{"id":"2faf0c1e-062b-4059-a156-8daf66088eee","entityType":"agent","slug":"clawhub-jarvis-drakon-shieldcortex","name":"ShieldCortex","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jarvis-drakon-shieldcortex","canonicalPath":"/agent/clawhub-jarvis-drakon-shieldcortex","generatedAt":"2026-10-09T17:49:39.935Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T02:47:05.669Z","emptyReason":null},"description":"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning. Skill: ShieldCortex Owner: jarvis-drakon Summary: Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning. Tags: latest:5.5.0 Version history: v5.5.0 | 2026-10-08T07:03:55.770Z | user Sync from npm publish v5.5.0 v5.4.0 | 2026-10-06T10:48:36.133Z | user Sync from npm publish v5.4.0 v5.3.1 | 20","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 7.9K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17e5x46byp69amedtav06x93n83ed6b:shieldcortex","sourceUrl":"https://clawhub.ai/jarvis-drakon/shieldcortex","homepage":"https://clawhub.ai/jarvis-drakon/skills/shieldcortex","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jarvis-drakon/shieldcortex","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jarvis-drakon/skills/shieldcortex","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credentia"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:47:05.669Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:47:05.669Z","emptyReason":null},"stars":null,"forks":null,"downloads":7927,"packageName":null,"latestVersion":"5.5.0","tractionLabel":"7.9K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:47:05.669Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T02:47:05.669Z","lastCrawledAt":"2026-10-09T02:47:05.669Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T02:47:05.669Z","lastVerifiedAt":null,"highlights":[{"version":"5.5.0","createdAt":"2026-10-08T07:03:55.770Z","changelog":"Sync from npm publish v5.5.0","fileCount":11,"zipByteSize":52856},{"version":"5.4.0","createdAt":"2026-10-06T10:48:36.133Z","changelog":"Sync from npm publish v5.4.0","fileCount":11,"zipByteSize":51737},{"version":"5.3.1","createdAt":"2026-10-03T18:00:06.796Z","changelog":"Sync from npm publish v5.3.1","fileCount":11,"zipByteSize":51789},{"version":"5.3.0","createdAt":"2026-10-03T10:04:07.736Z","changelog":"Sync from npm publish v5.3.0","fileCount":11,"zipByteSize":51793},{"version":"5.2.1","createdAt":"2026-09-27T13:07:24.719Z","changelog":"Sync from npm publish v5.2.1","fileCount":11,"zipByteSize":51752},{"version":"5.2.0","createdAt":"2026-09-24T21:28:53.895Z","changelog":"Sync from npm publish v5.2.0","fileCount":11,"zipByteSize":51731},{"version":"5.1.0","createdAt":"2026-09-22T23:44:59.912Z","changelog":"Sync from npm publish v5.1.0","fileCount":11,"zipByteSize":52095},{"version":"5.0.6","createdAt":"2026-09-20T09:05:07.011Z","changelog":"Sync from npm publish v5.0.6","fileCount":11,"zipByteSize":51654}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17e5x46byp69amedtav06x93n83ed6b:shieldcortex","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T17:49:39.931Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jarvis-drakon-shieldcortex/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T02:47:05.669Z","emptyReason":null},"readme":"Skill: ShieldCortex\n\nOwner: jarvis-drakon\n\nSummary: Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\n\nTags: latest:5.5.0\n\nVersion history:\n\nv5.5.0 | 2026-10-08T07:03:55.770Z | user\n\nSync from npm publish v5.5.0\n\nv5.4.0 | 2026-10-06T10:48:36.133Z | user\n\nSync from npm publish v5.4.0\n\nv5.3.1 | 2026-10-03T18:00:06.796Z | user\n\nSync from npm publish v5.3.1\n\nv5.3.0 | 2026-10-03T10:04:07.736Z | user\n\nSync from npm publish v5.3.0\n\nv5.2.1 | 2026-09-27T13:07:24.719Z | user\n\nSync from npm publish v5.2.1\n\nv5.2.0 | 2026-09-24T21:28:53.895Z | user\n\nSync from npm publish v5.2.0\n\nv5.1.0 | 2026-09-22T23:44:59.912Z | user\n\nSync from npm publish v5.1.0\n\nv5.0.6 | 2026-09-20T09:05:07.011Z | user\n\nSync from npm publish v5.0.6\n\nv5.0.5 | 2026-09-13T21:16:51.653Z | user\n\nSync from npm publish v5.0.5\n\nv5.0.4 | 2026-09-13T17:53:01.405Z | user\n\nSync from npm publish v5.0.4\n\nv5.0.3 | 2026-09-13T14:04:27.317Z | user\n\nSync from npm publish v5.0.3\n\nv5.0.2 | 2026-09-13T13:08:42.836Z | user\n\nSync from npm publish v5.0.2\n\nv5.0.1 | 2026-09-13T11:06:31.003Z | user\n\nSync from npm publish v5.0.1\n\nv5.0.0 | 2026-09-12T22:30:24.725Z | user\n\nSync from npm publish v5.0.0\n\nv4.54.15 | 2026-09-01T07:09:53.361Z | user\n\nSync from npm publish v4.54.15\n\nv4.54.14 | 2026-08-29T14:40:47.100Z | user\n\nSync from npm publish v4.54.14\n\nv4.54.13 | 2026-08-25T20:13:11.495Z | user\n\nSync from npm publish v4.54.13\n\nv4.54.12 | 2026-08-25T14:11:51.451Z | user\n\nSync from npm publish v4.54.12\n\nv4.54.11 | 2026-08-21T21:06:28.036Z | user\n\nSync from npm publish v4.54.11\n\nv4.54.10 | 2026-08-21T16:52:41.771Z | user\n\nSync from npm publish v4.54.10\n\nv4.54.9 | 2026-08-19T17:23:13.650Z | user\n\nSync from npm publish v4.54.9\n\nv4.54.8 | 2026-08-19T09:14:35.286Z | user\n\nSync from npm publish v4.54.8\n\nv4.54.7 | 2026-08-19T05:13:11.761Z | user\n\nSync from npm publish v4.54.7\n\nv4.54.5 | 2026-08-18T18:51:13.888Z | user\n\nSync from npm publish v4.54.5\n\nv4.54.4 | 2026-08-17T03:33:17.217Z | user\n\nSync from npm publish v4.54.4\n\nv4.54.3 | 2026-08-16T19:35:31.073Z | user\n\nSync from npm publish v4.54.3\n\nv4.54.2 | 2026-08-16T17:18:21.360Z | user\n\nSync from npm publish v4.54.2\n\nv4.54.1 | 2026-08-16T15:43:18.952Z | user\n\nSync from npm publish v4.54.1\n\nv4.54.0 | 2026-08-16T11:47:33.721Z | user\n\nSync from npm publish v4.54.0\n\nv4.53.0 | 2026-08-15T19:31:43.227Z | user\n\nSync from npm publish v4.53.0\n\nv4.52.3 | 2026-08-15T10:12:02.396Z | user\n\nSync from npm publish v4.52.3\n\nv4.52.2 | 2026-08-15T07:03:54.661Z | user\n\nSync from npm publish v4.52.2\n\nv4.52.1 | 2026-08-15T06:18:36.911Z | user\n\nSync from npm publish v4.52.1\n\nv4.52.0 | 2026-08-15T04:35:31.770Z | user\n\nSync from npm publish v4.52.0\n\nv4.51.0 | 2026-08-14T07:49:05.643Z | user\n\nSync from npm publish v4.51.0\n\nv4.50.0 | 2026-08-13T09:16:56.178Z | user\n\nSync from npm publish v4.50.0\n\nv4.49.0 | 2026-08-13T05:50:16.872Z | user\n\nSync from npm publish v4.49.0\n\nv4.48.0 | 2026-08-12T11:33:33.043Z | user\n\nSync from npm publish v4.48.0\n\nv4.47.40 | 2026-08-12T06:48:08.277Z | user\n\nSync from npm publish v4.47.40\n\nv4.47.39 | 2026-08-11T09:36:29.058Z | user\n\nSync from npm publish v4.47.39\n\nv4.47.38 | 2026-08-11T05:50:27.308Z | user\n\nSync from npm publish v4.47.38\n\nv4.47.37 | 2026-08-11T02:56:35.613Z | user\n\nSync from npm publish v4.47.37\n\nv4.47.36 | 2026-08-10T16:01:26.316Z | user\n\nAuto-sync from npm publish v4.47.36\n\nv4.47.35 | 2026-08-09T15:54:27.925Z | user\n\nAuto-sync from npm publish v4.47.35\n\nv4.47.34 | 2026-08-09T15:40:38.060Z | user\n\nAuto-sync from npm publish v4.47.34\n\nv4.47.33 | 2026-08-08T15:01:44.359Z | user\n\nAuto-sync from npm publish v4.47.33\n\nv4.47.32 | 2026-08-08T11:21:23.638Z | user\n\nAuto-sync from npm publish v4.47.32\n\nv4.47.31 | 2026-08-06T04:47:38.352Z | user\n\nAuto-sync from npm publish v4.47.31\n\nv4.47.30 | 2026-08-04T07:52:22.501Z | user\n\nSync from manual npm publish v4.47.30\n\nv4.47.29 | 2026-08-03T08:09:57.055Z | user\n\nAuto-sync from npm publish v4.47.29\n\nArchive index:\n\nArchive v5.5.0: 11 files, 52856 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (47661b), bundled/cortex-memory-hook/HOOK.md (8053b), bundled/cortex-memory-hook/runtime.mjs (9228b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (2265b), SKILL.md (31929b), _meta.json (131b)\n\nFile v5.5.0:SKILL.md\n\n---\nname: shieldcortex\ndescription: \"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\"\nlicense: MIT-0\nmetadata:\n  author: Drakon Systems\n  version: 5.5.0\n  mcp-server: shieldcortex\n  category: memory-and-security\n  tags: [memory, security, knowledge-graph, mcp, iron-dome, openclaw-plugin, audit]\n  source: https://github.com/Drakon-Systems-Ltd/ShieldCortex\n  homepage: https://shieldcortex.ai\n  npm: https://www.npmjs.com/package/shieldcortex\n  verified_publisher: Drakon Systems Ltd\n  publisher_github: https://github.com/Drakon-Systems-Ltd\n  npm_audit: \"0 unwaived production advisories; 4 waived (sharp: GHSA-f88m-g3jw-g9cj, GHSA-rgj7-g3m4-5g8c, GHSA-wq5f-xc86-pv6w; sprintf-js: GHSA-hp3w-g68c-fv3c, via optional @huggingface/transformers) - see docs/security/audit-waivers.md\"\n  downloads: 11K+/month\ninstall:\n  command: shieldcortex quickstart\n  runtime: node\n  minVersion: \"22.14.0\"\n  note: >\n    Requires Node 22.14+ LTS or Node 24+; Node 23 is unsupported. Run the installed\n    `shieldcortex` binary directly. The quickstart command\n    detects your environment. Claude Code and OpenClaw get hooks that can deny;\n    Codex/Cursor/VS Code get an MCP memory server only (not a tool gate).\n    All data stays local in ~/.shieldcortex/. No account or API key needed\n    for local use.\npermissions:\n  filesystem: readwrite\n  network: optional\n  credentials: optional\n  justification: >\n    Filesystem read: scans agent instruction files for prompt injection threats\n    (same files the agent already reads). Filesystem write: stores memory DB\n    and config in ~/.shieldcortex/. Network: local-first — outbound only for\n    the embedding-model download when it is not cached (huggingface.co;\n    disable with SHIELDCORTEX_SKIP_EMBEDDINGS=1), Cloud sync (opt-in),\n    licence-key validation when a key is activated, explicit update\n    checks/updates and X-Ray package lookups (npm registry), URLs you ask\n    `env scan` to fetch, and webhooks you configure. Credentials: optional\n    Cloud API key for team sync (not required for local use).\n  paths_read:\n    - ~/.shieldcortex/ (own config and memory database)\n    - ~/.claude/ (project memory files, MCP config)\n    - ~/.openclaw/ (MCP config, extensions)\n    - ~/.cursor/ (rules, memories, MCP config)\n    - ~/.windsurf/ (memories, rules)\n    - ~/.codex/ (MCP config)\n    - $CWD/.claude/, $CWD/.cursor/ (project-level configs)\n    - $CWD/.cursorrules, $CWD/.windsurfrules, $CWD/.clinerules\n    - $CWD/CLAUDE.md, $CWD/copilot-instructions.md\n    - $CWD/.aider.conf.yml, $CWD/.continue/config.json\n    - $CWD/.env (env-scanner checks for leaked secrets — reads, never writes)\n  paths_write:\n    - ~/.shieldcortex/ (memory DB, config, cortex log, licence, audit cache)\n    - ~/.cache/shieldcortex/models (embedding model download cache)\n    - ~/.openclaw/extensions/shieldcortex-realtime/ (OpenClaw plugin via the wrapper install only; native `openclaw plugins install` uses OpenClaw's managed npm tree instead)\n    - ~/.claude/mcp.json, ~/.cursor/mcp.json (MCP server registration, when user runs setup)\n  network_endpoints:\n    - https://api.shieldcortex.ai (Cloud sync + audit telemetry — only when Cloud sync is enabled; licence validation — only when a licence key is activated, fired at CLI `license activate` and the dashboard's activation call (POST /api/license/activate), with no periodic or background re-check; sends the subscription id, works with Cloud sync off; never called when no key is configured)\n    - https://huggingface.co (embedding-model download — Xenova/all-MiniLM-L6-v2, ~90 MB, fetched into ~/.cache/shieldcortex/models by the MCP server's background preload at startup or the first operation needing an embedding, whenever the model is not already cached, plus one re-download if a cached copy is detected corrupt; SHIELDCORTEX_SKIP_EMBEDDINGS=1 prevents it. The optional Local AI Explainer model downloads from the same host only on explicit, consent-prompted `review-copilot enable`/`download-model` — its review runs use the local cache only)\n    - https://registry.npmjs.org (three paths — explicit update actions via npm subprocess, dashboard \"Check for updates\"/\"Update\" or `shieldcortex update`; X-Ray package inspection, `shieldcortex xray <package>` or the dashboard X-Ray page, which queries package metadata directly over HTTPS and with `--deep` also downloads the package tarball from whatever URL that metadata names — normally registry.npmjs.org, size- and redirect-capped, but with no separate host allowlist; and the OpenClaw hook's `npx -y shieldcortex` fallback, which downloads the package on first use when ShieldCortex is not installed locally)\n    - User-configured webhook URLs (two POST paths — memory-event notifications to webhooks you add to ~/.shieldcortex/config.json, and Iron Dome operator-notify messages for action-guard holds/denies to the `actionGuard.notify` webhook you configure; both off until you configure them)\n    - The URL you pass to `shieldcortex env scan <url>` (fetched once for analysis)\n    - http://localhost:3001 (local REST API + WebSocket — loopback only)\n    - http://localhost:3030 (local dashboard UI; also the worker health check — loopback only)\n  env:\n    - SHIELDCORTEX_CONFIG_DIR: Override config directory (default ~/.shieldcortex/)\n    - SHIELDCORTEX_API_KEY: Cloud sync API key (optional; only used when Cloud is enabled)\n    - SHIELDCORTEX_LICENSE_TIER: Override licence tier (development use)\n    - SHIELDCORTEX_SKIP_EMBEDDINGS: Disable embedding generation\n    - SHIELDCORTEX_SKIP_SELF_HEAL: Set to 1 to make the cortex-memory hook's bootstrap self-heal warn-only (writes nothing)\n    - SHIELDCORTEX_HOST: Override dashboard/API bind host\n    - PORT: Override dashboard/API port\n---\n\n# ShieldCortex — Persistent Memory & Security for AI Agents\n\nMemory system with built-in security. Gives agents persistent memory (semantic search, knowledge graphs, decay, contradiction detection) and protects it with a 6-layer defence pipeline (input sanitisation → trust scoring → firewall → sensitivity classification → fragmentation detection → credential-leak detection). Skill threat patterns (tool injection, scope escalation, data exfiltration, persistence, supply-chain, agent manipulation, stealth instructions) block at memory-write time, not just on skill-file scans.\n\nThis is an enforcing memory boundary, not a passive scanner. Across the read/write boundary it actively: **quarantines or blocks** poisoned/credential-bearing writes; **trust/ACL-filters recalled memory** (RESTRICTED isolation, own-only for low-trust callers) before it reaches the agent, on both the prompt hooks and the MCP read tools; runs a **tool-output firewall** that, in enforce mode, redacts or withholds malicious tool results before the model sees them (advisory by default); and keeps a **provenance ledger** recording read/write/delete operations with content hashes for forensics. Enforcement that could surprise is opt-in (the tool-output firewall defaults to advisory; `shieldcortex config --tool-firewall-enforce` turns on blocking).\n\n## Provenance & Trust\n\n| Signal | Value |\n|--------|-------|\n| **Publisher** | [Drakon Systems Ltd](https://github.com/Drakon-Systems-Ltd) (UK company) |\n| **Source code** | [github.com/Drakon-Systems-Ltd/ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) — fully open, **MIT** licence (this skill file itself is published MIT-0, per the frontmatter) |\n| **npm package** | [npmjs.com/package/shieldcortex](https://www.npmjs.com/package/shieldcortex) — every release git-tagged with a matching GitHub release |\n| **npm audit** | Not clean: 0 unwaived production advisories, 4 waived (not fixed) — three `sharp` and one `sprintf-js`, all reachable only through the optional `@huggingface/transformers` package. Reachability and expiry dates: [docs/security/audit-waivers.md](https://github.com/Drakon-Systems-Ltd/ShieldCortex/blob/main/docs/security/audit-waivers.md) |\n| **Downloads** | 11,000+/month (July 2026) |\n| **CI/CD** | CI lint/test on every push; the maintainer manually tags each release, and the tag push triggers an automated CI publish to npm |\n| **Postinstall script** | Declared and bounded: prints setup instructions; on **global** installs it also smoke-tests the native SQLite binding, seeds default config on first install, and refreshes an OpenClaw hook/plugin that a previous setup already installed. It never adds integrations to a machine that had none, and it is a no-op for CI and local dependency installs. `SHIELDCORTEX_SKIP_AUTO_OPENCLAW=1` skips the refresh. |\n| **Dependencies** | 8 runtime deps: `better-sqlite3`, `zod`, `@modelcontextprotocol/sdk`, `express`, `ws`, `cors`, `safe-regex2`, `semver`. `express`/`ws`/`cors` serve the bundled localhost-only dashboard/API. One optional dep, `@huggingface/transformers`, runs the local embedding model and fetches it from huggingface.co when it is not cached (see `network_endpoints`). Nothing else dials out except the cases listed under `network_endpoints` (Cloud sync opt-in, licence-key validation, update checks, X-Ray package lookups, env-scan URLs, configured webhooks). |\n\n## Safety & Scope\n\nThis section explains every privileged operation the tool performs and why.\n\n- **Active interception, not scan-only — on hosts that can deny.** Writes failing the pipeline are quarantined/blocked; recalled memory is trust/ACL-filtered before the agent sees it. Tool-call denial is **bound** on Claude Code (PreToolUse), OpenClaw (`before_tool_call`), and Hermes (`pre_tool_call`, enforce by default). Codex, Cursor, Copilot, and generic MCP get a memory server / scanner the model may ignore — they are **not bound**. Tool-output firewall defaults to advisory. `shieldcortex doctor` and `shieldcortex lease` report bound / not-bound / unknown per plane.\n- **Setup is user-initiated, with one bounded exception.** Installing hooks, registering the MCP server, and migrating data are manual steps the user runs in their terminal, and `quickstart` asks before each action. The npm postinstall script (disclosed in the trust table above) never adds integrations that weren't already present — on global installs it only prints instructions, checks the native binding, seeds default config on first install, and refreshes an existing OpenClaw hook/plugin install. The exception: the bundled cortex-memory hook performs a small automatic self-heal at gateway bootstrap, documented in full under **\"Automatic self-heal at gateway bootstrap\"** below.\n- **Setup migrates legacy data.** The first `quickstart`/`setup` run may move or remove legacy config/memory directories (e.g. `~/.claude-cortex/`, `~/.claude-memory/`) into `~/.shieldcortex/` and copy hook files into place. This happens only on the user-run setup command — never on `npm install` (the postinstall script does not touch memory or config data beyond seeding defaults on a first-ever global install).\n- **Destructive `forget` is bounded and gated.** Per-memory and filtered bulk deletes go through a delete ACL (own-only) and are recorded in the audit ledger. Revoke-by-source (`forget --fromSource`, bulk-delete every memory from one source — for purging a poisoned agent) is **disabled by default** and only enabled by an out-of-band human action (`shieldcortex config --allow-revoke-by-source`); even then it is bounded by a trust-hierarchy ACL (you must own the source or out-rank it) and a per-call row cap. A compromised agent cannot mass-delete your memory.\n- **The bundled dashboard never renders RESTRICTED content.** The local visualization API and its WebSocket feed redact credential-class (`RESTRICTED`) memory content before it reaches the browser — the row stays visible (title/metadata) so you can manage it, but the secret is withheld (view full content via the CLI). Credential patterns in titles/metadata are masked too. This is a display-surface safeguard on top of the on-disk store; it does not weaken the firewall.\n- **No credentials required for local use.** Memory, scanning, and audit work fully offline. Cloud sync is opt-in and requires a user-provided API key via `shieldcortex config --cloud-enable --cloud-api-key <key>`.\n- **File access is declared and scoped.** Security scans read agent config directories listed in the permissions block above — the same directories the agent itself already has access to. They do not traverse arbitrary directories.\n- **Writes are contained.** All data goes to `~/.shieldcortex/` (plus the embedding-model cache at `~/.cache/shieldcortex/models`). MCP config edits (`setup`, `copilot`, `codex` commands) modify specific JSON files and confirm before writing.\n- **First-use model download (huggingface.co).