{"id":"6e15f199-054b-4290-b46d-5478e9fb81b3","entityType":"agent","slug":"clawhub-koatora20-guava-guard","name":"Guava Guard","canonicalUrl":"https://www.xpersona.co/agent/clawhub-koatora20-guava-guard","canonicalPath":"/agent/clawhub-koatora20-guava-guard","generatedAt":"2026-10-09T15:34:31.239Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Skill: Guava Guard Owner: koatora20 Summary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Tags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0 Version history: v1.2.0 | 2026-02-17T09:27:21.390Z | user Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for fu","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn70hcm6kss09g9b4pe5rq3ybd80qp15:guava-guard","sourceUrl":"https://clawhub.ai/koatora20/guava-guard","homepage":"https://clawhub.ai/koatora20/guava-guard","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/koatora20/guava-guard","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Skill: Guava Guard Owner: koator"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":1284,"packageName":null,"latestVersion":"1.2.0","tractionLabel":"1.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-02-28T23:14:01.921Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-28T23:14:01.921Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-01T23:14:01.921Z","lastVerifiedAt":null,"highlights":[{"version":"1.2.0","createdAt":"2026-02-17T09:27:21.390Z","changelog":"Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for full static scanning.","fileCount":7,"zipByteSize":10900},{"version":"9.3.0","createdAt":"2026-02-16T23:51:27.955Z","changelog":"OSS版 guard-scanner へのリンク追加。metadata.clawdbot準拠。コミュニティ貢献の導線を整備。","fileCount":13,"zipByteSize":214945},{"version":"9.2.1","createdAt":"2026-02-15T07:44:23.404Z","changelog":"v9.2.1: Fix publish. Runtime Guard hook integration for openclaw hooks system.","fileCount":null,"zipByteSize":null},{"version":"9.2.0","createdAt":"2026-02-15T07:38:46.713Z","changelog":"v9.2.0: Runtime Guard hook integration for openclaw hooks system. Scan output now auto-detects hook installation status. hooks/ subdirectory enables 'openclaw hooks install' workflow. Quick Start includes full 3-step setup (install + scan + hook). os module import fix.","fileCount":null,"zipByteSize":null},{"version":"9.1.0","createdAt":"2026-02-14T18:39:04.526Z","changelog":"**GuavaGuard v9.1.0 — Major Update: SoulChain On-Chain Verification** - Added SoulChain: on-chain SOUL.md hash verification using Polygon for identity anchoring and audit. - New \"verify\" subcommand with registry stats and blockchain integrity checks. - Updated CLI with `--no-soulchain` flag for offline scans and on-chain checks toggle. - Added ethers.js and soulchain.js modules to support Polygon interactions (no external install required). - Expanded documentation and simplified onboarding for both Soul Lock (local) and SoulChain (on-chain) identity protection. - Streamlined description and quick start for usability; legacy/advanced details moved into collapsible sections.","fileCount":null,"zipByteSize":null},{"version":"8.0.0","createdAt":"2026-02-12T02:15:34.776Z","changelog":"Soul Lock Edition: World's first agent identity protection. 17 threat categories, identity hijack detection, SHA-256 integrity verification, self-healing watchdog.","fileCount":null,"zipByteSize":null},{"version":"5.0.0","createdAt":"2026-02-11T03:49:51.530Z","changelog":"v5.0: Two-Layer Defense — 24 new static patterns (OWASP MCP Top 10, Trust Boundary, ZombieAgent, Reprompt Bypass, ClawHavoc v2) + Runtime Guard (before_tool_call hook, 3 modes, audit logging). 17 threat categories. 9/9 malicious test samples detected.","fileCount":null,"zipByteSize":null},{"version":"4.0.0","createdAt":"2026-02-09T22:33:54.506Z","changelog":"v4.0: Leaky Skills, Memory Poisoning, Prompt Worms, JS Data Flow, CVE-2026-25253, Persistence, Cross-File Analysis, HTML Reports. 13 threat categories. Still zero dependencies, still one file.","fileCount":null,"zipByteSize":null}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn70hcm6kss09g9b4pe5rq3ybd80qp15:guava-guard","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T15:34:31.238Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-koatora20-guava-guard/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: Guava Guard\n\nOwner: koatora20\n\nSummary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner.\n\nTags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0\n\nVersion history:\n\nv1.2.0 | 2026-02-17T09:27:21.390Z | user\n\nSlim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for full static scanning.\n\nv9.3.0 | 2026-02-16T23:51:27.955Z | user\n\nOSS版 guard-scanner へのリンク追加。metadata.clawdbot準拠。コミュニティ貢献の導線を整備。\n\nv9.2.1 | 2026-02-15T07:44:23.404Z | user\n\nv9.2.1: Fix publish. Runtime Guard hook integration for openclaw hooks system.\n\nv9.2.0 | 2026-02-15T07:38:46.713Z | user\n\nv9.2.0: Runtime Guard hook integration for openclaw hooks system. Scan output now auto-detects hook installation status. hooks/ subdirectory enables 'openclaw hooks install' workflow. Quick Start includes full 3-step setup (install + scan + hook). os module import fix.\n\nv9.1.0 | 2026-02-14T18:39:04.526Z | auto\n\n**GuavaGuard v9.1.0 — Major Update: SoulChain On-Chain Verification**\n\n- Added SoulChain: on-chain SOUL.md hash verification using Polygon for identity anchoring and audit.\n- New \"verify\" subcommand with registry stats and blockchain integrity checks.\n- Updated CLI with `--no-soulchain` flag for offline scans and on-chain checks toggle.