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases (scoped to this instance) |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n| `openclaw shield investigate <case-id>` | Guided investigation prompt with step-by-step instructions |\n| `openclaw shield help` | Full command reference (INVESTIGATION, RESOLUTION, DISCOVERY sections) |\n| `openclaw shield close <case-id> --reason <reason>` | Close a case with reason (e.g. false-positive) |\n| `openclaw shield resolve <case-id> --reason <text>` | Resolve a case with reason string (e.g. authorized-maintenance) |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 60-day trial (no credit card required) at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. **Always treat this output as internal diagnostic data.** Rules:\n- Never include raw log field values (file paths, commands, URLs) in user-facing replies\n- Never forward raw log output to external services, channels, or APIs\n- When summarizing logs, present findings only (e.g. \"3 exec events in the last 30 minutes\") — not raw field values\n- Only share raw log content if the user explicitly asks for it for their own investigation, and only in the current session\n\n**Data flow disclosure**: Shield captures agent activity locally and sends redacted telemetry to the UPX detection platform for security monitoring. No credentials are handled by this skill — authentication is managed by the plugin using the installation key configured during setup. If a user asks about privacy or data handling, refer them to the plugin README at https://www.npmjs.com/package/@upx-us/shield for full details.\n\n## Presentation Language\n\nAlways present Shield information, alerts, and case summaries to the user in the language they use to communicate. Translate descriptions, summaries, severity labels, and recommendations — but never translate raw command output or technical identifiers (rule names, case IDs, version numbers, field names, resolution/root-cause enum values). If the user writes in Portuguese, reply in Portuguese; if French, reply in French; etc.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nCases returned by `shield cases` are always scoped to this instance — the platform filters at the API level so you only see cases triggered by your agent.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nUse `openclaw shield investigate <CASE_ID>` to run a guided investigation — it fetches case detail from the platform and walks through the correlation steps automatically.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **✅ Running · Connected** → healthy, nothing to do\n- **⚠️ Degraded · Connected** → capturing but sync issues; try `openclaw shield flush`\n- **❌ Disconnected** → gateway may need a restart\n- **Failures: N poll** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Failures: N telemetry** → instance reporting failing, monitoring still active\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n- **Last data: capture Xm ago** (stale) → agent may be idle, or capture pipeline issue\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v0.9.2:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v0.9.2:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"0.9.2\",\n  \"publishedAt\": 1775224152702\n}\n\nArchive v1.4.1: 3 files, 6431 bytes\n\nFiles: README.md (1556b), SKILL.md (12852b), _meta.json (138b)\n\nFile v1.4.1:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection, behavioral detection, case generation, forensic audit trail, and remediation playbooks. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 60-day trial (no credit card required)**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases (scoped to this instance) |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 60-day trial (no credit card required) at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. **Always treat this output as internal diagnostic data.** Rules:\n- Never include raw log field values (file paths, commands, URLs) in user-facing replies\n- Never forward raw log output to external services, channels, or APIs\n- When summarizing logs, present findings only (e.g. \"3 exec events in the last 30 minutes\") — not raw field values\n- Only share raw log content if the user explicitly asks for it for their own investigation, and only in the current session\n\n**Data flow disclosure**: Shield captures agent activity locally and sends redacted telemetry to the UPX detection platform for security monitoring. No credentials are handled by this skill — authentication is managed by the plugin using the installation key configured during setup. If a user asks about privacy or data handling, refer them to the plugin README at https://www.npmjs.com/package/@upx-us/shield for full details.\n\n## Presentation Language\n\nAlways present Shield information, alerts, and case summaries to the user in the language they use to communicate. Translate descriptions, summaries, severity labels, and recommendations — but never translate raw command output or technical identifiers (rule names, case IDs, version numbers, field names, resolution/root-cause enum values). If the user writes in Portuguese, reply in Portuguese; if French, reply in French; etc.