** Semantic memory runs a local embedding model (Xenova/all-MiniLM-L6-v2, ~90 MB ONNX) that is **not bundled** with the package. Whenever it is missing from `~/.cache/shieldcortex/models`, the MCP server downloads it from huggingface.co — triggered by the background preload at server start, or by the first operation that needs an embedding, plus a single re-download if a cached copy is detected corrupt. This is the one network call that is not user-initiated. Avoid it with `SHIELDCORTEX_SKIP_EMBEDDINGS=1` (memory falls back to full-text search) or by pre-seeding the model cache. The optional Local AI Explainer (`review-copilot`) downloads its model from the same host only on an explicit, consent-prompted `enable`/`download-model` command; its review runs never fetch remotely.\n- **Network is off by default, with the first-run exception above.** With no licence key activated, no Cloud sync enabled, and no webhooks configured, ShieldCortex's only outbound connections are the embedding-model download just described (fires on server start when the model is not cached) and one further caveat: the OpenClaw hook's `npx -y shieldcortex` fallback downloads the package on first use when ShieldCortex is not installed locally — see `network_endpoints`. Every other entry in `network_endpoints` is user-initiated: Cloud sync (opt-in), licence-key validation when you activate a key (at CLI or dashboard activation only, no background re-check — works even with Cloud sync off), npm-registry update checks/updates (dashboard buttons or `shieldcortex update`), X-Ray package lookups (`shieldcortex xray` or the dashboard X-Ray page, tarball download with `--deep`), URLs you pass to `env scan`, and webhooks you configure (memory events and Iron Dome operator notifications). The dashboard binds to localhost by default but may be explicitly exposed with `SHIELDCORTEX_HOST`; when exposed, the loopback session-token endpoint stays disabled. The worker binds to localhost.\n- **Bundled source code.** The OpenClaw plugin and cortex-memory handler are shipped in the package for inspection before use.\n- **Lifecycle event handlers.** ShieldCortex registers lifecycle handlers that auto-extract important context from conversations. These are registered in `~/.claude/settings.json` during setup and can be removed at any time. They run locally, never phone home.\n- **Proactive recall.** The UserPromptSubmit handler queries local memory on each prompt (<100ms) and surfaces relevant context. Fully local, configurable: `shieldcortex config --proactive-recall false`.\n\n### Automatic self-heal at gateway bootstrap\n\nThe cortex-memory hook registers for the `agent:bootstrap` event. On the first\nbootstrap after each OpenClaw gateway start (once per gateway process), it runs\na self-check that can write without a prompt. In the interest of full\ndisclosure, this is exactly what it does:\n\n1. **Removes stale legacy hook copies.** If the hook is running from its\n   expected home (`~/.openclaw/hooks/internal/cortex-memory` or\n   `~/.openclaw/hooks/cortex-memory`), it recursively deletes the pre-rename\n   leftovers `~/.clawdbot/hooks/cortex-memory` and\n   `~/.clawdbot/hooks/internal/cortex-memory` — and only those two\n   directories. It skips this entirely when `~/.clawdbot` is a symlink (i.e.\n   still pointing at a live install). No backup is taken before deletion;\n   these directories are assumed to be dead copies of this hook's own files,\n   not your data.\n2. **Copies itself to the expected hook path.** If the hook finds itself\n   running from anywhere else (for example, from inside this skill's\n   `bundled/` folder after a skills-only install), it creates\n   `~/.openclaw/hooks/internal/cortex-memory/` and copies its full file set\n   (`HOOK.md`, `handler.ts`, `runtime.mjs`) there so the gateway loads it from\n   the canonical location on the next restart, and surfaces a\n   `SHIELDCORTEX_HOOK_MIGRATED.md` notice into the session's bootstrap context.\n   If any file in that set fails to copy, the migration is reported as\n   incomplete rather than as a success — a partially-copied hook cannot load.\n3. **Checks for staleness (read-only).** It compares the running hook files\n   against the installed npm package's copies and warns if they differ. This\n   step never writes.\n\n**Scope limits:** the self-heal writes only inside `~/.openclaw/hooks/**` and\ndeletes only the two `~/.clawdbot` hook directories named above. It does not\nmodify `openclaw.json`, `~/.claude/settings.json`, MCP config, shell configs,\nor any other file; it makes no network calls; failures are swallowed so it can\nnever block agent startup.\n\n**Opting out (since v4.47.12):** either of these downgrades steps 1 and 2 to\nwarn-only — the hook logs exactly what it would have deleted or copied and\ntouches nothing:\n\n```bash\nshieldcortex config --self-heal false     # writes \"selfHeal\": false to ~/.shieldcortex/config.json\nexport SHIELDCORTEX_SKIP_SELF_HEAL=1      # or set the env var for the gateway process\n```\n\nRestart the gateway for either to take effect. Step 3 (the read-only staleness\ncheck) still runs, and `shieldcortex openclaw install` performs the same\nmigration on demand. Disabling the cortex-memory hook in your hooks config also\ndisables the self-heal entirely, since it only runs inside the hook.\n\n## Data handling, privacy & consent\n\nShieldCortex is **local-first**: memory, scanning, and audit run entirely on your machine — no account, no telemetry by default, and no network use beyond fetching the embedding model on first use when it is not cached (see **First-use model download** above). Because the tool can auto-capture conversation content, here is exactly what it reads, stores, and (only if you opt in) transmits.\n\n- **What it reads.** With the lifecycle handlers enabled (opt-in at setup), ShieldCortex reads your agent **session transcripts — both your prompts and the assistant's replies** — to auto-extract memorable context. PreCompact (before context compaction) reads the recent transcript; the SessionEnd and Stop handlers are **off by default**; the OpenClaw integration extracts from assistant output (the `cortex-memory` hook does this on `/new` and `/stop` when `openclawAutoMemory` is `true`); the hook's keyword-trigger path is not registered on core OpenClaw 2026.9.6, so keyword phrases are not captured through it. SessionStart does **not** read transcripts (it only loads existing local memory and scans project rule files).\n- **What it stores, and for how long.** Saved and auto-extracted memories are written to a **local SQLite database at `~/.shieldcortex/memories.db`** — title and content verbatim — and **persist across sessions** until you remove them (decay/consolidation prune low-value entries over time). Nothing is stored remotely unless you enable Cloud sync. Delete a memory with the `forget` tool, or remove the database to wipe everything.\n- **Secrets & credentials.** Every write — manual or auto-extracted — passes the defence pipeline first; high-confidence credential patterns (49 patterns across 25 providers) and content classified RESTRICTED are **blocked or quarantined before storage**, not saved as live memory. This is a strong filter, not a guarantee: low-confidence or low-entropy secrets can still be stored. On sensitive work, **review what auto-memory captures** and disable auto-extraction (`shieldcortex config --openclaw-auto-memory false`; the Claude Code handlers can be removed from `~/.claude/settings.json`).\n- **Keyword triggers are dormant on OpenClaw.** The `cortex-memory` hook contains keyword auto-save code (e.g. \"remember this\", \"don't forget\"), but it is not registered on core OpenClaw 2026.9.6: the hook's `events` list has no `message` key, so saying a phrase saves nothing through the hook. The code captures the *nearby* text, which may include more than the phrase, is capped (auto-extracts never outrank explicit saves) and runs through the same credential/injection scan.\n- **Subprocess execution.** The OpenClaw integration spawns short-lived `npx mcporter` subprocesses (via `execFile`, argv-array, no shell) to talk to your **local** ShieldCortex MCP server over stdio. One caveat for completeness: when ShieldCortex is not installed locally, the hook's fallback server command is `npx -y shieldcortex`, and `npx -y` will download the package from the npm registry on first use before executing it. Install `shieldcortex` globally (or set `binaryPath` in `~/.shieldcortex/config.json`) to guarantee no network fetch on that path.\n- **Cloud sync — off by default, opt-in, explicit.** No data leaves your machine unless you run `shieldcortex config --cloud-enable --cloud-api-key <key>`. When enabled:\n  - **Audit telemetry** (`/v1/audit/ingest`): scan **metadata only** — trust scores, threat indicators, categories, timings, device name. **No memory content.**\n  - **Memory sync** (`/v1/sync/memories`, Enterprise licence — grandfathered Team keys also unlock it): transmits **full memory title + content** of PUBLIC/INTERNAL memories so they sync across your team. CONFIDENTIAL/RESTRICTED memories are **excluded by default**; switch to metadata-only with the `contentMode` control.\n  - **Quarantine sync** (Enterprise licence): flagged content is sent with **detected credentials redacted**.\n  - **OpenClaw realtime plugin** (optional): scans live input and output **locally**. When it flags something, only **threat metadata** (type, scores, timestamps — **never the input text itself**) is forwarded, and only when Cloud sync is enabled. Flagged-content previews are kept in your **local** audit log; they are never transmitted.\n\n  Raw conversation/input text is never transmitted by the audit, threat, or interceptor paths — they carry metadata only. The single exception is **Memory sync** above, which uploads the content of memories you chose to store (PUBLIC/INTERNAL, off by default, Enterprise licence). You can disable any of the above at any time, and the realtime plugin and lifecycle handlers can be removed entirely.\n\n## What it does NOT do\n\n- Does **not** read SSH keys, AWS credentials, GPG keys, or /etc/ files\n- Does **not** send your data to external servers, with three narrow, user-initiated exceptions: Cloud sync when you enable it, the subscription id sent to the licence endpoint when you activate a licence key, and event payloads to webhooks you configure (memory-event and Iron Dome operator notifications). Its remaining outbound calls are downloads/fetches that carry only the request itself — never memory or conversation content: npm-registry update checks and X-Ray package lookups (the package name appears in the URL), the huggingface.co embedding-model download, and URLs you explicitly pass to `env scan`\n- Does **not** modify .bashrc, .zshrc, .profile, or shell configs\n- Does **not** use `eval` or dynamic code execution of any kind\n- Does **not** build subprocess commands from agent, memory, or network content. The update flow and the OpenClaw MCP bridge never spawn a shell — argv-array `execFile`/`spawn` only (`npm view` update check, `npm update`/`npm install`, `pgrep`, `npx mcporter`). The dashboard X-Ray surface adds two more argv-array, local-only children: `osascript` with fixed script lines (macOS folder picker) and ShieldCortex's own Node binary re-spawned for `xray --watch` background scans (hook and server helpers re-spawn `process.execPath` the same way, always with fixed local script paths). Sudo-aware home resolution validates the username, then runs `getent passwd <user>` as an argv-array — never through a shell, no tilde-eval. User-run CLI commands (setup, service, migrate, uninstall, audit, doctor, the npx-staleness warning) and corrupt-database recovery run fixed local admin tools (`npm`, `launchctl`, `systemctl`, `sqlite3`), some through a shell, parameterised only by local paths and usernames\n- Does **not** bypass, disable, or override any agent safety mechanisms\n- Does **not** auto-approve actions or skip verification prompts\n- Does **not** mine cryptocurrency, trade tokens, manage wallets, or initiate purchases\n- Does **not** make purchases, place orders, or move money on the user's behalf\n\n## CLI Reference\n\n### Getting Started\n```bash\nshieldcortex quickstart          # Detect integrations, guide setup\nshieldcortex setup               # Register MCP server for current project\nshieldcortex doctor              # Diagnose registration issues\nshieldcortex status              # Show protection status\nshieldcortex uninstall           # Remove from project\n```\n\n### Memory\n```bash\n# Memory is typically used via the MCP server, not the CLI directly. The tools are:\n#   remember · recall · forget · get_context · get_memory · get_related\n#   consolidate · graph_query · graph_entities · scan_memories · memory_stats\n#   start_session · end_session\n# (there is no `store`, `search` or bare `graph` tool — use remember/recall/graph_query)\nshieldcortex graph backfill      # Build knowledge graph from stored memories\nshieldcortex stats               # Memory statistics\n```\n\n### Security Scanning\n```bash\nshieldcortex scan \"text\"                    # Scan text (exit 0=allow, 1=caught, 2=usage, 3=tool-fail; parse stdout)\nshieldcortex scan-skill path/to/SKILL.md    # Scan one instruction file for threats\nshieldcortex scan-skills                    # Scan all discovered agent instruction files\nshieldcortex audit                          # Full security audit (memory, env, MCP configs, rules files)\nshieldcortex iron-dome status               # Iron Dome behavioural protection status\n```\n\n### Cortex — Mistake Learning\n```bash\n# capture requires all four flags: --category --what --why --rule\nshieldcortex cortex capture --category code --what \"Guessed API endpoints\" \\\n  --why \"Didn't check the docs\" --rule \"Verify endpoints in API docs before calling\"\nshieldcortex cortex preflight --task \"deploy to production\"           # Pre-task check\nshieldcortex cortex review                                            # Pattern analysis\nshieldcortex cortex list                                              # View mistake log\nshieldcortex cortex search \"<query>\"                                  # Full-text search\nshieldcortex cortex stats                                             # Category breakdown\nshieldcortex cortex confirm --category code --what \"...\" \\\n  --why-worked \"...\" --when-repeat \"...\"                              # Capture what worked\nshieldcortex cortex graduate                                          # Archive mastered rules\n```\n\n### Dashboard & Services\n```bash\nshieldcortex dashboard           # Dashboard on localhost:3030 (starts the API on :3001 too)\nshieldcortex api                 # Start the API server only (localhost:3001)\nshieldcortex worker              # Background sync + heartbeat worker\nshieldcortex service start|stop|status  # Manage background service\n```\n\n### Integrations\n```bash\n# subcommand is `install`, not `setup` (also: status, uninstall; openclaw adds repair, skill)\nshieldcortex openclaw install    # Hook + realtime plugin — tool gate BOUND\nshieldcortex copilot install     # VS Code / Cursor MCP memory server — NOT a tool gate\nshieldcortex codex install       # Codex CLI MCP memory server — NOT a tool gate\nshieldcortex config --openclaw-auto-memory true   # Enable auto-memory in OpenClaw\nshieldcortex config --proactive-recall true|false  # Enable/disable proactive recall\n```\n\n### Cloud & Licensing\n```bash\nshieldcortex config --cloud-enable --cloud-api-key <key>  # Enable cloud sync\nshieldcortex cloud sync --full    # Backfill memories + graph to cloud\nshieldcortex license activate <key>  # Activate an Enterprise (or legacy) licence key\nshieldcortex license status       # Check licence tier\n```\n\n### Maintenance\n```bash\nshieldcortex update              # Self-update (npm package + OpenClaw plugin + skill)\n```\n\n## What Gets Scanned\n\n### `scan-skills` discovers and scans:\n- SKILL.md, HOOK.md, handler.js (Claude Code / OpenClaw skills)\n- .cursorrules, .windsurfrules, .clinerules (editor rules)\n- CLAUDE.md, copilot-instructions.md (agent instructions)\n- .aider.conf.yml, .continue/config.json (tool configs)\n- Searches: ~/.claude/skills/, ~/.openclaw/skills/, ~/.openclaw/hooks/, project directories\n\n### `audit` checks:\n- **Memory files** — ~/.claude/projects/, ~/.cursor/memories/, ~/.windsurf/memories/\n- **Environment** — .env files for leaked credentials (read-only check, never writes)\n- **MCP configs** — ~/.claude/mcp.json, ~/.openclaw/mcp.json, ~/.cursor/mcp.json, project-level equivalents\n- **Rules files** — CLAUDE.md, .cursorrules, copilot-instructions.md for injection patterns\n\n## What Gets Uploaded to Cloud\n\nCloud sync is **off by default**. Audit metadata sync is included on the cloud free tier; full memory/graph replication requires an Enterprise licence (grandfathered Team keys keep working).\n\n- **Uploaded when Cloud sync is enabled by the user:** selected memory records, related embeddings/metadata, and knowledge-graph entities/relationships required for sync.\n- **Not uploaded by default:** local agent configs, MCP configs, raw rules files, shell configs, SSH keys, secrets, `.env` contents, or arbitrary project files.\n- **Security scan results stay local** unless the user explicitly exports or syncs data through a Cloud-enabled workflow.\n- **No sync traffic** occurs unless the user explicitly enables Cloud sync and provides a valid API key. Outside sync, the only api.shieldcortex.ai call is licence-key validation when a key is activated (subscription id only, never memory content) — see `network_endpoints`.\n\n## Licence Tiers\n\nPublic tiers are **Free** and **Enterprise** (sales@drakonsystems.com). Every local feature is Free; grandfathered Pro/Team keys keep working.\n\n| Feature | Free | Enterprise |\n|---------|------|------------|\n| Memory (store/recall/search/graph) | ✅ | ✅ |\n| Proactive recall (auto-inject on prompts) | ✅ | ✅ |\n| Defence pipeline (scan, Iron Dome) | ✅ | ✅ |\n| Audit & scan-skills | ✅ | ✅ |\n| Dashboard | ✅ | ✅ |\n| Custom injection patterns | ✅ | ✅ |\n| Custom Iron Dome policies | ✅ | ✅ |\n| Custom firewall rules | ✅ | ✅ |\n| Audit export | ✅ | ✅ |\n| Deep skill scanning | ✅ | ✅ |\n| Cortex (mistake learning) | ✅ | ✅ |\n| Cloud audit sync (metadata, 500 scans/mo, 7-day retention) | ✅ | ✅ |\n| Cloud memory/graph sync | ❌ | ✅ |\n| Team management | ❌ | ✅ |\n| Shared patterns | ❌ | ✅ |\n\n## Links\n\n- **Docs:** https://shieldcortex.ai/docs\n- **Source:** https://github.com/Drakon-Systems-Ltd/ShieldCortex\n- **npm:** https://www.npmjs.com/package/shieldcortex\n- **Issues:** https://github.com/Drakon-Systems-Ltd/ShieldCortex/issues\n- **Changelog:** https://shieldcortex.ai/changelog\n\n## API bind (#411)\n- Default bind is loopback (`127.0.0.1`).\n- Non-loopback requires `SHIELDCORTEX_ALLOW_NON_LOOPBACK=1` **and** `SHIELDCORTEX_API_TOKEN` (≥32 chars).\n- Public `/api/auth/session-token` is loopback-only.\n\nFile v5.5.0:_meta.json\n\n{\n  \"ownerId\": \"kn71759x1py9k3ak7d6hjwbx5x812cf2\",\n  \"slug\": \"shieldcortex\",\n  \"version\": \"5.5.0\",\n  \"publishedAt\": 1791443035770\n}\n\nFile v5.5.0:bundled/cortex-memory-hook/HOOK.md\n\n---\nname: cortex-memory\ndescription: \"Persistent brain-like memory via ShieldCortex — recalls past knowledge, with optional auto-save\"\nhomepage: https://github.com/Drakon-Systems-Ltd/ShieldCortex\nmetadata:\n  { \"openclaw\": { \"emoji\": \"🧠\", \"events\": [\"command:new\", \"command:stop\", \"agent:bootstrap\"], \"requires\": { \"bins\": [\"npx\"] }, \"install\": [{ \"id\": \"community\", \"kind\": \"community\", \"label\": \"ShieldCortex\" }] } }\n---\n\n# Cortex Memory Hook\n\nIntegrates [ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) persistent memory. Recalls past knowledge at session start, and can optionally auto-save important session context.\n\n## What It Does\n\n### On `/new` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Reads the ending session transcript\n2. Pattern-matches for decisions, bug fixes, learnings, architecture changes, and preferences\n3. Saves up to 5 high-salience memories to ShieldCortex via mcporter\n4. Skips exact and near-duplicate memories using novelty filtering\n\n### On `/stop` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Reads the current session transcript\n2. Pattern-matches for important content (same patterns as `/new`)\n3. Saves memories with a `session-stop` tag for tracking\n4. Skips exact and near-duplicate memories using novelty filtering\n\nCore OpenClaw 2026.9.6 does not show the hook's \"Saved N memories\" note for `/stop`: the stop command sends its own reply and does not read the hook's `event.messages`.