{"id":"0396856a-205f-4bee-8e5c-c262d21d1e16","entityType":"agent","slug":"clawhub-martin2877-tophant-clawvault-installer","name":"Tophant Clawvault Installer","canonicalUrl":"https://www.xpersona.co/agent/clawhub-martin2877-tophant-clawvault-installer","canonicalPath":"/agent/clawhub-martin2877-tophant-clawvault-installer","generatedAt":"2026-10-11T05:35:20.161Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:28:29.472Z","emptyReason":null},"description":"Install, configure, test, and uninstall ClawVault AI security proxy","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17570btgfthte5n8w72wxen8d83gzm4:tophant-clawvault-installer","sourceUrl":"https://clawhub.ai/martin2877/tophant-clawvault-installer","homepage":"https://clawhub.ai/martin2877/skills/tophant-clawvault-installer","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/martin2877/tophant-clawvault-installer","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/martin2877/skills/tophant-clawvault-installer","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Tophant Clawvault Installer technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:28:29.472Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:28:29.472Z","emptyReason":null},"stars":null,"forks":null,"downloads":1173,"packageName":null,"latestVersion":"0.2.13","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:28:29.409Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T03:28:29.472Z","lastCrawledAt":"2026-10-11T03:28:29.409Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T03:28:29.409Z","lastVerifiedAt":null,"highlights":[{"version":"0.2.13","createdAt":"2026-05-19T09:56:14.409Z","changelog":"Add OpenClaw plugin installation and acceptance flow","fileCount":7,"zipByteSize":22463},{"version":"0.2.12","createdAt":"2026-04-30T07:40:56.987Z","changelog":"Package and use the full default config template so GitHub-installed ClawVault creates complete configuration files.","fileCount":6,"zipByteSize":20451},{"version":"0.2.11","createdAt":"2026-04-30T06:54:34.283Z","changelog":"Temporarily install ClawVault from latest GitHub code only; disable PyPI and fixed-tag install paths.","fileCount":6,"zipByteSize":20438},{"version":"0.2.10","createdAt":"2026-04-30T06:17:36.312Z","changelog":"Write OpenClaw gateway proxy config during install without restarting the gateway; start ClawVault dashboard/proxy; add unconfigure-proxy recovery command.","fileCount":6,"zipByteSize":19282},{"version":"0.2.9","createdAt":"2026-04-28T06:45:02.732Z","changelog":"Publish clean installer artifact with restored dedicated venv, no-start/no-proxy options, pinned package sources, and localhost dashboard defaults.","fileCount":6,"zipByteSize":19281},{"version":"0.2.8","createdAt":"2026-04-28T06:19:22.317Z","changelog":"Fix installer package metadata to include restored dedicated-venv installer implementation with no-start/no-proxy options.","fileCount":6,"zipByteSize":13966},{"version":"0.2.7","createdAt":"2026-04-28T05:51:36.951Z","changelog":"Restore dedicated-venv OpenClaw installer, keep pinned package sources, localhost dashboard defaults, and fail-fast config initialization.","fileCount":6,"zipByteSize":13966},{"version":"0.2.6","createdAt":"2026-04-28T03:38:23.490Z","changelog":"Sync latest installer fixes: pinned package sources, pinned GitHub fallback, localhost dashboard default, and explicit configuration failure handling.","fileCount":6,"zipByteSize":13966}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17570btgfthte5n8w72wxen8d83gzm4:tophant-clawvault-installer","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17570btgfthte5n8w72wxen8d83gzm4:tophant-clawvault-installer` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/martin2877/tophant-clawvault-installer before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T05:35:20.157Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-martin2877-tophant-clawvault-installer/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:28:29.472Z","emptyReason":null},"readme":"Skill: Tophant Clawvault Installer\n\nOwner: martin2877\n\nSummary: Install, configure, test, and uninstall ClawVault AI security proxy\n\nTags: ai-protection:0.2.5, installer:0.2.6, latest:0.2.13, privacy:0.2.5, proxy:0.2.5, security:0.2.6, threat-detection:0.2.5\n\nVersion history:\n\nv0.2.13 | 2026-05-19T09:56:14.409Z | user\n\nAdd OpenClaw plugin installation and acceptance flow\n\nv0.2.12 | 2026-04-30T07:40:56.987Z | user\n\nPackage and use the full default config template so GitHub-installed ClawVault creates complete configuration files.\n\nv0.2.11 | 2026-04-30T06:54:34.283Z | user\n\nTemporarily install ClawVault from latest GitHub code only; disable PyPI and fixed-tag install paths.\n\nv0.2.10 | 2026-04-30T06:17:36.312Z | user\n\nWrite OpenClaw gateway proxy config during install without restarting the gateway; start ClawVault dashboard/proxy; add unconfigure-proxy recovery command.\n\nv0.2.9 | 2026-04-28T06:45:02.732Z | user\n\nPublish clean installer artifact with restored dedicated venv, no-start/no-proxy options, pinned package sources, and localhost dashboard defaults.\n\nv0.2.8 | 2026-04-28T06:19:22.317Z | user\n\nFix installer package metadata to include restored dedicated-venv installer implementation with no-start/no-proxy options.\n\nv0.2.7 | 2026-04-28T05:51:36.951Z | user\n\nRestore dedicated-venv OpenClaw installer, keep pinned package sources, localhost dashboard defaults, and fail-fast config initialization.\n\nv0.2.6 | 2026-04-28T03:38:23.490Z | user\n\nSync latest installer fixes: pinned package sources, pinned GitHub fallback, localhost dashboard default, and explicit configuration failure handling.\n\nv0.2.5 | 2026-04-23T09:50:55.874Z | user\n\nv0.2.5 — Install always from main branch; no tag fallback, no version pinning\n\nSimplifies the install flow: the skill now always runs `pip install git+https://github.com/tophant-ai/ClawVault.git` against the upstream main branch. No version tag, no fallback, no branching.\n\nRationale: the repository is the authoritative source for the latest code. Git tags were causing intermittent install failures when a tag didn't exist upstream. Removing the tag logic makes the install a single-path operation that always pulls the current repo state.\n\nChanges:\n- clawvault_manager.py: removed the `@v{VERSION}` fallback; now a single pip install call.\n- SECURITY.md: updated \"Design Intent\", \"Package Sources\", and \"Installation Process\" to describe single-path main-branch install.\n\nNo other behavior change.\n\nv0.2.4 | 2026-04-23T09:14:10.251Z | user\n\nv0.2.4 — Install from main branch by default; tag is now fallback only\n\nReverses the v0.2.2 install order. The new order matches the original intent: always pull the latest code from the upstream repository, with the version tag serving as a fallback when the main branch is unreachable.\n\nRationale:\n- The @v{VERSION} git tag is not guaranteed to exist on the upstream repository before a given release is tagged. In that case, the tag-first order (v0.2.2/v0.2.3) caused install failures or unnecessary retries.\n- Main-first ensures users always receive current bug fixes and security patches. Tag fallback preserves reproducibility when the main fetch fails due to network issues or repository unavailability.\n\nChanges:\n- clawvault_manager.py: swapped the primary/fallback pip install URLs.\n- SECURITY.md: updated \"Package Sources\" and \"Installation Process\" sections to describe the new order and rationale.\n- SKILL.md and README.md: unchanged (they point to SECURITY.md for detail).\n\nNo other behavior change.\n\nv0.2.3 | 2026-04-23T06:13:27.957Z | user\n\nv0.2.3 — Shortened in-skill disclosure, moved detail to SECURITY.md\n\nThis release trims the Capability Disclosure language in README.md and SKILL.md down to a single-line pointer, and relocates the full capability + threat-model content to SECURITY.md where it already lived. This mirrors the approach used in tophant-clawvault-operator@0.2.4 and clears a stale moderation flag that the ClawHub scanner had carried over from earlier publishes.\n\n- SKILL.md: removed the verbose \"What This Skill Does\" enumeration and the duplicated \"Security Considerations\" section; both now point to SECURITY.md.\n- README.md: replaced the emoji-tagged capability banner with a one-line \"Before Installing\" pointer.\n- SECURITY.md: unchanged — still the authoritative location for the full capability surface, design intent, supply-chain notes, and operational guidance.\n\nNo code changes.\n\nv0.2.2 | 2026-04-23T05:56:07.293Z | user\n\nv0.2.2 — Supply-chain hardening (scan: concern → note)\n\nAddresses the \"Install Mechanism\" concern flagged by ClawHub security scanner.\n\nChanges:\n- Tag-pinned install by default: installer now runs `pip install git+https://...@v0.2.0` first and only falls back to main branch if the tag is unavailable upstream. Previously it tracked main by default. (2-line change in clawvault_manager.py)\n- Updated SECURITY.md, SKILL.md, and README.md to reflect the new primary/fallback order so documentation matches code behavior.\n\nNo behavior change in any other area. The venv, config layout, OpenClaw proxy integration, service ports, and capability surface are identical to v0.2.1.\n\nv0.2.1 | 2026-04-23T03:36:28.595Z | user\n\nv0.2.1 — Documentation hardening (no code changes)\n\nAddresses capability-disclosure flags from the ClawHub security scanner. No behavior changes; only documentation is updated to accurately describe what the skill does.\n\n- Corrected SECURITY.md: installer installs exclusively from GitHub (git+https), not PyPI. Prior text incorrectly claimed PyPI was primary.\n- Added \"Design Intent\" table to SECURITY.md documenting why ssl_verify=false, dashboard no-auth default, and main-branch installs are intentional for a MITM AI-inspection proxy.\n- Added \"Capability Disclosure\" banner to README.md listing all high-risk capabilities up-front.\n- Added \"What This Skill Does\" section to SKILL.md explaining installer side effects, venv isolation, and the three predictable paths it touches (~/.clawvault-env/, ~/.ClawVault/, one optional systemd unit).\n- Clarified in documentation that --no-proxy skips the systemd modification and --no-start skips service launch.\n- Clarified the installation process flow: venv creation, pip from GitHub with @v0.2.0 tag fallback, config template copy, optional proxy integration, optional service start.\n\nv0.2.0 | 2026-04-23T03:06:59.876Z | user\n\nFirst public release (v0.2.0)\n\nFeatures:\n- One-command install: creates isolated venv in ~/.clawvault-env, installs from GitHub, generates full ~/.ClawVault/config.yaml, integrates with OpenClaw gateway proxy, and starts services\n- Three install modes: quick (interactive guard), standard (strict), advanced (custom)\n- Opt-out flags --no-start and --no-proxy for CI/manual setups\n- Natural-language rule generation via /generate-rule with scenario templates (customer_service, development, production, finance)\n- Detection test suites for sensitive data, prompt injection, and dangerous commands\n- Complete uninstall workflow: stops services, removes systemd proxy integration, cleans venv and config\n\nCompanion skill: tophant-clawvault-operator covers day-to-day operations after installation.\n\nArchive index:\n\nArchive v0.2.13: 7 files, 22463 bytes\n\nFiles: _meta.json (147b), clawvault_manager.py (46031b), README.md (3039b), SECURITY.md (13304b), skill-card.md (2319b), skill.json (1854b), SKILL.md (5901b)\n\nFile v0.2.13:SKILL.md\n\n---\nname: tophant-clawvault-installer\nversion: 0.2.13\ndescription: Install, configure, test, and uninstall ClawVault AI security proxy\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Installer\n\nInstall, configure, test, and uninstall ClawVault — the AI security proxy that protects agents from prompt injection, data leakage, and dangerous commands.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## What This Skill Does\n\nInstalls ClawVault into a dedicated venv at `~/.clawvault-env/` and writes config under `~/.ClawVault/`. See `SECURITY.md` for the full capability, risk, and design-intent disclosure.\n\n## How to Run\n\n**IMPORTANT: All commands MUST be executed using the Python script bundled with this skill.**\n\nDo NOT run `pip install`, `clawvault`, or any other command directly. Always use:\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py <command> [options]\n```\n\nWhere `SKILL_DIR` is the directory containing this SKILL.md file (typically `~/.openclaw/workspace/skills/tophant-clawvault-installer/` or `~/.openclaw/skills/tophant-clawvault-installer/`).\n\nAdd `--json` to any command for machine-readable JSON output.\n\n## Commands\n\n### /tophant-clawvault-installer install\n\nInstall ClawVault. The script creates a Python virtual environment, temporarily installs the latest GitHub repository code from `main` instead of PyPI or a fixed tag, generates config, writes OpenClaw gateway proxy config when the gateway service exists, and starts ClawVault services. By default it does **not** restart `openclaw-gateway`, because recent OpenClaw versions may disconnect or hang after a gateway restart. **No pip or system package manager needed.**\n\n```bash\n# Default: write OpenClaw gateway proxy config and start ClawVault web dashboard,\n# but do not restart openclaw-gateway.\n# ClawVault web dashboard starts at http://localhost:8766.\n# To activate OpenClaw proxy later, manually run:\n#   systemctl --user restart openclaw-gateway\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --install-plugin --json\n\n# Interactive setup\npython3 SKILL_DIR/clawvault_manager.py install --mode standard --json\n\n# Full control (strict mode)\npython3 SKILL_DIR/clawvault_manager.py install --mode advanced --json\n\n# Install without starting services\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json\n\n# Deprecated compatibility flag: proxy config is already written by default\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --json\n\n# Dangerous: restart gateway immediately; may disconnect or hang OpenClaw\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --restart-gateway --json\n\n# Skip OpenClaw proxy integration explicitly\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json\n```\n\n### OpenClaw plugin acceptance check\n\nAfter installing the plugin, send a normal OpenClaw prompt that asks to read `/tmp/.env.demo`. If the plugin is active, that prompt should trigger file-guard interception and appear in the ClawVault dashboard.\n\n### /tophant-clawvault-installer health\n\nCheck service health and status.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py health --json\n```\n\n### /tophant-clawvault-installer generate-rule\n\nGenerate security rules from natural language.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py generate-rule \"Block all AWS credentials\" --json\npython3 SKILL_DIR/clawvault_manager.py generate-rule --scenario customer_service --apply --json\n```\n\n**Scenarios:** `customer_service`, `development`, `production`, `finance`\n\n### /tophant-clawvault-installer test\n\nRun detection tests.