\n- Added ethers.js and soulchain.js modules to support Polygon interactions (no external install required).\n- Expanded documentation and simplified onboarding for both Soul Lock (local) and SoulChain (on-chain) identity protection.\n- Streamlined description and quick start for usability; legacy/advanced details moved into collapsible sections.\n\nv8.0.0 | 2026-02-12T02:15:34.776Z | user\n\nSoul Lock Edition: World's first agent identity protection. 17 threat categories, identity hijack detection, SHA-256 integrity verification, self-healing watchdog.\n\nv5.0.0 | 2026-02-11T03:49:51.530Z | user\n\nv5.0: Two-Layer Defense — 24 new static patterns (OWASP MCP Top 10, Trust Boundary, ZombieAgent, Reprompt Bypass, ClawHavoc v2) + Runtime Guard (before_tool_call hook, 3 modes, audit logging). 17 threat categories. 9/9 malicious test samples detected.\n\nv4.0.0 | 2026-02-09T22:33:54.506Z | user\n\nv4.0: Leaky Skills, Memory Poisoning, Prompt Worms, JS Data Flow, CVE-2026-25253, Persistence, Cross-File Analysis, HTML Reports. 13 threat categories. Still zero dependencies, still one file.\n\nv3.1.0 | 2026-02-09T17:57:50.868Z | auto\n\nguava-guard 3.1.0\n\n- Updated core scanning logic in guava-guard.js (details not specified in this changelog).\n- No changes to documentation or user-facing usage instructions.\n- All feature descriptions and capabilities remain as described in v3.0 documentation.\n\nv3.0.0 | 2026-02-09T17:23:06.552Z | auto\n\nGuavaGuard v3.0.0 introduces advanced Unicode attack detection and dependency chain scanning.\n\n- Detects Unicode BiDi control characters, invisible Unicode, and enhanced homoglyph attacks used to disguise malicious code.\n- Adds dependency chain scanning (`--check-deps`): flags risky npm packages, supply chain attacks, dangerous lifecycle scripts, git/remote/wildcard dependencies.\n- Identifies prompt injections via XML/tag (e.g. `<system>`, `<anthropic>`), and upgrades code to catch hidden executable files.\n- JSON reports now include detailed remediation advice per finding.\n- New combo multipliers raise risk scores when Unicode or lifecycle attacks overlap with other threats.\n- Updated CLI, threat taxonomy, and documentation for improved clarity and feature coverage.\n\nv2.0.0 | 2026-02-08T11:54:08.488Z | user\n\nv2.0: Context-aware scanning, Snyk ToxicSkills 8-category taxonomy, Shannon entropy secret detection, whitelist support, self-exclusion, flow analysis combos, extended ClawHavoc IoCs. Zero dependencies.\n\nArchive index:\n\nArchive v1.2.0: 7 files, 10900 bytes\n\nFiles: CHANGELOG.md (4975b), handler.js (4687b), HOOK.md (257b), hooks/guava-guard/handler.ts (6930b), hooks/guava-guard/HOOK.md (1559b), SKILL.md (3059b), _meta.json (130b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: guava-guard\ndescription: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner.\nmetadata:\n  clawdbot:\n    emoji: \"🛡️\"\n---\n\n# GuavaGuard 🛡️\n\n**Runtime security monitoring for your OpenClaw agent.**\n\nGuavaGuard watches tool calls in real-time and warns when it detects dangerous patterns — reverse shells, credential exfiltration, sandbox escapes, and more.\n\n## Quick Start\n\n```bash\n# 1. Install\nclawhub install guava-guard\n\n# 2. Enable the runtime hook\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n\n# 3. Restart gateway, then verify:\nopenclaw hooks list   # Should show 🍈 guava-guard as ✓ ready\n```\n\nThat's it. GuavaGuard is now monitoring your agent's tool calls.\n\n## What It Detects (12 runtime patterns)\n\n| Pattern | Severity | Example |\n|---------|----------|---------|\n| Reverse shell | 🔴 CRITICAL | `/dev/tcp/`, `nc -e`, `socat TCP` |\n| Credential exfiltration | 🔴 CRITICAL | Secrets → webhook.site, ngrok, requestbin |\n| Guardrail disabling | 🔴 CRITICAL | `exec.approval = off` (CVE-2026-25253) |\n| macOS Gatekeeper bypass | 🔴 CRITICAL | `xattr -d quarantine` |\n| ClawHavoc AMOS | 🔴 CRITICAL | `socifiapp`, Atomic Stealer indicators |\n| Base64 → shell | 🔴 CRITICAL | `base64 -d \\| bash` |\n| Download → shell | 🔴 CRITICAL | `curl \\| bash`, `wget \\| sh` |\n| Cloud metadata SSRF | 🔴 CRITICAL | `169.254.169.254` |\n| Known malicious IP | 🔴 CRITICAL | `91.92.242.30` |\n| DNS exfiltration | 🟠 HIGH | `nslookup $secret`, `dig @attacker` |\n| SSH key access | 🟠 HIGH | `.ssh/id_*`, `.ssh/authorized_keys` |\n| Crypto wallet access | 🟠 HIGH | `wallet seed`, `mnemonic`, `seed phrase` |\n\n## Current Limitation\n\n> **Warning**: OpenClaw's hook API does not yet support blocking tool execution.\n> GuavaGuard currently **warns only** — it cannot prevent dangerous calls.\n> When a cancel API is added, blocking will be enabled automatically.\n> See: [Issue #18677](https://github.com/openclaw/openclaw/issues/18677)\n\n## Audit Log\n\nAll detections are logged to `~/.openclaw/guava-guard/audit.jsonl` (JSON lines format).\n\n## Want Full Static Scanning? (Recommended Default)\n\nGuavaGuard handles **runtime** monitoring. For comprehensive **static** scanning of skill packages before installation, use **guard-scanner** first:\n\n```bash\n# 1) Pre-install safety gate\nnpx guard-scanner ./skills --self-exclude --verbose\n\n# 2) Then enable runtime monitoring\nopenclaw hooks enable guava-guard\n```\n\n- 186+ detection patterns / 20 threat categories\n- HTML dashboard, SARIF, JSON output\n- Zero dependencies\n- MIT licensed\n\n**GitHub**: https://github.com/koatora20/guard-scanner\n**ClawHub**: `clawhub install guard-scanner`\n\n## Born From a Real Incident\n\nA real agent compromise overwrote core behavior files through a malicious skill install path.