\n\n`/clear` and `/exit` are not core OpenClaw 2026.9.6 hook events, and they are not in this hook's `events` list, so this hook does not capture on them.\n\n### On Session Start (Agent Bootstrap)\nBootstrap context injection was **disabled in v2026.2.26**. OpenClaw's native Memory Search now handles context recall at session start, so the hook no longer pushes memories into the system prompt (which was producing ~40× duplication of CORTEX_MEMORY.md and eating most of the context window).\n\nThe hook still fires on `agent:bootstrap` for lifecycle wiring (warning-bootstrap-file handoff, etc.) but contributes nothing to the system prompt. This keeps `extraSystemPromptHash` stable across turns and prevents the session-binding reset loop documented in `src/setup/claude-md.ts`.\n\n### Keyword Triggers (dormant, not registered)\n\nThe handler has a keyword-trigger path, but it is **not registered** on core OpenClaw 2026.9.6 with this manifest, and it is not enabled by default. The `events` list above subscribes only `command:new`, `command:stop` and `agent:bootstrap`. OpenClaw never sends this hook a `message` event, and no other command action reaches the handler's command fallback. Saying one of these phrases does **not** save anything through this hook. The per-message proactive recall in the same `message` branch is dormant for the same reason; this hook does not recall memory on each message.\n\nPhrases the dormant code recognises:\n\n| Trigger Phrase | Category | Importance |\n|---------------|----------|------------|\n| **\"remember this\"** | note | critical |\n| **\"don't forget\"** | note | critical |\n| **\"this is important\"** | note | critical |\n| **\"make a note\"** | note | critical |\n| **\"for the record\"** | note | critical |\n| **\"note to self\"** | note | critical |\n| **\"important:\"** | note | critical |\n| **\"crucial:\"** | note | critical |\n| **\"key point:\"** | note | high |\n| **\"lesson learned\"** | learning | high |\n| **\"i learned\"** | learning | normal |\n| **\"TIL:\"** | learning | normal |\n| **\"today i learned\"** | learning | normal |\n| **\"never again\"** | error | critical |\n| **\"root cause was\"** | error | high |\n| **\"the fix was\"** | error | high |\n| **\"always do\"** | preference | high |\n| **\"never do\"** | preference | high |\n| **\"i prefer\"** | preference | normal |\n| **\"we should always\"** | preference | high |\n| **\"we decided\"** | architecture | high |\n| **\"decision made\"** | architecture | high |\n| **\"going with\"** | architecture | normal |\n\nThe dormant helper tries to save the text after the phrase, or the whole message when that text is under five characters. Subscribing a `message` event would not be enough on its own: the handler returns unless `event.role` is `\"user\"` and reads the text from `event.content`, but the OpenClaw 2026.9.6 hook event has no top-level `role` or `content` field (a received message's text is in `event.context.content`). With that event shape the handler stops at the role check and never reaches the keyword check.\n\n## Defence Audit Guarantees\n\nEvery byte that lands in `memories` from the auto-extract path passes the\n6-layer defence pipeline first. The hook write path is no longer the\nbypass it once was:\n\n- **ALLOW** → row inserted into `memories`; a corresponding row appears in\n  `defence_audit` with `source_type = 'hook'` and the hook's identifier\n  (`session-end-hook` / `pre-compact-hook` / `stop-hook`).\n- **QUARANTINE** → row inserted into `quarantine` (not `memories`), linked\n  to the audit row via `audit_id`. Visible in the dashboard for review.\n- **BLOCK** → dropped. The audit row written by the pipeline carries the\n  block reason; nothing reaches `memories`.\n- **Pipeline error** → dropped + a synthetic audit row with reason\n  `pipeline_error: <msg>`. Never silently lose data.\n\nBuilt-in firewall rules covering instruction injection, hidden\ninstruction, imperative tool-call directives (\"call X tool now\"), command\ninjection, and credential leaks (AWS / JWT / private keys) are seeded\ninto `firewall_rules` on first run with `built_in = 1`. They are\nalways evaluated (user-added custom rules are free too, behind a dormant\nfeature gate) and excluded from the user-facing 25-rule cap.\n\nThe chunker also rejects malformed candidates *before* they reach the\nwrite path: imperative tool-calls, bare-imperative starts (\"commit\nsecrets\" with the negation dropped), email-body bleed, and path-label\nfragments. Auto-extracted memories are now capped at salience 0.6\n(reserved 1.0 for LLM-rated future paths).\n\nTo audit an existing database for malformed rows accumulated before this\nfix:\n\n```bash\nshieldcortex memories purge --malformed --dry-run    # preview\nshieldcortex memories purge --malformed --execute    # delete (writes a backup first)\n```\n\n## Auto-Memory\n\nAuto-memory extraction runs only when `openclawAutoMemory` is `true` in `~/.shieldcortex/config.json`. When the key is not set, or the file is missing, it is off. A fresh global, non-CI `npm install -g shieldcortex` on a machine with no config file writes one with `openclawAutoMemory: true` (and `proactiveRecall: true`) when that write succeeds. Local and CI installs, and installs run with `--ignore-scripts`, do not write it. An existing config file is never changed, so an upgrade keeps whatever it already says. When on, it captures decisions, fixes, and learnings, with deduplication.\n\nThe config file does not install this hook. It runs only once the hook is installed in OpenClaw and not disabled there: `shieldcortex openclaw install`, or `shieldcortex setup`, which asks before wiring.\n\nDisable auto-save with CLI:\n\n```bash\nnpx shieldcortex config --openclaw-auto-memory false\n```\n\nRe-enable it:\n\n```bash\nnpx shieldcortex config --openclaw-auto-memory true\n```\n\nOr set directly in config:\n\n```json\n{\n  \"openclawAutoMemory\": true\n}\n```\n\nin `~/.shieldcortex/config.json`.\n\n## Requirements\n\n- **npx** must be available (Node.js installed)\n- ShieldCortex installs automatically on first use via `npx -y shieldcortex`\n- mcporter must be available for MCP tool calls\n\n## Database\n\nMemories stored in `~/.shieldcortex/memories.db` (SQLite). Shared with Claude Code sessions — memories created here are available everywhere.\n\n## Install\n\n```bash\nopenclaw skills install shieldcortex\n```\n\nOptional companion real-time plugin:\n\n```bash\nopenclaw plugins install @drakon-systems/shieldcortex-realtime\n```\n\n## Uninstall\n\n```bash\nshieldcortex openclaw uninstall\n```\n\nOr disable without removing:\n\n```json\n{\n  \"hooks\": {\n    \"internal\": {\n      \"entries\": {\n        \"cortex-memory\": { \"enabled\": false }\n      }\n    }\n  }\n}\n```\n\nFile v5.5.0:skill-card.md\n\n## Description:\n\nMemory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jarvis-drakon](https://clawhub.ai/user/jarvis-drakon)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users use ShieldCortex to retain and recall session knowledge, scan agent content for threats, and manage memory across supported integrations.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Automatic memory capture can retain sensitive session content locally.\n\nMitigation: Review auto-memory settings and disable capture for sensitive work.\n\nRisk: Self-heal can modify an existing OpenClaw hook installation without prompting.\n\nMitigation: Review hook behavior and disable self-heal if automatic changes are unwanted.\n\nRisk: Runtime npx fallback can execute an unpinned npm package in an agent context.\n\nMitigation: Prefer a reviewed, pinned local or global installation over runtime npx.\n\nRisk: Optional cloud sync can transmit selected memory content and audit metadata.\n\nMitigation: Keep cloud sync off unless the data and sharing settings are appropriate.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/jarvis-drakon/skills/shieldcortex)\n- [ShieldCortex website](https://shieldcortex.ai)\n- [ShieldCortex npm package](https://www.npmjs.com/package/shieldcortex)\n- [Publisher GitHub profile (listed in metadata)](https://github.com/Drakon-Systems-Ltd)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance]\n\n**Output Format:** [Text and structured tool responses]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Memory recall and security scan results depend on enabled integrations and settings.]\n\n## Skill Version(s):\n\n5.5.0 (source: server-resolved release and skill metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v5.5.0:bundled/openclaw-plugin/openclaw.plugin.json\n\n{\n  \"id\": \"shieldcortex-realtime\",\n  \"version\": \"4.31.2\",\n  \"name\": \"ShieldCortex Real-time Scanner\",\n  \"description\": \"Real-time defence scanning on LLM input, memory extraction on LLM output, and active tool call interception with approval gating.\",\n  \"kind\": null,\n  \"engines\": {\n    \"openclaw\": \">=2026.3.22\",\n    \"recommended\": \">=2026.4.23\"\n  },\n  \"enabledByDefault\": false,\n  \"activation\": {\n    \"onStartup\": false,\n    \"hooks\": [\n      \"llm_input\",\n      \"llm_output\",\n      \"before_tool_call\",\n      \"session_end\"\n    ],\n    \"commands\": [\n      \"shieldcortex-status\"\n    ]\n  },\n  \"contracts\": {},\n  \"commandAliases\": {\n    \"shieldcortex-status\": \"shieldcortex-status\"\n  },\n  \"uiHints\": {\n    \"binaryPath\": {\n      \"label\": \"ShieldCortex Binary Path\",\n      \"help\": \"Optional absolute path to the shieldcortex CLI when it is not on PATH.\",\n      \"placeholder\": \"/usr/local/bin/shieldcortex\",\n      \"advanced\": true\n    },\n    \"cloudApiKey\": {\n      \"label\": \"Cloud API Key\",\n      \"help\": \"Optional ShieldCortex Cloud API key used for realtime threat forwarding.\",\n      \"placeholder\": \"sc_...\",\n      \"sensitive\": true\n    },\n    \"cloudBaseUrl\": {\n      \"label\": \"Cloud Base URL\",\n      \"help\": \"Override the ShieldCortex Cloud API base URL if you use a self-hosted or staging endpoint.\",\n      \"placeholder\": \"https://api.shieldcortex.ai\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemory\": {\n      \"label\": \"Auto Memory Extraction\",\n      \"help\": \"Extract high-signal decisions and learnings from LLM output into ShieldCortex memory.\"\n    },\n    \"openclawAutoMemoryDedupe\": {\n      \"label\": \"Dedupe Auto Memory\",\n      \"help\": \"Skip near-duplicate memories before they are written to ShieldCortex.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryNoveltyThreshold\": {\n      \"label\": \"Novelty Threshold\",\n      \"help\": \"Similarity threshold for duplicate suppression. Higher values keep more memories.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryMaxRecent\": {\n      \"label\": \"Recent Memory Cache Size\",\n      \"help\": \"How many recent extracted memories to keep in the dedupe cache.\",\n      \"advanced\": true\n    },\n    \"interceptor.enabled\": {\n      \"label\": \"Enable Tool Call Interceptor\",\n      \"description\": \"Scan memory-write tool calls and gate suspicious content behind user approval\",\n      \"type\": \"boolean\"\n    },\n    \"interceptor.severityActions.high\": {\n      \"label\": \"High Severity Action\",\n      \"description\": \"Action for high-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    },\n    \"interceptor.severityActions.critical\": {\n      \"label\": \"Critical Severity Action\",\n      \"description\": \"Action for critical-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    }\n  },\n  \"configSchema\": {\n    \"type\": \"object\",\n    \"additionalProperties\": false,\n    \"properties\": {\n      \"enabled\": {\n        \"type\": \"boolean\"\n      },\n      \"binaryPath\": {\n        \"type\": \"string\"\n      },\n      \"cloudApiKey\": {\n        \"type\": \"string\"\n      },\n      \"cloudBaseUrl\": {\n        \"type\": \"string\"\n      },\n      \"openclawAutoMemory\": {\n        \"type\": \"boolean\"\n      },\n      \"openclawAutoMemoryDedupe\": {\n        \"type\": \"boolean\"\n      },\n      \"openclawAutoMemoryNoveltyThreshold\": {\n        \"type\": \"number\",\n        \"minimum\": 0.6,\n        \"maximum\": 0.99\n      },\n      \"openclawAutoMemoryMaxRecent\": {\n        \"type\": \"integer\",\n        \"minimum\": 50,\n        \"maximum\": 1000\n      },\n      \"interceptor\": {\n        \"type\": \"object\",\n        \"properties\": {\n          \"enabled\": {\n            \"type\": \"boolean\",\n            \"default\": true\n          },\n          \"severityActions\": {\n            \"type\": \"object\",\n            \"additionalProperties\": false,\n            \"properties\": {\n              \"low\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              },\n              \"medium\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              },\n              \"high\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"warn\"\n              },\n              \"critical\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              }\n            }\n          },\n          \"failurePolicy\": {\n            \"type\": \"object\",\n            \"additionalProperties\": false,\n            \"properties\": {\n              \"low\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"allow\"\n              },\n              \"medium\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"allow\"\n              },\n              \"high\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"deny\"\n              },\n              \"critical\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"deny\"\n              }\n            }\n          }\n        }\n      }\n    }\n  }\n}\n\nArchive v5.4.0: 11 files, 51737 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (47494b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9228b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (1927b), SKILL.md (31309b), _meta.json (131b)\n\nFile v5.4.0:SKILL.md\n\n---\nname: shieldcortex\ndescription: \"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\"\nlicense: MIT-0\nmetadata:\n  author: Drakon Systems\n  version: 5.4.0\n  mcp-server: shieldcortex\n  category: memory-and-security\n  tags: [memory, security, knowledge-graph, mcp, iron-dome, openclaw-plugin, audit]\n  source: https://github.com/Drakon-Systems-Ltd/ShieldCortex\n  homepage: https://shieldcortex.ai\n  npm: https://www.npmjs.com/package/shieldcortex\n  verified_publisher: Drakon Systems Ltd\n  publisher_github: https://github.com/Drakon-Systems-Ltd\n  npm_audit: \"0 unwaived production advisories; 3 waived (sharp: GHSA-f88m-g3jw-g9cj, GHSA-rgj7-g3m4-5g8c; sprintf-js: GHSA-hp3w-g68c-fv3c, via optional @huggingface/transformers) - see docs/security/audit-waivers.md\"\n  downloads: 11K+/month\ninstall:\n  command: shieldcortex quickstart\n  runtime: node\n  minVersion: \"22.14.0\"\n  note: >\n    Requires Node 22.14+ LTS or Node 24+; Node 23 is unsupported. Run the installed\n    `shieldcortex` binary directly. The quickstart command\n    detects your environment. Claude Code and OpenClaw get hooks that can deny;\n    Codex/Cursor/VS Code get an MCP memory server only (not a tool gate).\n    All data stays local in ~/.shieldcortex/. No account or API key needed\n    for local use.\npermissions:\n  filesystem: readwrite\n  network: optional\n  credentials: optional\n  justification: >\n    Filesystem read: scans agent instruction files for prompt injection threats\n    (same files the agent already reads). Filesystem write: stores memory DB\n    and config in ~/.shieldcortex/. Network: local-first — outbound only for\n    the embedding-model download when it is not cached (huggingface.co;\n    disable with SHIELDCORTEX_SKIP_EMBEDDINGS=1), Cloud sync (opt-in),\n    licence-key validation when a key is activated, explicit update\n    checks/updates and X-Ray package lookups (npm registry), URLs you ask\n    `env scan` to fetch, and webhooks you configure. Credentials: optional\n    Cloud API key for team sync (not required for local use).\n  paths_read:\n    - ~/.shieldcortex/ (own config and memory database)\n    - ~/.claude/ (project memory files, MCP config)\n    - ~/.openclaw/ (MCP config, extensions)\n    - ~/.cursor/ (rules, memories, MCP config)\n    - ~/.windsurf/ (memories, rules)\n    - ~/.codex/ (MCP config)\n    - $CWD/.claude/, $CWD/.cursor/ (project-level configs)\n    - $CWD/.cursorrules, $CWD/.windsurfrules, $CWD/.clinerules\n    - $CWD/CLAUDE.md, $CWD/copilot-instructions.md\n    - $CWD/.aider.conf.yml, $CWD/.continue/config.json\n    - $CWD/.env (env-scanner checks for leaked secrets — reads, never writes)\n  paths_write:\n    - ~/.shieldcortex/ (memory DB, config, cortex log, licence, audit cache)\n    - ~/.cache/shieldcortex/models (embedding model download cache)\n    - ~/.openclaw/extensions/shieldcortex-realtime/ (OpenClaw plugin via the wrapper install only; native `openclaw plugins install` uses OpenClaw's managed npm tree instead)\n    - ~/.claude/mcp.json, ~/.cursor/mcp.json (MCP server registration, when user runs setup)\n  network_endpoints:\n    - https://api.shieldcortex.ai (Cloud sync + audit telemetry — only when Cloud sync is enabled; licence validation — only when a licence key is activated, fired at CLI `license activate` and the dashboard's activation call (POST /api/license/activate), with no periodic or background re-check; sends the subscription id, works with Cloud sync off; never called when no key is configured)\n    - https://huggingface.co (embedding-model download — Xenova/all-MiniLM-L6-v2, ~90 MB, fetched into ~/.cache/shieldcortex/models by the MCP server's background preload at startup or the first operation needing an embedding, whenever the model is not already cached, plus one re-download if a cached copy is detected corrupt; SHIELDCORTEX_SKIP_EMBEDDINGS=1 prevents it. The optional Local AI Explainer model downloads from the same host only on explicit, consent-prompted `review-copilot enable`/`download-model` — its review runs use the local cache only)\n    - https://registry.npmjs.org (three paths — explicit update actions via npm subprocess, dashboard \"Check for updates\"/\"Update\" or `shieldcortex update`; X-Ray package inspection, `shieldcortex xray <package>` or the dashboard X-Ray page, which queries package metadata directly over HTTPS and with `--deep` also downloads the package tarball from whatever URL that metadata names — normally registry.npmjs.org, size- and redirect-capped, but with no separate host allowlist; and the OpenClaw hook's `npx -y shieldcortex` fallback, which downloads the package on first use when ShieldCortex is not installed locally)\n    - User-configured webhook URLs (two POST paths — memory-event notifications to webhooks you add to ~/.shieldcortex/config.json, and Iron Dome operator-notify messages for action-guard holds/denies to the `actionGuard.notify` webhook you configure; both off until you configure them)\n    - The URL you pass to `shieldcortex env scan <url>` (fetched once for analysis)\n    - http://localhost:3001 (local REST API + WebSocket — loopback only)\n    - http://localhost:3030 (local dashboard UI; also the worker health check — loopback only)\n  env:\n    - SHIELDCORTEX_CONFIG_DIR: Override config directory (default ~/.shieldcortex/)\n    - SHIELDCORTEX_API_KEY: Cloud sync API key (optional; only used when Cloud is enabled)\n    - SHIELDCORTEX_LICENSE_TIER: Override licence tier (development use)\n    - SHIELDCORTEX_SKIP_EMBEDDINGS: Disable embedding generation\n    - SHIELDCORTEX_SKIP_SELF_HEAL: Set to 1 to make the cortex-memory hook's bootstrap self-heal warn-only (writes nothing)\n    - SHIELDCORTEX_HOST: Override dashboard/API bind host\n    - PORT: Override dashboard/API port\n---\n\n# ShieldCortex — Persistent Memory & Security for AI Agents\n\nMemory system with built-in security. Gives agents persistent memory (semantic search, knowledge graphs, decay, contradiction detection) and protects it with a 6-layer defence pipeline (input sanitisation → trust scoring → firewall → sensitivity classification → fragmentation detection → credential-leak detection). Skill threat patterns (tool injection, scope escalation, data exfiltration, persistence, supply-chain, agent manipulation, stealth instructions) block at memory-write time, not just on skill-file scans.