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py test --category all --json\npython3 SKILL_DIR/clawvault_manager.py test --category sensitive --json\n```\n\n**Categories:** `all`, `sensitive`, `injection`, `commands`\n\n### /tophant-clawvault-installer unconfigure-proxy\n\nRemove ClawVault proxy environment variables from `openclaw-gateway.service` without restarting the gateway. Use this if OpenClaw conversations hang after proxy integration.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py unconfigure-proxy --json\n```\n\n### /tophant-clawvault-installer uninstall\n\nRemove ClawVault completely (stops services, removes proxy, deletes venv and config).\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py uninstall --json\npython3 SKILL_DIR/clawvault_manager.py uninstall --keep-config --json\n```\n\n## Quick Examples\n\n```bash\n# Set the skill directory path\nCV=\"python3 ~/.openclaw/workspace/skills/tophant-clawvault-installer/clawvault_manager.py\"\n\n# Install (one command handles everything)\n$CV install --mode quick --json\n\n# Check health\n$CV health --json\n\n# Generate rule\n$CV generate-rule \"Detect database passwords\" --apply --json\n\n# Apply scenario\n$CV generate-rule --scenario customer_service --apply --json\n\n# Run tests\n$CV test --category all --json\n\n# Uninstall\n$CV uninstall --json\n```\n\n## Requirements\n\n- Python 3.10+ (with venv module)\n- Ports 8765, 8766 available\n- No pip or system packages needed — the install script creates its own virtual environment\n\n## Permissions\n\n- `execute_command` - Run installation and ClawVault commands\n- `write_files` - Create configuration files\n- `read_files` - Read configurations\n- `network` - Download packages and API calls\n\n## Security Considerations\n\nSee [SECURITY.md](./SECURITY.md) for capability disclosure, threat model, and deployment guidance.\n\n## Documentation\n\n- **Full Guide**: https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md\n- **中文文档**: https://github.com/tophant-ai/ClawVault/blob/main/doc/zh/OPENCLAW_SKILL.md\n- **Repository**: https://github.com/tophant-ai/ClawVault\n\n## License\n\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.13:README.md\n\n# ClawVault Installer Skill\r\n\r\nAI security system for OpenClaw — protect your AI agents from prompt injection, data leakage, and dangerous commands.\r\n\r\n## Before Installing\r\n\r\nThis skill installs and operates a local HTTPS-inspection proxy. Capabilities, defaults, and risks are documented in [SECURITY.md](./SECURITY.md) — please review it before installing.\r\n\r\n## Quick Start\r\n\r\n### Installation\r\n\r\n**Option 1: Install from ClawHub (Recommended)**\r\n\r\n```bash\r\n# Install from ClawHub\r\nopenclaw skills install tophant-clawvault-installer\r\n\r\n# Or use clawhub CLI\r\nclawhub install tophant-clawvault-installer\r\n```\r\n\r\n**ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault-installer\r\n\r\n**Option 2: Install from Local Repository**\r\n\r\n```bash\r\n# Copy to OpenClaw skills directory\r\ncp -r skills/tophant-clawvault-installer ~/.openclaw/skills/\r\n\r\n# Or create symbolic link\r\nln -s /path/to/ClawVault/skills/tophant-clawvault-installer ~/.openclaw/skills/tophant-clawvault-installer\r\n\r\n# Restart OpenClaw\r\nopenclaw restart\r\n```\r\n\r\n### Basic Usage\r\n\r\n```bash\r\n# Install ClawVault and link the OpenClaw file-guard plugin\r\n/tophant-clawvault-installer install --mode quick --install-plugin\r\n\r\n# Check health\r\n/tophant-clawvault-installer health\r\n\r\n# Generate security rule\r\n/tophant-clawvault-installer generate-rule \"Block all AWS credentials\" --apply\r\n\r\n# Run tests\r\n/tophant-clawvault-installer test --category all\r\n```\r\n\r\n## Features\r\n\r\n- **AI-guided installation** - Quick, standard, or advanced setup modes\r\n- **Dedicated virtualenv** - Installs into `~/.clawvault-env` instead of the system Python\r\n- **Latest GitHub install source** - Temporarily installs from the latest GitHub `main` code instead of PyPI or a fixed tag\r\n- **Failure-aware setup** - Reports configuration initialization failures as installation failures\r\n- **Secure dashboard defaults** - Binds the dashboard to `127.0.0.1` by default\r\n- **OpenClaw proxy integration and validation** - Can configure OpenClaw gateway proxy settings and verify the normal prompt path that triggers file-guard plugin interception\r\n- **Rule generation** - Create security rules from natural language\r\n- **Scenario templates** - Pre-configured policies (customer_service, development, production, finance)\r\n- **Detection testing** - Built-in test suites for validation\r\n- **Health monitoring** - Real-time service status\r\n\r\n## Documentation\r\n\r\n- **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first**\r\n- **Skill Reference**: [SKILL.md](./SKILL.md)\r\n- **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md)\r\n- **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md)\r\n\r\n## Requirements\r\n\r\n- Python 3.10+\r\n- OpenClaw installed\r\n- Ports 8765, 8766 available\r\n\r\n## Support\r\n\r\n- **Repository**: https://github.com/tophant-ai/ClawVault\r\n- **Issues**: https://github.com/tophant-ai/ClawVault/issues\r\n- **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n\r\n## License\r\n\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.13:_meta.json\n\n{\n  \"ownerId\": \"kn70av3n6bs6dqfaajr8drm90d82v5tt\",\n  \"slug\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.13\",\n  \"publishedAt\": 1779184574409\n}\n\nFile v0.2.13:SECURITY.md\n\n# Security Documentation\r\n\r\n## Overview\r\n\r\nClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.\r\n\r\n## Design Intent — Why Several Defaults Look Permissive\r\n\r\nClawVault is a **man-in-the-middle (MITM) inspection proxy for AI traffic**. To do its job, it necessarily exhibits behaviors that automated security scanners flag as high-risk. Every one of these is intentional. This section documents them up-front so there is no ambiguity between \"intentional capability\" and \"bug.\"\r\n\r\n| Behavior | Why it's required | How to constrain it |\r\n|---|---|---|\r\n| `ssl_verify: false` in default config | Decrypts HTTPS so detectors can scan request/response bodies. Without this, ClawVault cannot see the AI traffic it is meant to protect. | MITM only applies to hosts listed in `proxy.intercept_hosts`. Non-AI traffic passes through untouched. Limit the list if you only want specific providers inspected. |\r\n| Dashboard has no authentication by default | Default bind is `127.0.0.1` (localhost only); anyone with a shell on the machine already has more access than the dashboard exposes. | **Never** start with `--dashboard-host 0.0.0.0` on untrusted networks. Use SSH port-forwarding for remote viewing. |\r\n| The skill sees your API keys and prompts | API keys travel inside the HTTPS requests being inspected. A proxy that inspects requests will see them. | All traffic stays on `localhost`. Nothing is uploaded. Audit logs in `~/.ClawVault/audit.db` are local-only. |\r\n| Installer writes `HTTP_PROXY`/`HTTPS_PROXY` into `openclaw-gateway.service` | Routes OpenClaw traffic through ClawVault when the gateway is restarted later. The installer does not restart the gateway by default because recent OpenClaw versions may disconnect or hang after gateway restart. | Pass `--no-proxy` to skip the unit-file change. Restart `openclaw-gateway` manually only when safe to reconnect. Use `unconfigure-proxy` to remove the injected env lines. |\r\n| Installs from latest GitHub source | Temporary behavior: PyPI and fixed-tag installs are disabled so users get the newest repository code. | Review the repository before installing or run in a disposable VM for higher assurance. See \"Package Sources\" below. |\r\n\r\nIf any of these trade-offs are unacceptable for your threat model, **do not install this skill.**\r\n\r\n## How ClawVault Works\r\n\r\n### Proxy Architecture\r\n\r\nClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:\r\n\r\n```\r\nAI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs\r\n                    ↓\r\n            Detection Engine\r\n                    ↓\r\n            Dashboard (localhost:8766)\r\n```\r\n\r\n**What This Means:**\r\n- All API requests pass through ClawVault for inspection\r\n- ClawVault can see request/response content including API keys\r\n- This is intentional and necessary for threat detection\r\n- The proxy runs locally on your machine, not on external servers\r\n\r\n### SSL/TLS Verification\r\n\r\n**Default Behavior:**\r\n- ClawVault's default configuration sets `ssl_verify: false` for proxied connections\r\n- This is required for the proxy to inspect HTTPS traffic (MITM-style interception)\r\n\r\n**Security Implications:**\r\n- Disabling SSL verification allows ClawVault to decrypt and inspect encrypted traffic\r\n- This is necessary for detecting threats in API requests/responses\r\n- Traffic between your machine and LLM providers is still encrypted\r\n- The decryption happens locally on your machine, not in transit\r\n\r\n**Recommendation:**\r\n- Only use ClawVault on trusted networks\r\n- The proxy is designed for local development/testing\r\n- For production, consider using ClawVault's detection rules without the proxy\r\n\r\n## Dashboard Security\r\n\r\n### Default Configuration (Secure)\r\n\r\n```bash\r\n# Dashboard binds to localhost only\r\nclawvault start\r\n# Access: http://127.0.0.1:8766 (local machine only)\r\n```\r\n\r\n**This is the recommended configuration** for most users.\r\n\r\n### Remote Access Configuration (Risky)\r\n\r\n```bash\r\n# Dashboard accessible from any IP\r\nclawvault start --dashboard-host 0.0.0.0\r\n# Access: http://<your-ip>:8766 (anyone on network can access)\r\n```\r\n\r\n**⚠️ Security Risks:**\r\n- Dashboard shows sensitive detection data (API keys, PII, etc.)\r\n- No authentication by default\r\n- Anyone on your network can view the dashboard\r\n- Potential data exposure if misconfigured\r\n\r\n**When to Use Remote Access:**\r\n- Only in trusted, isolated networks\r\n- Behind a firewall with strict access controls\r\n- For temporary debugging/demonstration purposes\r\n\r\n**Production Recommendations:**\r\n1. Keep dashboard on localhost (127.0.0.1)\r\n2. Use SSH tunneling for remote access:\r\n   ```bash\r\n   ssh -L 8766:localhost:8766 user@remote-server\r\n   ```\r\n3. Or use a reverse proxy with authentication (nginx + basic auth)\r\n4. Never expose dashboard to public internet without authentication\r\n\r\n## Permissions Explained\r\n\r\nThe skill requires these permissions:\r\n\r\n### `execute_command`\r\n- **Purpose:** Create a Python venv in `~/.clawvault-env/`, install latest ClawVault code from GitHub `main`, write OpenClaw gateway proxy env when the gateway unit exists, and start/stop the proxy + dashboard services. Gateway restart is opt-in via `--restart-gateway`.\r\n- **Risk:** Can execute arbitrary commands on your system; gateway integration modifies one OpenClaw unit file when present and may make OpenClaw disconnect or hang after restart.\r\n- **Mitigation:** All commands are explicit in `clawvault_manager.py`. Default install writes proxy env but does not restart `openclaw-gateway`. Pass `--no-proxy` to skip the gateway change. Use `unconfigure-proxy` to remove injected proxy settings without restarting the gateway.\r\n\r\n### `write_files`\r\n- **Purpose:** Create configuration files in `~/.ClawVault/`\r\n- **Risk:** Can write to your home directory\r\n- **Mitigation:** Skill only writes to dedicated ClawVault config directory\r\n\r\n### `read_files`\r\n- **Purpose:** Read existing ClawVault configuration\r\n- **Risk:** Can read files on your system\r\n- **Mitigation:** Skill only reads from `~/.ClawVault/` directory\r\n\r\n### `network`\r\n- **Purpose:** Download ClawVault package, proxy API traffic, call local dashboard API\r\n- **Risk:** Can make network requests\r\n- **Mitigation:** Network access is essential for proxy functionality; all traffic is logged\r\n\r\n## Data Handling\r\n\r\n### What Data ClawVault Sees\r\n\r\nClawVault inspects:\r\n- API requests to LLM providers (OpenAI, Anthropic, etc.)\r\n- API responses from LLM providers\r\n- API keys and authentication tokens (in request headers)\r\n- User prompts and AI responses\r\n- Potentially sensitive data (PII, credentials) in prompts/responses\r\n\r\n### Where Data Is Stored\r\n\r\n- **Audit logs:** `~/.ClawVault/audit.db` (SQLite database)\r\n- **Detection logs:** `~/.ClawVault/logs/detection.log`\r\n- **Configuration:** `~/.ClawVault/config.yaml`\r\n\r\n### Data Retention\r\n\r\n- Audit logs are stored indefinitely by default\r\n- You can configure retention policies in `config.yaml`\r\n- To clear logs: `rm ~/.ClawVault/audit.db`\r\n\r\n### Data Privacy\r\n\r\n- All data stays on your local machine\r\n- ClawVault does not send data to external servers (except when proxying to LLM providers)\r\n- No telemetry or analytics are collected\r\n- You control all data through local configuration files\r\n\r\n## Installation Security\r\n\r\n### Package Sources\r\n\r\nThe skill temporarily installs ClawVault from the latest GitHub repository code on `main`. PyPI and fixed-tag install paths are currently disabled.\r\n\r\n```\r\npip install git+https://github.com/tophant-ai/ClawVault.git@main\r\n```\r\n\r\nThe installer does **not** perform:\r\n- Checksum verification\r\n- Signature verification\r\n- Dependency-graph auditing\r\n\r\n**Supply-chain risk:** Installing latest code from GitHub carries supply-chain risk and is less reproducible than a pinned release. This behavior is temporary; review the repository before installing in sensitive environments.\r\n\r\n**How to reduce supply-chain exposure:**\r\n1. Review the repository before installing: https://github.com/tophant-ai/ClawVault\r\n2. Check out a specific commit/tag locally and point `pip` at that path instead\r\n3. Run `./venv/bin/pip install git+https://github.com/tophant-ai/ClawVault.git@<sha>` with an audited commit SHA\r\n4. Run the installer inside a disposable VM or container\r\n5. Subscribe to the repo's security advisories on GitHub\r\n\r\n### Installation Process\r\n\r\nWhat happens, in order, during `install --mode quick`:\r\n\r\n1. Verifies Python version (≥ 3.10)\r\n2. Creates a **dedicated virtual environment** at `~/.clawvault-env/` (isolates ClawVault from system Python — nothing is installed globally)\r\n3. Runs `pip install git+https://github.com/tophant-ai/ClawVault.git@main` inside that venv\r\n4. Copies `config.example.yaml` from the installed package to `~/.ClawVault/config.yaml`; if the template is unavailable, generates a complete 11-section default config\r\n5. If `~/.config/systemd/user/openclaw-gateway.service` exists, injects `HTTP_PROXY`/`HTTPS_PROXY`/`NO_PROXY`/`NODE_TLS_REJECT_UNAUTHORIZED` into it, then tells the user to manually run `systemctl --user restart openclaw-gateway` later when safe. Skipped if `--no-proxy` is passed or if the service file is absent.\r\n6. Launches the proxy (port 8765) and dashboard (port 8766) via `subprocess.Popen`. Skipped if `--no-start` is passed. `openclaw-gateway` is only restarted when `--restart-gateway` is explicitly requested.