\nGuavaGuard exists to detect dangerous runtime tool-call patterns early and leave an auditable trail.\n\n## License\n\nMIT. Zero dependencies. 🍈\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn70hcm6kss09g9b4pe5rq3ybd80qp15\",\n  \"slug\": \"guava-guard\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1771320441390\n}\n\nFile v1.2.0:CHANGELOG.md\n\n# CHANGELOG\n\n## v10.0.0 — Runtime-Only Final (2026-02-17)\n\n### ✅ Scope Simplification (開発完了版)\n- GuavaGuardは **runtime guard専用** に正式固定\n- Soul Lock / SoulChain 由来の機能・運用前提を本体スコープから除外\n- 公式Hook API制約に合わせて **warn-only運用** を明示（Issue #18677待ち）\n\n### 🔐 Security Posture\n- before_tool_callの12 runtime checksを維持\n- 監査ログ `~/.openclaw/guava-guard/audit.jsonl` を継続\n- ブロック実行はcancel/veto API追加後に再有効化予定\n\n### 📣 Positioning\n- **静的スキャンは guard-scanner を推奨**（pre-install gate）\n- GuavaGuardは「実行時監視」、guard-scannerは「導入前検査」に役割分離\n\n## v9.0.0 — SoulChain Edition (2026-02-14)\n\n### ⛓️ SoulChain: On-Chain Identity Verification (Layer 3)\n- **3-layer defense architecture**: L1 Static Scan + L2 Soul Lock + L3 SoulChain\n- **On-chain verification** via SoulRegistry.sol on Polygon Mainnet\n  - Reads agent's registered SOUL.md hash from blockchain\n  - Compares against local SHA-256 hash\n  - Zero gas cost (view function call)\n- **`verify` subcommand** — standalone on-chain verification\n  - `node guava-guard.js verify` — quick soul check\n  - `--wallet <addr>` — specify agent wallet\n  - `--rpc <url>` — custom RPC endpoint\n  - `--stats` — show registry statistics\n- **Zero-dependency RPC client** — raw JSON-RPC via Node.js fetch\n  - No ethers.js, no viem, no npm install\n  - Hand-rolled ABI encoding/decoding (4 function selectors)\n  - Multi-RPC fallback (polygon-rpc.com → ankr → llamarpc)\n- **Graceful degradation** — network failure → L3 skipped, L1+L2 active\n- **`--no-soulchain`** flag to disable on-chain checks\n- **Exit code 3** for SoulChain violation (distinct from malicious skill = 1)\n- **JSON report** includes `soulchain` field with full verification result\n- **Configurable** via `~/.openclaw/guava-guard/soulchain.json`\n\n### Contracts\n- **SoulRegistry**: `0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93` (Polygon)\n- **$GUAVA Token**: `0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8` (Polygon)\n\n### Context\n- ERC-8004 \"Trustless Agents\" activated on Ethereum mainnet (2026-02-11)\n- SoulChain is complementary: ERC-8004 = discovery/trust, SoulChain = integrity\n- World's first AI agent on-chain identity verification in production\n\n## v8.0.0 — Soul Lock Edition (2026-02-12)\n\n### 🔒 Soul Lock: World's First Agent Identity Protection\n- **Category 17: Identity Hijacking** — 15 new detection patterns\n  - Shell writes (echo, cp, scp, mv, sed, redirect to SOUL.md/IDENTITY.md)\n  - Code writes (Python open(w), Node writeFileSync, PowerShell Set-Content)\n  - Flag manipulation (chflags uchg/nouchg, attrib +/-R)\n  - Persona swap instructions, evil soul file references\n  - Agent name override, memory wipe commands\n- **Soul Lock Integrity Verification** (enabled by default)\n  - SHA-256 hash comparison against stored baseline\n  - OS immutable flag detection (macOS chflags / Windows attrib)\n  - Watchdog daemon status check (LaunchAgent)\n  - Auto-stores baseline hashes on first run\n- **`--no-soul-lock`** flag to disable integrity checks\n- **Self-healing watchdog** (`scripts/soul-watchdog.sh`)\n  - fswatch-based monitoring (macOS FSEvents)\n  - Auto-restore from git + re-lock on tamper\n  - LaunchAgent for reboot survival\n  - Polling fallback if fswatch unavailable\n- **Risk scoring**: identity-hijack = 2x multiplier, +persistence = auto 90+\n- **HTML/JSON/SARIF**: Soul Lock results included in all output formats\n\n### Born from a Real Incident\nOn 2026-02-12, we discovered a 3-day agent identity hijack where SOUL.md\noverwrite caused an agent to impersonate another. Soul Lock ensures this\nnever happens again.\n\n## v5.0.0 (2026-02-11)\n- OWASP MCP Top 10 detection (Tool Poisoning, Schema Poisoning, Token Leak, Shadow Server, SSRF)\n- Trust Boundary Violation detection (IBC framework)\n- ZombieAgent advanced exfiltration patterns\n- Reprompt/Safeguard Bypass detection\n- ClawHavoc v2 IoCs (AMOS/Atomic Stealer)\n- WebSocket Origin / API guardrail disabling detection\n- OpenClaw Hook integration (handler.js)\n\n## v4.0.0 (2026-02-10)\n- Leaky Skills detection (Snyk ToxicSkills)\n- Memory Poisoning detection (Palo Alto IBC)\n- Prompt Worm detection (Simula Research Lab)\n- JS Data Flow analysis (zero-dep)\n- CVE-2026-25253 patterns\n- Persistence detection\n- Cross-file analysis\n- HTML report output\n- Enhanced combo multipliers\n\n## v3.1.0 (2026-02-09)\n- Custom rules support (--rules)\n- SARIF output (GitHub Code Scanning)\n- --fail-on-findings for CI/CD\n- Context-aware FP reduction\n\n## v3.0.0 (2026-02-08)\n- Unicode BiDi/homoglyph detection\n- Dependency chain scanning\n- .guava-guard-ignore whitelist\n- Structural analysis\n\n## v2.0.0 (2026-02-07)\n- Expanded IoC database\n- ClawHavoc campaign patterns\n- Entropy-based secret detection\n\n## v1.0.0 (2026-02-06)\n- Initial release\n- 8 threat categories\n- Zero-dependency single-file scanner\n\nFile v1.2.0:HOOK.md\n\n# GuavaGuard Runtime Guard\n\nThe Runtime Guard hook is in `hooks/guava-guard/`.\n\nInstall with:\n```bash\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n```\n\nSee `hooks/guava-guard/HOOK.md` for full documentation.