\n\nThis is an enforcing memory boundary, not a passive scanner. Across the read/write boundary it actively: **quarantines or blocks** poisoned/credential-bearing writes; **trust/ACL-filters recalled memory** (RESTRICTED isolation, own-only for low-trust callers) before it reaches the agent, on both the prompt hooks and the MCP read tools; runs a **tool-output firewall** that, in enforce mode, redacts or withholds malicious tool results before the model sees them (advisory by default); and keeps a **provenance ledger** recording read/write/delete operations with content hashes for forensics. Enforcement that could surprise is opt-in (the tool-output firewall defaults to advisory; `shieldcortex config --tool-firewall-enforce` turns on blocking).\n\n## Provenance & Trust\n\n| Signal | Value |\n|--------|-------|\n| **Publisher** | [Drakon Systems Ltd](https://github.com/Drakon-Systems-Ltd) (UK company) |\n| **Source code** | [github.com/Drakon-Systems-Ltd/ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) — fully open, **MIT** licence (this skill file itself is published MIT-0, per the frontmatter) |\n| **npm package** | [npmjs.com/package/shieldcortex](https://www.npmjs.com/package/shieldcortex) — every release git-tagged with a matching GitHub release |\n| **npm audit** | Clean — `npm audit` returns 0 vulnerabilities |\n| **Downloads** | 11,000+/month (July 2026) |\n| **CI/CD** | CI lint/test on every push; the maintainer manually tags each release, and the tag push triggers an automated CI publish to npm |\n| **Postinstall script** | Declared and bounded: prints setup instructions; on **global** installs it also smoke-tests the native SQLite binding, seeds default config on first install, and refreshes an OpenClaw hook/plugin that a previous setup already installed. It never adds integrations to a machine that had none, and it is a no-op for CI and local dependency installs. `SHIELDCORTEX_SKIP_AUTO_OPENCLAW=1` skips the refresh. |\n| **Dependencies** | 8 runtime deps: `better-sqlite3`, `zod`, `@modelcontextprotocol/sdk`, `express`, `ws`, `cors`, `safe-regex2`, `semver`. `express`/`ws`/`cors` serve the bundled localhost-only dashboard/API. One optional dep, `@huggingface/transformers`, runs the local embedding model and fetches it from huggingface.co when it is not cached (see `network_endpoints`). Nothing else dials out except the cases listed under `network_endpoints` (Cloud sync opt-in, licence-key validation, update checks, X-Ray package lookups, env-scan URLs, configured webhooks). |\n\n## Safety & Scope\n\nThis section explains every privileged operation the tool performs and why.\n\n- **Active interception, not scan-only — on hosts that can deny.** Writes failing the pipeline are quarantined/blocked; recalled memory is trust/ACL-filtered before the agent sees it. Tool-call denial is **bound** on Claude Code (PreToolUse), OpenClaw (`before_tool_call`), and Hermes (`pre_tool_call`, enforce by default). Codex, Cursor, Copilot, and generic MCP get a memory server / scanner the model may ignore — they are **not bound**. Tool-output firewall defaults to advisory. `shieldcortex doctor` and `shieldcortex lease` report bound / not-bound / unknown per plane.\n- **Setup is user-initiated, with one bounded exception.** Installing hooks, registering the MCP server, and migrating data are manual steps the user runs in their terminal, and `quickstart` asks before each action. The npm postinstall script (disclosed in the trust table above) never adds integrations that weren't already present — on global installs it only prints instructions, checks the native binding, seeds default config on first install, and refreshes an existing OpenClaw hook/plugin install. The exception: the bundled cortex-memory hook performs a small automatic self-heal at gateway bootstrap, documented in full under **\"Automatic self-heal at gateway bootstrap\"** below.\n- **Setup migrates legacy data.** The first `quickstart`/`setup` run may move or remove legacy config/memory directories (e.g. `~/.claude-cortex/`, `~/.claude-memory/`) into `~/.shieldcortex/` and copy hook files into place. This happens only on the user-run setup command — never on `npm install` (the postinstall script does not touch memory or config data beyond seeding defaults on a first-ever global install).\n- **Destructive `forget` is bounded and gated.** Per-memory and filtered bulk deletes go through a delete ACL (own-only) and are recorded in the audit ledger. Revoke-by-source (`forget --fromSource`, bulk-delete every memory from one source — for purging a poisoned agent) is **disabled by default** and only enabled by an out-of-band human action (`shieldcortex config --allow-revoke-by-source`); even then it is bounded by a trust-hierarchy ACL (you must own the source or out-rank it) and a per-call row cap. A compromised agent cannot mass-delete your memory.\n- **The bundled dashboard never renders RESTRICTED content.** The local visualization API and its WebSocket feed redact credential-class (`RESTRICTED`) memory content before it reaches the browser — the row stays visible (title/metadata) so you can manage it, but the secret is withheld (view full content via the CLI). Credential patterns in titles/metadata are masked too. This is a display-surface safeguard on top of the on-disk store; it does not weaken the firewall.\n- **No credentials required for local use.** Memory, scanning, and audit work fully offline. Cloud sync is opt-in and requires a user-provided API key via `shieldcortex config --cloud-enable --cloud-api-key <key>`.\n- **File access is declared and scoped.** Security scans read agent config directories listed in the permissions block above — the same directories the agent itself already has access to. They do not traverse arbitrary directories.\n- **Writes are contained.** All data goes to `~/.shieldcortex/` (plus the embedding-model cache at `~/.cache/shieldcortex/models`). MCP config edits (`setup`, `copilot`, `codex` commands) modify specific JSON files and confirm before writing.\n- **First-use model download (huggingface.co).** Semantic memory runs a local embedding model (Xenova/all-MiniLM-L6-v2, ~90 MB ONNX) that is **not bundled** with the package. Whenever it is missing from `~/.cache/shieldcortex/models`, the MCP server downloads it from huggingface.co — triggered by the background preload at server start, or by the first operation that needs an embedding, plus a single re-download if a cached copy is detected corrupt. This is the one network call that is not user-initiated. Avoid it with `SHIELDCORTEX_SKIP_EMBEDDINGS=1` (memory falls back to full-text search) or by pre-seeding the model cache. The optional Local AI Explainer (`review-copilot`) downloads its model from the same host only on an explicit, consent-prompted `enable`/`download-model` command; its review runs never fetch remotely.\n- **Network is off by default, with the first-run exception above.** With no licence key activated, no Cloud sync enabled, and no webhooks configured, ShieldCortex's only outbound connections are the embedding-model download just described (fires on server start when the model is not cached) and one further caveat: the OpenClaw hook's `npx -y shieldcortex` fallback downloads the package on first use when ShieldCortex is not installed locally — see `network_endpoints`. Every other entry in `network_endpoints` is user-initiated: Cloud sync (opt-in), licence-key validation when you activate a key (at CLI or dashboard activation only, no background re-check — works even with Cloud sync off), npm-registry update checks/updates (dashboard buttons or `shieldcortex update`), X-Ray package lookups (`shieldcortex xray` or the dashboard X-Ray page, tarball download with `--deep`), URLs you pass to `env scan`, and webhooks you configure (memory events and Iron Dome operator notifications). The dashboard binds to localhost by default but may be explicitly exposed with `SHIELDCORTEX_HOST`; when exposed, the loopback session-token endpoint stays disabled. The worker binds to localhost.\n- **Bundled source code.** The OpenClaw plugin and cortex-memory handler are shipped in the package for inspection before use.\n- **Lifecycle event handlers.** ShieldCortex registers lifecycle handlers that auto-extract important context from conversations. These are registered in `~/.claude/settings.json` during setup and can be removed at any time. They run locally, never phone home.\n- **Proactive recall.** The UserPromptSubmit handler queries local memory on each prompt (<100ms) and surfaces relevant context. Fully local, configurable: `shieldcortex config --proactive-recall false`.\n\n### Automatic self-heal at gateway bootstrap\n\nThe cortex-memory hook registers for the `agent:bootstrap` event. On the first\nbootstrap after each OpenClaw gateway start (once per gateway process), it runs\na self-check that can write without a prompt. In the interest of full\ndisclosure, this is exactly what it does:\n\n1. **Removes stale legacy hook copies.** If the hook is running from its\n   expected home (`~/.openclaw/hooks/internal/cortex-memory` or\n   `~/.openclaw/hooks/cortex-memory`), it recursively deletes the pre-rename\n   leftovers `~/.clawdbot/hooks/cortex-memory` and\n   `~/.clawdbot/hooks/internal/cortex-memory` — and only those two\n   directories. It skips this entirely when `~/.clawdbot` is a symlink (i.e.\n   still pointing at a live install). No backup is taken before deletion;\n   these directories are assumed to be dead copies of this hook's own files,\n   not your data.\n2. **Copies itself to the expected hook path.** If the hook finds itself\n   running from anywhere else (for example, from inside this skill's\n   `bundled/` folder after a skills-only install), it creates\n   `~/.openclaw/hooks/internal/cortex-memory/` and copies its full file set\n   (`HOOK.md`, `handler.ts`, `runtime.mjs`) there so the gateway loads it from\n   the canonical location on the next restart, and surfaces a\n   `SHIELDCORTEX_HOOK_MIGRATED.md` notice into the session's bootstrap context.\n   If any file in that set fails to copy, the migration is reported as\n   incomplete rather than as a success — a partially-copied hook cannot load.\n3. **Checks for staleness (read-only).** It compares the running hook files\n   against the installed npm package's copies and warns if they differ. This\n   step never writes.\n\n**Scope limits:** the self-heal writes only inside `~/.openclaw/hooks/**` and\ndeletes only the two `~/.clawdbot` hook directories named above. It does not\nmodify `openclaw.json`, `~/.claude/settings.json`, MCP config, shell configs,\nor any other file; it makes no network calls; failures are swallowed so it can\nnever block agent startup.\n\n**Opting out (since v4.47.12):** either of these downgrades steps 1 and 2 to\nwarn-only — the hook logs exactly what it would have deleted or copied and\ntouches nothing:\n\n```bash\nshieldcortex config --self-heal false     # writes \"selfHeal\": false to ~/.shieldcortex/config.json\nexport SHIELDCORTEX_SKIP_SELF_HEAL=1      # or set the env var for the gateway process\n```\n\nRestart the gateway for either to take effect. Step 3 (the read-only staleness\ncheck) still runs, and `shieldcortex openclaw install` performs the same\nmigration on demand. Disabling the cortex-memory hook in your hooks config also\ndisables the self-heal entirely, since it only runs inside the hook.\n\n## Data handling, privacy & consent\n\nShieldCortex is **local-first**: memory, scanning, and audit run entirely on your machine — no account, no telemetry by default, and no network use beyond fetching the embedding model on first use when it is not cached (see **First-use model download** above). Because the tool can auto-capture conversation content, here is exactly what it reads, stores, and (only if you opt in) transmits.\n\n- **What it reads.** With the lifecycle handlers enabled (opt-in at setup), ShieldCortex reads your agent **session transcripts — both your prompts and the assistant's replies** — to auto-extract memorable context. PreCompact (before context compaction) reads the recent transcript; the SessionEnd and Stop handlers are **off by default**; the OpenClaw integration extracts from assistant output and explicit keyword triggers. SessionStart does **not** read transcripts (it only loads existing local memory and scans project rule files).\n- **What it stores, and for how long.** Saved and auto-extracted memories are written to a **local SQLite database at `~/.shieldcortex/memories.db`** — title and content verbatim — and **persist across sessions** until you remove them (decay/consolidation prune low-value entries over time). Nothing is stored remotely unless you enable Cloud sync. Delete a memory with the `forget` tool, or remove the database to wipe everything.\n- **Secrets & credentials.** Every write — manual or auto-extracted — passes the defence pipeline first; high-confidence credential patterns (49 patterns across 25 providers) and content classified RESTRICTED are **blocked or quarantined before storage**, not saved as live memory. This is a strong filter, not a guarantee: low-confidence or low-entropy secrets can still be stored. On sensitive work, **review what auto-memory captures** and disable auto-extraction (`shieldcortex config --openclaw-auto-memory false`; the Claude Code handlers can be removed from `~/.claude/settings.json`).\n- **Triggers capture surrounding context.** Keyword auto-save triggers (e.g. \"remember this\", \"don't forget\") capture the *nearby* text, which may include more than you intend — treat them as \"save the recent context,\" not \"save exactly this line.\" They're capped (auto-extracts never outrank explicit saves) and run through the same credential/injection scan.\n- **Subprocess execution.** The OpenClaw integration spawns short-lived `npx mcporter` subprocesses (via `execFile`, argv-array, no shell) to talk to your **local** ShieldCortex MCP server over stdio. One caveat for completeness: when ShieldCortex is not installed locally, the hook's fallback server command is `npx -y shieldcortex`, and `npx -y` will download the package from the npm registry on first use before executing it. Install `shieldcortex` globally (or set `binaryPath` in `~/.shieldcortex/config.json`) to guarantee no network fetch on that path.\n- **Cloud sync — off by default, opt-in, explicit.** No data leaves your machine unless you run `shieldcortex config --cloud-enable --cloud-api-key <key>`. When enabled:\n  - **Audit telemetry** (`/v1/audit/ingest`): scan **metadata only** — trust scores, threat indicators, categories, timings, device name. **No memory content.**\n  - **Memory sync** (`/v1/sync/memories`, Enterprise licence — grandfathered Team keys also unlock it): transmits **full memory title + content** of PUBLIC/INTERNAL memories so they sync across your team. CONFIDENTIAL/RESTRICTED memories are **excluded by default**; switch to metadata-only with the `contentMode` control.\n  - **Quarantine sync** (Enterprise licence): flagged content is sent with **detected credentials redacted**.\n  - **OpenClaw realtime plugin** (optional): scans live input and output **locally**. When it flags something, only **threat metadata** (type, scores, timestamps — **never the input text itself**) is forwarded, and only when Cloud sync is enabled. Flagged-content previews are kept in your **local** audit log; they are never transmitted.\n\n  Raw conversation/input text is never transmitted by the audit, threat, or interceptor paths — they carry metadata only. The single exception is **Memory sync** above, which uploads the content of memories you chose to store (PUBLIC/INTERNAL, off by default, Enterprise licence). You can disable any of the above at any time, and the realtime plugin and lifecycle handlers can be removed entirely.\n\n## What it does NOT do\n\n- Does **not** read SSH keys, AWS credentials, GPG keys, or /etc/ files\n- Does **not** send your data to external servers, with three narrow, user-initiated exceptions: Cloud sync when you enable it, the subscription id sent to the licence endpoint when you activate a licence key, and event payloads to webhooks you configure (memory-event and Iron Dome operator notifications). Its remaining outbound calls are downloads/fetches that carry only the request itself — never memory or conversation content: npm-registry update checks and X-Ray package lookups (the package name appears in the URL), the huggingface.co embedding-model download, and URLs you explicitly pass to `env scan`\n- Does **not** modify .bashrc, .zshrc, .profile, or shell configs\n- Does **not** use `eval` or dynamic code execution of any kind\n- Does **not** build subprocess commands from agent, memory, or network content. The update flow and the OpenClaw MCP bridge never spawn a shell — argv-array `execFile`/`spawn` only (`npm view` update check, `npm update`/`npm install`, `pgrep`, `npx mcporter`). The dashboard X-Ray surface adds two more argv-array, local-only children: `osascript` with fixed script lines (macOS folder picker) and ShieldCortex's own Node binary re-spawned for `xray --watch` background scans (hook and server helpers re-spawn `process.execPath` the same way, always with fixed local script paths). Sudo-aware home resolution validates the username, then runs `getent passwd <user>` as an argv-array — never through a shell, no tilde-eval. User-run CLI commands (setup, service, migrate, uninstall, audit, doctor, the npx-staleness warning) and corrupt-database recovery run fixed local admin tools (`npm`, `launchctl`, `systemctl`, `sqlite3`), some through a shell, parameterised only by local paths and usernames\n- Does **not** bypass, disable, or override any agent safety mechanisms\n- Does **not** auto-approve actions or skip verification prompts\n- Does **not** mine cryptocurrency, trade tokens, manage wallets, or initiate purchases\n- Does **not** make purchases, place orders, or move money on the user's behalf\n\n## CLI Reference\n\n### Getting Started\n```bash\nshieldcortex quickstart          # Detect integrations, guide setup\nshieldcortex setup               # Register MCP server for current project\nshieldcortex doctor              # Diagnose registration issues\nshieldcortex status              # Show protection status\nshieldcortex uninstall           # Remove from project\n```\n\n### Memory\n```bash\n# Memory is typically used via the MCP server, not the CLI directly. The tools are:\n#   remember · recall · forget · get_context · get_memory · get_related\n#   consolidate · graph_query · graph_entities · scan_memories · memory_stats\n#   start_session · end_session\n# (there is no `store`, `search` or bare `graph` tool — use remember/recall/graph_query)\nshieldcortex graph backfill      # Build knowledge graph from stored memories\nshieldcortex stats               # Memory statistics\n```\n\n### Security Scanning\n```bash\nshieldcortex scan \"text\"                    # Scan text (exit 0=allow, 1=caught, 2=usage, 3=tool-fail; parse stdout)\nshieldcortex scan-skill path/to/SKILL.md    # Scan one instruction file for threats\nshieldcortex scan-skills                    # Scan all discovered agent instruction files\nshieldcortex audit                          # Full security audit (memory, env, MCP configs, rules files)\nshieldcortex iron-dome status               # Iron Dome behavioural protection status\n```\n\n### Cortex — Mistake Learning\n```bash\n# capture requires all four flags: --category --what --why --rule\nshieldcortex cortex capture --category code --what \"Guessed API endpoints\" \\\n  --why \"Didn't check the docs\" --rule \"Verify endpoints in API docs before calling\"\nshieldcortex cortex preflight --task \"deploy to production\"           # Pre-task check\nshieldcortex cortex review                                            # Pattern analysis\nshieldcortex cortex list                                              # View mistake log\nshieldcortex cortex search \"<query>\"                                  # Full-text search\nshieldcortex cortex stats                                             # Category breakdown\nshieldcortex cortex confirm --category code --what \"...\" \\\n  --why-worked \"...\" --when-repeat \"...