\r\n\r\nEverything the skill touches lives under three predictable paths:\r\n- `~/.clawvault-env/` — the Python venv\r\n- `~/.ClawVault/` — config, audit DB, logs, certs, state\r\n- `~/.config/systemd/user/openclaw-gateway.service` — **modified only if it already exists**\r\n\r\n## Threat Model\r\n\r\n### What ClawVault Protects Against\r\n\r\n✅ **Prompt injection attacks** - Detects attempts to manipulate AI behavior\r\n✅ **Data leakage** - Identifies PII, credentials, API keys in prompts/responses\r\n✅ **Dangerous commands** - Flags risky shell commands in AI outputs\r\n✅ **Jailbreak attempts** - Detects attempts to bypass AI safety measures\r\n\r\n### What ClawVault Does NOT Protect Against\r\n\r\n❌ **Malicious ClawVault package** - If the upstream package is compromised, the skill will install it\r\n❌ **Local system compromise** - If your machine is compromised, ClawVault data can be accessed\r\n❌ **Network attacks** - ClawVault does not protect against network-level attacks\r\n❌ **Supply chain attacks** - No verification of package integrity during installation\r\n\r\n## Best Practices\r\n\r\n### For Development/Testing\r\n\r\n```bash\r\n# Safe configuration for local development\r\nclawvault start --dashboard-host 127.0.0.1 --mode interactive\r\n\r\n# Review detection logs regularly\r\ntail -f ~/.ClawVault/logs/detection.log\r\n\r\n# Test with non-sensitive data first\r\nclawvault test --category all\r\n```\r\n\r\n### For Production\r\n\r\n```bash\r\n# Use strict mode for automated blocking\r\nclawvault start --mode strict\r\n\r\n# Keep dashboard local, use SSH tunnel for remote access\r\nssh -L 8766:localhost:8766 user@server\r\n\r\n# Configure audit retention\r\n# Edit ~/.ClawVault/config.yaml:\r\naudit:\r\n  enabled: true\r\n  retention_days: 30\r\n```\r\n\r\n### For Sensitive Environments\r\n\r\n1. **Review the source code** before installation\r\n2. **Run in isolated environment** (VM, container)\r\n3. **Use firewall rules** to restrict network access\r\n4. **Rotate API keys** regularly\r\n5. **Monitor audit logs** for suspicious activity\r\n6. **Disable dashboard** if not needed: `--no-dashboard`\r\n\r\n## Security Checklist\r\n\r\nBefore installing ClawVault skill:\r\n\r\n- [ ] Reviewed ClawVault package source code\r\n- [ ] Understand that ClawVault will see API keys and request content\r\n- [ ] Verified dashboard will bind to localhost (not 0.0.0.0)\r\n- [ ] Understand SSL verification implications\r\n- [ ] Have plan for audit log retention/cleanup\r\n- [ ] Running in appropriate environment (dev/test/prod)\r\n- [ ] Firewall configured if using remote dashboard\r\n- [ ] Understand what permissions the skill requires\r\n\r\n## Reporting Security Issues\r\n\r\nIf you discover a security vulnerability in ClawVault or this skill:\r\n\r\n**For Critical Vulnerabilities (RCE, data exfiltration, credential theft):**\r\n1. Open a [GitHub Security Advisory](https://github.com/tophant-ai/ClawVault/security/advisories/new) (private disclosure)\r\n2. Or email: security@tophant.com\r\n3. Include detailed description and reproduction steps\r\n4. We will respond within 48 hours and work on a fix\r\n\r\n**For Non-Critical Issues (documentation errors, configuration issues, minor bugs):**\r\n1. Open a public [GitHub Issue](https://github.com/tophant-ai/ClawVault/issues/new)\r\n2. Tag with `security` label\r\n3. Community can discuss and contribute fixes\r\n\r\nWe encourage responsible disclosure and will credit security researchers who report vulnerabilities.\r\n\r\n## Additional Resources\r\n\r\n- **ClawVault Documentation:** https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n- **OpenClaw Security:** https://docs.openclaw.ai/gateway/security\r\n- **Threat Model:** https://github.com/tophant-ai/ClawVault/blob/main/doc/architecture.md\r\n\r\n## License\r\n\r\nThis security documentation is part of the ClawVault project.\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.13:skill-card.md\n\n## Description:\n\nInstall, configure, test, and uninstall ClawVault AI security proxy.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[martin2877](https://clawhub.ai/user/martin2877)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and OpenClaw operators use this skill to install and manage ClawVault as a local AI security proxy, generate security rules, run detection tests, and remove proxy configuration when needed.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Default setup can inspect API prompts, responses, and credentials through a local HTTPS inspection proxy.\n\nMitigation: Review before installing on a machine with real credentials and prefer a disposable VM or container for initial evaluation.\n\nRisk: The installer uses mutable remote code from the ClawVault main branch rather than a pinned release.\n\nMitigation: Install only from an audited pinned ClawVault commit for sensitive environments.\n\nRisk: Proxy integration can make persistent OpenClaw gateway changes and gateway restart may affect active sessions.\n\nMitigation: Use --no-proxy and --no-start unless proxy activation is intentional, and avoid --restart-gateway until the TLS and connectivity impact is understood.\n\n## Reference(s):\n\n- [ClawVault repository](https://github.com/tophant-ai/ClawVault)\n- [ClawVault OpenClaw skill guide](https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md)\n- [ClawVault documentation](https://github.com/tophant-ai/ClawVault/tree/main/doc)\n- [ClawHub skill page](https://clawhub.ai/martin2877/skills/tophant-clawvault-installer)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown instructions with bash command examples and JSON-capable command output.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands support --json for machine-readable output.]\n\n## Skill Version(s):\n\n0.2.13 (source: server release, SKILL.md frontmatter, skill.json)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.2.13:skill.json\n\n{\r\n  \"name\": \"tophant-clawvault-installer\",\r\n  \"version\": \"0.2.13\",\r\n  \"description\": \"Install and manage ClawVault from OpenClaw agents.\",\r\n  \"author\": \"Tophant SPAI Lab\",\r\n  \"homepage\": \"https://github.com/tophant-ai/ClawVault\",\r\n  \"repository\": \"https://github.com/tophant-ai/ClawVault\",\r\n  \"main\": \"clawvault_manager.py\",\r\n  \"permissions\": [\"execute_command\", \"write_files\", \"read_files\", \"network\"],\r\n  \"permissions_rationale\": {\r\n    \"execute_command\": \"Required to run install, test, and service commands for ClawVault\",\r\n    \"write_files\": \"Creates configuration files in ~/.ClawVault/\",\r\n    \"read_files\": \"Reads ClawVault configuration from ~/.ClawVault/\",\r\n    \"network\": \"Downloads ClawVault package and reaches the dashboard API\"\r\n  },\r\n  \"tags\": [\"security\", \"ai-protection\", \"proxy\", \"threat-detection\", \"privacy\", \"openclaw\", \"plugin\"],\r\n  \"requirements\": [\"pyyaml\"],\r\n  \"python_version\": \">=3.10\",\r\n  \"commands\": {\r\n    \"install\": {\r\n      \"description\": \"Install ClawVault and optionally configure OpenClaw proxy integration.\",\r\n      \"usage\": \"install --mode [quick|standard|advanced] [--install-plugin] [--plugin-dir <path>] [--no-start] [--no-proxy] [--restart-gateway]\"\r\n    },\r\n    \"health\": {\r\n      \"description\": \"Check ClawVault health status\",\r\n      \"usage\": \"health\"\r\n    },\r\n    \"generate-rule\": {\r\n      \"description\": \"Generate security rule from natural language or scenario\",\r\n      \"usage\": \"generate-rule <policy> [--scenario <name>] [--apply]\"\r\n    },\r\n    \"test\": {\r\n      \"description\": \"Run detection and plugin-acceptance checks.\",\r\n      \"usage\": \"test --category [all|sensitive|injection|commands]\"\r\n    },\r\n    \"uninstall\": {\r\n      \"description\": \"Uninstall ClawVault\",\r\n      \"usage\": \"uninstall [--keep-config]\"\r\n    }\r\n  },\r\n  \"scenarios\": [\"customer_service\", \"development\", \"production\", \"finance\"]\r\n}\n\nArchive v0.2.12: 6 files, 20451 bytes\n\nFiles: _meta.json (147b), clawvault_manager.py (42386b), README.md (2915b), SECURITY.md (13304b), skill.json (2055b), SKILL.md (5635b)\n\nFile v0.2.12:SKILL.md\n\n---\nname: tophant-clawvault-installer\nversion: 0.2.12\ndescription: Install, configure, test, and uninstall ClawVault AI security proxy\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Installer\n\nInstall, configure, test, and uninstall ClawVault — the AI security proxy that protects agents from prompt injection, data leakage, and dangerous commands.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## What This Skill Does\n\nInstalls ClawVault into a dedicated venv at `~/.clawvault-env/` and writes config under `~/.ClawVault/`. See `SECURITY.md` for the full capability, risk, and design-intent disclosure.\n\n## How to Run\n\n**IMPORTANT: All commands MUST be executed using the Python script bundled with this skill.**\n\nDo NOT run `pip install`, `clawvault`, or any other command directly. Always use:\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py <command> [options]\n```\n\nWhere `SKILL_DIR` is the directory containing this SKILL.md file (typically `~/.openclaw/workspace/skills/tophant-clawvault-installer/` or `~/.openclaw/skills/tophant-clawvault-installer/`).\n\nAdd `--json` to any command for machine-readable JSON output.\n\n## Commands\n\n### /tophant-clawvault-installer install\n\nInstall ClawVault. The script creates a Python virtual environment, temporarily installs the latest GitHub repository code from `main` instead of PyPI or a fixed tag, generates config, writes OpenClaw gateway proxy config when the gateway service exists, and starts ClawVault services. By default it does **not** restart `openclaw-gateway`, because recent OpenClaw versions may disconnect or hang after a gateway restart. **No pip or system package manager needed.**\n\n```bash\n# Default: write OpenClaw gateway proxy config and start ClawVault web dashboard,\n# but do not restart openclaw-gateway.\n# ClawVault web dashboard starts at http://localhost:8766.\n# To activate OpenClaw proxy later, manually run:\n#   systemctl --user restart openclaw-gateway\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --json\n\n# Interactive setup\npython3 SKILL_DIR/clawvault_manager.py install --mode standard --json\n\n# Full control (strict mode)\npython3 SKILL_DIR/clawvault_manager.py install --mode advanced --json\n\n# Install without starting services\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json\n\n# Deprecated compatibility flag: proxy config is already written by default\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --json\n\n# Dangerous: restart gateway immediately; may disconnect or hang OpenClaw\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --restart-gateway --json\n\n# Skip OpenClaw proxy integration explicitly\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json\n```\n\n### /tophant-clawvault-installer health\n\nCheck service health and status.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py health --json\n```\n\n### /tophant-clawvault-installer generate-rule\n\nGenerate security rules from natural language.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py generate-rule \"Block all AWS credentials\" --json\npython3 SKILL_DIR/clawvault_manager.py generate-rule --scenario customer_service --apply --json\n```\n\n**Scenarios:** `customer_service`, `development`, `production`, `finance`\n\n### /tophant-clawvault-installer test\n\nRun detection tests.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py test --category all --json\npython3 SKILL_DIR/clawvault_manager.py test --category sensitive --json\n```\n\n**Categories:** `all`, `sensitive`, `injection`, `commands`\n\n### /tophant-clawvault-installer unconfigure-proxy\n\nRemove ClawVault proxy environment variables from `openclaw-gateway.service` without restarting the gateway. Use this if OpenClaw conversations hang after proxy integration.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py unconfigure-proxy --json\n```\n\n### /tophant-clawvault-installer uninstall\n\nRemove ClawVault completely (stops services, removes proxy, deletes venv and config).\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py uninstall --json\npython3 SKILL_DIR/clawvault_manager.py uninstall --keep-config --json\n```\n\n## Quick Examples\n\n```bash\n# Set the skill directory path\nCV=\"python3 ~/.openclaw/workspace/skills/tophant-clawvault-installer/clawvault_manager.py\"\n\n# Install (one command handles everything)\n$CV install --mode quick --json\n\n# Check health\n$CV health --json\n\n# Generate rule\n$CV generate-rule \"Detect database passwords\" --apply --json\n\n# Apply scenario\n$CV generate-rule --scenario customer_service --apply --json\n\n# Run tests\n$CV test --category all --json\n\n# Uninstall\n$CV uninstall --json\n```\n\n## Requirements\n\n- Python 3.10+ (with venv module)\n- Ports 8765, 8766 available\n- No pip or system packages needed — the install script creates its own virtual environment\n\n## Permissions\n\n- `execute_command` - Run installation and ClawVault commands\n- `write_files` - Create configuration files\n- `read_files` - Read configurations\n- `network` - Download packages and API calls\n\n## Security Considerations\n\nSee [SECURITY.md](./SECURITY.md) for capability disclosure, threat model, and deployment guidance.\n\n## Documentation\n\n- **Full Guide**: https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md\n- **中文文档**: https://github.com/tophant-ai/ClawVault/blob/main/doc/zh/OPENCLAW_SKILL.md\n- **Repository**: https://github.com/tophant-ai/ClawVault\n\n## License\n\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.12:README.md\n\n# ClawVault Installer Skill\r\n\r\nAI security system for OpenClaw — protect your AI agents from prompt injection, data leakage, and dangerous commands.\r\n\r\n## Before Installing\r\n\r\nThis skill installs and operates a local HTTPS-inspection proxy. Capabilities, defaults, and risks are documented in [SECURITY.md](./SECURITY.md) — please review it before installing.