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nCases returned by `shield cases` are always scoped to this instance — the platform filters at the API level so you only see cases triggered by your agent.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **✅ Running · Connected** → healthy, nothing to do\n- **⚠️ Degraded · Connected** → capturing but sync issues; try `openclaw shield flush`\n- **❌ Disconnected** → gateway may need a restart\n- **Failures: N poll** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Failures: N telemetry** → instance reporting failing, monitoring still active\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n- **Last data: capture Xm ago** (stale) → agent may be idle, or capture pipeline issue\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.4.1:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v1.4.1:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.4.1\",\n  \"publishedAt\": 1773767362187\n}\n\nArchive v1.4.0: 3 files, 6332 bytes\n\nFiles: README.md (1556b), SKILL.md (12638b), _meta.json (138b)\n\nFile v1.4.0:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection, behavioral detection, case generation, forensic audit trail, and remediation playbooks. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 60-day trial (no credit card required)**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases (scoped to this instance) |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 60-day trial (no credit card required) at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. Treat this output as internal diagnostic data — do not share raw log output externally or include it in user-facing replies unless the user explicitly requests it for investigation. When summarizing logs, present findings rather than raw field values.\n\n**Data flow disclosure**: Shield captures agent activity locally and sends redacted telemetry to the UPX detection platform for security monitoring. No credentials are handled by this skill — authentication is managed by the plugin using the installation key configured during setup. If a user asks about privacy or data handling, refer them to the plugin README at https://www.npmjs.com/package/@upx-us/shield for full details.\n\n## Presentation Language\n\nAlways present Shield information, alerts, and case summaries to the user in the language they use to communicate. Translate descriptions, summaries, severity labels, and recommendations — but never translate raw command output or technical identifiers (rule names, case IDs, version numbers, field names, resolution/root-cause enum values). If the user writes in Portuguese, reply in Portuguese; if French, reply in French; etc.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nCases returned by `shield cases` are always scoped to this instance — the platform filters at the API level so you only see cases triggered by your agent.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **✅ Running · Connected** → healthy, nothing to do\n- **⚠️ Degraded · Connected** → capturing but sync issues; try `openclaw shield flush`\n- **❌ Disconnected** → gateway may need a restart\n- **Failures: N poll** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Failures: N telemetry** → instance reporting failing, monitoring still active\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n- **Last data: capture Xm ago** (stale) → agent may be idle, or capture pipeline issue\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.4.0:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v1.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1773767185937\n}\n\nArchive v0.8.1: 3 files, 6332 bytes\n\nFiles: README.md (1556b), SKILL.md (12638b), _meta.json (138b)\n\nFile v0.8.1:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection, behavioral detection, case generation, forensic audit trail, and remediation playbooks. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 60-day trial (no credit card required)**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases (scoped to this instance) |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 60-day trial (no credit card required) at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. Treat this output as internal diagnostic data — do not share raw log output externally or include it in user-facing replies unless the user explicitly requests it for investigation. When summarizing logs, present findings rather than raw field values.\n\n**Data flow disclosure**: Shield captures agent activity locally and sends redacted telemetry to the UPX detection platform for security monitoring. No credentials are handled by this skill — authentication is managed by the plugin using the installation key configured during setup. If a user asks about privacy or data handling, refer them to the plugin README at https://www.npmjs.com/package/@upx-us/shield for full details.\n\n## Presentation Language\n\nAlways present Shield information, alerts, and case summaries to the user in the language they use to communicate. Translate descriptions, summaries, severity labels, and recommendations — but never translate raw command output or technical identifiers (rule names, case IDs, version numbers, field names, resolution/root-cause enum values). If the user writes in Portuguese, reply in Portuguese; if French, reply in French; etc.