\"                              # Capture what worked\nshieldcortex cortex graduate                                          # Archive mastered rules\n```\n\n### Dashboard & Services\n```bash\nshieldcortex dashboard           # Dashboard on localhost:3030 (starts the API on :3001 too)\nshieldcortex api                 # Start the API server only (localhost:3001)\nshieldcortex worker              # Background sync + heartbeat worker\nshieldcortex service start|stop|status  # Manage background service\n```\n\n### Integrations\n```bash\n# subcommand is `install`, not `setup` (also: status, uninstall; openclaw adds repair, skill)\nshieldcortex openclaw install    # Hook + realtime plugin — tool gate BOUND\nshieldcortex copilot install     # VS Code / Cursor MCP memory server — NOT a tool gate\nshieldcortex codex install       # Codex CLI MCP memory server — NOT a tool gate\nshieldcortex config --openclaw-auto-memory true   # Enable auto-memory in OpenClaw\nshieldcortex config --proactive-recall true|false  # Enable/disable proactive recall\n```\n\n### Cloud & Licensing\n```bash\nshieldcortex config --cloud-enable --cloud-api-key <key>  # Enable cloud sync\nshieldcortex cloud sync --full    # Backfill memories + graph to cloud\nshieldcortex license activate <key>  # Activate an Enterprise (or legacy) licence key\nshieldcortex license status       # Check licence tier\n```\n\n### Maintenance\n```bash\nshieldcortex update              # Self-update (npm package + OpenClaw plugin + skill)\n```\n\n## What Gets Scanned\n\n### `scan-skills` discovers and scans:\n- SKILL.md, HOOK.md, handler.js (Claude Code / OpenClaw skills)\n- .cursorrules, .windsurfrules, .clinerules (editor rules)\n- CLAUDE.md, copilot-instructions.md (agent instructions)\n- .aider.conf.yml, .continue/config.json (tool configs)\n- Searches: ~/.claude/skills/, ~/.openclaw/skills/, ~/.openclaw/hooks/, project directories\n\n### `audit` checks:\n- **Memory files** — ~/.claude/projects/, ~/.cursor/memories/, ~/.windsurf/memories/\n- **Environment** — .env files for leaked credentials (read-only check, never writes)\n- **MCP configs** — ~/.claude/mcp.json, ~/.openclaw/mcp.json, ~/.cursor/mcp.json, project-level equivalents\n- **Rules files** — CLAUDE.md, .cursorrules, copilot-instructions.md for injection patterns\n\n## What Gets Uploaded to Cloud\n\nCloud sync is **off by default**. Audit metadata sync is included on the cloud free tier; full memory/graph replication requires an Enterprise licence (grandfathered Team keys keep working).\n\n- **Uploaded when Cloud sync is enabled by the user:** selected memory records, related embeddings/metadata, and knowledge-graph entities/relationships required for sync.\n- **Not uploaded by default:** local agent configs, MCP configs, raw rules files, shell configs, SSH keys, secrets, `.env` contents, or arbitrary project files.\n- **Security scan results stay local** unless the user explicitly exports or syncs data through a Cloud-enabled workflow.\n- **No sync traffic** occurs unless the user explicitly enables Cloud sync and provides a valid API key. Outside sync, the only api.shieldcortex.ai call is licence-key validation when a key is activated (subscription id only, never memory content) — see `network_endpoints`.\n\n## Licence Tiers\n\nPublic tiers are **Free** and **Enterprise** (sales@drakonsystems.com). Every local feature is Free; grandfathered Pro/Team keys keep working.\n\n| Feature | Free | Enterprise |\n|---------|------|------------|\n| Memory (store/recall/search/graph) | ✅ | ✅ |\n| Proactive recall (auto-inject on prompts) | ✅ | ✅ |\n| Defence pipeline (scan, Iron Dome) | ✅ | ✅ |\n| Audit & scan-skills | ✅ | ✅ |\n| Dashboard | ✅ | ✅ |\n| Custom injection patterns | ✅ | ✅ |\n| Custom Iron Dome policies | ✅ | ✅ |\n| Custom firewall rules | ✅ | ✅ |\n| Audit export | ✅ | ✅ |\n| Deep skill scanning | ✅ | ✅ |\n| Cortex (mistake learning) | ✅ | ✅ |\n| Cloud audit sync (metadata, 500 scans/mo, 7-day retention) | ✅ | ✅ |\n| Cloud memory/graph sync | ❌ | ✅ |\n| Team management | ❌ | ✅ |\n| Shared patterns | ❌ | ✅ |\n\n## Links\n\n- **Docs:** https://shieldcortex.ai/docs\n- **Source:** https://github.com/Drakon-Systems-Ltd/ShieldCortex\n- **npm:** https://www.npmjs.com/package/shieldcortex\n- **Issues:** https://github.com/Drakon-Systems-Ltd/ShieldCortex/issues\n- **Changelog:** https://shieldcortex.ai/changelog\n\n## API bind (#411)\n- Default bind is loopback (`127.0.0.1`).\n- Non-loopback requires `SHIELDCORTEX_ALLOW_NON_LOOPBACK=1` **and** `SHIELDCORTEX_API_TOKEN` (≥32 chars).\n- Public `/api/auth/session-token` is loopback-only.\n\nFile v5.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn71759x1py9k3ak7d6hjwbx5x812cf2\",\n  \"slug\": \"shieldcortex\",\n  \"version\": \"5.4.0\",\n  \"publishedAt\": 1791283716133\n}\n\nFile v5.4.0:bundled/cortex-memory-hook/HOOK.md\n\n---\nname: cortex-memory\ndescription: \"Persistent brain-like memory via ShieldCortex — recalls past knowledge, with optional auto-save\"\nhomepage: https://github.com/Drakon-Systems-Ltd/ShieldCortex\nmetadata:\n  { \"openclaw\": { \"emoji\": \"🧠\", \"events\": [\"command:new\", \"command:stop\", \"agent:bootstrap\"], \"requires\": { \"bins\": [\"npx\"] }, \"install\": [{ \"id\": \"community\", \"kind\": \"community\", \"label\": \"ShieldCortex\" }] } }\n---\n\n# Cortex Memory Hook\n\nIntegrates [ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) persistent memory. Recalls past knowledge at session start, and can optionally auto-save important session context.\n\n## What It Does\n\n### On `/new` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Reads the ending session transcript\n2. Pattern-matches for decisions, bug fixes, learnings, architecture changes, and preferences\n3. Saves up to 5 high-salience memories to ShieldCortex via mcporter\n4. Skips exact and near-duplicate memories using novelty filtering\n\n### On `/stop`, `/clear`, `/exit` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Captures the current session transcript before it ends\n2. Pattern-matches for important content (same patterns as `/new`)\n3. Saves memories with a `session-stop` tag for tracking\n4. **Ensures work is saved** even when explicitly ending a session\n5. Skips exact and near-duplicate memories using novelty filtering\n\n### On Session Start (Agent Bootstrap)\nBootstrap context injection was **disabled in v2026.2.26**. OpenClaw's native Memory Search now handles context recall at session start, so the hook no longer pushes memories into the system prompt (which was producing ~40× duplication of CORTEX_MEMORY.md and eating most of the context window).\n\nThe hook still fires on `agent:bootstrap` for lifecycle wiring (warning-bootstrap-file handoff, etc.) but contributes nothing to the system prompt. This keeps `extraSystemPromptHash` stable across turns and prevents the session-binding reset loop documented in `src/setup/claude-md.ts`.\n\n### Keyword Triggers\n\nSay any of these phrases to trigger an instant save to Cortex memory:\n\n| Trigger Phrase | Category | Importance |\n|---------------|----------|------------|\n| **\"remember this\"** | note | critical |\n| **\"don't forget\"** | note | critical |\n| **\"this is important\"** | note | critical |\n| **\"make a note\"** | note | critical |\n| **\"for the record\"** | note | critical |\n| **\"note to self\"** | note | critical |\n| **\"important:\"** | note | critical |\n| **\"crucial:\"** | note | critical |\n| **\"key point:\"** | note | high |\n| **\"lesson learned\"** | learning | high |\n| **\"i learned\"** | learning | normal |\n| **\"TIL:\"** | learning | normal |\n| **\"today i learned\"** | learning | normal |\n| **\"never again\"** | error | critical |\n| **\"root cause was\"** | error | high |\n| **\"the fix was\"** | error | high |\n| **\"always do\"** | preference | high |\n| **\"never do\"** | preference | high |\n| **\"i prefer\"** | preference | normal |\n| **\"we should always\"** | preference | high |\n| **\"we decided\"** | architecture | high |\n| **\"decision made\"** | architecture | high |\n| **\"going with\"** | architecture | normal |\n\nContent after the trigger phrase is extracted and saved as the memory content.\n\n## Defence Audit Guarantees\n\nEvery byte that lands in `memories` from the auto-extract path passes the\n6-layer defence pipeline first. The hook write path is no longer the\nbypass it once was:\n\n- **ALLOW** → row inserted into `memories`; a corresponding row appears in\n  `defence_audit` with `source_type = 'hook'` and the hook's identifier\n  (`session-end-hook` / `pre-compact-hook` / `stop-hook`).\n- **QUARANTINE** → row inserted into `quarantine` (not `memories`), linked\n  to the audit row via `audit_id`. Visible in the dashboard for review.\n- **BLOCK** → dropped. The audit row written by the pipeline carries the\n  block reason; nothing reaches `memories`.\n- **Pipeline error** → dropped + a synthetic audit row with reason\n  `pipeline_error: <msg>`. Never silently lose data.\n\nBuilt-in firewall rules covering instruction injection, hidden\ninstruction, imperative tool-call directives (\"call X tool now\"), command\ninjection, and credential leaks (AWS / JWT / private keys) are seeded\ninto `firewall_rules` on first run with `built_in = 1`. They are\nalways evaluated (user-added custom rules are free too, behind a dormant\nfeature gate) and excluded from the user-facing 25-rule cap.\n\nThe chunker also rejects malformed candidates *before* they reach the\nwrite path: imperative tool-calls, bare-imperative starts (\"commit\nsecrets\" with the negation dropped), email-body bleed, and path-label\nfragments. Auto-extracted memories are now capped at salience 0.6\n(reserved 1.0 for LLM-rated future paths).\n\nTo audit an existing database for malformed rows accumulated before this\nfix:\n\n```bash\nshieldcortex memories purge --malformed --dry-run    # preview\nshieldcortex memories purge --malformed --execute    # delete (writes a backup first)\n```\n\n## Auto-Memory\n\nAuto-memory extraction is enabled by default. ShieldCortex complements your existing memory system by capturing decisions, fixes, and learnings with built-in deduplication to avoid noise.\n\nDisable auto-save with CLI:\n\n```bash\nnpx shieldcortex config --openclaw-auto-memory false\n```\n\nRe-enable it:\n\n```bash\nnpx shieldcortex config --openclaw-auto-memory true\n```\n\nOr set directly in config:\n\n```json\n{\n  \"openclawAutoMemory\": true\n}\n```\n\nin `~/.shieldcortex/config.json`.\n\n## Requirements\n\n- **npx** must be available (Node.js installed)\n- ShieldCortex installs automatically on first use via `npx -y shieldcortex`\n- mcporter must be available for MCP tool calls\n\n## Database\n\nMemories stored in `~/.shieldcortex/memories.db` (SQLite). Shared with Claude Code sessions — memories created here are available everywhere.\n\n## Install\n\n```bash\nopenclaw skills install shieldcortex\n```\n\nOptional companion real-time plugin:\n\n```bash\nopenclaw plugins install @drakon-systems/shieldcortex-realtime\n```\n\n## Uninstall\n\n```bash\nshieldcortex openclaw uninstall\n```\n\nOr disable without removing:\n\n```json\n{\n  \"hooks\": {\n    \"internal\": {\n      \"entries\": {\n        \"cortex-memory\": { \"enabled\": false }\n      }\n    }\n  }\n}\n```\n\nFile v5.4.0:skill-card.md\n\n## Description:\n\nProvides persistent agent memory and security scanning for prompt injection, credential leaks, and memory poisoning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jarvis-drakon](https://clawhub.ai/user/jarvis-drakon)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users use ShieldCortex to recall information across sessions, organize memories, and scan agent content for security threats.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Automatic memory capture may persist sensitive conversation content.\n\nMitigation: Review saved memories and disable auto-memory on sensitive projects.\n\nRisk: Bootstrap self-heal can modify agent hook locations without a prompt.\n\nMitigation: Disable self-heal when automatic hook changes are not desired.\n\nRisk: Fallback execution may fetch and run a package from the npm registry.\n\nMitigation: Preinstall a trusted ShieldCortex binary or configure binaryPath.\n\nRisk: Enabling Cloud sync can transmit stored memory data.\n\nMitigation: Keep Cloud sync off unless sharing memories is intended.\n\n## Reference(s):\n\n- [ShieldCortex website](https://shieldcortex.ai)\n- [ShieldCortex documentation](https://shieldcortex.ai/docs)\n- [ShieldCortex npm package](https://www.npmjs.com/package/shieldcortex)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance]\n\n**Output Format:** [Markdown and plain text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include recalled memories and security scan findings.]\n\n## Skill Version(s):\n\n5.4.0 (source: ClawHub release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v5.4.0:bundled/openclaw-plugin/openclaw.plugin.json\n\n{\n  \"id\": \"shieldcortex-realtime\",\n  \"version\": \"4.31.2\",\n  \"name\": \"ShieldCortex Real-time Scanner\",\n  \"description\": \"Real-time defence scanning on LLM input, memory extraction on LLM output, and active tool call interception with approval gating.\",\n  \"kind\": null,\n  \"engines\": {\n    \"openclaw\": \">=2026.3.22\",\n    \"recommended\": \">=2026.4.23\"\n  },\n  \"enabledByDefault\": false,\n  \"activation\": {\n    \"onStartup\": false,\n    \"hooks\": [\n      \"llm_input\",\n      \"llm_output\",\n      \"before_tool_call\",\n      \"session_end\"\n    ],\n    \"commands\": [\n      \"shieldcortex-status\"\n    ]\n  },\n  \"contracts\": {},\n  \"commandAliases\": {\n    \"shieldcortex-status\": \"shieldcortex-status\"\n  },\n  \"uiHints\": {\n    \"binaryPath\": {\n      \"label\": \"ShieldCortex Binary Path\",\n      \"help\": \"Optional absolute path to the shieldcortex CLI when it is not on PATH.\",\n      \"placeholder\": \"/usr/local/bin/shieldcortex\",\n      \"advanced\": true\n    },\n    \"cloudApiKey\": {\n      \"label\": \"Cloud API Key\",\n      \"help\": \"Optional ShieldCortex Cloud API key used for realtime threat forwarding.\",\n      \"placeholder\": \"sc_...\",\n      \"sensitive\": true\n    },\n    \"cloudBaseUrl\": {\n      \"label\": \"Cloud Base URL\",\n      \"help\": \"Override the ShieldCortex Cloud API base URL if you use a self-hosted or staging endpoint.\",\n      \"placeholder\": \"https://api.shieldcortex.ai\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemory\": {\n      \"label\": \"Auto Memory Extraction\",\n      \"help\": \"Extract high-signal decisions and learnings from LLM output into ShieldCortex memory.\"\n    },\n    \"openclawAutoMemoryDedupe\": {\n      \"label\": \"Dedupe Auto Memory\",\n      \"help\": \"Skip near-duplicate memories before they are written to ShieldCortex.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryNoveltyThreshold\": {\n      \"label\": \"Novelty Threshold\",\n      \"help\": \"Similarity threshold for duplicate suppression. Higher values keep more memories.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryMaxRecent\": {\n      \"label\": \"Recent Memory Cache Size\",\n      \"help\": \"How many recent extracted memories to keep in the dedupe cache.\",\n      \"advanced\": true\n    },\n    \"interceptor.enabled\": {\n      \"label\": \"Enable Tool Call Interceptor\",\n      \"description\": \"Scan memory-write tool calls and gate suspicious content behind user approval\",\n      \"type\": \"boolean\"\n    },\n    \"interceptor.severityActions.high\": {\n      \"label\": \"High Severity Action\",\n      \"description\": \"Action for high-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    },\n    \"interceptor.severityActions.critical\": {\n      \"label\": \"Critical Severity Action\",\n      \"description\": \"Action for critical-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    }\n  },\n  \"configSchema\": {\n    \"type\": \"object\",\n    \"additionalProperties\": false,\n    \"properties\": {\n      \"enabled\": {\n        \"type\": \"boolean\"\n      },\n      \"binaryPath\": {\n        \"type\": \"string\"\n      },\n      \"cloudApiKey\": {\n        \"type\": \"string\"\n      },\n      \"cloudBaseUrl\": {\n        \"type\": \"string\"\n      },\n      \"openclawAutoMemory\": {\n        \"type\": \"boolean\"\n      },\n      \"openclawAutoMemoryDedupe\": {\n        \"type\": \"boolean\"\n      },\n      \"openclawAutoMemoryNoveltyThreshold\": {\n        \"type\": \"number\",\n        \"minimum\": 0.6,\n        \"maximum\": 0.99\n      },\n      \"openclawAutoMemoryMaxRecent\": {\n        \"type\": \"integer\",\n        \"minimum\": 50,\n        \"maximum\": 1000\n      },\n      \"interceptor\": {\n        \"type\": \"object\",\n        \"properties\": {\n          \"enabled\": {\n            \"type\": \"boolean\",\n            \"default\": true\n          },\n          \"severityActions\": {\n            \"type\": \"object\",\n            \"additionalProperties\": false,\n            \"properties\": {\n              \"low\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              },\n              \"medium\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              },\n              \"high\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"warn\"\n              },\n              \"critical\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              }\n            }\n          },\n          \"failurePolicy\": {\n            \"type\": \"object\",\n            \"additionalProperties\": false,\n            \"properties\": {\n              \"low\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"allow\"\n              },\n              \"medium\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"allow\"\n              },\n              \"high\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"deny\"\n              },\n              \"critical\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"deny\"\n              }\n            }\n          }\n        }\n      }\n    }\n  }\n}\n\nArchive v5.3.1: 11 files, 51789 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (47494b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (2295b), SKILL.md (31295b), _meta.json (131b)\n\nFile v5.3.1:SKILL.md\n\n---\nname: shieldcortex\ndescription: \"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\"\nlicense: MIT-0\nmetadata:\n  author: Drakon Systems\n  version: 5.3.1\n  mcp-server: shieldcortex\n  category: memory-and-security\n  tags: [memory, security, knowledge-graph, mcp, iron-dome, openclaw-plugin, audit]\n  source: https://github.com/Drakon-Systems-Ltd/ShieldCortex\n  homepage: https://shieldcortex.ai\n  npm: https://www.npmjs.com/package/shieldcortex\n  verified_publisher: Drakon Systems Ltd\n  publisher_github: https://github.com/Drakon-Systems-Ltd\n  npm_audit: \"0 unwaived production advisories; 2 waived (sharp: GHSA-f88m-g3jw-g9cj, GHSA-rgj7-g3m4-5g8c, reachable only via the optional @huggingface/transformers) - see docs/security/audit-waivers.md\"\n  downloads: 11K+/month\ninstall:\n  command: shieldcortex quickstart\n  runtime: node\n  minVersion: \"22.14.0\"\n  note: >\n    Requires Node 22.14+ LTS or Node 24+; Node 23 is unsupported. Run the installed\n    `shieldcortex` binary directly. The quickstart command\n    detects your environment. Claude Code and OpenClaw get hooks that can deny;\n    Codex/Cursor/VS Code get an MCP memory server only (not a tool gate).\n    All data stays local in ~/.shieldcortex/. No account or API key needed\n    for local use.\npermissions:\n  filesystem: readwrite\n  network: optional\n  credentials: optional\n  justification: >\n    Filesystem read: scans agent instruction files for prompt injection threats\n    (same files the agent already reads). Filesystem write: stores memory DB\n    and config in ~/.shieldcortex/. Network: local-first — outbound only for\n    the embedding-model download when it is not cached (huggingface.co;\n    disable with SHIELDCORTEX_SKIP_EMBEDDINGS=1), Cloud sync (opt-in),\n    licence-key validation when a key is activated, explicit update\n    checks/updates and X-Ray package lookups (npm registry), URLs you ask\n    `env scan` to fetch, and webhooks you configure. Credentials: optional\n    Cloud API key for team sync (not required for local use).