\r\n\r\n## Quick Start\r\n\r\n### Installation\r\n\r\n**Option 1: Install from ClawHub (Recommended)**\r\n\r\n```bash\r\n# Install from ClawHub\r\nopenclaw skills install tophant-clawvault-installer\r\n\r\n# Or use clawhub CLI\r\nclawhub install tophant-clawvault-installer\r\n```\r\n\r\n**ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault-installer\r\n\r\n**Option 2: Install from Local Repository**\r\n\r\n```bash\r\n# Copy to OpenClaw skills directory\r\ncp -r skills/tophant-clawvault-installer ~/.openclaw/skills/\r\n\r\n# Or create symbolic link\r\nln -s /path/to/ClawVault/skills/tophant-clawvault-installer ~/.openclaw/skills/tophant-clawvault-installer\r\n\r\n# Restart OpenClaw\r\nopenclaw restart\r\n```\r\n\r\n### Basic Usage\r\n\r\n```bash\r\n# Install ClawVault\r\n/tophant-clawvault-installer install --mode quick\r\n\r\n# Check health\r\n/tophant-clawvault-installer health\r\n\r\n# Generate security rule\r\n/tophant-clawvault-installer generate-rule \"Block all AWS credentials\" --apply\r\n\r\n# Run tests\r\n/tophant-clawvault-installer test --category all\r\n```\r\n\r\n## Features\r\n\r\n- **AI-guided installation** - Quick, standard, or advanced setup modes\r\n- **Dedicated virtualenv** - Installs into `~/.clawvault-env` instead of the system Python\r\n- **Latest GitHub install source** - Temporarily installs from the latest GitHub `main` code instead of PyPI or a fixed tag\r\n- **Failure-aware setup** - Reports configuration initialization failures as installation failures\r\n- **Secure dashboard defaults** - Binds the dashboard to `127.0.0.1` by default\r\n- **OpenClaw proxy integration** - Can configure OpenClaw gateway proxy settings, with `--no-proxy` opt-out\r\n- **Rule generation** - Create security rules from natural language\r\n- **Scenario templates** - Pre-configured policies (customer_service, development, production, finance)\r\n- **Detection testing** - Built-in test suites for validation\r\n- **Health monitoring** - Real-time service status\r\n\r\n## Documentation\r\n\r\n- **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first**\r\n- **Skill Reference**: [SKILL.md](./SKILL.md)\r\n- **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md)\r\n- **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md)\r\n\r\n## Requirements\r\n\r\n- Python 3.10+\r\n- OpenClaw installed\r\n- Ports 8765, 8766 available\r\n\r\n## Support\r\n\r\n- **Repository**: https://github.com/tophant-ai/ClawVault\r\n- **Issues**: https://github.com/tophant-ai/ClawVault/issues\r\n- **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n\r\n## License\r\n\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.12:_meta.json\n\n{\n  \"ownerId\": \"kn70av3n6bs6dqfaajr8drm90d82v5tt\",\n  \"slug\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.12\",\n  \"publishedAt\": 1777534856987\n}\n\nFile v0.2.12:SECURITY.md\n\n# Security Documentation\r\n\r\n## Overview\r\n\r\nClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.\r\n\r\n## Design Intent — Why Several Defaults Look Permissive\r\n\r\nClawVault is a **man-in-the-middle (MITM) inspection proxy for AI traffic**. To do its job, it necessarily exhibits behaviors that automated security scanners flag as high-risk. Every one of these is intentional. This section documents them up-front so there is no ambiguity between \"intentional capability\" and \"bug.\"\r\n\r\n| Behavior | Why it's required | How to constrain it |\r\n|---|---|---|\r\n| `ssl_verify: false` in default config | Decrypts HTTPS so detectors can scan request/response bodies. Without this, ClawVault cannot see the AI traffic it is meant to protect. | MITM only applies to hosts listed in `proxy.intercept_hosts`. Non-AI traffic passes through untouched. Limit the list if you only want specific providers inspected. |\r\n| Dashboard has no authentication by default | Default bind is `127.0.0.1` (localhost only); anyone with a shell on the machine already has more access than the dashboard exposes. | **Never** start with `--dashboard-host 0.0.0.0` on untrusted networks. Use SSH port-forwarding for remote viewing. |\r\n| The skill sees your API keys and prompts | API keys travel inside the HTTPS requests being inspected. A proxy that inspects requests will see them. | All traffic stays on `localhost`. Nothing is uploaded. Audit logs in `~/.ClawVault/audit.db` are local-only. |\r\n| Installer writes `HTTP_PROXY`/`HTTPS_PROXY` into `openclaw-gateway.service` | Routes OpenClaw traffic through ClawVault when the gateway is restarted later. The installer does not restart the gateway by default because recent OpenClaw versions may disconnect or hang after gateway restart. | Pass `--no-proxy` to skip the unit-file change. Restart `openclaw-gateway` manually only when safe to reconnect. Use `unconfigure-proxy` to remove the injected env lines. |\r\n| Installs from latest GitHub source | Temporary behavior: PyPI and fixed-tag installs are disabled so users get the newest repository code. | Review the repository before installing or run in a disposable VM for higher assurance. See \"Package Sources\" below. |\r\n\r\nIf any of these trade-offs are unacceptable for your threat model, **do not install this skill.**\r\n\r\n## How ClawVault Works\r\n\r\n### Proxy Architecture\r\n\r\nClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:\r\n\r\n```\r\nAI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs\r\n                    ↓\r\n            Detection Engine\r\n                    ↓\r\n            Dashboard (localhost:8766)\r\n```\r\n\r\n**What This Means:**\r\n- All API requests pass through ClawVault for inspection\r\n- ClawVault can see request/response content including API keys\r\n- This is intentional and necessary for threat detection\r\n- The proxy runs locally on your machine, not on external servers\r\n\r\n### SSL/TLS Verification\r\n\r\n**Default Behavior:**\r\n- ClawVault's default configuration sets `ssl_verify: false` for proxied connections\r\n- This is required for the proxy to inspect HTTPS traffic (MITM-style interception)\r\n\r\n**Security Implications:**\r\n- Disabling SSL verification allows ClawVault to decrypt and inspect encrypted traffic\r\n- This is necessary for detecting threats in API requests/responses\r\n- Traffic between your machine and LLM providers is still encrypted\r\n- The decryption happens locally on your machine, not in transit\r\n\r\n**Recommendation:**\r\n- Only use ClawVault on trusted networks\r\n- The proxy is designed for local development/testing\r\n- For production, consider using ClawVault's detection rules without the proxy\r\n\r\n## Dashboard Security\r\n\r\n### Default Configuration (Secure)\r\n\r\n```bash\r\n# Dashboard binds to localhost only\r\nclawvault start\r\n# Access: http://127.0.0.1:8766 (local machine only)\r\n```\r\n\r\n**This is the recommended configuration** for most users.\r\n\r\n### Remote Access Configuration (Risky)\r\n\r\n```bash\r\n# Dashboard accessible from any IP\r\nclawvault start --dashboard-host 0.0.0.0\r\n# Access: http://<your-ip>:8766 (anyone on network can access)\r\n```\r\n\r\n**⚠️ Security Risks:**\r\n- Dashboard shows sensitive detection data (API keys, PII, etc.)\r\n- No authentication by default\r\n- Anyone on your network can view the dashboard\r\n- Potential data exposure if misconfigured\r\n\r\n**When to Use Remote Access:**\r\n- Only in trusted, isolated networks\r\n- Behind a firewall with strict access controls\r\n- For temporary debugging/demonstration purposes\r\n\r\n**Production Recommendations:**\r\n1. Keep dashboard on localhost (127.0.0.1)\r\n2. Use SSH tunneling for remote access:\r\n   ```bash\r\n   ssh -L 8766:localhost:8766 user@remote-server\r\n   ```\r\n3. Or use a reverse proxy with authentication (nginx + basic auth)\r\n4. Never expose dashboard to public internet without authentication\r\n\r\n## Permissions Explained\r\n\r\nThe skill requires these permissions:\r\n\r\n### `execute_command`\r\n- **Purpose:** Create a Python venv in `~/.clawvault-env/`, install latest ClawVault code from GitHub `main`, write OpenClaw gateway proxy env when the gateway unit exists, and start/stop the proxy + dashboard services. Gateway restart is opt-in via `--restart-gateway`.\r\n- **Risk:** Can execute arbitrary commands on your system; gateway integration modifies one OpenClaw unit file when present and may make OpenClaw disconnect or hang after restart.\r\n- **Mitigation:** All commands are explicit in `clawvault_manager.py`. Default install writes proxy env but does not restart `openclaw-gateway`. Pass `--no-proxy` to skip the gateway change. Use `unconfigure-proxy` to remove injected proxy settings without restarting the gateway.\r\n\r\n### `write_files`\r\n- **Purpose:** Create configuration files in `~/.ClawVault/`\r\n- **Risk:** Can write to your home directory\r\n- **Mitigation:** Skill only writes to dedicated ClawVault config directory\r\n\r\n### `read_files`\r\n- **Purpose:** Read existing ClawVault configuration\r\n- **Risk:** Can read files on your system\r\n- **Mitigation:** Skill only reads from `~/.ClawVault/` directory\r\n\r\n### `network`\r\n- **Purpose:** Download ClawVault package, proxy API traffic, call local dashboard API\r\n- **Risk:** Can make network requests\r\n- **Mitigation:** Network access is essential for proxy functionality; all traffic is logged\r\n\r\n## Data Handling\r\n\r\n### What Data ClawVault Sees\r\n\r\nClawVault inspects:\r\n- API requests to LLM providers (OpenAI, Anthropic, etc.)\r\n- API responses from LLM providers\r\n- API keys and authentication tokens (in request headers)\r\n- User prompts and AI responses\r\n- Potentially sensitive data (PII, credentials) in prompts/responses\r\n\r\n### Where Data Is Stored\r\n\r\n- **Audit logs:** `~/.ClawVault/audit.db` (SQLite database)\r\n- **Detection logs:** `~/.ClawVault/logs/detection.log`\r\n- **Configuration:** `~/.ClawVault/config.yaml`\r\n\r\n### Data Retention\r\n\r\n- Audit logs are stored indefinitely by default\r\n- You can configure retention policies in `config.yaml`\r\n- To clear logs: `rm ~/.ClawVault/audit.db`\r\n\r\n### Data Privacy\r\n\r\n- All data stays on your local machine\r\n- ClawVault does not send data to external servers (except when proxying to LLM providers)\r\n- No telemetry or analytics are collected\r\n- You control all data through local configuration files\r\n\r\n## Installation Security\r\n\r\n### Package Sources\r\n\r\nThe skill temporarily installs ClawVault from the latest GitHub repository code on `main`. PyPI and fixed-tag install paths are currently disabled.\r\n\r\n```\r\npip install git+https://github.com/tophant-ai/ClawVault.git@main\r\n```\r\n\r\nThe installer does **not** perform:\r\n- Checksum verification\r\n- Signature verification\r\n- Dependency-graph auditing\r\n\r\n**Supply-chain risk:** Installing latest code from GitHub carries supply-chain risk and is less reproducible than a pinned release. This behavior is temporary; review the repository before installing in sensitive environments.\r\n\r\n**How to reduce supply-chain exposure:**\r\n1. Review the repository before installing: https://github.com/tophant-ai/ClawVault\r\n2. Check out a specific commit/tag locally and point `pip` at that path instead\r\n3. Run `./venv/bin/pip install git+https://github.com/tophant-ai/ClawVault.git@<sha>` with an audited commit SHA\r\n4. Run the installer inside a disposable VM or container\r\n5. Subscribe to the repo's security advisories on GitHub\r\n\r\n### Installation Process\r\n\r\nWhat happens, in order, during `install --mode quick`:\r\n\r\n1. Verifies Python version (≥ 3.10)\r\n2. Creates a **dedicated virtual environment** at `~/.clawvault-env/` (isolates ClawVault from system Python — nothing is installed globally)\r\n3. Runs `pip install git+https://github.com/tophant-ai/ClawVault.git@main` inside that venv\r\n4. Copies `config.example.yaml` from the installed package to `~/.ClawVault/config.yaml`; if the template is unavailable, generates a complete 11-section default config\r\n5. If `~/.config/systemd/user/openclaw-gateway.service` exists, injects `HTTP_PROXY`/`HTTPS_PROXY`/`NO_PROXY`/`NODE_TLS_REJECT_UNAUTHORIZED` into it, then tells the user to manually run `systemctl --user restart openclaw-gateway` later when safe. Skipped if `--no-proxy` is passed or if the service file is absent.\r\n6. Launches the proxy (port 8765) and dashboard (port 8766) via `subprocess.Popen`. Skipped if `--no-start` is passed. `openclaw-gateway` is only restarted when `--restart-gateway` is explicitly requested.\r\n\r\nEverything the skill touches lives under three predictable paths:\r\n- `~/.clawvault-env/` — the Python venv\r\n- `~/.ClawVault/` — config, audit DB, logs, certs, state\r\n- `~/.config/systemd/user/openclaw-gateway.service` — **modified only if it already exists**\r\n\r\n## Threat Model\r\n\r\n### What ClawVault Protects Against\r\n\r\n✅ **Prompt injection attacks** - Detects attempts to manipulate AI behavior\r\n✅ **Data leakage** - Identifies PII, credentials, API keys in prompts/responses\r\n✅ **Dangerous commands** - Flags risky shell commands in AI outputs\r\n✅ **Jailbreak attempts** - Detects attempts to bypass AI safety measures\r\n\r\n### What ClawVault Does NOT Protect Against\r\n\r\n❌ **Malicious ClawVault package** - If the upstream package is compromised, the skill will install it\r\n❌ **Local system compromise** - If your machine is compromised, ClawVault data can be accessed\r\n❌ **Network attacks** - ClawVault does not protect against network-level attacks\r\n❌ **Supply chain attacks** - No verification of package integrity during installation\r\n\r\n## Best Practices\r\n\r\n### For Development/Testing\r\n\r\n```bash\r\n# Safe configuration for local development\r\nclawvault start --dashboard-host 127.0.0.1 --mode interactive\r\n\r\n# Review detection logs regularly\r\ntail -f ~/.ClawVault/logs/detection.log\r\n\r\n# Test with non-sensitive data first\r\nclawvault test --category all\r\n```\r\n\r\n### For Production\r\n\r\n```bash\r\n# Use strict mode for automated blocking\r\nclawvault start --mode strict\r\n\r\n# Keep dashboard local, use SSH tunnel for remote access\r\nssh -L 8766:localhost:8766 user@server\r\n\r\n# Configure audit retention\r\n# Edit ~/.ClawVault/config.yaml:\r\naudit:\r\n  enabled: true\r\n  retention_days: 30\r\n```\r\n\r\n### For Sensitive Environments\r\n\r\n1. **Review the source code** before installation\r\n2. **Run in isolated environment** (VM, container)\r\n3. **Use firewall rules** to restrict network access\r\n4. **Rotate API keys** regularly\r\n5. **Monitor audit logs** for suspicious activity\r\n6. **Disable dashboard** if not needed: `--no-dashboard`\r\n\r\n## Security Checklist\r\n\r\nBefore installing ClawVault skill:\r\n\r\n- [ ] Reviewed ClawVault package source code\r\n- [ ] Understand that ClawVault will see API keys and request content\r\n- [ ] Verified dashboard will bind to localhost (not 0.0.0.0)\r\n- [ ] Understand SSL verification implications\r\n- [ ] Have plan for audit log retention/cleanup\r\n- [ ] Running in appropriate environment (dev/test/prod)\r\n- [ ] Firewall configured if using remote dashboard\r\n- [ ] Understand what permissions the skill requires\r\n\r\n## Reporting Security Issues\r\n\r\nIf you discover a security vulnerability in ClawVault or this skill:\r\n\r\n**For Critical Vulnerabilities (RCE, data exfiltration, credential theft):**\r\n1. Open a [GitHub Security Advisory](https://github.com/tophant-ai/ClawVault/security/advisories/new) (private disclosure)\r\n2. Or email: security@tophant.com\r\n3. Include detailed description and reproduction steps\r\n4. We will respond within 48 hours and work on a fix\r\n\r\n**For Non-Critical Issues (documentation errors, configuration issues, minor bugs):**\r\n1. Open a public [GitHub Issue](https://github.com/tophant-ai/ClawVault/issues/new)\r\n2. Tag with `security` label\r\n3. Community can discuss and contribute fixes\r\n\r\nWe encourage responsible disclosure and will credit security researchers who report vulnerabilities.