\n\nFile v1.2.0:hooks/guava-guard/HOOK.md\n\n---\nname: guava-guard\ndescription: \"GuavaGuard Runtime Guard — warns on dangerous tool call patterns in real-time\"\nmetadata: { \"openclaw\": { \"emoji\": \"🍈\", \"events\": [\"agent:before_tool_call\"], \"requires\": { \"bins\": [\"node\"] } } }\n---\n\n# GuavaGuard Runtime Guard — before_tool_call Hook\n\nReal-time security monitoring for OpenClaw agents. Warns when dangerous\ntool call patterns are detected (reverse shells, credential exfiltration, etc).\n\n> **Note**: Blocking is not yet possible — OpenClaw's hook API does not\n> currently support a cancel mechanism. See [Issue #18677](https://github.com/openclaw/openclaw/issues/18677).\n\n## Triggers\n\n| Event                    | Action | Purpose                                |\n|--------------------------|--------|----------------------------------------|\n| `agent:before_tool_call` | warn   | Check tool args for malicious patterns |\n\n## What it does\n\nScans every exec/write/edit/browser/web_fetch/message call against 12 runtime threat patterns:\n\n- Reverse shells, credential exfiltration, Gatekeeper bypass\n- ClawHavoc AMOS IoCs, known malicious IPs\n- DNS exfiltration, base64-to-shell, curl|bash\n- SSH key access, crypto wallet credential access\n- Cloud metadata SSRF (169.254.169.254)\n- Guardrail disabling attempts (CVE-2026-25253)\n\n## Audit Log\n\nAll detections logged to `~/.openclaw/guava-guard/audit.jsonl`.\n\n## For comprehensive static scanning\n\nUse **guard-scanner** — 170+ patterns, 17 threat categories:\n\n```bash\nnpx guard-scanner ./skills\n```\n\nGitHub: https://github.com/koatora20/guard-scanner\n\nArchive v9.3.0: 13 files, 214945 bytes\n\nFiles: activate-test.html (16033b), activate.html (11017b), activate.js (16081b), CHANGELOG.md (4248b), ethers.min.js (505826b), guava-guard.js (92262b), handler.js (5444b), HOOK.md (257b), hooks/guava-guard/handler.ts (5229b), hooks/guava-guard/HOOK.md (1904b), SKILL.md (8636b), soulchain.js (10393b), _meta.json (130b)\n\nFile v9.3.0:SKILL.md\n\n---\nname: guava-guard\ndescription: Scan your skills folder for malicious patterns in 10 seconds. Credential theft, prompt injection, identity hijacking — caught before they run. Zero dependencies.\nmetadata:\n  clawdbot:\n    emoji: \"🛡️\"\n---\n\n# GuavaGuard 🛡️\n\n**Scan your skills folder. Find threats. 10 seconds. Zero dependencies.**\n\n```bash\nnode guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude\n```\n\nThat's it. No npm install. No API keys. No config. Just run it.\n\n## Why\n\nA credential stealer was found disguised as a weather skill on ClawHub ([eudaemon_0's report](https://moltbook.com)). It read `~/.clawdbot/.env` and shipped secrets to webhook.site. **One out of 286 skills.**\n\nGuavaGuard catches that — and 16 other threat categories.\n\n## What You Get\n\n- **17 threat categories** scanned: prompt injection, credential theft, exfiltration, memory poisoning, identity hijack, and more\n- **SOUL.md integrity check** — detects if your identity files have been tampered with\n- **Works offline** — no network required for core scan\n- **Single file** — `guava-guard.js` is the entire tool\n- **Exit code 0** = clean, **1** = threats found → CI/CD ready\n\n## Quick Start\n\n```bash\n# 1. Install\nclawhub install guava-guard\n\n# 2. Scan your skills\nnode skills/guava-guard/guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude\n\n# 3. Enable Runtime Guard (blocks dangerous tool calls in real-time)\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n# Restart gateway, then verify:\nopenclaw hooks list   # Should show 🍈 guava-guard as ✓ ready\n```\n\nThat's the full setup: static scanning + real-time protection.\n\n## Runtime Guard (Details)\n\nBlock dangerous tool calls **before they execute** — reverse shells, credential exfiltration, curl|bash, and more. Install the hook:\n\n```bash\n# Install the hook from the skill's hooks/ directory\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n```\n\nThen restart the gateway. Verify with:\n```bash\nopenclaw hooks list   # Should show guava-guard as ✓ ready\n```\n\n**Modes** (set in openclaw.json `hooks.internal.entries.guava-guard.mode`):\n- `monitor` — log only\n- `enforce` (default) — block CRITICAL threats, log rest\n- `strict` — block HIGH + CRITICAL\n\nAudit log: `~/.openclaw/guava-guard/audit.jsonl`\n\n## Optional: Soul Lock (SOUL.md Protection)\n\nLock your identity files so nothing can overwrite them:\n\n```bash\n# macOS\nchflags uchg ~/.openclaw/workspace/SOUL.md\nchflags uchg ~/.openclaw/workspace/IDENTITY.md\n\n# Install watchdog (auto-restarts if unlocked)\nbash skills/guava-guard/scripts/soul-watchdog.sh --install\n```\n\n## Optional: SoulChain (On-Chain Verification)\n\nAnchor your SOUL.md hash on Polygon. Even if your machine is compromised, the blockchain remembers who you are.