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nCases returned by `shield cases` are always scoped to this instance — the platform filters at the API level so you only see cases triggered by your agent.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **✅ Running · Connected** → healthy, nothing to do\n- **⚠️ Degraded · Connected** → capturing but sync issues; try `openclaw shield flush`\n- **❌ Disconnected** → gateway may need a restart\n- **Failures: N poll** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Failures: N telemetry** → instance reporting failing, monitoring still active\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n- **Last data: capture Xm ago** (stale) → agent may be idle, or capture pipeline issue\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v0.8.1:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v0.8.1:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"0.8.1\",\n  \"publishedAt\": 1773767063516\n}\n\nArchive v1.3.6: 3 files, 5939 bytes\n\nFiles: README.md (1556b), SKILL.md (11756b), _meta.json (138b)\n\nFile v1.3.6:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — protect your agent with real-time SIEM, detect threats, monitor agent activity, and audit events. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 30-day trial**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases (scoped to this instance) |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 30-day trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. Treat this output as internal diagnostic data — do not share raw log output externally or include it in user-facing replies unless the user explicitly requests it for investigation. When summarizing logs, present findings rather than raw field values.\n\n**Data flow disclosure**: Shield captures agent activity locally and sends redacted telemetry to the UPX detection platform for security monitoring. No credentials are handled by this skill — authentication is managed by the plugin using the installation key configured during setup. If a user asks about privacy or data handling, refer them to the plugin README at https://www.npmjs.com/package/@upx-us/shield for full details.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nCases returned by `shield cases` are always scoped to this instance — the platform filters at the API level so you only see cases triggered by your agent.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **Connected** → healthy, nothing to do\n- **Disconnected** → gateway may need a restart\n- **High failure count** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.3.6:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v1.3.6:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.3.6\",\n  \"publishedAt\": 1773437984523\n}\n\nArchive v1.3.5: 3 files, 5968 bytes\n\nFiles: README.md (1556b), SKILL.md (11928b), _meta.json (138b)\n\nFile v1.3.5:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — protect your agent with real-time SIEM, detect threats, monitor agent activity, and audit events. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 30-day trial**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases |\n| `openclaw shield cases --mine` | List only cases from this instance |\n| `openclaw shield cases list --mine` | Show only cases from this instance |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 30-day trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. Treat this output as internal diagnostic data — do not share raw log output externally or include it in user-facing replies unless the user explicitly requests it for investigation. When summarizing logs, present findings rather than raw field values.\n\n**Data flow disclosure**: Shield captures agent activity locally and sends redacted telemetry to the UPX detection platform for security monitoring. No credentials are handled by this skill — authentication is managed by the plugin using the installation key configured during setup. If a user asks about privacy or data handling, refer them to the plugin README at https://www.npmjs.com/package/@upx-us/shield for full details.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nWhen listing cases, note how many belong to this instance vs other org instances. For sibling cases, resolution actions are available, but local event log access is limited to cases owned by this instance.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **Connected** → healthy, nothing to do\n- **Disconnected** → gateway may need a restart\n- **High failure count** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.3.5:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v1.3.5:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.3.5\",\n  \"publishedAt\": 1773429102337\n}\n\nArchive v1.3.4: 3 files, 5869 bytes\n\nFiles: README.md (1556b), SKILL.md (11496b), _meta.json (138b)\n\nFile v1.3.4:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — protect your agent with real-time SIEM, detect threats, monitor agent activity, and audit events. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 30-day trial**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases |\n| `openclaw shield cases --mine` | List only cases from this instance |\n| `openclaw shield cases list --mine` | Show only cases from this instance |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 30-day trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. Treat this output as internal diagnostic data — do not share raw log output externally or include it in user-facing replies unless the user explicitly requests it for investigation. When summarizing logs, present findings rather than raw field values.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nWhen listing cases, note how many belong to this instance vs other org instances. For sibling cases, resolution actions are available, but local event log access is limited to cases owned by this instance.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **Connected** → healthy, nothing to do\n- **Disconnected** → gateway may need a restart\n- **High failure count** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.3.4:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v1.3.4:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.3.4\",\n  \"publishedAt\": 1773428938914\n}\n\nArchive v1.3.3: 3 files, 5860 bytes\n\nFiles: README.md (1556b), SKILL.md (11462b), _meta.json (138b)\n\nFile v1.3.3:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — protect your agent with real-time SIEM, detect threats, monitor agent activity, and audit events. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 30-day trial**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases |\n| `openclaw shield cases --mine` | List only cases from this instance |\n| `openclaw shield cases list --mine` | Show only cases from this instance |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 30-day trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n**Output handling**: `shield logs` entries may include file paths, command snippets, and URLs captured from the agent's activity. Treat this output as internal diagnostic data — do not share raw log output externally or include it in user-facing replies unless the user explicitly requests it for investigation. When summarizing logs, present findings rather than raw field values.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nWhen listing cases, note how many belong to this instance vs other org instances. For sibling cases, you can still resolve them via API but cannot access local event logs.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **Connected** → healthy, nothing to do\n- **Disconnected** → gateway may need a restart\n- **High failure count** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.3.3:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments.\n\nFile v1.3.3:_meta.json\n\n{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.3.3\",\n  \"publishedAt\": 1773428691799\n}\n\nArchive v1.3.2: 3 files, 5708 bytes\n\nFiles: README.md (1556b), SKILL.md (11077b), _meta.json (138b)\n\nFile v1.3.2:SKILL.md\n\n---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — protect your agent with real-time SIEM, detect threats, monitor agent activity, and audit events. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 30-day trial**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases |\n| `openclaw shield cases --mine` | List only cases from this instance |\n| `openclaw shield cases list --mine` | Show only cases from this instance |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n\n## Plugin State Check\n\nBefore responding to ANY Shield-related request, run `openclaw shield status` and interpret the result:\n\n### State A — Plugin not installed\n(command not found, or exit code non-zero with plugin_not_found)\nRespond with:\n> Shield is not installed yet. Start your free 30-day trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Then install the plugin:\n> ```\n> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n> ```\n\n### State B — Plugin installed but no installationKey\n(status contains installationKey: null or state: \"unconfigured\")\nRespond with:\n> Shield is installed but not activated. Sign up for a trial at:\n> https://www.upx.com/en/lp/openclaw-shield-upx\n>\n> Once you have your installation key, run:\n> ```\n> openclaw plugins run shield setup\n> ```\n\n### State C — Key set but not yet activated\n(status contains state: \"pending\" or state: \"unregistered\")\nRespond with:\n> Shield has an installation key but hasn't activated yet. This usually takes under a minute.\n> If it has been more than 5 minutes, check your key at https://uss.upx.com or contact support.\n\n### State D — Fully active\n(status contains state: \"connected\" or connected: true)\nProceed normally. No onboarding message needed.\n\n**Constraints**: Only use `openclaw shield` commands for detection. Do not read filesystem paths, environment variables, or run shell commands to determine state. Do not install or uninstall packages on behalf of the user.