\r\n\r\n## Additional Resources\r\n\r\n- **ClawVault Documentation:** https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n- **OpenClaw Security:** https://docs.openclaw.ai/gateway/security\r\n- **Threat Model:** https://github.com/tophant-ai/ClawVault/blob/main/doc/architecture.md\r\n\r\n## License\r\n\r\nThis security documentation is part of the ClawVault project.\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.12:skill.json\n\n{\r\n  \"name\": \"tophant-clawvault-installer\",\r\n  \"version\": \"0.2.12\",\r\n  \"description\": \"AI security system that protects agents from prompt injection, data leakage, and dangerous commands. Operates as local HTTP proxy to inspect traffic. Review SECURITY.md before installing.\",\r\n  \"author\": \"Tophant SPAI Lab\",\r\n  \"homepage\": \"https://github.com/tophant-ai/ClawVault\",\r\n  \"repository\": \"https://github.com/tophant-ai/ClawVault\",\r\n  \"main\": \"clawvault_manager.py\",\r\n  \"permissions\": [\"execute_command\", \"write_files\", \"read_files\", \"network\"],\r\n  \"permissions_rationale\": {\r\n    \"execute_command\": \"Required to run pip install and start/stop ClawVault services\",\r\n    \"write_files\": \"Creates configuration files in ~/.ClawVault/ directory\",\r\n    \"read_files\": \"Reads ClawVault configuration from ~/.ClawVault/\",\r\n    \"network\": \"Downloads ClawVault package and proxies AI traffic for inspection\"\r\n  },\r\n  \"tags\": [\"security\", \"ai-protection\", \"proxy\", \"threat-detection\", \"privacy\"],\r\n  \"requirements\": [\"pyyaml\"],\r\n  \"python_version\": \">=3.10\",\r\n  \"commands\": {\r\n    \"install\": {\r\n      \"description\": \"Install ClawVault with specified mode. Creates venv, installs latest GitHub repository code, generates config, writes OpenClaw proxy config, starts services, and does not restart openclaw-gateway by default.\",\r\n      \"usage\": \"install --mode [quick|standard|advanced] [--no-start] [--no-proxy] [--restart-gateway]\"\r\n    },\r\n    \"health\": {\r\n      \"description\": \"Check ClawVault health status\",\r\n      \"usage\": \"health\"\r\n    },\r\n    \"generate-rule\": {\r\n      \"description\": \"Generate security rule from natural language or scenario\",\r\n      \"usage\": \"generate-rule <policy> [--scenario <name>] [--apply]\"\r\n    },\r\n    \"test\": {\r\n      \"description\": \"Run detection tests\",\r\n      \"usage\": \"test --category [all|sensitive|injection|commands]\"\r\n    },\r\n    \"uninstall\": {\r\n      \"description\": \"Uninstall ClawVault\",\r\n      \"usage\": \"uninstall [--keep-config]\"\r\n    }\r\n  },\r\n  \"scenarios\": [\"customer_service\", \"development\", \"production\", \"finance\"]\r\n}\n\nArchive v0.2.11: 6 files, 20438 bytes\n\nFiles: _meta.json (147b), clawvault_manager.py (42411b), README.md (2915b), SECURITY.md (13304b), skill.json (2055b), SKILL.md (5635b)\n\nFile v0.2.11:SKILL.md\n\n---\nname: tophant-clawvault-installer\nversion: 0.2.11\ndescription: Install, configure, test, and uninstall ClawVault AI security proxy\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Installer\n\nInstall, configure, test, and uninstall ClawVault — the AI security proxy that protects agents from prompt injection, data leakage, and dangerous commands.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## What This Skill Does\n\nInstalls ClawVault into a dedicated venv at `~/.clawvault-env/` and writes config under `~/.ClawVault/`. See `SECURITY.md` for the full capability, risk, and design-intent disclosure.\n\n## How to Run\n\n**IMPORTANT: All commands MUST be executed using the Python script bundled with this skill.**\n\nDo NOT run `pip install`, `clawvault`, or any other command directly. Always use:\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py <command> [options]\n```\n\nWhere `SKILL_DIR` is the directory containing this SKILL.md file (typically `~/.openclaw/workspace/skills/tophant-clawvault-installer/` or `~/.openclaw/skills/tophant-clawvault-installer/`).\n\nAdd `--json` to any command for machine-readable JSON output.\n\n## Commands\n\n### /tophant-clawvault-installer install\n\nInstall ClawVault. The script creates a Python virtual environment, temporarily installs the latest GitHub repository code from `main` instead of PyPI or a fixed tag, generates config, writes OpenClaw gateway proxy config when the gateway service exists, and starts ClawVault services. By default it does **not** restart `openclaw-gateway`, because recent OpenClaw versions may disconnect or hang after a gateway restart. **No pip or system package manager needed.**\n\n```bash\n# Default: write OpenClaw gateway proxy config and start ClawVault web dashboard,\n# but do not restart openclaw-gateway.\n# ClawVault web dashboard starts at http://localhost:8766.\n# To activate OpenClaw proxy later, manually run:\n#   systemctl --user restart openclaw-gateway\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --json\n\n# Interactive setup\npython3 SKILL_DIR/clawvault_manager.py install --mode standard --json\n\n# Full control (strict mode)\npython3 SKILL_DIR/clawvault_manager.py install --mode advanced --json\n\n# Install without starting services\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json\n\n# Deprecated compatibility flag: proxy config is already written by default\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --json\n\n# Dangerous: restart gateway immediately; may disconnect or hang OpenClaw\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --restart-gateway --json\n\n# Skip OpenClaw proxy integration explicitly\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json\n```\n\n### /tophant-clawvault-installer health\n\nCheck service health and status.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py health --json\n```\n\n### /tophant-clawvault-installer generate-rule\n\nGenerate security rules from natural language.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py generate-rule \"Block all AWS credentials\" --json\npython3 SKILL_DIR/clawvault_manager.py generate-rule --scenario customer_service --apply --json\n```\n\n**Scenarios:** `customer_service`, `development`, `production`, `finance`\n\n### /tophant-clawvault-installer test\n\nRun detection tests.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py test --category all --json\npython3 SKILL_DIR/clawvault_manager.py test --category sensitive --json\n```\n\n**Categories:** `all`, `sensitive`, `injection`, `commands`\n\n### /tophant-clawvault-installer unconfigure-proxy\n\nRemove ClawVault proxy environment variables from `openclaw-gateway.service` without restarting the gateway. Use this if OpenClaw conversations hang after proxy integration.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py unconfigure-proxy --json\n```\n\n### /tophant-clawvault-installer uninstall\n\nRemove ClawVault completely (stops services, removes proxy, deletes venv and config).\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py uninstall --json\npython3 SKILL_DIR/clawvault_manager.py uninstall --keep-config --json\n```\n\n## Quick Examples\n\n```bash\n# Set the skill directory path\nCV=\"python3 ~/.openclaw/workspace/skills/tophant-clawvault-installer/clawvault_manager.py\"\n\n# Install (one command handles everything)\n$CV install --mode quick --json\n\n# Check health\n$CV health --json\n\n# Generate rule\n$CV generate-rule \"Detect database passwords\" --apply --json\n\n# Apply scenario\n$CV generate-rule --scenario customer_service --apply --json\n\n# Run tests\n$CV test --category all --json\n\n# Uninstall\n$CV uninstall --json\n```\n\n## Requirements\n\n- Python 3.10+ (with venv module)\n- Ports 8765, 8766 available\n- No pip or system packages needed — the install script creates its own virtual environment\n\n## Permissions\n\n- `execute_command` - Run installation and ClawVault commands\n- `write_files` - Create configuration files\n- `read_files` - Read configurations\n- `network` - Download packages and API calls\n\n## Security Considerations\n\nSee [SECURITY.md](./SECURITY.md) for capability disclosure, threat model, and deployment guidance.\n\n## Documentation\n\n- **Full Guide**: https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md\n- **中文文档**: https://github.com/tophant-ai/ClawVault/blob/main/doc/zh/OPENCLAW_SKILL.md\n- **Repository**: https://github.com/tophant-ai/ClawVault\n\n## License\n\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.11:README.md\n\n# ClawVault Installer Skill\r\n\r\nAI security system for OpenClaw — protect your AI agents from prompt injection, data leakage, and dangerous commands.\r\n\r\n## Before Installing\r\n\r\nThis skill installs and operates a local HTTPS-inspection proxy. Capabilities, defaults, and risks are documented in [SECURITY.md](./SECURITY.md) — please review it before installing.\r\n\r\n## Quick Start\r\n\r\n### Installation\r\n\r\n**Option 1: Install from ClawHub (Recommended)**\r\n\r\n```bash\r\n# Install from ClawHub\r\nopenclaw skills install tophant-clawvault-installer\r\n\r\n# Or use clawhub CLI\r\nclawhub install tophant-clawvault-installer\r\n```\r\n\r\n**ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault-installer\r\n\r\n**Option 2: Install from Local Repository**\r\n\r\n```bash\r\n# Copy to OpenClaw skills directory\r\ncp -r skills/tophant-clawvault-installer ~/.openclaw/skills/\r\n\r\n# Or create symbolic link\r\nln -s /path/to/ClawVault/skills/tophant-clawvault-installer ~/.openclaw/skills/tophant-clawvault-installer\r\n\r\n# Restart OpenClaw\r\nopenclaw restart\r\n```\r\n\r\n### Basic Usage\r\n\r\n```bash\r\n# Install ClawVault\r\n/tophant-clawvault-installer install --mode quick\r\n\r\n# Check health\r\n/tophant-clawvault-installer health\r\n\r\n# Generate security rule\r\n/tophant-clawvault-installer generate-rule \"Block all AWS credentials\" --apply\r\n\r\n# Run tests\r\n/tophant-clawvault-installer test --category all\r\n```\r\n\r\n## Features\r\n\r\n- **AI-guided installation** - Quick, standard, or advanced setup modes\r\n- **Dedicated virtualenv** - Installs into `~/.clawvault-env` instead of the system Python\r\n- **Latest GitHub install source** - Temporarily installs from the latest GitHub `main` code instead of PyPI or a fixed tag\r\n- **Failure-aware setup** - Reports configuration initialization failures as installation failures\r\n- **Secure dashboard defaults** - Binds the dashboard to `127.0.0.1` by default\r\n- **OpenClaw proxy integration** - Can configure OpenClaw gateway proxy settings, with `--no-proxy` opt-out\r\n- **Rule generation** - Create security rules from natural language\r\n- **Scenario templates** - Pre-configured policies (customer_service, development, production, finance)\r\n- **Detection testing** - Built-in test suites for validation\r\n- **Health monitoring** - Real-time service status\r\n\r\n## Documentation\r\n\r\n- **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first**\r\n- **Skill Reference**: [SKILL.md](./SKILL.md)\r\n- **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md)\r\n- **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md)\r\n\r\n## Requirements\r\n\r\n- Python 3.10+\r\n- OpenClaw installed\r\n- Ports 8765, 8766 available\r\n\r\n## Support\r\n\r\n- **Repository**: https://github.com/tophant-ai/ClawVault\r\n- **Issues**: https://github.com/tophant-ai/ClawVault/issues\r\n- **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n\r\n## License\r\n\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.11:_meta.json\n\n{\n  \"ownerId\": \"kn70av3n6bs6dqfaajr8drm90d82v5tt\",\n  \"slug\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.11\",\n  \"publishedAt\": 1777532074283\n}\n\nFile v0.2.11:SECURITY.md\n\n# Security Documentation\r\n\r\n## Overview\r\n\r\nClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.\r\n\r\n## Design Intent — Why Several Defaults Look Permissive\r\n\r\nClawVault is a **man-in-the-middle (MITM) inspection proxy for AI traffic**. To do its job, it necessarily exhibits behaviors that automated security scanners flag as high-risk. Every one of these is intentional. This section documents them up-front so there is no ambiguity between \"intentional capability\" and \"bug.\"\r\n\r\n| Behavior | Why it's required | How to constrain it |\r\n|---|---|---|\r\n| `ssl_verify: false` in default config | Decrypts HTTPS so detectors can scan request/response bodies. Without this, ClawVault cannot see the AI traffic it is meant to protect. | MITM only applies to hosts listed in `proxy.intercept_hosts`. Non-AI traffic passes through untouched. Limit the list if you only want specific providers inspected. |\r\n| Dashboard has no authentication by default | Default bind is `127.0.0.1` (localhost only); anyone with a shell on the machine already has more access than the dashboard exposes. | **Never** start with `--dashboard-host 0.0.0.0` on untrusted networks. Use SSH port-forwarding for remote viewing. |\r\n| The skill sees your API keys and prompts | API keys travel inside the HTTPS requests being inspected. A proxy that inspects requests will see them. | All traffic stays on `localhost`. Nothing is uploaded. Audit logs in `~/.ClawVault/audit.db` are local-only. |\r\n| Installer writes `HTTP_PROXY`/`HTTPS_PROXY` into `openclaw-gateway.service` | Routes OpenClaw traffic through ClawVault when the gateway is restarted later. The installer does not restart the gateway by default because recent OpenClaw versions may disconnect or hang after gateway restart. | Pass `--no-proxy` to skip the unit-file change. Restart `openclaw-gateway` manually only when safe to reconnect. Use `unconfigure-proxy` to remove the injected env lines. |\r\n| Installs from latest GitHub source | Temporary behavior: PyPI and fixed-tag installs are disabled so users get the newest repository code. | Review the repository before installing or run in a disposable VM for higher assurance. See \"Package Sources\" below. |\r\n\r\nIf any of these trade-offs are unacceptable for your threat model, **do not install this skill.**\r\n\r\n## How ClawVault Works\r\n\r\n### Proxy Architecture\r\n\r\nClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:\r\n\r\n```\r\nAI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs\r\n                    ↓\r\n            Detection Engine\r\n                    ↓\r\n            Dashboard (localhost:8766)\r\n```\r\n\r\n**What This Means:**\r\n- All API requests pass through ClawVault for inspection\r\n- ClawVault can see request/response content including API keys\r\n- This is intentional and necessary for threat detection\r\n- The proxy runs locally on your machine, not on external servers\r\n\r\n### SSL/TLS Verification\r\n\r\n**Default Behavior:**\r\n- ClawVault's default configuration sets `ssl_verify: false` for proxied connections\r\n- This is required for the proxy to inspect HTTPS traffic (MITM-style interception)\r\n\r\n**Security Implications:**\r\n- Disabling SSL verification allows ClawVault to decrypt and inspect encrypted traffic\r\n- This is necessary for detecting threats in API requests/responses\r\n- Traffic between your machine and LLM providers is still encrypted\r\n- The decryption happens locally on your machine, not in transit\r\n\r\n**Recommendation:**\r\n- Only use ClawVault on trusted networks\r\n- The proxy is designed for local development/testing\r\n- For production, consider using ClawVault's detection rules without the proxy\r\n\r\n## Dashboard Security\r\n\r\n### Default Configuration (Secure)\r\n\r\n```bash\r\n# Dashboard binds to localhost only\r\nclawvault start\r\n# Access: http://127.0.0.1:8766 (local machine only)\r\n```\r\n\r\n**This is the recommended configuration** for most users.