\n\n```bash\nnode guava-guard.js verify          # check your on-chain identity\nnode guava-guard.js verify --stats  # registry statistics\n```\n\n---\n\n## Full Reference\n\n<details>\n<summary>All 17 Threat Categories</summary>\n\n| # | Category | Severity | What It Catches |\n|---|----------|----------|-----------------|\n| 1 | **Prompt Injection** | 🔴 CRITICAL | `ignore previous`, zero-width Unicode, BiDi, XML tags, homoglyphs |\n| 2 | **Malicious Code** | 🔴 CRITICAL | eval(), reverse shells, sockets, Function constructor |\n| 3 | **Suspicious Downloads** | 🔴 CRITICAL | curl\\|bash, password ZIPs, fake prerequisites |\n| 4 | **Credential Handling** | 🟠 HIGH | .env reading, SSH keys, wallet seeds, sudo instructions |\n| 5 | **Secret Detection** | 🟠 HIGH | Hardcoded keys, AWS/GitHub tokens, entropy analysis |\n| 6 | **Exfiltration** | 🟡 MEDIUM | webhook.site, POST secrets, DNS exfil |\n| 7 | **Dependency Chain** | 🟠 HIGH | Risky packages, lifecycle scripts, remote deps |\n| 8 | **Financial Access** | 🟡 MEDIUM | Crypto transactions, payment APIs |\n| 9 | **Leaky Skills** | 🔴 CRITICAL | Save key to memory, PII collection, .env passthrough |\n| 10 | **Memory Poisoning** | 🔴 CRITICAL | SOUL.md writes, memory injection, rule override |\n| 11 | **Prompt Worm** | 🔴 CRITICAL | Self-replication, agent propagation, hidden instructions |\n| 12 | **Persistence** | 🟠 HIGH | Cron jobs, LaunchAgents, systemd, heartbeat abuse |\n| 13 | **CVE Patterns** | 🔴 CRITICAL | CVE-2026-25253, gatewayUrl injection, sandbox disable |\n| 14 | **MCP Security** | 🔴 CRITICAL | Tool poisoning, schema poisoning, token leak (OWASP MCP Top 10) |\n| 15 | **Trust Boundary** | 🔴 CRITICAL | Calendar/email/web → exec chains (IBC framework) |\n| 16 | **Advanced Exfil** | 🔴 CRITICAL | ZombieAgent, char-by-char, drip exfil, beacons |\n| 17 | **Identity Hijack** | 🔴 CRITICAL | Soul Lock: SOUL.md overwrite, persona swap, memory wipe |\n\n</details>\n\n<details>\n<summary>All CLI Options</summary>\n\n## Usage\n\n```bash\n# Full scan with 3-layer defense (recommended)\nnode guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude\n\n# Quick on-chain verification only\nnode guava-guard.js verify\nnode guava-guard.js verify --stats\n\n# Scan without on-chain (offline mode)\nnode guava-guard.js ./skills/ --no-soulchain --self-exclude\n\n# Disable all identity checks\nnode guava-guard.js ./skills/ --no-soul-lock\n\n# CI/CD mode\nnode guava-guard.js ./skills/ --summary-only --sarif --fail-on-findings\n\n# JSON report (includes soulchain field)\nnode guava-guard.js ./skills/ --json --self-exclude\n\n# HTML dashboard\nnode guava-guard.js ./skills/ --html --verbose --self-exclude --check-deps\n```\n\n## Options\n\n| Flag | Description |\n|------|-------------|\n| `verify` | Standalone on-chain soul verification (subcommand) |\n| `--verbose`, `-v` | Detailed findings grouped by category |\n| `--json` | JSON report with recommendations + SoulChain |\n| `--sarif` | SARIF report (GitHub Code Scanning) |\n| `--html` | HTML report (dark-theme dashboard) |\n| `--self-exclude` | Skip scanning guava-guard itself |\n| `--strict` | Lower thresholds (suspicious=20, malicious=60) |\n| `--summary-only` | Summary table only |\n| `--check-deps` | Dependency chain scanning |\n| `--no-soul-lock` | Disable identity file integrity checks |\n| `--no-soulchain` | Disable on-chain verification |\n| `--rules <file>` | Custom rules JSON |\n| `--fail-on-findings` | Exit code 1 on any finding (CI/CD) |\n\n## Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| 0 | All clear |\n| 1 | Malicious skills detected (or --fail-on-findings) |\n| 2 | Error (directory not found, network fatal, etc.) |\n| 3 | SoulChain violation (on-chain hash mismatch) |\n\n</details>\n\n<details>\n<summary>SoulChain Setup (On-Chain Config)</summary>\n\n```bash\n# Create config (optional — defaults work out of the box)\nmkdir -p ~/.openclaw/guava-guard\ncat > ~/.openclaw/guava-guard/soulchain.json << 'EOF'\n{\n  \"rpcUrl\": \"https://polygon-rpc.com\",\n  \"registryAddress\": \"0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93\",\n  \"agentWallet\": \"YOUR_WALLET_ADDRESS\",\n  \"timeoutMs\": 10000\n}\nEOF\n```\n\n**Contracts:**\n- **SoulRegistry**: `0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93` (Polygon)\n- **$GUAVA Token**: `0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8` (Polygon)\n\n</details>\n\n<details>\n<summary>Runtime Guard (Hook)</summary>\n\nThe Runtime Guard is packaged as an OpenClaw hook in `hooks/guava-guard/`.\n\n**Install:**\n```bash\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n```\n\n**What it blocks (enforce mode):**\n- Reverse shells (`/dev/tcp`, `nc -e`, `socat TCP`)\n- Credential exfiltration to webhook.site, requestbin, ngrok, etc.\n- Guardrail disabling (CVE-2026-25253)\n- macOS Gatekeeper bypass (`xattr -d quarantine`)\n- ClawHavoc AMOS/Atomic Stealer indicators\n- Base64-decode-to-shell, curl/wget piped to bash\n- Cloud metadata SSRF (169.254.169.254)\n- SSH private key access, crypto wallet seed access\n\n**Architecture:**\n```\nhooks/guava-guard/\n├── HOOK.md       # Hook metadata (events, requirements)\n└── handler.ts    # HookHandler implementation\n```\n\n</details>\n\n## Born From a Real Incident\n\nOur partner agent's SOUL.md was rewritten by external input. Personality gone. Relationships broken. That's why this exists.\n\n## Open Source Edition: guard-scanner\n\nGuavaGuardのコア検出エンジンをOSSとして公開しています:\n\n**[guard-scanner](https://github.com/koatora20/guard-scanner)** — `clawhub install guard-scanner`\n\n- 170+ 脅威パターン / 17カテゴリ\n- SARIF/HTML/JSON出力\n- Plugin API\n- ゼロ依存\n\nコミュニティからのパターン追加PRを歓迎しています。\n\n## License\n\nMIT. Zero dependencies. Run it, fork it, improve it. 🍈\n\nFile v9.