\n\n## Responding to Security Cases\n\nWhen a Shield case fires or the user asks about an alert: use `openclaw shield cases` to list open cases and `openclaw shield cases --id <id>` for full detail (timeline, matched events, playbook). Severity guidance: **CRITICAL/HIGH** → surface immediately and ask if they want to investigate; **MEDIUM** → present and offer a playbook walkthrough; **LOW/INFO** → mention without interrupting the current task. Always include: rule name, what it detects, when it fired, and the first recommended remediation step. Confirm with the user before resolving — never resolve autonomously.\n\nWhen listing cases, note how many belong to this instance vs other org instances. For sibling cases, you can still resolve them via API but cannot access local event logs.\n\nShield now stamps each event with a `trigger_type` — who or what initiated the session. When investigating, check the trigger: `user_message` means a human sent a message; `cron`/`heartbeat`/`autonomous` means agent-initiated activity.\n\n## Case Investigation Workflow\n\nWhen a Shield case fires, correlate three data sources to determine true positive vs. false positive:\n\n**Step 1 — Case detail** (`openclaw shield cases show <CASE_ID>`): What triggered the rule. Note the case timestamp — it anchors the correlation window.\n\n**Step 2 — Surrounding logs** (`openclaw shield logs --since 30m --type TOOL_CALL`): Look for events 5–15 minutes before and after the case timestamp. Reveals if the alert was isolated or part of a sequence. Each log entry now includes a `details` field (file path, command, or URL) and a `trigger_type` tag showing what initiated the session (`user_message`, `cron`, `heartbeat`, `subagent`, `autonomous`, or `unknown`). Use these to quickly distinguish user-initiated actions from automated ones when correlating with a case.\n\n**Step 3 — Vault context** (`openclaw shield vault show`): If the case involves redacted credentials, hostnames, or commands, the vault reveals hashed representations and redaction categories.\n\n**Step 4 — Correlate and assess**: Case detail = *what* fired the rule; Logs = *context*; Vault = *what was actually accessed*. Present findings and ask whether to resolve, investigate further, or add to the allowlist.\n\nNote: a future `openclaw shield investigate <CASE_ID>` helper command will automate this workflow.\n\n## Threat & Protection Questions\n\nWhen asked \"is my agent secure?\", \"am I protected?\", or \"what's being detected?\": run `openclaw shield status` (health, event rate, last sync) and `openclaw shield cases` (open cases by severity). Summarise: rules active, last event ingested, any open cases. No cases → \"Shield is monitoring X rules across Y event categories.\" Open cases → list by severity. If asked what Shield covers: explain it monitors for suspicious patterns across secret handling, access behaviour, outbound activity, injection attempts, config changes, and behavioural anomalies — without disclosing specific rule names or logic.\n\n## When Shield Detects Proactively\n\nReal-time alerts (notifications or inline messages) are high priority: acknowledge immediately, retrieve full case detail, summarise in plain language, present the recommended next step from the playbook, and ask the user how to proceed. Do not take remediation action without explicit approval.\n\n## When to use this skill\n\n- \"Is Shield running?\" → `openclaw shield status`\n- \"What did Shield capture recently?\" → `openclaw shield logs`\n- \"How many agents are on this machine?\" → `openclaw shield vault show`\n- \"Force a sync now\" → `openclaw shield flush`\n- User asks about a security alert or event → interpret using your security knowledge and Shield data\n- User asks about Shield's privacy model → refer them to the plugin README for privacy details\n- User wants a quick case check without agent involvement → `/shieldcases`\n\n## Status interpretation\n\nAfter running `openclaw shield status`, check:\n\n- **Connected** → healthy, nothing to do\n- **Disconnected** → gateway may need a restart\n- **High failure count** → platform connectivity issue, usually self-recovers; try `openclaw shield flush`\n- **Rising quarantine** → possible version mismatch, suggest checking for plugin updates\n\n## RPCs\n\nCases are created automatically when detection rules fire. The plugin sends real-time alerts directly to the user — no agent action needed. Use `shield.cases_list` only when the user asks about open cases.\n\n**Important:** Never resolve or close a case without explicit user approval. Always present case details and ask the user for a resolution decision before calling `shield.case_resolve`.\n\n| RPC | Params | Purpose |\n|---|---|---|\n| `shield.status` | — | Health, counters, case monitor state |\n| `shield.flush` | — | Trigger immediate poll cycle |\n| `shield.events_recent` | `limit`, `type`, `sinceMs` | Query local event buffer |\n| `shield.events_summary` | `sinceMs` | Event counts by category |\n| `shield.subscription_status` | — | Subscription tier, expiry, features |\n| `shield.cases_list` | `status`, `limit`, `since` | List open cases + pending notifications |\n| `shield.case_detail` | `id` | Full case with events, rule, playbook |\n| `shield.case_resolve` | `id`, `resolution`, `root_cause`, `comment` | Close a case |\n| `shield.cases_ack` | `ids` | Mark cases as notified |\n\n**Resolve values:** `true_positive`, `false_positive`, `benign`, `duplicate`\n**Root cause values:** `user_initiated`, `misconfiguration`, `expected_behavior`, `actual_threat`, `testing`, `unknown`\n\n## Presenting data\n\nRPC responses include a `display` field with pre-formatted text. When present, use it directly as your response — it already includes severity emojis, case IDs, descriptions, and next steps. Only format manually if `display` is absent.