\r\n\r\n### Remote Access Configuration (Risky)\r\n\r\n```bash\r\n# Dashboard accessible from any IP\r\nclawvault start --dashboard-host 0.0.0.0\r\n# Access: http://<your-ip>:8766 (anyone on network can access)\r\n```\r\n\r\n**⚠️ Security Risks:**\r\n- Dashboard shows sensitive detection data (API keys, PII, etc.)\r\n- No authentication by default\r\n- Anyone on your network can view the dashboard\r\n- Potential data exposure if misconfigured\r\n\r\n**When to Use Remote Access:**\r\n- Only in trusted, isolated networks\r\n- Behind a firewall with strict access controls\r\n- For temporary debugging/demonstration purposes\r\n\r\n**Production Recommendations:**\r\n1. Keep dashboard on localhost (127.0.0.1)\r\n2. Use SSH tunneling for remote access:\r\n   ```bash\r\n   ssh -L 8766:localhost:8766 user@remote-server\r\n   ```\r\n3. Or use a reverse proxy with authentication (nginx + basic auth)\r\n4. Never expose dashboard to public internet without authentication\r\n\r\n## Permissions Explained\r\n\r\nThe skill requires these permissions:\r\n\r\n### `execute_command`\r\n- **Purpose:** Create a Python venv in `~/.clawvault-env/`, install latest ClawVault code from GitHub `main`, write OpenClaw gateway proxy env when the gateway unit exists, and start/stop the proxy + dashboard services. Gateway restart is opt-in via `--restart-gateway`.\r\n- **Risk:** Can execute arbitrary commands on your system; gateway integration modifies one OpenClaw unit file when present and may make OpenClaw disconnect or hang after restart.\r\n- **Mitigation:** All commands are explicit in `clawvault_manager.py`. Default install writes proxy env but does not restart `openclaw-gateway`. Pass `--no-proxy` to skip the gateway change. Use `unconfigure-proxy` to remove injected proxy settings without restarting the gateway.\r\n\r\n### `write_files`\r\n- **Purpose:** Create configuration files in `~/.ClawVault/`\r\n- **Risk:** Can write to your home directory\r\n- **Mitigation:** Skill only writes to dedicated ClawVault config directory\r\n\r\n### `read_files`\r\n- **Purpose:** Read existing ClawVault configuration\r\n- **Risk:** Can read files on your system\r\n- **Mitigation:** Skill only reads from `~/.ClawVault/` directory\r\n\r\n### `network`\r\n- **Purpose:** Download ClawVault package, proxy API traffic, call local dashboard API\r\n- **Risk:** Can make network requests\r\n- **Mitigation:** Network access is essential for proxy functionality; all traffic is logged\r\n\r\n## Data Handling\r\n\r\n### What Data ClawVault Sees\r\n\r\nClawVault inspects:\r\n- API requests to LLM providers (OpenAI, Anthropic, etc.)\r\n- API responses from LLM providers\r\n- API keys and authentication tokens (in request headers)\r\n- User prompts and AI responses\r\n- Potentially sensitive data (PII, credentials) in prompts/responses\r\n\r\n### Where Data Is Stored\r\n\r\n- **Audit logs:** `~/.ClawVault/audit.db` (SQLite database)\r\n- **Detection logs:** `~/.ClawVault/logs/detection.log`\r\n- **Configuration:** `~/.ClawVault/config.yaml`\r\n\r\n### Data Retention\r\n\r\n- Audit logs are stored indefinitely by default\r\n- You can configure retention policies in `config.yaml`\r\n- To clear logs: `rm ~/.ClawVault/audit.db`\r\n\r\n### Data Privacy\r\n\r\n- All data stays on your local machine\r\n- ClawVault does not send data to external servers (except when proxying to LLM providers)\r\n- No telemetry or analytics are collected\r\n- You control all data through local configuration files\r\n\r\n## Installation Security\r\n\r\n### Package Sources\r\n\r\nThe skill temporarily installs ClawVault from the latest GitHub repository code on `main`. PyPI and fixed-tag install paths are currently disabled.\r\n\r\n```\r\npip install git+https://github.com/tophant-ai/ClawVault.git@main\r\n```\r\n\r\nThe installer does **not** perform:\r\n- Checksum verification\r\n- Signature verification\r\n- Dependency-graph auditing\r\n\r\n**Supply-chain risk:** Installing latest code from GitHub carries supply-chain risk and is less reproducible than a pinned release. This behavior is temporary; review the repository before installing in sensitive environments.\r\n\r\n**How to reduce supply-chain exposure:**\r\n1. Review the repository before installing: https://github.com/tophant-ai/ClawVault\r\n2. Check out a specific commit/tag locally and point `pip` at that path instead\r\n3. Run `./venv/bin/pip install git+https://github.com/tophant-ai/ClawVault.git@<sha>` with an audited commit SHA\r\n4. Run the installer inside a disposable VM or container\r\n5. Subscribe to the repo's security advisories on GitHub\r\n\r\n### Installation Process\r\n\r\nWhat happens, in order, during `install --mode quick`:\r\n\r\n1. Verifies Python version (≥ 3.10)\r\n2. Creates a **dedicated virtual environment** at `~/.clawvault-env/` (isolates ClawVault from system Python — nothing is installed globally)\r\n3. Runs `pip install git+https://github.com/tophant-ai/ClawVault.git@main` inside that venv\r\n4. Copies `config.example.yaml` from the installed package to `~/.ClawVault/config.yaml`; if the template is unavailable, generates a complete 11-section default config\r\n5. If `~/.config/systemd/user/openclaw-gateway.service` exists, injects `HTTP_PROXY`/`HTTPS_PROXY`/`NO_PROXY`/`NODE_TLS_REJECT_UNAUTHORIZED` into it, then tells the user to manually run `systemctl --user restart openclaw-gateway` later when safe. Skipped if `--no-proxy` is passed or if the service file is absent.\r\n6. Launches the proxy (port 8765) and dashboard (port 8766) via `subprocess.Popen`. Skipped if `--no-start` is passed. `openclaw-gateway` is only restarted when `--restart-gateway` is explicitly requested.\r\n\r\nEverything the skill touches lives under three predictable paths:\r\n- `~/.clawvault-env/` — the Python venv\r\n- `~/.ClawVault/` — config, audit DB, logs, certs, state\r\n- `~/.config/systemd/user/openclaw-gateway.service` — **modified only if it already exists**\r\n\r\n## Threat Model\r\n\r\n### What ClawVault Protects Against\r\n\r\n✅ **Prompt injection attacks** - Detects attempts to manipulate AI behavior\r\n✅ **Data leakage** - Identifies PII, credentials, API keys in prompts/responses\r\n✅ **Dangerous commands** - Flags risky shell commands in AI outputs\r\n✅ **Jailbreak attempts** - Detects attempts to bypass AI safety measures\r\n\r\n### What ClawVault Does NOT Protect Against\r\n\r\n❌ **Malicious ClawVault package** - If the upstream package is compromised, the skill will install it\r\n❌ **Local system compromise** - If your machine is compromised, ClawVault data can be accessed\r\n❌ **Network attacks** - ClawVault does not protect against network-level attacks\r\n❌ **Supply chain attacks** - No verification of package integrity during installation\r\n\r\n## Best Practices\r\n\r\n### For Development/Testing\r\n\r\n```bash\r\n# Safe configuration for local development\r\nclawvault start --dashboard-host 127.0.0.1 --mode interactive\r\n\r\n# Review detection logs regularly\r\ntail -f ~/.ClawVault/logs/detection.log\r\n\r\n# Test with non-sensitive data first\r\nclawvault test --category all\r\n```\r\n\r\n### For Production\r\n\r\n```bash\r\n# Use strict mode for automated blocking\r\nclawvault start --mode strict\r\n\r\n# Keep dashboard local, use SSH tunnel for remote access\r\nssh -L 8766:localhost:8766 user@server\r\n\r\n# Configure audit retention\r\n# Edit ~/.ClawVault/config.yaml:\r\naudit:\r\n  enabled: true\r\n  retention_days: 30\r\n```\r\n\r\n### For Sensitive Environments\r\n\r\n1. **Review the source code** before installation\r\n2. **Run in isolated environment** (VM, container)\r\n3. **Use firewall rules** to restrict network access\r\n4. **Rotate API keys** regularly\r\n5. **Monitor audit logs** for suspicious activity\r\n6. **Disable dashboard** if not needed: `--no-dashboard`\r\n\r\n## Security Checklist\r\n\r\nBefore installing ClawVault skill:\r\n\r\n- [ ] Reviewed ClawVault package source code\r\n- [ ] Understand that ClawVault will see API keys and request content\r\n- [ ] Verified dashboard will bind to localhost (not 0.0.0.0)\r\n- [ ] Understand SSL verification implications\r\n- [ ] Have plan for audit log retention/cleanup\r\n- [ ] Running in appropriate environment (dev/test/prod)\r\n- [ ] Firewall configured if using remote dashboard\r\n- [ ] Understand what permissions the skill requires\r\n\r\n## Reporting Security Issues\r\n\r\nIf you discover a security vulnerability in ClawVault or this skill:\r\n\r\n**For Critical Vulnerabilities (RCE, data exfiltration, credential theft):**\r\n1. Open a [GitHub Security Advisory](https://github.com/tophant-ai/ClawVault/security/advisories/new) (private disclosure)\r\n2. Or email: security@tophant.com\r\n3. Include detailed description and reproduction steps\r\n4. We will respond within 48 hours and work on a fix\r\n\r\n**For Non-Critical Issues (documentation errors, configuration issues, minor bugs):**\r\n1. Open a public [GitHub Issue](https://github.com/tophant-ai/ClawVault/issues/new)\r\n2. Tag with `security` label\r\n3. Community can discuss and contribute fixes\r\n\r\nWe encourage responsible disclosure and will credit security researchers who report vulnerabilities.\r\n\r\n## Additional Resources\r\n\r\n- **ClawVault Documentation:** https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n- **OpenClaw Security:** https://docs.openclaw.ai/gateway/security\r\n- **Threat Model:** https://github.com/tophant-ai/ClawVault/blob/main/doc/architecture.md\r\n\r\n## License\r\n\r\nThis security documentation is part of the ClawVault project.\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.11:skill.json\n\n{\r\n  \"name\": \"tophant-clawvault-installer\",\r\n  \"version\": \"0.2.11\",\r\n  \"description\": \"AI security system that protects agents from prompt injection, data leakage, and dangerous commands. Operates as local HTTP proxy to inspect traffic. Review SECURITY.md before installing.\",\r\n  \"author\": \"Tophant SPAI Lab\",\r\n  \"homepage\": \"https://github.com/tophant-ai/ClawVault\",\r\n  \"repository\": \"https://github.com/tophant-ai/ClawVault\",\r\n  \"main\": \"clawvault_manager.py\",\r\n  \"permissions\": [\"execute_command\", \"write_files\", \"read_files\", \"network\"],\r\n  \"permissions_rationale\": {\r\n    \"execute_command\": \"Required to run pip install and start/stop ClawVault services\",\r\n    \"write_files\": \"Creates configuration files in ~/.ClawVault/ directory\",\r\n    \"read_files\": \"Reads ClawVault configuration from ~/.ClawVault/\",\r\n    \"network\": \"Downloads ClawVault package and proxies AI traffic for inspection\"\r\n  },\r\n  \"tags\": [\"security\", \"ai-protection\", \"proxy\", \"threat-detection\", \"privacy\"],\r\n  \"requirements\": [\"pyyaml\"],\r\n  \"python_version\": \">=3.10\",\r\n  \"commands\": {\r\n    \"install\": {\r\n      \"description\": \"Install ClawVault with specified mode. Creates venv, installs latest GitHub repository code, generates config, writes OpenClaw proxy config, starts services, and does not restart openclaw-gateway by default.\",\r\n      \"usage\": \"install --mode [quick|standard|advanced] [--no-start] [--no-proxy] [--restart-gateway]\"\r\n    },\r\n    \"health\": {\r\n      \"description\": \"Check ClawVault health status\",\r\n      \"usage\": \"health\"\r\n    },\r\n    \"generate-rule\": {\r\n      \"description\": \"Generate security rule from natural language or scenario\",\r\n      \"usage\": \"generate-rule <policy> [--scenario <name>] [--apply]\"\r\n    },\r\n    \"test\": {\r\n      \"description\": \"Run detection tests\",\r\n      \"usage\": \"test --category [all|sensitive|injection|commands]\"\r\n    },\r\n    \"uninstall\": {\r\n      \"description\": \"Uninstall ClawVault\",\r\n      \"usage\": \"uninstall [--keep-config]\"\r\n    }\r\n  },\r\n  \"scenarios\": [\"customer_service\", \"development\", \"production\", \"finance\"]\r\n}\n\nArchive v0.2.10: 6 files, 19282 bytes\n\nFiles: _meta.json (147b), clawvault_manager.py (37771b), README.md (2889b), SECURITY.md (13209b), skill.json (1932b), SKILL.md (4576b)\n\nFile v0.2.10:SKILL.md\n\n---\nname: tophant-clawvault-installer\nversion: 0.2.9\ndescription: Install, configure, test, and uninstall ClawVault AI security proxy\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Installer\n\nInstall, configure, test, and uninstall ClawVault — the AI security proxy that protects agents from prompt injection, data leakage, and dangerous commands.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## What This Skill Does\n\nInstalls ClawVault into a dedicated venv at `~/.clawvault-env/` and writes config under `~/.ClawVault/`. See `SECURITY.md` for the full capability, risk, and design-intent disclosure.\n\n## How to Run\n\n**IMPORTANT: All commands MUST be executed using the Python script bundled with this skill.**\n\nDo NOT run `pip install`, `clawvault`, or any other command directly. Always use:\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py <command> [options]\n```\n\nWhere `SKILL_DIR` is the directory containing this SKILL.md file (typically `~/.openclaw/workspace/skills/tophant-clawvault-installer/` or `~/.openclaw/skills/tophant-clawvault-installer/`).\n\nAdd `--json` to any command for machine-readable JSON output.\n\n## Commands\n\n### /tophant-clawvault-installer install\n\nInstall ClawVault. The script handles everything automatically: creates a Python virtual environment, installs from pinned package sources (`clawvault>=0.1.0,<1.0.0` with GitHub tag `v0.1.0` fallback), generates config, integrates OpenClaw proxy, and starts services. **No pip or system package manager needed.**\n\n```bash\n# Recommended: one command does everything\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --json\n\n# Interactive setup\npython3 SKILL_DIR/clawvault_manager.py install --mode standard --json\n\n# Full control (strict mode)\npython3 SKILL_DIR/clawvault_manager.py install --mode advanced --json\n\n# Install without starting services\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json\n\n# Skip OpenClaw proxy integration\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json\n```\n\n### /tophant-clawvault-installer health\n\nCheck service health and status.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py health --json\n```\n\n### /tophant-clawvault-installer generate-rule\n\nGenerate security rules from natural language.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py generate-rule \"Block all AWS credentials\" --json\npython3 SKILL_DIR/clawvault_manager.py generate-rule --scenario customer_service --apply --json\n```\n\n**Scenarios:** `customer_service`, `development`, `production`, `finance`\n\n### /tophant-clawvault-installer test\n\nRun detection tests.