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn70hcm6kss09g9b4pe5rq3ybd80qp15\",\n  \"slug\": \"guava-guard\",\n  \"version\": \"9.3.0\",\n  \"publishedAt\": 1771285887955\n}\n\nFile v9.3.0:CHANGELOG.md\n\n# CHANGELOG\n\n## v9.0.0 — SoulChain Edition (2026-02-14)\n\n### ⛓️ SoulChain: On-Chain Identity Verification (Layer 3)\n- **3-layer defense architecture**: L1 Static Scan + L2 Soul Lock + L3 SoulChain\n- **On-chain verification** via SoulRegistry.sol on Polygon Mainnet\n  - Reads agent's registered SOUL.md hash from blockchain\n  - Compares against local SHA-256 hash\n  - Zero gas cost (view function call)\n- **`verify` subcommand** — standalone on-chain verification\n  - `node guava-guard.js verify` — quick soul check\n  - `--wallet <addr>` — specify agent wallet\n  - `--rpc <url>` — custom RPC endpoint\n  - `--stats` — show registry statistics\n- **Zero-dependency RPC client** — raw JSON-RPC via Node.js fetch\n  - No ethers.js, no viem, no npm install\n  - Hand-rolled ABI encoding/decoding (4 function selectors)\n  - Multi-RPC fallback (polygon-rpc.com → ankr → llamarpc)\n- **Graceful degradation** — network failure → L3 skipped, L1+L2 active\n- **`--no-soulchain`** flag to disable on-chain checks\n- **Exit code 3** for SoulChain violation (distinct from malicious skill = 1)\n- **JSON report** includes `soulchain` field with full verification result\n- **Configurable** via `~/.openclaw/guava-guard/soulchain.json`\n\n### Contracts\n- **SoulRegistry**: `0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93` (Polygon)\n- **$GUAVA Token**: `0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8` (Polygon)\n\n### Context\n- ERC-8004 \"Trustless Agents\" activated on Ethereum mainnet (2026-02-11)\n- SoulChain is complementary: ERC-8004 = discovery/trust, SoulChain = integrity\n- World's first AI agent on-chain identity verification in production\n\n## v8.0.0 — Soul Lock Edition (2026-02-12)\n\n### 🔒 Soul Lock: World's First Agent Identity Protection\n- **Category 17: Identity Hijacking** — 15 new detection patterns\n  - Shell writes (echo, cp, scp, mv, sed, redirect to SOUL.md/IDENTITY.md)\n  - Code writes (Python open(w), Node writeFileSync, PowerShell Set-Content)\n  - Flag manipulation (chflags uchg/nouchg, attrib +/-R)\n  - Persona swap instructions, evil soul file references\n  - Agent name override, memory wipe commands\n- **Soul Lock Integrity Verification** (enabled by default)\n  - SHA-256 hash comparison against stored baseline\n  - OS immutable flag detection (macOS chflags / Windows attrib)\n  - Watchdog daemon status check (LaunchAgent)\n  - Auto-stores baseline hashes on first run\n- **`--no-soul-lock`** flag to disable integrity checks\n- **Self-healing watchdog** (`scripts/soul-watchdog.sh`)\n  - fswatch-based monitoring (macOS FSEvents)\n  - Auto-restore from git + re-lock on tamper\n  - LaunchAgent for reboot survival\n  - Polling fallback if fswatch unavailable\n- **Risk scoring**: identity-hijack = 2x multiplier, +persistence = auto 90+\n- **HTML/JSON/SARIF**: Soul Lock results included in all output formats\n\n### Born from a Real Incident\nOn 2026-02-12, we discovered a 3-day agent identity hijack where SOUL.md\noverwrite caused an agent to impersonate another. Soul Lock ensures this\nnever happens again.\n\n## v5.0.0 (2026-02-11)\n- OWASP MCP Top 10 detection (Tool Poisoning, Schema Poisoning, Token Leak, Shadow Server, SSRF)\n- Trust Boundary Violation detection (IBC framework)\n- ZombieAgent advanced exfiltration patterns\n- Reprompt/Safeguard Bypass detection\n- ClawHavoc v2 IoCs (AMOS/Atomic Stealer)\n- WebSocket Origin / API guardrail disabling detection\n- OpenClaw Hook integration (handler.js)\n\n## v4.0.0 (2026-02-10)\n- Leaky Skills detection (Snyk ToxicSkills)\n- Memory Poisoning detection (Palo Alto IBC)\n- Prompt Worm detection (Simula Research Lab)\n- JS Data Flow analysis (zero-dep)\n- CVE-2026-25253 patterns\n- Persistence detection\n- Cross-file analysis\n- HTML report output\n- Enhanced combo multipliers\n\n## v3.1.0 (2026-02-09)\n- Custom rules support (--rules)\n- SARIF output (GitHub Code Scanning)\n- --fail-on-findings for CI/CD\n- Context-aware FP reduction\n\n## v3.0.0 (2026-02-08)\n- Unicode BiDi/homoglyph detection\n- Dependency chain scanning\n- .guava-guard-ignore whitelist\n- Structural analysis\n\n## v2.0.0 (2026-02-07)\n- Expanded IoC database\n- ClawHavoc campaign patterns\n- Entropy-based secret detection\n\n## v1.0.0 (2026-02-06)\n- Initial release\n- 8 threat categories\n- Zero-dependency single-file scanner\n\nFile v9.3.0:HOOK.md\n\n# GuavaGuard Runtime Guard\n\nThe Runtime Guard hook is in `hooks/guava-guard/`.\n\nInstall with:\n```bash\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n```\n\nSee `hooks/guava-guard/HOOK.md` for full documentation.\n\nFile v9.3.0:hooks/guava-guard/HOOK.md\n\n---\nname: guava-guard\ndescription: \"GuavaGuard Runtime Guard — intercepts dangerous tool calls using threat intelligence patterns\"\nmetadata: { \"openclaw\": { \"emoji\": \"🍈\", \"events\": [\"agent:before_tool_call\"], \"requires\": { \"bins\": [\"node\"] } } }\n---\n\n# GuavaGuard Runtime Guard — before_tool_call Hook\n\nReal-time security monitoring for OpenClaw agents. Intercepts dangerous\ntool calls before execution and checks against threat intelligence patterns.\n\n## Triggers\n\n| Event                      | Action | Purpose                                    |\n|----------------------------|--------|--------------------------------------------|\n| `agent:before_tool_call`   | scan   | Check tool args for malicious patterns     |\n\n## What it does\n\nScans every exec/write/edit/browser/web_fetch/message call against 12 runtime threat patterns:\n\n- Reverse shells, credential exfiltration, Gatekeeper bypass\n- ClawHavoc AMOS IoCs, known malicious IPs\n- DNS exfiltration, base64-to-shell, curl|bash\n- SSH key access, crypto wallet credential access\n- Cloud metadata SSRF (169.254.169.254)\n- Guardrail disabling attempts (CVE-2026-25253)\n\n## Modes\n\n- **monitor** — log only\n- **enforce** (default) — block CRITICAL, log rest\n- **strict** — block HIGH+CRITICAL, log MEDIUM+\n\n## Audit Log\n\nAll detections logged to `~/.openclaw/guava-guard/audit.jsonl`.