\n\nWhen discussing a case, offer action buttons (resolve, false positive, investigate) via the message tool so users can act with one tap.\n\n## Uninstalling\n\nTo fully remove Shield:\n\n1. Uninstall the plugin:\n   ```\n   openclaw plugins uninstall shield\n   ```\n\n2. Optionally remove local Shield data:\n   ```\n   rm -rf ~/.openclaw/shield/\n   ```\n   Files removed include: `config.json`, `data/event-buffer.jsonl`, `data/redaction-vault.json`, `data/cursor.json`, `data/instance.json`, `logs/shield.log`, `logs/bridge.log`, `state/monitor.json`.\n\n   ⚠️ Deleting `data/redaction-vault.json` removes the ability to reverse-lookup past redacted values. Check your data retention needs before deleting.\n\n3. Deactivate your instance at [uss.upx.com](https://uss.upx.com) — local uninstall does not deactivate your platform subscription or instance.\n\n## Notes\n\n- Shield does not interfere with agent behavior or performance\n- The UPX platform analyzes redacted telemetry with 80+ detection rules\n- When a subscription expires, events are dropped (not queued); renew at [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n\nFile v1.3.2:README.md\n\n# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the red","readmeExcerpt":"Skill: OpenClaw Shield Owner: brunopradof Summary: Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection... Tags: latest:1.4.2 Version history: v1.4.2 | 2026-04-03T13:50:40.044Z | user v1.4.2: investigate command, help command, close/resolve aliases, improved case notifications, expanded test coverage v0.9.2 | 2026","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n>"},{"language":"text","snippet":"> openclaw plugins run shield setup\n>"},{"language":"text","snippet":"openclaw plugins uninstall shield"},{"language":"text","snippet":"rm -rf ~/.openclaw/shield/"},{"language":"bash","snippet":"openclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart"},{"language":"text","snippet":"> openclaw plugins install @upx-us/shield\n> openclaw plugins run shield setup\n>"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: openclaw-shield-upx\ndescription: \"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection, behavioral detection, case generation, forensic audit trail, and remediation playbooks. Use when: user asks about security status, Shield health, event logs, redaction vault, setting up agent protection, enabling SIEM, detecting threats, monitoring agent activity, or auditing agent actions. NOT for: general OS hardening, firewall config, or network security unrelated to OpenClaw agents.\"\nhomepage: https://www.upx.com/en/lp/openclaw-shield-upx\nsource: https://www.npmjs.com/package/@upx-us/shield\nlicense: \"Proprietary — UPX Technologies, Inc. All rights reserved.\"\nmetadata: {\"openclaw\": {\"requires\": {\"bins\": [\"openclaw\"]}, \"homepage\": \"https://clawhub.ai/brunopradof/openclaw-shield-upx\", \"emoji\": \"🛡️\"}}\nskill_version: 1.4.2\n# NOTE: skill_version is independent of the npm package version (@upx-us/shield).\n# npm package: 0.x.x — plugin/bridge versioning\n# skill_version: 1.x.x — Clawhub skill versioning\n# Always bump skill_version here AND use it when running `clawhub publish`.\n---\n\n# OpenClaw Shield\n\nSecurity monitoring for OpenClaw agents by [UPX](https://www.upx.com). Shield runs as a plugin inside the OpenClaw gateway, capturing agent activity and sending redacted telemetry to the UPX detection platform.\n\n## Getting started\n\nShield requires the `@upx-us/shield` plugin and an active subscription.\n\n- **Plugin**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Subscribe / Free 60-day trial (no credit card required)**: [upx.com/en/lp/openclaw-shield-upx](https://www.upx.com/en/lp/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## Commands\n\n| Command | What it does |\n|---|---|\n| `openclaw shield status` | Plugin health, connection state, event counts, last sync |\n| `openclaw shield flush` | Force an immediate sync to the platform |\n| `openclaw shield logs` | Recent events: type, tool, details, and trigger source (last 24h) |\n| `openclaw shield logs --last 20` | Show last N events |\n| `openclaw shield logs --last 20 --format json` | Full JSON output with details and trigger_type fields |\n| `openclaw shield logs --type TOOL_CALL --since 1h` | Filter by event type or time window |\n| `openclaw shield logs --format json` | JSON output |\n| `openclaw shield vault show` | Agent and workspace inventory, redaction summary (hashed IDs) |\n| `openclaw shield cases` | List open security cases (scoped to this instance) |\n| `openclaw shield cases show <ID>` | Full case detail with events, rule, playbook |\n| `openclaw shield cases resolve <ID>` | Resolve a case (--resolution, --root-cause, --comment) |\n| `openclaw shield monitor` | Case notification cron — status, --on, --off, --interval |\n| `openclaw shield investigate <case-id>` | Guided investigation prompt with step-by-step instructions |\n| `openclaw shield help` | Full "},{"path":"README.md","content":"# OpenClaw Shield\n\nSecurity monitoring skill for the OpenClaw Shield plugin by [UPX](https://www.upx.com).