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py test --category all --json\npython3 SKILL_DIR/clawvault_manager.py test --category sensitive --json\n```\n\n**Categories:** `all`, `sensitive`, `injection`, `commands`\n\n### /tophant-clawvault-installer uninstall\n\nRemove ClawVault completely (stops services, removes proxy, deletes venv and config).\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py uninstall --json\npython3 SKILL_DIR/clawvault_manager.py uninstall --keep-config --json\n```\n\n## Quick Examples\n\n```bash\n# Set the skill directory path\nCV=\"python3 ~/.openclaw/workspace/skills/tophant-clawvault-installer/clawvault_manager.py\"\n\n# Install (one command handles everything)\n$CV install --mode quick --json\n\n# Check health\n$CV health --json\n\n# Generate rule\n$CV generate-rule \"Detect database passwords\" --apply --json\n\n# Apply scenario\n$CV generate-rule --scenario customer_service --apply --json\n\n# Run tests\n$CV test --category all --json\n\n# Uninstall\n$CV uninstall --json\n```\n\n## Requirements\n\n- Python 3.10+ (with venv module)\n- Ports 8765, 8766 available\n- No pip or system packages needed — the install script creates its own virtual environment\n\n## Permissions\n\n- `execute_command` - Run installation and ClawVault commands\n- `write_files` - Create configuration files\n- `read_files` - Read configurations\n- `network` - Download packages and API calls\n\n## Security Considerations\n\nSee [SECURITY.md](./SECURITY.md) for capability disclosure, threat model, and deployment guidance.\n\n## Documentation\n\n- **Full Guide**: https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md\n- **中文文档**: https://github.com/tophant-ai/ClawVault/blob/main/doc/zh/OPENCLAW_SKILL.md\n- **Repository**: https://github.com/tophant-ai/ClawVault\n\n## License\n\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.10:README.md\n\n# ClawVault Installer Skill\r\n\r\nAI security system for OpenClaw — protect your AI agents from prompt injection, data leakage, and dangerous commands.\r\n\r\n## Before Installing\r\n\r\nThis skill installs and operates a local HTTPS-inspection proxy. Capabilities, defaults, and risks are documented in [SECURITY.md](./SECURITY.md) — please review it before installing.\r\n\r\n## Quick Start\r\n\r\n### Installation\r\n\r\n**Option 1: Install from ClawHub (Recommended)**\r\n\r\n```bash\r\n# Install from ClawHub\r\nopenclaw skills install tophant-clawvault-installer\r\n\r\n# Or use clawhub CLI\r\nclawhub install tophant-clawvault-installer\r\n```\r\n\r\n**ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault-installer\r\n\r\n**Option 2: Install from Local Repository**\r\n\r\n```bash\r\n# Copy to OpenClaw skills directory\r\ncp -r skills/tophant-clawvault-installer ~/.openclaw/skills/\r\n\r\n# Or create symbolic link\r\nln -s /path/to/ClawVault/skills/tophant-clawvault-installer ~/.openclaw/skills/tophant-clawvault-installer\r\n\r\n# Restart OpenClaw\r\nopenclaw restart\r\n```\r\n\r\n### Basic Usage\r\n\r\n```bash\r\n# Install ClawVault\r\n/tophant-clawvault-installer install --mode quick\r\n\r\n# Check health\r\n/tophant-clawvault-installer health\r\n\r\n# Generate security rule\r\n/tophant-clawvault-installer generate-rule \"Block all AWS credentials\" --apply\r\n\r\n# Run tests\r\n/tophant-clawvault-installer test --category all\r\n```\r\n\r\n## Features\r\n\r\n- **AI-guided installation** - Quick, standard, or advanced setup modes\r\n- **Dedicated virtualenv** - Installs into `~/.clawvault-env` instead of the system Python\r\n- **Pinned install sources** - Uses `clawvault>=0.1.0,<1.0.0` and pinned GitHub fallback `v0.1.0`\r\n- **Failure-aware setup** - Reports configuration initialization failures as installation failures\r\n- **Secure dashboard defaults** - Binds the dashboard to `127.0.0.1` by default\r\n- **OpenClaw proxy integration** - Can configure OpenClaw gateway proxy settings, with `--no-proxy` opt-out\r\n- **Rule generation** - Create security rules from natural language\r\n- **Scenario templates** - Pre-configured policies (customer_service, development, production, finance)\r\n- **Detection testing** - Built-in test suites for validation\r\n- **Health monitoring** - Real-time service status\r\n\r\n## Documentation\r\n\r\n- **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first**\r\n- **Skill Reference**: [SKILL.md](./SKILL.md)\r\n- **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md)\r\n- **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md)\r\n\r\n## Requirements\r\n\r\n- Python 3.10+\r\n- OpenClaw installed\r\n- Ports 8765, 8766 available\r\n\r\n## Support\r\n\r\n- **Repository**: https://github.com/tophant-ai/ClawVault\r\n- **Issues**: https://github.com/tophant-ai/ClawVault/issues\r\n- **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n\r\n## License\r\n\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.10:_meta.json\n\n{\n  \"ownerId\": \"kn70av3n6bs6dqfaajr8drm90d82v5tt\",\n  \"slug\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.10\",\n  \"publishedAt\": 1777529856312\n}\n\nFile v0.2.10:SECURITY.md\n\n# Security Documentation\r\n\r\n## Overview\r\n\r\nClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.\r\n\r\n## Design Intent — Why Several Defaults Look Permissive\r\n\r\nClawVault is a **man-in-the-middle (MITM) inspection proxy for AI traffic**. To do its job, it necessarily exhibits behaviors that automated security scanners flag as high-risk. Every one of these is intentional. This section documents them up-front so there is no ambiguity between \"intentional capability\" and \"bug.\"\r\n\r\n| Behavior | Why it's required | How to constrain it |\r\n|---|---|---|\r\n| `ssl_verify: false` in default config | Decrypts HTTPS so detectors can scan request/response bodies. Without this, ClawVault cannot see the AI traffic it is meant to protect. | MITM only applies to hosts listed in `proxy.intercept_hosts`. Non-AI traffic passes through untouched. Limit the list if you only want specific providers inspected. |\r\n| Dashboard has no authentication by default | Default bind is `127.0.0.1` (localhost only); anyone with a shell on the machine already has more access than the dashboard exposes. | **Never** start with `--dashboard-host 0.0.0.0` on untrusted networks. Use SSH port-forwarding for remote viewing. |\r\n| The skill sees your API keys and prompts | API keys travel inside the HTTPS requests being inspected. A proxy that inspects requests will see them. | All traffic stays on `localhost`. Nothing is uploaded. Audit logs in `~/.ClawVault/audit.db` are local-only. |\r\n| Installer writes `HTTP_PROXY`/`HTTPS_PROXY` into `openclaw-gateway.service` | Required for OpenClaw to route traffic through ClawVault. Without this, the proxy is installed but inert. | Pass `--no-proxy` at install time to skip this step — you can wire it up manually later. The modification is only applied if the unit file already exists. |\r\n| Installs from pinned package sources | The installer uses the PyPI constraint `clawvault>=0.1.0,<1.0.0` first and falls back to the pinned GitHub tag `v0.1.0` if PyPI is unavailable. | Review the pinned package/tag before installing, or run in a disposable VM for higher assurance. See \"Package Sources\" below. |\r\n\r\nIf any of these trade-offs are unacceptable for your threat model, **do not install this skill.**\r\n\r\n## How ClawVault Works\r\n\r\n### Proxy Architecture\r\n\r\nClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:\r\n\r\n```\r\nAI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs\r\n                    ↓\r\n            Detection Engine\r\n                    ↓\r\n            Dashboard (localhost:8766)\r\n```\r\n\r\n**What This Means:**\r\n- All API requests pass through ClawVault for inspection\r\n- ClawVault can see request/response content including API keys\r\n- This is intentional and necessary for threat detection\r\n- The proxy runs locally on your machine, not on external servers\r\n\r\n### SSL/TLS Verification\r\n\r\n**Default Behavior:**\r\n- ClawVault's default configuration sets `ssl_verify: false` for proxied connections\r\n- This is required for the proxy to inspect HTTPS traffic (MITM-style interception)\r\n\r\n**Security Implications:**\r\n- Disabling SSL verification allows ClawVault to decrypt and inspect encrypted traffic\r\n- This is necessary for detecting threats in API requests/responses\r\n- Traffic between your machine and LLM providers is still encrypted\r\n- The decryption happens locally on your machine, not in transit\r\n\r\n**Recommendation:**\r\n- Only use ClawVault on trusted networks\r\n- The proxy is designed for local development/testing\r\n- For production, consider using ClawVault's detection rules without the proxy\r\n\r\n## Dashboard Security\r\n\r\n### Default Configuration (Secure)\r\n\r\n```bash\r\n# Dashboard binds to localhost only\r\nclawvault start\r\n# Access: http://127.0.0.1:8766 (local machine only)\r\n```\r\n\r\n**This is the recommended configuration** for most users.\r\n\r\n### Remote Access Configuration (Risky)\r\n\r\n```bash\r\n# Dashboard accessible from any IP\r\nclawvault start --dashboard-host 0.0.0.0\r\n# Access: http://<your-ip>:8766 (anyone on network can access)\r\n```\r\n\r\n**⚠️ Security Risks:**\r\n- Dashboard shows sensitive detection data (API keys, PII, etc.)\r\n- No authentication by default\r\n- Anyone on your network can view the dashboard\r\n- Potential data exposure if misconfigured\r\n\r\n**When to Use Remote Access:**\r\n- Only in trusted, isolated networks\r\n- Behind a firewall with strict access controls\r\n- For temporary debugging/demonstration purposes\r\n\r\n**Production Recommendations:**\r\n1. Keep dashboard on localhost (127.0.0.1)\r\n2. Use SSH tunneling for remote access:\r\n   ```bash\r\n   ssh -L 8766:localhost:8766 user@remote-server\r\n   ```\r\n3. Or use a reverse proxy with authentication (nginx + basic auth)\r\n4. Never expose dashboard to public internet without authentication\r\n\r\n## Permissions Explained\r\n\r\nThe skill requires these permissions:\r\n\r\n### `execute_command`\r\n- **Purpose:** Create a Python venv in `~/.clawvault-env/`, install `clawvault>=0.1.0,<1.0.0` from PyPI with pinned GitHub tag `v0.1.0` fallback, and start/stop the proxy + dashboard services. On OpenClaw systems the installer also writes `HTTP_PROXY`/`HTTPS_PROXY` environment variables into `~/.config/systemd/user/openclaw-gateway.service` so the gateway routes AI traffic through ClawVault.\r\n- **Risk:** Can execute arbitrary commands on your system; modifies one OpenClaw unit file when present.\r\n- **Mitigation:** All commands are explicit in `clawvault_manager.py`. Pass `--no-proxy` to skip the systemd modification, or `--no-start` to skip launching services. No command runs without being visible in `clawvault_manager.py:install()`.\r\n\r\n### `write_files`\r\n- **Purpose:** Create configuration files in `~/.ClawVault/`\r\n- **Risk:** Can write to your home directory\r\n- **Mitigation:** Skill only writes to dedicated ClawVault config directory\r\n\r\n### `read_files`\r\n- **Purpose:** Read existing ClawVault configuration\r\n- **Risk:** Can read files on your system\r\n- **Mitigation:** Skill only reads from `~/.ClawVault/` directory\r\n\r\n### `network`\r\n- **Purpose:** Download ClawVault package, proxy API traffic, call local dashboard API\r\n- **Risk:** Can make network requests\r\n- **Mitigation:** Network access is essential for proxy functionality; all traffic is logged\r\n\r\n## Data Handling\r\n\r\n### What Data ClawVault Sees\r\n\r\nClawVault inspects:\r\n- API requests to LLM providers (OpenAI, Anthropic, etc.)\r\n- API responses from LLM providers\r\n- API keys and authentication tokens (in request headers)\r\n- User prompts and AI responses\r\n- Potentially sensitive data (PII, credentials) in prompts/responses\r\n\r\n### Where Data Is Stored\r\n\r\n- **Audit logs:** `~/.ClawVault/audit.db` (SQLite database)\r\n- **Detection logs:** `~/.ClawVault/logs/detection.log`\r\n- **Configuration:** `~/.ClawVault/config.yaml`\r\n\r\n### Data Retention\r\n\r\n- Audit logs are stored indefinitely by default\r\n- You can configure retention policies in `config.yaml`\r\n- To clear logs: `rm ~/.ClawVault/audit.db`\r\n\r\n### Data Privacy\r\n\r\n- All data stays on your local machine\r\n- ClawVault does not send data to external servers (except when proxying to LLM providers)\r\n- No telemetry or analytics are collected\r\n- You control all data through local configuration files\r\n\r\n## Installation Security\r\n\r\n### Package Sources\r\n\r\nThe skill installs ClawVault from pinned package sources. It first tries the PyPI constraint `clawvault>=0.1.0,<1.0.0`; if PyPI installation fails, it falls back to the pinned GitHub tag `v0.1.0`.\r\n\r\n```\r\npip install 'clawvault>=0.1.0,<1.0.0'\r\npip install git+https://github.com/tophant-ai/ClawVault.git@v0.1.0\r\n```\r\n\r\nThe installer does **not** perform:\r\n- Checksum verification\r\n- Signature verification\r\n- Dependency-graph auditing\r\n\r\n**Supply-chain risk:** Installing any package from PyPI or GitHub carries supply-chain risk, but the installer avoids tracking an unpinned main branch. Review the package/tag before installing in sensitive environments.\r\n\r\n**How to reduce supply-chain exposure:**\r\n1. Review the repository before installing: https://github.com/tophant-ai/ClawVault\r\n2. Check out a specific commit/tag locally and point `pip` at that path instead\r\n3. Run `./venv/bin/pip install git+https://github.com/tophant-ai/ClawVault.git@<sha>` with an audited commit SHA\r\n4. Run the installer inside a disposable VM or container\r\n5. Subscribe to the repo's security advisories on GitHub\r\n\r\n### Installation Process\r\n\r\nWhat happens, in order, during `install --mode quick`:\r\n\r\n1. Verifies Python version (≥ 3.10)\r\n2. Creates a **dedicated virtual environment** at `~/.clawvault-env/` (isolates ClawVault from system Python — nothing is installed globally)\r\n3. Runs `pip install 'clawvault>=0.1.0,<1.0.0'` inside that venv, with pinned GitHub tag `v0.1.0` fallback\r\n4. Copies `config.example.yaml` from the installed package to `~/.ClawVault/config.yaml`; if the template is unavailable, generates a complete 11-section default config\r\n5. If `~/.config/systemd/user/openclaw-gateway.service` exists, injects `HTTP_PROXY`/`HTTPS_PROXY`/`NO_PROXY`/`NODE_TLS_REJECT_UNAUTHORIZED` into it so OpenClaw routes AI traffic through ClawVault. Skipped if `--no-proxy` is passed or if the service file is absent.\r\n6. Launches the proxy (port 8765) and dashboard (port 8766) via `subprocess.Popen`. Skipped if `--no-start` is passed.