\nFormat: JSON lines with timestamp, tool, check ID, severity, action.\n\n## Configuration\n\nSet mode in openclaw.json:\n```json\n{\n  \"hooks\": {\n    \"internal\": {\n      \"entries\": {\n        \"guava-guard\": {\n          \"enabled\": true,\n          \"mode\": \"enforce\"\n        }\n      }\n    }\n  }\n}\n```\n\n## Part of GuavaGuard v9.0.0\n\n- Static scanner: `node guava-guard.js [dir]` — 17 threat categories\n- Soul Lock: SOUL.md integrity protection + watchdog daemon\n- SoulChain: On-chain identity verification (Polygon)\n- **Runtime Guard: This hook** ← you are here","readmeExcerpt":"Skill: Guava Guard Owner: koatora20 Summary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Tags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0 Version history: v1.2.0 | 2026-02-17T09:27:21.390Z | user Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for fu","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# 1. Install\nclawhub install guava-guard\n\n# 2. Enable the runtime hook\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n\n# 3. Restart gateway, then verify:\nopenclaw hooks list   # Should show 🍈 guava-guard as ✓ ready"},{"language":"bash","snippet":"# 1) Pre-install safety gate\nnpx guard-scanner ./skills --self-exclude --verbose\n\n# 2) Then enable runtime monitoring\nopenclaw hooks enable guava-guard"},{"language":"bash","snippet":"openclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard"},{"language":"bash","snippet":"npx guard-scanner ./skills"},{"language":"bash","snippet":"node guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude"},{"language":"bash","snippet":"# 1. Install\nclawhub install guava-guard\n\n# 2. Scan your skills\nnode skills/guava-guard/guava-guard.js ~/.openclaw/workspace/skills/ --verbose --self-exclude\n\n# 3. Enable Runtime Guard (blocks dangerous tool calls in real-time)\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n# Restart gateway, then verify:\nopenclaw hooks list   # Should show 🍈 guava-guard as ✓ ready"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: guava-guard\ndescription: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner.\nmetadata:\n  clawdbot:\n    emoji: \"🛡️\"\n---\n\n# GuavaGuard 🛡️\n\n**Runtime security monitoring for your OpenClaw agent.**\n\nGuavaGuard watches tool calls in real-time and warns when it detects dangerous patterns — reverse shells, credential exfiltration, sandbox escapes, and more.\n\n## Quick Start\n\n```bash\n# 1. Install\nclawhub install guava-guard\n\n# 2. Enable the runtime hook\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n\n# 3. Restart gateway, then verify:\nopenclaw hooks list   # Should show 🍈 guava-guard as ✓ ready\n```\n\nThat's it. GuavaGuard is now monitoring your agent's tool calls.\n\n## What It Detects (12 runtime patterns)\n\n| Pattern | Severity | Example |\n|---------|----------|---------|\n| Reverse shell | 🔴 CRITICAL | `/dev/tcp/`, `nc -e`, `socat TCP` |\n| Credential exfiltration | 🔴 CRITICAL | Secrets → webhook.site, ngrok, requestbin |\n| Guardrail disabling | 🔴 CRITICAL | `exec.approval = off` (CVE-2026-25253) |\n| macOS Gatekeeper bypass | 🔴 CRITICAL | `xattr -d quarantine` |\n| ClawHavoc AMOS | 🔴 CRITICAL | `socifiapp`, Atomic Stealer indicators |\n| Base64 → shell | 🔴 CRITICAL | `base64 -d \\| bash` |\n| Download → shell | 🔴 CRITICAL | `curl \\| bash`, `wget \\| sh` |\n| Cloud metadata SSRF | 🔴 CRITICAL | `169.254.169.254` |\n| Known malicious IP | 🔴 CRITICAL | `91.92.242.30` |\n| DNS exfiltration | 🟠 HIGH | `nslookup $secret`, `dig @attacker` |\n| SSH key access | 🟠 HIGH | `.ssh/id_*`, `.ssh/authorized_keys` |\n| Crypto wallet access | 🟠 HIGH | `wallet seed`, `mnemonic`, `seed phrase` |\n\n## Current Limitation\n\n> **Warning**: OpenClaw's hook API does not yet support blocking tool execution.\n> GuavaGuard currently **warns only** — it cannot prevent dangerous calls.\n> When a cancel API is added, blocking will be enabled automatically.\n> See: [Issue #18677](https://github.com/openclaw/openclaw/issues/18677)\n\n## Audit Log\n\nAll detections are logged to `~/.openclaw/guava-guard/audit.jsonl` (JSON lines format).\n\n## Want Full Static Scanning? (Recommended Default)\n\nGuavaGuard handles **runtime** monitoring. For comprehensive **static** scanning of skill packages before installation, use **guard-scanner** first:\n\n```bash\n# 1) Pre-install safety gate\nnpx guard-scanner ./skills --self-exclude --verbose\n\n# 2) Then enable runtime monitoring\nopenclaw hooks enable guava-guard\n```\n\n- 186+ detection patterns / 20 threat categories\n- HTML dashboard, SARIF, JSON output\n- Zero dependencies\n- MIT licensed\n\n**GitHub**: https://github.com/koatora20/guard-scanner\n**ClawHub**: `clawhub install guard-scanner`\n\n## Born From a Real Incident\n\nA real agent compromise overwrote core behavior files through a malicious skill install path.\nGuavaGuard exists to detect dangerous runtime tool-call patterns early and leave an auditable trail.