\n  paths_read:\n    - ~/.shieldcortex/ (own config and memory database)\n    - ~/.claude/ (project memory files, MCP config)\n    - ~/.openclaw/ (MCP config, extensions)\n    - ~/.cursor/ (rules, memories, MCP config)\n    - ~/.windsurf/ (memories, rules)\n    - ~/.codex/ (MCP config)\n    - $CWD/.claude/, $CWD/.cursor/ (project-level configs)\n    - $CWD/.cursorrules, $CWD/.windsurfrules, $CWD/.clinerules\n    - $CWD/CLAUDE.md, $CWD/copilot-instructions.md\n    - $CWD/.aider.conf.yml, $CWD/.continue/config.json\n    - $CWD/.env (env-scanner checks for leaked secrets — reads, never writes)\n  paths_write:\n    - ~/.shieldcortex/ (memory DB, config, cortex log, licence, audit cache)\n    - ~/.cache/shieldcortex/models (embedding model download cache)\n    - ~/.openclaw/extensions/shieldcortex-realtime/ (OpenClaw plugin via the wrapper install only; native `openclaw plugins install` uses OpenClaw's managed npm tree instead)\n    - ~/.claude/mcp.json, ~/.cursor/mcp.json (MCP server registration, when user runs setup)\n  network_endpoints:\n    - https://api.shieldcortex.ai (Cloud sync + audit telemetry — only when Cloud sync is enabled; licence validation — only when a licence key is activated, fired at CLI `license activate` and the dashboard's activation call (POST /api/license/activate), with no periodic or background re-check; sends the subscription id, works with Cloud sync off; never called when no key is configured)\n    - https://huggingface.co (embedding-model download — Xenova/all-MiniLM-L6-v2, ~90 MB, fetched into ~/.cache/shieldcortex/models by the MCP server's background preload at startup or the first operation needing an embedding, whenever the model is not already cached, plus one re-download if a cached copy is detected corrupt; SHIELDCORTEX_SKIP_EMBEDDINGS=1 prevents it. The optional Local AI Explainer model downloads from the same host only on explicit, consent-prompted `review-copilot enable`/`download-model` — its review runs use the local cache only)\n    - https://registry.npmjs.org (three paths — explicit update actions via npm subprocess, dashboard \"Check for updates\"/\"Update\" or `shieldcortex update`; X-Ray package inspection, `shieldcortex xray <package>` or the dashboard X-Ray page, which queries package metadata directly over HTTPS and with `--deep` also downloads the package tarball from whatever URL that metadata names — normally registry.npmjs.org, size- and redirect-capped, but with no separate host allowlist; and the OpenClaw hook's `npx -y shieldcortex` fallback, which downloads the package on first use when ShieldCortex is not installed locally)\n    - User-configured webhook URLs (two POST paths — memory-event notifications to webhooks you add to ~/.shieldcortex/config.json, and Iron Dome operator-notify messages for action-guard holds/denies to the `actionGuard.notify` webhook you configure; both off until you configure them)\n    - The URL you pass to `shieldcortex env scan <url>` (fetched once for analysis)\n    - http://localhost:3001 (local REST API + WebSocket — loopback only)\n    - http://localhost:3030 (local dashboard UI; also the worker health check — loopback only)\n  env:\n    - SHIELDCORTEX_CONFIG_DIR: Override config directory (default ~/.shieldcortex/)\n    - SHIELDCORTEX_API_KEY: Cloud sync API key (optional; only used when Cloud is enabled)\n    - SHIELDCORTEX_LICENSE_TIER: Override licence tier (development use)\n    - SHIELDCORTEX_SKIP_EMBEDDINGS: Disable embedding generation\n    - SHIELDCORTEX_SKIP_SELF_HEAL: Set to 1 to make the cortex-memory hook's bootstrap self-heal warn-only (writes nothing)\n    - SHIELDCORTEX_HOST: Override dashboard/API bind host\n    - PORT: Override dashboard/API port\n---\n\n# ShieldCortex — Persistent Memory & Security for AI Agents\n\nMemory system with built-in security. Gives agents persistent memory (semantic search, knowledge graphs, decay, contradiction detection) and protects it with a 6-layer defence pipeline (input sanitisation → trust scoring → firewall → sensitivity classification → fragmentation detection → credential-leak detection). Skill threat patterns (tool injection, scope escalation, data exfiltration, persistence, supply-chain, agent manipulation, stealth instructions) block at memory-write time, not just on skill-file scans.\n\nThis is an enforcing memory boundary, not a passive scanner. Across the read/write boundary it actively: **quarantines or blocks** poisoned/credential-bearing writes; **trust/ACL-filters recalled memory** (RESTRICTED isolation, own-only for low-trust callers) before it reaches the agent, on both the prompt hooks and the MCP read tools; runs a **tool-output firewall** that, in enforce mode, redacts or withholds malicious tool results before the model sees them (advisory by default); and keeps a **provenance ledger** recording read/write/delete operations with content hashes for forensics. Enforcement that could surprise is opt-in (the tool-output firewall defaults to advisory; `shieldcortex config --tool-firewall-enforce` turns on blocking).\n\n## Provenance & Trust\n\n| Signal | Value |\n|--------|-------|\n| **Publisher** | [Drakon Systems Ltd](https://github.com/Drakon-Systems-Ltd) (UK company) |\n| **Source code** | [github.com/Drakon-Systems-Ltd/ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) — fully open, **MIT** licence (this skill file itself is published MIT-0, per the frontmatter) |\n| **npm package** | [npmjs.com/package/shieldcortex](https://www.npmjs.com/package/shieldcortex) — every release git-tagged with a matching GitHub release |\n| **npm audit** | Clean — `npm audit` returns 0 vulnerabilities |\n| **Downloads** | 11,000+/month (July 2026) |\n| **CI/CD** | CI lint/test on every push; the maintainer manually tags each release, and the tag push triggers an automated CI publish to npm |\n| **Postinstall script** | Declared and bounded: prints setup instructions; on **global** installs it also smoke-tests the native SQLite binding, seeds default config on first install, and refreshes an OpenClaw hook/plugin that a previous setup already installed. It never adds integrations to a machine that had none, and it is a no-op for CI and local dependency installs. `SHIELDCORTEX_SKIP_AUTO_OPENCLAW=1` skips the refresh. |\n| **Dependencies** | 8 runtime deps: `better-sqlite3`, `zod`, `@modelcontextprotocol/sdk`, `express`, `ws`, `cors`, `safe-regex2`, `semver`. `express`/`ws`/`cors` serve the bundled localhost-only dashboard/API. One optional dep, `@huggingface/transformers`, runs the local embedding model and fetches it from huggingface.co when it is not cached (see `network_endpoints`). Nothing else dials out except the cases listed under `network_endpoints` (Cloud sync opt-in, licence-key validation, update checks, X-Ray package lookups, env-scan URLs, configured webhooks). |\n\n## Safety & Scope\n\nThis section explains every privileged operation the tool performs and why.\n\n- **Active interception, not scan-only — on hosts that can deny.** Writes failing the pipeline are quarantined/blocked; recalled memory is trust/ACL-filtered before the agent sees it. Tool-call denial is **bound** on Claude Code (PreToolUse), OpenClaw (`before_tool_call`), and Hermes (`pre_tool_call`, enforce by default). Codex, Cursor, Copilot, and generic MCP get a memory server / scanner the model may ignore — they are **not bound**. Tool-output firewall defaults to advisory. `shieldcortex doctor` and `shieldcortex lease` report bound / not-bound / unknown per plane.\n- **Setup is user-initiated, with one bounded exception.** Installing hooks, registering the MCP server, and migrating data are manual steps the user runs in their terminal, and `quickstart` asks before each action. The npm postinstall script (disclosed in the trust table above) never adds integrations that weren't already present — on global installs it only prints instructions, checks the native binding, seeds default config on first install, and refreshes an existing OpenClaw hook/plugin install. The exception: the bundled cortex-memory hook performs a small automatic self-heal at gateway bootstrap, documented in full under **\"Automatic self-heal at gateway bootstrap\"** below.\n- **Setup migrates legacy data.** The first `quickstart`/`setup` run may move or remove legacy config/memory directories (e.g. `~/.claude-cortex/`, `~/.claude-memory/`) into `~/.shieldcortex/` and copy hook files into place. This happens only on the user-run setup command — never on `npm install` (the postinstall script does not touch memory or config data beyond seeding defaults on a first-ever global install).\n- **Destructive `forget` is bounded and gated.** Per-memory and filtered bulk deletes go through a delete ACL (own-only) and are recorded in the audit ledger. Revoke-by-source (`forget --fromSource`, bulk-delete every memory from one source — for purging a poisoned agent) is **disabled by default** and only enabled by an out-of-band human action (`shieldcortex config --allow-revoke-by-source`); even then it is bounded by a trust-hierarchy ACL (you must own the source or out-rank it) and a per-call row cap. A compromised agent cannot mass-delete your memory.\n- **The bundled dashboard never renders RESTRICTED content.** The local visualization API and its WebSocket feed redact credential-class (`RESTRICTED`) memory content before it reaches the browser — the row stays visible (title/metadata) so you can manage it, but the secret is withheld (view full content via the CLI). Credential patterns in titles/metadata are masked too. This is a display-surface safeguard on top of the on-disk store; it does not weaken the firewall.\n- **No credentials required for local use.** Memory, scanning, and audit work fully offline. Cloud sync is opt-in and requires a user-provided API key via `shieldcortex config --cloud-enable --cloud-api-key <key>`.\n- **File access is declared and scoped.** Security scans read agent config directories listed in the permissions block above — the same directories the agent itself already has access to. They do not traverse arbitrary directories.\n- **Writes are contained.** All data goes to `~/.shieldcortex/` (plus the embedding-model cache at `~/.cache/shieldcortex/models`). MCP config edits (`setup`, `copilot`, `codex` commands) modify specific JSON files and confirm before writing.\n- **First-use model download (huggingface.co).** Semantic memory runs a local embedding model (Xenova/all-MiniLM-L6-v2, ~90 MB ONNX) that is **not bundled** with the package. Whenever it is missing from `~/.cache/shieldcortex/models`, the MCP server downloads it from huggingface.co — triggered by the background preload at server start, or by the first operation that needs an embedding, plus a single re-download if a cached copy is detected corrupt. This is the one network call that is not user-initiated. Avoid it with `SHIELDCORTEX_SKIP_EMBEDDINGS=1` (memory falls back to full-text search) or by pre-seeding the model cache. The optional Local AI Explainer (`review-copilot`) downloads its model from the same host only on an explicit, consent-prompted `enable`/`download-model` command; its review runs never fetch remotely.\n- **Network is off by default, with the first-run exception above.** With no licence key activated, no Cloud sync enabled, and no webhooks configured, ShieldCortex's only outbound connections are the embedding-model download just described (fires on server start when the model is not cached) and one further caveat: the OpenClaw hook's `npx -y shieldcortex` fallback downloads the package on first use when ShieldCortex is not installed locally — see `network_endpoints`. Every other entry in `network_endpoints` is user-initiated: Cloud sync (opt-in), licence-key validation when you activate a key (at CLI or dashboard activation only, no background re-check — works even with Cloud sync off), npm-registry update checks/updates (dashboard buttons or `shieldcortex update`), X-Ray package lookups (`shieldcortex xray` or the dashboard X-Ray page, tarball download with `--deep`), URLs you pass to `env scan`, and webhooks you configure (memory events and Iron Dome operator notifications). The dashboard binds to localhost by default but may be explicitly exposed with `SHIELDCORTEX_HOST`; when exposed, the loopback session-token endpoint stays disabled. The worker binds to localhost.\n- **Bundled source code.** The OpenClaw plugin and cortex-memory handler are shipped in the package for inspection before use.\n- **Lifecycle event handlers.** ShieldCortex registers lifecycle handlers that auto-extract important context from conversations. These are registered in `~/.claude/settings.json` during setup and can be removed at any time. They run locally, never phone home.\n- **Proactive recall.** The UserPromptSubmit handler queries local memory on each prompt (<100ms) and surfaces relevant context. Fully local, configurable: `shieldcortex config --proactive-recall false`.\n\n### Automatic self-heal at gateway bootstrap\n\nThe cortex-memory hook registers for the `agent:bootstrap` event. On the first\nbootstrap after each OpenClaw gateway start (once per gateway process), it runs\na self-check that can write without a prompt. In the interest of full\ndisclosure, this is exactly what it does:\n\n1. **Removes stale legacy hook copies.** If the hook is running from its\n   expected home (`~/.openclaw/hooks/internal/cortex-memory` or\n   `~/.openclaw/hooks/cortex-memory`), it recursively deletes the pre-rename\n   leftovers `~/.clawdbot/hooks/cortex-memory` and\n   `~/.clawdbot/hooks/internal/cortex-memory` — and only those two\n   directories. It skips this entirely when `~/.clawdbot` is a symlink (i.e.\n   still pointing at a live install). No backup is taken before deletion;\n   these directories are assumed to be dead copies of this hook's own files,\n   not your data.\n2. **Copies itself to the expected hook path.** If the hook finds itself\n   running from anywhere else (for example, from inside this skill's\n   `bundled/` folder after a skills-only install), it creates\n   `~/.openclaw/hooks/internal/cortex-memory/` and copies its full file set\n   (`HOOK.md`, `handler.ts`, `runtime.mjs`) there so the gateway loads it from\n   the canonical location on the next restart, and surfaces a\n   `SHIELDCORTEX_HOOK_MIGRATED.md` notice into the session's bootstrap context.\n   If any file in that set fails to copy, the migration is reported as\n   incomplete rather than as a success — a partially-copied hook cannot load.\n3. **Checks for staleness (read-only).** It compares the running hook files\n   against the installed npm package's copies and warns if they differ. This\n   step never writes.\n\n**Scope limits:** the self-heal writes only inside `~/.openclaw/hooks/**` and\ndeletes only the two `~/.clawdbot` hook directories named above. It does not\nmodify `openclaw.json`, `~/.claude/settings.json`, MCP config, shell configs,\nor any other file; it makes no network calls; failures are swallowed so it can\nnever block agent startup.\n\n**Opting out (since v4.47.12):** either of these downgrades steps 1 and 2 to\nwarn-only — the hook logs exactly what it would have deleted or copied and\ntouches nothing:\n\n```bash\nshieldcortex config --self-heal false     # writes \"selfHeal\": false to ~/.shieldcortex/config.json\nexport SHIELDCORTEX_SKIP_SELF_HEAL=1      # or set the env var for the gateway process\n```\n\nRestart the gateway for either to take effect. Step 3 (the read-only staleness\ncheck) still runs, and `shieldcortex openclaw install` performs the same\nmigration on demand. Disabling the cortex-memory hook in your hooks config also\ndisables the self-heal entirely, since it only runs inside the hook.\n\n## Data handling, privacy & consent\n\nShieldCortex is **local-first**: memory, scanning, and audit run entirely on your machine — no account, no telemetry by default, and no network use beyond fetching the embedding model on first use when it is not cached (see **First-use model download** above). Because the tool can auto-capture conversation content, here is exactly what it reads, stores, and (only if you opt in) transmits.\n\n- **What it reads.** With the lifecycle handlers enabled (opt-in at setup), ShieldCortex reads your agent **session transcripts — both your prompts and the assistant's replies** — to auto-extract memorable context. PreCompact (before context compaction) reads the recent transcript; the SessionEnd and Stop handlers are **off by default**; the OpenClaw integration extracts from assistant output and explicit keyword triggers. SessionStart does **not** read transcripts (it only loads existing local memory and scans project rule files).\n- **What it stores, and for how long.** Saved and auto-extracted memories are written to a **local SQLite database at `~/.shieldcortex/memories.db`** — title and content verbatim — and **persist across sessions** until you remove them (decay/consolidation prune low-value entries over time). Nothing is stored remotely unless you enable Cloud sync. Delete a memory with the `forget` tool, or remove the database to wipe everything.\n- **Secrets & credentials.** Every write — manual or auto-extracted — passes the defence pipeline first; high-confidence credential patterns (49 patterns across 25 providers) and content classified RESTRICTED are **blocked or quarantined before storage**, not saved as live memory. This is a strong filter, not a guarantee: low-confidence or low-entropy secrets can still be stored. On sensitive work, **review what auto-memory captures** and disable auto-extraction (`shieldcortex config --openclaw-auto-memory false`; the Claude Code handlers can be removed from `~/.claude/settings.json`).\n- **Triggers capture surrounding context.** Keyword auto-save triggers (e.g. \"remember this\", \"don't forget\") capture the *nearby* text, which may include more than you intend — treat them as \"save the recent context,\" not \"save exactly this line.\" They're capped (auto-extracts never outrank explicit saves) and run through the same credential/injection scan.\n- **Subprocess execution.** The OpenClaw integration spawns short-lived `npx mcporter` subprocesses (via `execFile`, argv-array, no shell) to talk to your **local** ShieldCortex MCP server over stdio. One caveat for completeness: when ShieldCortex is not installed locally, the hook's fallback server command is `npx -y shieldcortex`, and `npx -y` will download the package from the npm registry on first use before executing it. Install `shieldcortex` globally (or set `binaryPath` in `~/.shieldcortex/config.json`) to guarantee no network fetch on that path.\n- **Cloud sync — off by default, opt-in, explicit.** No data leaves your machine unless you run `shieldcortex config --cloud-enable --cloud-api-key <key>`. When enabled:\n  - **Audit telemetry** (`/v1/audit/ingest`): scan **metadata only** — trust scores, threat indicators, categories, timings, device name. **No memory content.**\n  - **Memory sync** (`/v1/sync/memories`, Enterprise licence — grandfathered Team keys also unlock it): transmits **full memory title + content** of PUBLIC/INTERNAL memories so they sync across your team. CONFIDENTIAL/RESTRICTED memories are **excluded by default**; switch to metadata-only with the `contentMode` control.\n  - **Quarantine sync** (Enterprise licence): flagged content is sent with **detected credentials redacted**.\n  - **OpenClaw realtime plugin** (optional): scans live input and output **locally**. When it flags something, only **threat metadata** (type, scores, timestamps — **never the input text itself**) is forwarded, and only when Cloud sync is enabled. Flagged-content previews are kept in your **local** audit log; they are never transmitted.\n\n  Raw conversation/input text is never transmitted by the audit, threat, or interceptor paths — they carry metadata only. The single exception is **Memory sync** above, which uploads the content of memories you chose to store (PUBLIC/INTERNAL, off by default, Enterprise licence). You can disable any of the above at any time, and the realtime plugin and lifecycle handlers can be removed entirely.