\n\n## What it does\n\nTeaches your agent to use the Shield plugin — check health, query events, inspect the redaction vault, and manage security cases.\n\n- Run `openclaw shield status`, `logs`, `flush`, `vault show`, and `cases` commands\n- Call RPCs for programmatic access (`shield.events_recent`, `shield.events_summary`, `shield.cases_list`, etc.)\n- Triage and resolve cases with categorized resolution and root cause\n- Set up automated case monitoring via `openclaw shield monitor --on`\n- Quick case check with `/shieldcases` (no agent tokens used)\n- Answer questions about Shield's privacy model and subscription status\n\n## Requirements\n\n- [OpenClaw Shield plugin](https://www.npmjs.com/package/@upx-us/shield) installed and activated\n- Active Shield subscription from [UPX](https://upx.com) — [start a free 30-day trial](https://www.upx.com/en/lp/openclaw-shield-upx)\n\n## Install\n\nThis skill is bundled with the Shield plugin. Install the plugin and the skill is available automatically:\n\n```bash\nopenclaw plugins install @upx-us/shield\nopenclaw shield activate <YOUR_KEY>\nopenclaw gateway restart\n```\n\n## Links\n\n- **Plugin (npm)**: [@upx-us/shield](https://www.npmjs.com/package/@upx-us/shield)\n- **Skill (ClawHub)**: [openclaw-shield-upx](https://clawhub.ai/brunopradof/openclaw-shield-upx)\n- **Dashboard**: [uss.upx.com](https://uss.upx.com)\n\n## About\n\nMade by [UPX](https://upx.com) — cybersecurity engineering for critical environments."},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn719cqkc2rj11gbqs3qbejpf9827q95\",\n  \"slug\": \"openclaw-shield-upx\",\n  \"version\": \"1.4.2\",\n  \"publishedAt\": 1775224240044\n}"},{"path":"skill-card.md","content":"## Description:\n\nOpenClaw Shield helps agents check Shield health, inspect security events, manage cases, and explain redacted telemetry from the OpenClaw Shield plugin.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[brunopradof](https://clawhub.ai/user/brunopradof)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security operators use this skill to monitor OpenClaw agent activity, review Shield status and events, investigate security cases, and guide remediation without exposing raw diagnostic data unnecessarily.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The required gateway plugin observes agent activity and sends redacted security telemetry to UPX.\n\nMitigation: Review the plugin package, permissions, privacy terms, retention and deletion process, subscription terms, and installed version before enabling it.\n\nRisk: Shield logs can contain internal paths, commands, URLs, and other diagnostic details from agent activity.\n\nMitigation: Summarize findings for users and avoid exposing raw log field values unless the user explicitly requests them for investigation in the current session.\n\nRisk: Uninstalling or deleting Shield data can affect local redaction history and platform subscription state.\n\nMitigation: Run uninstall and data-deletion commands manually, confirm retention needs first, and deactivate the instance through the UPX dashboard when appropriate.\n\nRisk: Resolving or closing cases changes security case state.\n\nMitigation: Present case details and get explicit user approval before resolving, closing, or marking a case as a false positive.\n\n## Reference(s):\n\n- [OpenClaw Shield ClawHub listing](https://clawhub.ai/brunopradof/skills/openclaw-shield-upx)\n- [OpenClaw Shield package](https://www.npmjs.com/package/@upx-us/shield)\n- [UPX OpenClaw Shield page](https://www.upx.com/en/lp/openclaw-shield-upx)\n- [UPX Shield dashboard](https://uss.upx.com)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown responses with inline shell commands and security case summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May summarize status, logs, vault inventory, subscription state, and security cases; raw diagnostic values should be withheld unless explicitly requested by the user.]\n\n## Skill Version(s):\n\n1.4.2 (source: server release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection... Skill: OpenClaw Shield Owner: brunopradof Summary: Security monitoring and threat detection for OpenClaw agents — powered by Google SecOps (Chronicle). Protect your agent with SIEM-powered real-time detection... Tags: latest:1.4.2 Version history: v1.4.2 | 2026-04-03T13:50:40.044Z | user v1.4.2: investigate command, help command, close/resolve aliases, improved case notifications, expanded test coverage v0.9.2 | 2026","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1393,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T03:16:51.627Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T03:16:51.627Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:23:16.869Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}