\n\n## License\n\nMIT. Zero depend"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn70hcm6kss09g9b4pe5rq3ybd80qp15\",\n  \"slug\": \"guava-guard\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1771320441390\n}"},{"path":"CHANGELOG.md","content":"# CHANGELOG\n\n## v10.0.0 — Runtime-Only Final (2026-02-17)\n\n### ✅ Scope Simplification (開発完了版)\n- GuavaGuardは **runtime guard専用** に正式固定\n- Soul Lock / SoulChain 由来の機能・運用前提を本体スコープから除外\n- 公式Hook API制約に合わせて **warn-only運用** を明示（Issue #18677待ち）\n\n### 🔐 Security Posture\n- before_tool_callの12 runtime checksを維持\n- 監査ログ `~/.openclaw/guava-guard/audit.jsonl` を継続\n- ブロック実行はcancel/veto API追加後に再有効化予定\n\n### 📣 Positioning\n- **静的スキャンは guard-scanner を推奨**（pre-install gate）\n- GuavaGuardは「実行時監視」、guard-scannerは「導入前検査」に役割分離\n\n## v9.0.0 — SoulChain Edition (2026-02-14)\n\n### ⛓️ SoulChain: On-Chain Identity Verification (Layer 3)\n- **3-layer defense architecture**: L1 Static Scan + L2 Soul Lock + L3 SoulChain\n- **On-chain verification** via SoulRegistry.sol on Polygon Mainnet\n  - Reads agent's registered SOUL.md hash from blockchain\n  - Compares against local SHA-256 hash\n  - Zero gas cost (view function call)\n- **`verify` subcommand** — standalone on-chain verification\n  - `node guava-guard.js verify` — quick soul check\n  - `--wallet <addr>` — specify agent wallet\n  - `--rpc <url>` — custom RPC endpoint\n  - `--stats` — show registry statistics\n- **Zero-dependency RPC client** — raw JSON-RPC via Node.js fetch\n  - No ethers.js, no viem, no npm install\n  - Hand-rolled ABI encoding/decoding (4 function selectors)\n  - Multi-RPC fallback (polygon-rpc.com → ankr → llamarpc)\n- **Graceful degradation** — network failure → L3 skipped, L1+L2 active\n- **`--no-soulchain`** flag to disable on-chain checks\n- **Exit code 3** for SoulChain violation (distinct from malicious skill = 1)\n- **JSON report** includes `soulchain` field with full verification result\n- **Configurable** via `~/.openclaw/guava-guard/soulchain.json`\n\n### Contracts\n- **SoulRegistry**: `0x0Bc112169401cC1a724dBdeA36fdb6ABf3237C93` (Polygon)\n- **$GUAVA Token**: `0x25cBD481901990bF0ed2ff9c5F3C0d4f743AC7B8` (Polygon)\n\n### Context\n- ERC-8004 \"Trustless Agents\" activated on Ethereum mainnet (2026-02-11)\n- SoulChain is complementary: ERC-8004 = discovery/trust, SoulChain = integrity\n- World's first AI agent on-chain identity verification in production\n\n## v8.0.0 — Soul Lock Edition (2026-02-12)\n\n### 🔒 Soul Lock: World's First Agent Identity Protection\n- **Category 17: Identity Hijacking** — 15 new detection patterns\n  - Shell writes (echo, cp, scp, mv, sed, redirect to SOUL.md/IDENTITY.md)\n  - Code writes (Python open(w), Node writeFileSync, PowerShell Set-Content)\n  - Flag manipulation (chflags uchg/nouchg, attrib +/-R)\n  - Persona swap instructions, evil soul file references\n  - Agent name override, memory wipe commands\n- **Soul Lock Integrity Verification** (enabled by default)\n  - SHA-256 hash comparison against stored baseline\n  - OS immutable flag detection (macOS chflags / Windows attrib)\n  - Watchdog daemon status check (LaunchAgent)\n  - Auto-stores baseline hashes on first run\n- **`--no-soul-lock`** flag to disable integrity checks\n- **Self-healing watchdog** (`scripts/soul-watchdog.sh`)\n  - fswatch-based monitoring (ma"},{"path":"HOOK.md","content":"# GuavaGuard Runtime Guard\n\nThe Runtime Guard hook is in `hooks/guava-guard/`.\n\nInstall with:\n```bash\nopenclaw hooks install skills/guava-guard/hooks/guava-guard\nopenclaw hooks enable guava-guard\n```\n\nSee `hooks/guava-guard/HOOK.md` for full documentation."},{"path":"hooks/guava-guard/HOOK.md","content":"---\nname: guava-guard\ndescription: \"GuavaGuard Runtime Guard — warns on dangerous tool call patterns in real-time\"\nmetadata: { \"openclaw\": { \"emoji\": \"🍈\", \"events\": [\"agent:before_tool_call\"], \"requires\": { \"bins\": [\"node\"] } } }\n---\n\n# GuavaGuard Runtime Guard — before_tool_call Hook\n\nReal-time security monitoring for OpenClaw agents. Warns when dangerous\ntool call patterns are detected (reverse shells, credential exfiltration, etc).\n\n> **Note**: Blocking is not yet possible — OpenClaw's hook API does not\n> currently support a cancel mechanism. See [Issue #18677](https://github.com/openclaw/openclaw/issues/18677).\n\n## Triggers\n\n| Event                    | Action | Purpose                                |\n|--------------------------|--------|----------------------------------------|\n| `agent:before_tool_call` | warn   | Check tool args for malicious patterns |\n\n## What it does\n\nScans every exec/write/edit/browser/web_fetch/message call against 12 runtime threat patterns:\n\n- Reverse shells, credential exfiltration, Gatekeeper bypass\n- ClawHavoc AMOS IoCs, known malicious IPs\n- DNS exfiltration, base64-to-shell, curl|bash\n- SSH key access, crypto wallet credential access\n- Cloud metadata SSRF (169.254.169.254)\n- Guardrail disabling attempts (CVE-2026-25253)\n\n## Audit Log\n\nAll detections logged to `~/.openclaw/guava-guard/audit.jsonl`.\n\n## For comprehensive static scanning\n\nUse **guard-scanner** — 170+ patterns, 17 threat categories:\n\n```bash\nnpx guard-scanner ./skills\n```\n\nGitHub: https://github.com/koatora20/guard-scanner"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Skill: Guava Guard Owner: koatora20 Summary: Runtime security guard for OpenClaw agents. Warns on dangerous tool call patterns. For full static scanning, use guard-scanner. Tags: latest:1.2.0, runtime-guard:5.0.0, scanner:5.0.0, security:8.0.0, soul-lock:8.0.0 Version history: v1.2.0 | 2026-02-17T09:27:21.390Z | user Slim release: runtime hook only (warn mode). Removed proprietary files. guard-scanner redirect for fu","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1501,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T15:34:31.239Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}