\n\n## What it does NOT do\n\n- Does **not** read SSH keys, AWS credentials, GPG keys, or /etc/ files\n- Does **not** send your data to external servers, with three narrow, user-initiated exceptions: Cloud sync when you enable it, the subscription id sent to the licence endpoint when you activate a licence key, and event payloads to webhooks you configure (memory-event and Iron Dome operator notifications). Its remaining outbound calls are downloads/fetches that carry only the request itself — never memory or conversation content: npm-registry update checks and X-Ray package lookups (the package name appears in the URL), the huggingface.co embedding-model download, and URLs you explicitly pass to `env scan`\n- Does **not** modify .bashrc, .zshrc, .profile, or shell configs\n- Does **not** use `eval` or dynamic code execution of any kind\n- Does **not** build subprocess commands from agent, memory, or network content. The update flow and the OpenClaw MCP bridge never spawn a shell — argv-array `execFile`/`spawn` only (`npm view` update check, `npm update`/`npm install`, `pgrep`, `npx mcporter`). The dashboard X-Ray surface adds two more argv-array, local-only children: `osascript` with fixed script lines (macOS folder picker) and ShieldCortex's own Node binary re-spawned for `xray --watch` background scans (hook and server helpers re-spawn `process.execPath` the same way, always with fixed local script paths). Sudo-aware home resolution validates the username, then runs `getent passwd <user>` as an argv-array — never through a shell, no tilde-eval. User-run CLI commands (setup, service, migrate, uninstall, audit, doctor, the npx-staleness warning) and corrupt-database recovery run fixed local admin tools (`npm`, `launchctl`, `systemctl`, `sqlite3`), some through a shell, parameterised only by local paths and usernames\n- Does **not** bypass, disable, or override any agent safety mechanisms\n- Does **not** auto-approve actions or skip verification prompts\n- Does **not** mine cryptocurrency, trade tokens, manage wallets, or initiate purchases\n- Does **not** make purchases, place orders, or move money on the user's behalf\n\n## CLI Reference\n\n### Getting Started\n```bash\nshieldcortex quickstart          # Detect integrations, guide setup\nshieldcortex setup               # Register MCP server for current project\nshieldcortex doctor              # Diagnose registration issues\nshieldcortex status              # Show protection status\nshieldcortex uninstall           # Remove from project\n```\n\n### Memory\n```bash\n# Memory is typically used via the MCP server, not the CLI directly. The tools are:\n#   remember · recall · forget · get_context · get_memory · get_related\n#   consolidate · graph_query · graph_entities · scan_memories · memory_stats\n#   start_session · end_session\n# (there is no `store`, `search` or bare `graph` tool — use remember/recall/graph_query)\nshieldcortex graph backfill      # Build knowledge graph from stored memories\nshieldcortex stats               # Memory statistics\n```\n\n### Security Scanning\n```bash\nshieldcortex scan \"text\"                    # Scan text (exit 0=allow, 1=caught, 2=usage, 3=tool-fail; parse stdout)\nshieldcortex scan-skill path/to/SKILL.md    # Scan one instruction file for threats\nshieldcortex scan-skills                    # Scan all discovered agent instruction files\nshieldcortex audit                          # Full security audit (memory, env, MCP configs, rules files)\nshieldcortex iron-dome status               # Iron Dome behavioural protection status\n```\n\n### Cortex — Mistake Learning\n```bash\n# capture requires all four flags: --category --what --why --rule\nshieldcortex cortex capture --category code --what \"Guessed API endpoints\" \\\n  --why \"Didn't check the docs\" --rule \"Verify endpoints in API docs before calling\"\nshieldcortex cortex preflight --task \"deploy to production\"           # Pre-task check\nshieldcortex cortex review                                            # Pattern analysis\nshieldcortex cortex list                                              # View mistake log\nshieldcortex cortex search \"<query>\"                                  # Full-text search\nshieldcortex cortex stats                                             # Category breakdown\nshieldcortex cortex confirm --category code --what \"...\" \\\n  --why-worked \"...\" --when-repeat \"...\"                              # Capture what worked\nshieldcortex cortex graduate                                          # Archive mastered rules\n```\n\n### Dashboard & Services\n```bash\nshieldcortex dashboard           # Dashboard on localhost:3030 (starts the API on :3001 too)\nshieldcortex api                 # Start the API server only (localhost:3001)\nshieldcortex worker              # Background sync + heartbeat worker\nshieldcortex service start|stop|status  # Manage background service\n```\n\n### Integrations\n```bash\n# subcommand is `install`, not `setup` (also: status, uninstall; openclaw adds repair, skill)\nshieldcortex openclaw install    # Hook + realtime plugin — tool gate BOUND\nshieldcortex copilot install     # VS Code / Cursor MCP memory server — NOT a tool gate\nshieldcortex codex install       # Codex CLI MCP memory server — NOT a tool gate\nshieldcortex config --openclaw-auto-memory true   # Enable auto-memory in OpenClaw\nshieldcortex config --proactive-recall true|false  # Enable/disable proactive recall\n```\n\n### Cloud & Licensing\n```bash\nshieldcortex config --cloud-enable --cloud-api-key <key>  # Enable cloud sync\nshieldcortex cloud sync --full    # Backfill memories + graph to cloud\nshieldcortex license activate <key>  # Activate an Enterprise (or legacy) licence key\nshieldcortex license status       # Check licence tier\n```\n\n### Maintenance\n```bash\nshieldcortex update              # Self-update (npm package + OpenClaw plugin + skill)\n```\n\n## What Gets Scanned\n\n### `scan-skills` discovers and scans:\n- SKILL.md, HOOK.md, handler.js (Claude Code / OpenClaw skills)\n- .cursorrules, .windsurfrules, .clinerules (editor rules)\n- CLAUDE.md, copilot-instructions.md (agent instructions)\n- .aider.conf.yml, .continue/config.json (tool configs)\n- Searches: ~/.claude/skills/, ~/.openclaw/skills/, ~/.openclaw/hooks/, project directories\n\n### `audit` checks:\n- **Memory files** — ~/.claude/projects/, ~/.cursor/memories/, ~/.windsurf/memories/\n- **Environment** — .env files for leaked credentials (read-only check, never writes)\n- **MCP configs** — ~/.claude/mcp.json, ~/.openclaw/mcp.json, ~/.cursor/mcp.json, project-level equivalents\n- **Rules files** — CLAUDE.md, .cursorrules, copilot-instructions.md for injection patterns\n\n## What Gets Uploaded to Cloud\n\nCloud sync is **off by default**. Audit metadata sync is included on the cloud free tier; full memory/graph replication requires an Enterprise licence (grandfathered Team keys keep working).\n\n- **Uploaded when Cloud sync is enabled by the user:** selected memory records, related embeddings/metadata, and knowledge-graph entities/relationships required for sync.\n- **Not uploaded by default:** local agent configs, MCP configs, raw rules files, shell configs, SSH keys, secrets, `.env` contents, or arbitrary project files.\n- **Security scan results stay local** unless the user explicitly exports or syncs data through a Cloud-enabled workflow.\n- **No sync traffic** occurs unless the user explicitly enables Cloud sync and provides a valid API key. Outside sync, the only api.shieldcortex.ai call is licence-key validation when a key is activated (subscription id only, never memory content) — see `network_endpoints`.\n\n## Licence Tiers\n\nPublic tiers are **Free** and **Enterprise** (sales@drakonsystems.com). Every local feature is Free; grandfathered Pro/Team keys keep working.\n\n| Feature | Free | Enterprise |\n|---------|------|------------|\n| Memory (store/recall/search/graph) | ✅ | ✅ |\n| Proactive recall (auto-inject on prompts) | ✅ | ✅ |\n| Defence pipeline (scan, Iron Dome) | ✅ | ✅ |\n| Audit & scan-skills | ✅ | ✅ |\n| Dashboard | ✅ | ✅ |\n| Custom injection patterns | ✅ | ✅ |\n| Custom Iron Dome policies | ✅ | ✅ |\n| Custom firewall rules | ✅ | ✅ |\n| Audit export | ✅ | ✅ |\n| Deep skill scanning | ✅ | ✅ |\n| Cortex (mistake learning) | ✅ | ✅ |\n| Cloud audit sync (metadata, 500 scans/mo, 7-day retention) | ✅ | ✅ |\n| Cloud memory/graph sync | ❌ | ✅ |\n| Team management | ❌ | ✅ |\n| Shared patterns | ❌ | ✅ |\n\n## Links\n\n- **Docs:** https://shieldcortex.ai/docs\n- **Source:** https://github.com/Drakon-Systems-Ltd/ShieldCortex\n- **npm:** https://www.npmjs.com/package/shieldcortex\n- **Issues:** https://github.com/Drakon-Systems-Ltd/ShieldCortex/issues\n- **Changelog:** https://shieldcortex.ai/changelog\n\n## API bind (#411)\n- Default bind is loopback (`127.0.0.1`).\n- Non-loopback requires `SHIELDCORTEX_ALLOW_NON_LOOPBACK=1` **and** `SHIELDCORTEX_API_TOKEN` (≥32 chars).\n- Public `/api/auth/session-token` is loopback-only.\n\nFile v5.3.1:_meta.json\n\n{\n  \"ownerId\": \"kn71759x1py9k3ak7d6hjwbx5x812cf2\",\n  \"slug\": \"shieldcortex\",\n  \"version\": \"5.3.1\",\n  \"publishedAt\": 1791050406796\n}\n\nFile v5.3.1:bundled/cortex-memory-hook/HOOK.md\n\n---\nname: cortex-memory\ndescription: \"Persistent brain-like memory via ShieldCortex — recalls past knowledge, with optional auto-save\"\nhomepage: https://github.com/Drakon-Systems-Ltd/ShieldCortex\nmetadata:\n  { \"openclaw\": { \"emoji\": \"🧠\", \"events\": [\"command:new\", \"command:stop\", \"agent:bootstrap\"], \"requires\": { \"bins\": [\"npx\"] }, \"install\": [{ \"id\": \"community\", \"kind\": \"community\", \"label\": \"ShieldCortex\" }] } }\n---\n\n# Cortex Memory Hook\n\nIntegrates [ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) persistent memory. Recalls past knowledge at session start, and can optionally auto-save important session context.\n\n## What It Does\n\n### On `/new` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Reads the ending session transcript\n2. Pattern-matches for decisions, bug fixes, learnings, architecture changes, and preferences\n3. Saves up to 5 high-salience memories to ShieldCortex via mcporter\n4. Skips exact and near-duplicate memories using novelty filtering\n\n### On `/stop`, `/clear`, `/exit` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Captures the current session transcript before it ends\n2. Pattern-matches for important content (same patterns as `/new`)\n3. Saves memories with a `session-stop` tag for tracking\n4. **Ensures work is saved** even when explicitly ending a session\n5. Skips exact and near-duplicate memories using novelty filtering\n\n### On Session Start (Agent Bootstrap)\nBootstrap context injection was **disabled in v2026.2.26**. OpenClaw's native Memory Search now handles context recall at session start, so the hook no longer pushes memories into the system prompt (which was producing ~40× duplication of CORTEX_MEMORY.md and eating most of the context window).\n\nThe hook still fires on `agent:bootstrap` for lifecycle wiring (warning-bootstrap-file handoff, etc.) but contributes nothing to the system prompt. This keeps `extraSystemPromptHash` stable across turns and prevents the session-binding reset loop documented in `src/setup/claude-md.ts`.\n\n### Keyword Triggers\n\nSay any of these phrases to trigger an instant save to Cortex memory:\n\n| Trigger Phrase | Category | Importance |\n|---------------|----------|------------|\n| **\"remember this\"** | note | critical |\n| **\"don't forget\"** | note | critical |\n| **\"this is important\"** | note | critical |\n| **\"make a note\"** | note | critical |\n| **\"for the record\"** | note | critical |\n| **\"note to self\"** | note | critical |\n| **\"important:\"** | note | critical |\n| **\"crucial:\"** | note | critical |\n| **\"key point:\"** | note | high |\n| **\"lesson learned\"** | learning | high |\n| **\"i learned\"** | learning | normal |\n| **\"TIL:\"** | learning | normal |\n| **\"today i learned\"** | learning | normal |\n| **\"never again\"** | error | critical |\n| **\"root cause was\"** | error | high |\n| **\"the fix was\"** | error | high |\n| **\"always do\"** | preference | high |\n| **\"never do\"** | preference | high |\n| **\"i prefer\"** | preference | normal |\n| **\"we should always\"** | preference | high |\n| **\"we decided\"** | architecture | high |\n| **\"decision made\"** | architecture | high |\n| **\"going with\"** | architecture | normal |\n\nContent after the trigger phrase is extracted and saved as the memory content.\n\n## Defence Audit Guarantees\n\nEvery byte that lands in `memories` from the auto-extract path passes the\n6-layer defence pipeline first. The hook write path is no longer the\nbypass it once was:\n\n- **ALLOW** → row inserted into `memories`; a corresponding row appears in\n  `defence_audit` with `source_type = 'hook'` and the hook's identifier\n  (`session-end-hook` / `pre-compact-hook` / `stop-hook`).\n- **QUARANTINE** → row inserted into `quarantine` (not `memories`), linked\n  to the audit row via `audit_id`. Visible in the dashboard for review.\n- **BLOCK** → dropped. The audit row written by the pipeline carries the\n  block reason; nothing reaches `memories`.\n- **Pipeline error** → dropped + a synthetic audit row with reason\n  `pipeline_error: <msg>`. Never silently lose data.\n\nBuilt-in firewall rules covering instruction injection, hidden\ninstruction, imperative tool-call directives (\"call X tool now\"), command\ninjection, and credential leaks (AWS / JWT / private keys) are seeded\ninto `firewall_rules` on first run with `built_in = 1`. They are\nalways evaluated (user-added custom rules are free too, behind a dormant\nfeature gate) and excluded from the user-facing 25-rule cap.\n\nThe chunker also rejects malformed candidates *before* they reach the\nwrite path: imperative tool-calls, bare-imperative starts (\"commit\nsecrets\" with the negation dropped), email-body bleed, and path-label\nfragments. Auto-extracted memories are now capped at salience 0.6\n(reserved 1.0 for LLM-rated future paths).\n\nTo audit an existing database for malformed rows accumulated before this\nfix:\n\n```bash\nshieldcortex memories purge --malformed --dry-run    # preview\nshieldcortex memories purge --malformed --execute    # delete (writes a backup first)\n```\n\n## Auto-Memory\n\nAuto-memory extraction is enabled by default. ShieldCortex complements your existing memory system by capturing decisions, fixes, and learnings with built-in deduplication to avoid noise.\n\nDisable auto-save with CLI:\n\n```bash\nnpx shieldcortex config --openclaw-auto-memory false\n```\n\nRe-enable it:\n\n```bash\nnpx shieldcortex config --openclaw-auto-memory true\n```\n\nOr set directly in config:\n\n```json\n{\n  \"openclawAutoMemory\": true\n}\n```\n\nin `~/.shieldcortex/config.json`.\n\n## Requirements\n\n- **npx** must be available (Node.js installed)\n- ShieldCortex installs automatically on first use via `npx -y shieldcortex`\n- mcporter must be available for MCP tool calls\n\n## Database\n\nMemories stored in `~/.shieldcortex/memories.db` (SQLite). Shared with Claude Code sessions — memories created here are available everywhere.\n\n## Install\n\n```bash\nopenclaw skills install shieldcortex\n```\n\nOptional companion real-time plugin:\n\n```bash\nopenclaw plugins install @drakon-systems/shieldcortex-realtime\n```\n\n## Uninstall\n\n```bash\nshieldcortex openclaw uninstall\n```\n\nOr disable without removing:\n\n```json\n{\n  \"hooks\": {\n    \"internal\": {\n      \"entries\": {\n        \"cortex-memory\": { \"enabled\": false }\n      }\n    }\n  }\n}\n```\n\nFile v5.3.1:skill-card.md\n\n## Description:\n\nGives AI agents persistent semantic memory and a memory firewall that scans for prompt injection, credential leaks, and poisoned content.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jarvis-drakon](https://clawhub.ai/user/jarvis-drakon)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use ShieldCortex to retain and retrieve conversation-derived context, scan agent environments, and protect memory reads and writes from unsafe content.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Conversation-derived memories may persist across sessions and become available to other agent interactions.\n\nMitigation: Review auto-memory settings and disable automatic capture where persistent recall is not wanted.\n\nRisk: OpenClaw startup may automatically modify hook files.\n\nMitigation: Set SHIELDCORTEX_SKIP_SELF_HEAL=1 if startup file mutation is not acceptable.\n\nRisk: An OpenClaw hook may fetch a package through npx when no local binary is available.\n\nMitigation: Install and pin a local shieldcortex binary instead of relying on the npx fallback.\n\nRisk: Enabling Cloud sync can upload selected memory content.\n\nMitigation: Keep Cloud sync disabled unless the content and upload destination are acceptable.\n\n## Reference(s):\n\n- [ShieldCortex documentation](https://shieldcortex.ai/docs)\n- [ShieldCortex homepage](https://shieldcortex.ai)\n- [ShieldCortex npm package](https://www.npmjs.com/package/shieldcortex)\n- [ClawHub skill listing](https://clawhub.ai/jarvis-drakon/skills/shieldcortex)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration instructions, Analysis]\n\n**Output Format:** [Markdown with inline shell commands and scan findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Memory recall and security scan results depend on local configuration and available agent integrations.]\n\n## Skill Version(s):\n\n5.3.1 (source: ClawHub release and skill metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v5.3.1:bundled/openclaw-plugin/openclaw.plugin.json\n\n{\n  \"id\": \"shieldcortex-realtime\",\n  \"version\": \"4.31.2\",\n  \"name\": \"ShieldCortex Real-time Scanner\",\n  \"description\": \"Real-time defence scanning on LLM input, memory extraction on LLM output, and active tool call interception with approval gating.\",\n  \"kind\": null,\n  \"engines\": {\n    \"openclaw\": \">=2026.3.22\",\n    \"recommended\": \">=2026.4.23\"\n  },\n  \"enabledByDefault\": false,\n  \"activation\": {\n    \"onStartup\": false,\n    \"hooks\": [\n      \"llm_input\",\n      \"llm_output\",\n      \"before_tool_call\",\n      \"session_end\"\n    ],\n    \"commands\": [\n      \"shieldcortex-status\"\n    ]\n  },\n  \"contracts\": {},\n  \"commandAliases\": {\n    \"shieldcortex-status\": \"shieldcortex-status\"\n  },\n  \"uiHints\": {\n    \"binaryPath\": {\n      \"label\": \"ShieldCortex Binary Path\",\n      \"help\": \"Optional absolute path to the shieldcortex CLI when it is not on PATH.\",\n      \"placeholder\": \"/usr/local/bin/shieldcortex\",\n      \"advanced\": true\n    },\n    \"cloudApiKey\": {\n      \"label\": \"Cloud API Key\",\n      \"help\": \"Optional ShieldCortex Cloud API key used for realtime threat forwarding.\",\n      \"placeholder\": \"sc_...\",\n      \"sensitive\": true\n    },\n    \"cloudBaseUrl\": {\n      \"label\": \"Cloud Base URL\",\n      \"help\": \"Override the ShieldCortex Cloud API base URL if you use a self-hosted or staging endpoint.\",\n      \"placeholder\": \"https://api.shieldcortex.ai\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemory\": {\n      \"label\": \"Auto Memory Extraction\",\n      \"help\": \"Extract high-signal decisions and learnings from LLM output into ShieldCortex memory.\"\n    },\n    \"openclawAutoMemoryDedupe\": {\n      \"label\": \"Dedupe Auto Memory\",\n      \"help\": \"Skip near-duplicate memories before they are written to ShieldCortex.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryNoveltyThreshold\": {\n      \"label\": \"Novelty Threshold\",\n      \"help\": \"Similarity threshold for duplicate suppression. Higher values keep more memories.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryMaxRecent\": {\n      \"label\": \"Recent Memory Cache Size\",\n      \"help\": \"How many recent extracted memories to keep in the dedupe cache.\",\n      \"advanced\": true\n    },\n    \"interceptor.enabled\": {\n      \"label\": \"Enable Tool Call Interceptor\",\n      \"description\": \"Scan memory-write tool calls and gate suspicious content behind user approval\",\n      \"type\": \"boolean\"\n    },\n    \"interceptor.severityActions.high\": {\n      \"label\": \"High Severity Action\",\n      \"description\": \"Action for high-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    },\n    \"interceptor.severityActions.critical\": {\n      \"label\": \"Critical Severity Action\",\n      \"description\": \"Action for critical-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    }\n  },\n  \"configSchema\": {\n    \"type\": \"object\",\n    \"additionalProperties\": false,\n    \"properties\": {\n      \"enabled\": {\n        \"type\": \"boolean\"\n      },\n      \"binaryPath\": {\n        \"type\": \"string\"\n      },\n      \"cloudApiKey\": {\n        \"type\": \"string\"\n      },\n      \"cloudBaseUrl\": {\n        \"type\": \"string\"\n      },\n      \"openclawAutoMemory\": {\n        \"type\": \"boolean\"\n      },\n      \"openclawAutoMemoryDedupe\": {\n        \"type\": \"boolean\"\n      },\n      \"openclawAutoMemoryNoveltyThreshold\": {\n        \"type\": \"number\",\n        \"minimum\": 0.6,\n        \"maximum\": 0.99\n      },\n      \"openclawAutoMemoryMaxRecent\": {\n        \"type\": \"integer\",\n        \"minimum\": 50,\n        \"maximum\": 1000\n      },\n      \"interceptor\": {\n        \"type\": \"object\",\n        \"properties\": {\n          \"enabled\": {\n            \"type\": \"boolean\",\n            \"default\": true\n          },\n          \"severityActions\": {\n            \"type\": \"object\",\n            \"additionalProperties\": false,\n            \"properties\": {\n              \"low\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              },\n              \"medium\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              },\n              \"high\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"warn\"\n              },\n              \"critical\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"log\",\n                  \"warn\",\n                  \"require_approval\"\n                ],\n                \"default\": \"log\"\n              }\n            }\n          },\n          \"failurePolicy\": {\n            \"type\": \"object\",\n            \"additionalProperties\": false,\n            \"properties\": {\n              \"low\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"allow\"\n              },\n              \"medium\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"allow\"\n              },\n              \"high\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"deny\"\n              },\n              \"critical\": {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"allow\",\n                  \"deny\"\n                ],\n                \"default\": \"deny\"\n              }\n            }\n          }\n        }\n      }\n    }\n  }\n}\n\nArchive v5.3.0: 11 files, 51793 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (47494b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (2292b), SKILL.md (31295b), _meta.json (131b)\n\nFile v5.3.0:SKILL.md\n\n---\nname: shieldcortex\ndescription: \"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\"\nlicense: MIT-0\nmetadata:\n  author: Drakon Systems\n  version: 5.3.0\n  mcp-server: shieldcortex\n  category: memory-and-security\n  tags: [memory, security, knowledge-graph, mcp, iron-dome, openclaw-plugin, audit]\n  source: https://github.com/Drakon-Systems-Ltd/ShieldCortex\n  homepage: https://shieldcortex.ai\n  npm: https://www.npmjs.com/package/shieldcortex\n  verified_publisher: Drakon Systems Ltd\n  publisher_github: https://github.com/Drakon-Systems-Ltd\n  npm_audit: \"0 unwaived production advisories; 2 waived (sharp: GHSA-f88m-g3jw-g9cj, GHSA-rgj7-g3m4-5g8c, reachable only via the optional @huggingface/transformers) - see docs/security/audit-waivers.md\"\n  downloads: 11K+/month\ninstall:\n  command: shieldcortex quickstart\n  runtime: node\n  minVersion: \"22.14.0\"\n  note: >\n    Requires Node 22.14+ LTS or Node 24+; Node 23 is unsupported. Run the installed\n    `shieldcortex` binary directly. The quickstart command\n    detects your environment. Claude Code and OpenClaw get hooks that can deny;\n    Codex/Cursor/VS Code get an MCP memory server only (not a tool gate).\n    All data stays local in ~/.shieldcortex/. No account o\n\nArchive v5.2.1: 11 files, 51752 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (47494b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (2253b), SKILL.md (31295b), _meta.json (131b)\n\nArchive v5.2.0: 11 files, 51731 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (47494b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (2207b), SKILL.md (31295b), _meta.json (131b)\n\nArchive v5.1.0: 11 files, 52095 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (47494b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (3039b), SKILL.md (31295b), _meta.json (131b)\n\nArchive v5.0.6: 11 files, 51654 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (45419b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (3260b), SKILL.md (31295b), _meta.json (131b)\n\nArchive v5.0.5: 11 files, 51509 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (45419b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (2940b), SKILL.md (31295b), _meta.json (131b)\n\nArchive v5.0.4: 11 files, 51526 bytes\n\nFiles: bundled/cortex-memory-hook/handler.ts (45419b), bundled/cortex-memory-hook/HOOK.md (6222b), bundled/cortex-memory-hook/runtime.mjs (9073b), bundled/openclaw-plugin/cloud-sync.js (1371b), bundled/openclaw-plugin/index.js (30321b), bundled/openclaw-plugin/intercept-ingest.js (936b), bundled/openclaw-plugin/interceptor.js (14883b), bundled/openclaw-plugin/openclaw.plugin.json (5788b), skill-card.md (3084b), SKILL.md (31295b), _meta.json (131b)","readmeExcerpt":"Skill: ShieldCortex Owner: jarvis-drakon Summary: Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning. Tags: latest:5.5.0 Version history: v5.5.0 | 2026-10-08T07:03:55.770Z | user Sync from npm publish v5.5.0 v5.4.0 | 2026-10-06T10:48:36.133Z | user Sync from npm publish v5.4.0 v5.3.1 | 20","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"shieldcortex config --self-heal false     # writes \"selfHeal\": false to ~/.shieldcortex/config.json\nexport SHIELDCORTEX_SKIP_SELF_HEAL=1      # or set the env var for the gateway process"},{"language":"bash","snippet":"shieldcortex quickstart          # Detect integrations, guide setup\nshieldcortex setup               # Register MCP server for current project\nshieldcortex doctor              # Diagnose registration issues\nshieldcortex status              # Show protection status\nshieldcortex uninstall           # Remove from project"},{"language":"bash","snippet":"# Memory is typically used via the MCP server, not the CLI directly. The tools are:\n#   remember · recall · forget · get_context · get_memory · get_related\n#   consolidate · graph_query · graph_entities · scan_memories · memory_stats\n#   start_session · end_session\n# (there is no `store`, `search` or bare `graph` tool — use remember/recall/graph_query)\nshieldcortex graph backfill      # Build knowledge graph from stored memories\nshieldcortex stats               # Memory statistics"},{"language":"bash","snippet":"shieldcortex scan \"text\"                    # Scan text (exit 0=allow, 1=caught, 2=usage, 3=tool-fail; parse stdout)\nshieldcortex scan-skill path/to/SKILL.md    # Scan one instruction file for threats\nshieldcortex scan-skills                    # Scan all discovered agent instruction files\nshieldcortex audit                          # Full security audit (memory, env, MCP configs, rules files)\nshieldcortex iron-dome status               # Iron Dome behavioural protection status"},{"language":"bash","snippet":"# capture requires all four flags: --category --what --why --rule\nshieldcortex cortex capture --category code --what \"Guessed API endpoints\" \\\n  --why \"Didn't check the docs\" --rule \"Verify endpoints in API docs before calling\"\nshieldcortex cortex preflight --task \"deploy to production\"           # Pre-task check\nshieldcortex cortex review                                            # Pattern analysis\nshieldcortex cortex list                                              # View mistake log\nshieldcortex cortex search \"<query>\"                                  # Full-text search\nshieldcortex cortex stats                                             # Category breakdown\nshieldcortex cortex confirm --category code --what \"...\" \\\n  --why-worked \"...\" --when-repeat \"...\"                              # Capture what worked\nshieldcortex cortex graduate                                          # Archive mastered rules"},{"language":"bash","snippet":"shieldcortex dashboard           # Dashboard on localhost:3030 (starts the API on :3001 too)\nshieldcortex api                 # Start the API server only (localhost:3001)\nshieldcortex worker              # Background sync + heartbeat worker\nshieldcortex service start|stop|status  # Manage background service"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: shieldcortex\ndescription: \"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\"\nlicense: MIT-0\nmetadata:\n  author: Drakon Systems\n  version: 5.5.0\n  mcp-server: shieldcortex\n  category: memory-and-security\n  tags: [memory, security, knowledge-graph, mcp, iron-dome, openclaw-plugin, audit]\n  source: https://github.com/Drakon-Systems-Ltd/ShieldCortex\n  homepage: https://shieldcortex.ai\n  npm: https://www.npmjs.com/package/shieldcortex\n  verified_publisher: Drakon Systems Ltd\n  publisher_github: https://github.com/Drakon-Systems-Ltd\n  npm_audit: \"0 unwaived production advisories; 4 waived (sharp: GHSA-f88m-g3jw-g9cj, GHSA-rgj7-g3m4-5g8c, GHSA-wq5f-xc86-pv6w; sprintf-js: GHSA-hp3w-g68c-fv3c, via optional @huggingface/transformers) - see docs/security/audit-waivers.md\"\n  downloads: 11K+/month\ninstall:\n  command: shieldcortex quickstart\n  runtime: node\n  minVersion: \"22.14.0\"\n  note: >\n    Requires Node 22.14+ LTS or Node 24+; Node 23 is unsupported. Run the installed\n    `shieldcortex` binary directly. The quickstart command\n    detects your environment. Claude Code and OpenClaw get hooks that can deny;\n    Codex/Cursor/VS Code get an MCP memory server only (not a tool gate).\n    All data stays local in ~/.shieldcortex/. No account or API key needed\n    for local use.\npermissions:\n  filesystem: readwrite\n  network: optional\n  credentials: optional\n  justification: >\n    Filesystem read: scans agent instruction files for prompt injection threats\n    (same files the agent already reads). Filesystem write: stores memory DB\n    and config in ~/.shieldcortex/. Network: local-first — outbound only for\n    the embedding-model download when it is not cached (huggingface.co;\n    disable with SHIELDCORTEX_SKIP_EMBEDDINGS=1), Cloud sync (opt-in),\n    licence-key validation when a key is activated, explicit update\n    checks/updates and X-Ray package lookups (npm registry), URLs you ask\n    `env scan` to fetch, and webhooks you configure. Credentials: optional\n    Cloud API key for team sync (not required for local use).\n  paths_read:\n    - ~/.shieldcortex/ (own config and memory database)\n    - ~/.claude/ (project memory files, MCP config)\n    - ~/.openclaw/ (MCP config, extensions)\n    - ~/.cursor/ (rules, memories, MCP config)\n    - ~/.windsurf/ (memories, rules)\n    - ~/.codex/ (MCP config)\n    - $CWD/.claude/, $CWD/.cursor/ (project-level configs)\n    - $CWD/.cursorrules, $CWD/.windsurfrules, $CWD/.clinerules\n    - $CWD/CLAUDE.md, $CWD/copilot-instructions.md\n    - $CWD/.aider.conf.yml, $CWD/.continue/config.json\n    - $CWD/.env (env-scanner checks for leaked secrets — reads, never writes)\n  paths_write:\n    - ~/.shieldcortex/ (memory DB, config, cortex log, licence, audit cache)\n    - ~/.cache/shieldcortex/models (embedding model download cache)\n    - ~/.openclaw/extensions/shieldcortex-realtime/ (OpenClaw plugin via t"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71759x1py9k3ak7d6hjwbx5x812cf2\",\n  \"slug\": \"shieldcortex\",\n  \"version\": \"5.5.0\",\n  \"publishedAt\": 1791443035770\n}"},{"path":"bundled/cortex-memory-hook/HOOK.md","content":"---\nname: cortex-memory\ndescription: \"Persistent brain-like memory via ShieldCortex — recalls past knowledge, with optional auto-save\"\nhomepage: https://github.com/Drakon-Systems-Ltd/ShieldCortex\nmetadata:\n  { \"openclaw\": { \"emoji\": \"🧠\", \"events\": [\"command:new\", \"command:stop\", \"agent:bootstrap\"], \"requires\": { \"bins\": [\"npx\"] }, \"install\": [{ \"id\": \"community\", \"kind\": \"community\", \"label\": \"ShieldCortex\" }] } }\n---\n\n# Cortex Memory Hook\n\nIntegrates [ShieldCortex](https://github.com/Drakon-Systems-Ltd/ShieldCortex) persistent memory. Recalls past knowledge at session start, and can optionally auto-save important session context.\n\n## What It Does\n\n### On `/new` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Reads the ending session transcript\n2. Pattern-matches for decisions, bug fixes, learnings, architecture changes, and preferences\n3. Saves up to 5 high-salience memories to ShieldCortex via mcporter\n4. Skips exact and near-duplicate memories using novelty filtering\n\n### On `/stop` (Session End)\nWhen `openclawAutoMemory` is enabled:\n1. Reads the current session transcript\n2. Pattern-matches for important content (same patterns as `/new`)\n3. Saves memories with a `session-stop` tag for tracking\n4. Skips exact and near-duplicate memories using novelty filtering\n\nCore OpenClaw 2026.9.6 does not show the hook's \"Saved N memories\" note for `/stop`: the stop command sends its own reply and does not read the hook's `event.messages`.\n\n`/clear` and `/exit` are not core OpenClaw 2026.9.6 hook events, and they are not in this hook's `events` list, so this hook does not capture on them.\n\n### On Session Start (Agent Bootstrap)\nBootstrap context injection was **disabled in v2026.2.26**. OpenClaw's native Memory Search now handles context recall at session start, so the hook no longer pushes memories into the system prompt (which was producing ~40× duplication of CORTEX_MEMORY.md and eating most of the context window).\n\nThe hook still fires on `agent:bootstrap` for lifecycle wiring (warning-bootstrap-file handoff, etc.) but contributes nothing to the system prompt. This keeps `extraSystemPromptHash` stable across turns and prevents the session-binding reset loop documented in `src/setup/claude-md.ts`.\n\n### Keyword Triggers (dormant, not registered)\n\nThe handler has a keyword-trigger path, but it is **not registered** on core OpenClaw 2026.9.6 with this manifest, and it is not enabled by default. The `events` list above subscribes only `command:new`, `command:stop` and `agent:bootstrap`. OpenClaw never sends this hook a `message` event, and no other command action reaches the handler's command fallback. Saying one of these phrases does **not** save anything through this hook. The per-message proactive recall in the same `message` branch is dormant for the same reason; this hook does not recall memory on each message.\n\nPhrases the dormant code recognises:\n\n| Trigger Phrase | Category | Importance |\n|---------------|----------|------------|\n| **\"rememb"},{"path":"skill-card.md","content":"## Description:\n\nMemory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jarvis-drakon](https://clawhub.ai/user/jarvis-drakon)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users use ShieldCortex to retain and recall session knowledge, scan agent content for threats, and manage memory across supported integrations.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Automatic memory capture can retain sensitive session content locally.\n\nMitigation: Review auto-memory settings and disable capture for sensitive work.\n\nRisk: Self-heal can modify an existing OpenClaw hook installation without prompting.\n\nMitigation: Review hook behavior and disable self-heal if automatic changes are unwanted.\n\nRisk: Runtime npx fallback can execute an unpinned npm package in an agent context.\n\nMitigation: Prefer a reviewed, pinned local or global installation over runtime npx.\n\nRisk: Optional cloud sync can transmit selected memory content and audit metadata.\n\nMitigation: Keep cloud sync off unless the data and sharing settings are appropriate.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/jarvis-drakon/skills/shieldcortex)\n- [ShieldCortex website](https://shieldcortex.ai)\n- [ShieldCortex npm package](https://www.npmjs.com/package/shieldcortex)\n- [Publisher GitHub profile (listed in metadata)](https://github.com/Drakon-Systems-Ltd)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance]\n\n**Output Format:** [Text and structured tool responses]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Memory recall and security scan results depend on enabled integrations and settings.]\n\n## Skill Version(s):\n\n5.5.0 (source: server-resolved release and skill metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"bundled/openclaw-plugin/openclaw.plugin.json","content":"{\n  \"id\": \"shieldcortex-realtime\",\n  \"version\": \"4.31.2\",\n  \"name\": \"ShieldCortex Real-time Scanner\",\n  \"description\": \"Real-time defence scanning on LLM input, memory extraction on LLM output, and active tool call interception with approval gating.\",\n  \"kind\": null,\n  \"engines\": {\n    \"openclaw\": \">=2026.3.22\",\n    \"recommended\": \">=2026.4.23\"\n  },\n  \"enabledByDefault\": false,\n  \"activation\": {\n    \"onStartup\": false,\n    \"hooks\": [\n      \"llm_input\",\n      \"llm_output\",\n      \"before_tool_call\",\n      \"session_end\"\n    ],\n    \"commands\": [\n      \"shieldcortex-status\"\n    ]\n  },\n  \"contracts\": {},\n  \"commandAliases\": {\n    \"shieldcortex-status\": \"shieldcortex-status\"\n  },\n  \"uiHints\": {\n    \"binaryPath\": {\n      \"label\": \"ShieldCortex Binary Path\",\n      \"help\": \"Optional absolute path to the shieldcortex CLI when it is not on PATH.\",\n      \"placeholder\": \"/usr/local/bin/shieldcortex\",\n      \"advanced\": true\n    },\n    \"cloudApiKey\": {\n      \"label\": \"Cloud API Key\",\n      \"help\": \"Optional ShieldCortex Cloud API key used for realtime threat forwarding.\",\n      \"placeholder\": \"sc_...\",\n      \"sensitive\": true\n    },\n    \"cloudBaseUrl\": {\n      \"label\": \"Cloud Base URL\",\n      \"help\": \"Override the ShieldCortex Cloud API base URL if you use a self-hosted or staging endpoint.\",\n      \"placeholder\": \"https://api.shieldcortex.ai\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemory\": {\n      \"label\": \"Auto Memory Extraction\",\n      \"help\": \"Extract high-signal decisions and learnings from LLM output into ShieldCortex memory.\"\n    },\n    \"openclawAutoMemoryDedupe\": {\n      \"label\": \"Dedupe Auto Memory\",\n      \"help\": \"Skip near-duplicate memories before they are written to ShieldCortex.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryNoveltyThreshold\": {\n      \"label\": \"Novelty Threshold\",\n      \"help\": \"Similarity threshold for duplicate suppression. Higher values keep more memories.\",\n      \"advanced\": true\n    },\n    \"openclawAutoMemoryMaxRecent\": {\n      \"label\": \"Recent Memory Cache Size\",\n      \"help\": \"How many recent extracted memories to keep in the dedupe cache.\",\n      \"advanced\": true\n    },\n    \"interceptor.enabled\": {\n      \"label\": \"Enable Tool Call Interceptor\",\n      \"description\": \"Scan memory-write tool calls and gate suspicious content behind user approval\",\n      \"type\": \"boolean\"\n    },\n    \"interceptor.severityActions.high\": {\n      \"label\": \"High Severity Action\",\n      \"description\": \"Action for high-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    },\n    \"interceptor.severityActions.critical\": {\n      \"label\": \"Critical Severity Action\",\n      \"description\": \"Action for critical-severity threats (log, warn, require_approval)\",\n      \"type\": \"string\"\n    }\n  },\n  \"configSchema\": {\n    \"type\": \"object\",\n    \"additionalProperties\": false,\n    \"properties\": {\n      \"enabled\": {\n        \"type\": \"boolean\"\n      },\n      \"binaryPath\": {\n        \"type\": \"string\"\n      },\n      \"cloudApiKey\": {\n   "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning. Skill: ShieldCortex Owner: jarvis-drakon Summary: Memory and defence for AI agents: semantic recall, knowledge graph and decay, plus a memory firewall that scans and enforces against prompt injection, credential leaks and poisoning. Tags: latest:5.5.0 Version history: v5.5.0 | 2026-10-08T07:03:55.770Z | user Sync from npm publish v5.5.0 v5.4.0 | 2026-10-06T10:48:36.133Z | user Sync from npm publish v5.4.0 v5.3.1 | 20","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1786,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T02:47:05.669Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T02:47:05.669Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T17:49:39.935Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}