\r\n\r\nEverything the skill touches lives under three predictable paths:\r\n- `~/.clawvault-env/` — the Python venv\r\n- `~/.ClawVault/` — config, audit DB, logs, certs, state\r\n- `~/.config/systemd/user/openclaw-gateway.service` — **modified only if it already exists**\r\n\r\n## Threat Model\r\n\r\n### What ClawVault Protects Against\r\n\r\n✅ **Prompt injection attacks** - Detects attempts to manipulate AI behavior\r\n✅ **Data leakage** - Identifies PII, credentials, API keys in prompts/responses\r\n✅ **Dangerous commands** - Flags risky shell commands in AI outputs\r\n✅ **Jailbreak attempts** - Detects attempts to bypass AI safety measures\r\n\r\n### What ClawVault Does NOT Protect Against\r\n\r\n❌ **Malicious ClawVault package** - If the upstream package is compromised, the skill will install it\r\n❌ **Local system compromise** - If your machine is compromised, ClawVault data can be accessed\r\n❌ **Network attacks** - ClawVault does not protect against network-level attacks\r\n❌ **Supply chain attacks** - No verification of package integrity during installation\r\n\r\n## Best Practices\r\n\r\n### For Development/Testing\r\n\r\n```bash\r\n# Safe configuration for local development\r\nclawvault start --dashboard-host 127.0.0.1 --mode interactive\r\n\r\n# Review detection logs regularly\r\ntail -f ~/.ClawVault/logs/detection.log\r\n\r\n# Test with non-sensitive data first\r\nclawvault test --category all\r\n```\r\n\r\n### For Production\r\n\r\n```bash\r\n# Use strict mode for automated blocking\r\nclawvault start --mode strict\r\n\r\n# Keep dashboard local, use SSH tunnel for remote access\r\nssh -L 8766:localhost:8766 user@server\r\n\r\n# Configure audit retention\r\n# Edit ~/.ClawVault/config.yaml:\r\naudit:\r\n  enabled: true\r\n  retention_days: 30\r\n```\r\n\r\n### For Sensitive Environments\r\n\r\n1. **Review the source code** before installation\r\n2. **Run in isolated environment** (VM, container)\r\n3. **Use firewall rules** to restrict network access\r\n4. **Rotate API keys** regularly\r\n5. **Monitor audit logs** for suspicious activity\r\n6. **Disable dashboard** if not needed: `--no-dashboard`\r\n\r\n## Security Checklist\r\n\r\nBefore installing ClawVault skill:\r\n\r\n- [ ] Reviewed ClawVault package source code\r\n- [ ] Understand that ClawVault will see API keys and request content\r\n- [ ] Verified dashboard will bind to localhost (not 0.0.0.0)\r\n- [ ] Understand SSL verification implications\r\n- [ ] Have plan for audit log retention/cleanup\r\n- [ ] Running in appropriate environment (dev/test/prod)\r\n- [ ] Firewall configured if using remote dashboard\r\n- [ ] Understand what permissions the skill requires\r\n\r\n## Reporting Security Issues\r\n\r\nIf you discover a security vulnerability in ClawVault or this skill:\r\n\r\n**For Critical Vulnerabilities (RCE, data exfiltration, credential theft):**\r\n1. Open a [GitHub Security Advisory](https://github.com/tophant-ai/ClawVault/security/advisories/new) (private disclosure)\r\n2. Or email: security@tophant.com\r\n3. Include detailed description and reproduction steps\r\n4. We will respond within 48 hours and work on a fix\r\n\r\n**For Non-Critical Issues (documentation errors, configuration issues, minor bugs):**\r\n1. Open a public [GitHub Issue](https://github.com/tophant-ai/ClawVault/issues/new)\r\n2. Tag with `security` label\r\n3. Community can discuss and contribute fixes\r\n\r\nWe encourage responsible disclosure and will credit security researchers who report vulnerabilities.\r\n\r\n## Additional Resources\r\n\r\n- **ClawVault Documentation:** https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n- **OpenClaw Security:** https://docs.openclaw.ai/gateway/security\r\n- **Threat Model:** https://github.com/tophant-ai/ClawVault/blob/main/doc/architecture.md\r\n\r\n## License\r\n\r\nThis security documentation is part of the ClawVault project.\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.10:skill.json\n\n{\n  \"name\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.9\",\n  \"description\": \"AI security system that protects agents from prompt injection, data leakage, and dangerous commands. Operates as local HTTP proxy to inspect traffic. Review SECURITY.md before installing.\",\n  \"author\": \"Tophant SPAI Lab\",\n  \"homepage\": \"https://github.com/tophant-ai/ClawVault\",\n  \"repository\": \"https://github.com/tophant-ai/ClawVault\",\n  \"main\": \"clawvault_manager.py\",\n  \"permissions\": [\"execute_command\", \"write_files\", \"read_files\", \"network\"],\n  \"permissions_rationale\": {\n    \"execute_command\": \"Required to run pip install and start/stop ClawVault services\",\n    \"write_files\": \"Creates configuration files in ~/.ClawVault/ directory\",\n    \"read_files\": \"Reads ClawVault configuration from ~/.ClawVault/\",\n    \"network\": \"Downloads ClawVault package and proxies AI traffic for inspection\"\n  },\n  \"tags\": [\"security\", \"ai-protection\", \"proxy\", \"threat-detection\", \"privacy\"],\n  \"requirements\": [\"pyyaml\"],\n  \"python_version\": \">=3.10\",\n  \"commands\": {\n    \"install\": {\n      \"description\": \"Install ClawVault with specified mode. Creates venv, installs from pinned package sources, generates config, integrates proxy, and starts services.\",\n      \"usage\": \"install --mode [quick|standard|advanced] [--no-start] [--no-proxy]\"\n    },\n    \"health\": {\n      \"description\": \"Check ClawVault health status\",\n      \"usage\": \"health\"\n    },\n    \"generate-rule\": {\n      \"description\": \"Generate security rule from natural language or scenario\",\n      \"usage\": \"generate-rule <policy> [--scenario <name>] [--apply]\"\n    },\n    \"test\": {\n      \"description\": \"Run detection tests\",\n      \"usage\": \"test --category [all|sensitive|injection|commands]\"\n    },\n    \"uninstall\": {\n      \"description\": \"Uninstall ClawVault\",\n      \"usage\": \"uninstall [--keep-config]\"\n    }\n  },\n  \"scenarios\": [\"customer_service\", \"development\", \"production\", \"finance\"]\n}\n\nArchive v0.2.9: 6 files, 19281 bytes\n\nFiles: clawvault_manager.py (37771b), README.md (2889b), SECURITY.md (13209b), skill.json (1932b), SKILL.md (4576b), _meta.json (146b)\n\nFile v0.2.9:SKILL.md\n\n---\nname: tophant-clawvault-installer\nversion: 0.2.9\ndescription: Install, configure, test, and uninstall ClawVault AI security proxy\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Installer\n\nInstall, configure, test, and uninstall ClawVault — the AI security proxy that protects agents from prompt injection, data leakage, and dangerous commands.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## What This Skill Does\n\nInstalls ClawVault into a dedicated venv at `~/.clawvault-env/` and writes config under `~/.ClawVault/`. See `SECURITY.md` for the full capability, risk, and design-intent disclosure.\n\n## How to Run\n\n**IMPORTANT: All commands MUST be executed using the Python script bundled with this skill.**\n\nDo NOT run `pip install`, `clawvault`, or any other command directly. Always use:\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py <command> [options]\n```\n\nWhere `SKILL_DIR` is the directory containing this SKILL.md file (typically `~/.openclaw/workspace/skills/tophant-clawvault-installer/` or `~/.openclaw/skills/tophant-clawvault-installer/`).\n\nAdd `--json` to any command for machine-readable JSON output.\n\n## Commands\n\n### /tophant-clawvault-installer install\n\nInstall ClawVault. The script handles everything automatically: creates a Python virtual environment, installs from pinned package sources (`clawvault>=0.1.0,<1.0.0` with GitHub tag `v0.1.0` fallback), generates config, integrates OpenClaw proxy, and starts services. **No pip or system package manager needed.**\n\n```bash\n# Recommended: one command does everything\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --json\n\n# Interactive setup\npython3 SKILL_DIR/clawvault_manager.py install --mode standard --json\n\n# Full control (strict mode)\npython3 SKILL_DIR/clawvault_manager.py install --mode advanced --json\n\n# Install without starting services\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json\n\n# Skip OpenClaw proxy integration\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json\n```\n\n### /tophant-clawvault-installer health\n\nCheck service health and status.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py health --json\n```\n\n### /tophant-clawvault-installer generate-rule\n\nGenerate security rules from natural language.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py generate-rule \"Block all AWS credentials\" --json\npython3 SKILL_DIR/clawvault_manager.py generate-rule --scenario customer_service --apply --json\n```\n\n**Scenarios:** `customer_service`, `development`, `production`, `finance`\n\n### /tophant-clawvault-installer test\n\nRun detection tests.\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py test --category all --json\npython3 SKILL_DIR/clawvault_manager.py test --category sensitive --json\n```\n\n**Categories:** `all`, `sensitive`, `injection`, `commands`\n\n### /tophant-clawvault-installer uninstall\n\nRemove ClawVault completely (stops services, removes proxy, deletes venv and config).\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py uninstall --json\npython3 SKILL_DIR/clawvault_manager.py uninstall --keep-config --json\n```\n\n## Quick Examples\n\n```bash\n# Set the skill directory path\nCV=\"python3 ~/.openclaw/workspace/skills/tophant-clawvault-installer/clawvault_manager.py\"\n\n# Install (one command handles everything)\n$CV install --mode quick --json\n\n# Check health\n$CV health --json\n\n# Generate rule\n$CV generate-rule \"Detect database passwords\" --apply --json\n\n# Apply scenario\n$CV generate-rule --scenario customer_service --apply --json\n\n# Run tests\n$CV test --category all --json\n\n# Uninstall\n$CV uninstall --json\n```\n\n## Requirements\n\n- Python 3.10+ (with venv module)\n- Ports 8765, 8766 available\n- No pip or system packages needed — the install script creates its own virtual environment\n\n## Permissions\n\n- `execute_command` - Run installation and ClawVault commands\n- `write_files` - Create configuration files\n- `read_files` - Read configurations\n- `network` - Download packages and API calls\n\n## Security Considerations\n\nSee [SECURITY.md](./SECURITY.md) for capability disclosure, threat model, and deployment guidance.\n\n## Documentation\n\n- **Full Guide**: https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md\n- **中文文档**: https://github.com/tophant-ai/ClawVault/blob/main/doc/zh/OPENCLAW_SKILL.md\n- **Repository**: https://github.com/tophant-ai/ClawVault\n\n## License\n\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.9:README.md\n\n# ClawVault Installer Skill\r\n\r\nAI security system for OpenClaw — protect your AI agents from prompt injection, data leakage, and dangerous commands.\r\n\r\n## Before Installing\r\n\r\nThis skill installs and operates a local HTTPS-inspection proxy. Capabilities, defaults, and risks are documented in [SECURITY.md](./SECURITY.md) — please review it before installing.\r\n\r\n## Quick Start\r\n\r\n### Installation\r\n\r\n**Option 1: Install from ClawHub (Recommended)**\r\n\r\n```bash\r\n# Install from ClawHub\r\nopenclaw skills install tophant-clawvault-installer\r\n\r\n# Or use clawhub CLI\r\nclawhub install tophant-clawvault-installer\r\n```\r\n\r\n**ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault-installer\r\n\r\n**Option 2: Install from Local Repository**\r\n\r\n```bash\r\n# Copy to OpenClaw skills directory\r\ncp -r skills/tophant-clawvault-installer ~/.openclaw/skills/\r\n\r\n# Or create symbolic link\r\nln -s /path/to/ClawVault/skills/tophant-clawvault-installer ~/.openclaw/skills/tophant-clawvault-installer\r\n\r\n# Restart OpenClaw\r\nopenclaw restart\r\n```\r\n\r\n### Basic Usage\r\n\r\n```bash\r\n# Install ClawVault\r\n/tophant-clawvault-installer install --mode quick\r\n\r\n# Check health\r\n/tophant-clawvault-installer health\r\n\r\n# Generate security rule\r\n/tophant-clawvault-installer generate-rule \"Block all AWS credentials\" --apply\r\n\r\n# Run tests\r\n/tophant-clawvault-installer test --category all\r\n```\r\n\r\n## Features\r\n\r\n- **AI-guided installation** - Quick, standard, or advanced setup modes\r\n- **Dedicated virtualenv** - Installs into `~/.clawvault-env` instead of the system Python\r\n- **Pinned install sources** - Uses `clawvault>=0.1.0,<1.0.0` and pinned GitHub fallback `v0.1.0`\r\n- **Failure-aware setup** - Reports configuration initialization failures as installation failures\r\n- **Secure dashboard defaults** - Binds the dashboard to `127.0.0.1` by default\r\n- **OpenClaw proxy integration** - Can configure OpenClaw gateway proxy settings, with `--no-proxy` opt-out\r\n- **Rule generation** - Create security rules from natural language\r\n- **Scenario templates** - Pre-configured policies (customer_service, development, production, finance)\r\n- **Detection testing** - Built-in test suites for validation\r\n- **Health monitoring** - Real-time service status\r\n\r\n## Documentation\r\n\r\n- **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first**\r\n- **Skill Reference**: [SKILL.md](./SKILL.md)\r\n- **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md)\r\n- **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md)\r\n\r\n## Requirements\r\n\r\n- Python 3.10+\r\n- OpenClaw installed\r\n- Ports 8765, 8766 available\r\n\r\n## Support\r\n\r\n- **Repository**: https://github.com/tophant-ai/ClawVault\r\n- **Issues**: https://github.com/tophant-ai/ClawVault/issues\r\n- **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n\r\n## License\r\n\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.9:_meta.json\n\n{\n  \"ownerId\": \"kn70av3n6bs6dqfaajr8drm90d82v5tt\",\n  \"slug\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.9\",\n  \"publishedAt\": 1777358702732\n}\n\nFile v0.2.9:SECURITY.md\n\n# Security Documentation\r\n\r\n## Overview\r\n\r\nClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.\r\n\r\n## Design Intent — Why Several Defaults Look Permissive\r\n\r\nClawVault is a **man-in-the-middle (MITM) inspection proxy for AI traffic**. To do its job, it necessarily exhibits behaviors that automated security scanners flag as high-risk. Every one of these is intentional. This section documents them up-front so there is no ambiguity between \"intentional capability\" and \"bug.\"\r\n\r\n| Behavior | Why it's required | How to constrain it |\r\n|---|---|---|\r\n| `ssl_verify: false` in default config | Decrypts HTTPS so detectors can scan request/response bodies. Without this, ClawVault cannot see the AI traffic it is meant to protect. | MITM only applies to hosts listed in `proxy.intercept_hosts`. Non-AI traffic passes through untouched. Limit the list if you only want specific providers inspected. |\r\n| Dashboard has no authentication by default | Default bind is `127.0.0.1` (localhost only); anyone with a shell on the machine already has more access than the dashboard exposes. | **Never** start with `--dashboard-host 0.0.0.0` on untrusted networks. Use SSH port-forwarding for remote viewing. |\r\n| The skill sees your API keys and prompts | API keys travel inside the HTTPS requests being inspected. A proxy that inspects requests will see them. | All traffic stays on `localhost`. Nothing is uploaded. Audit logs in `~/.ClawVault/audit.db` are local-only. |\r\n| Installer writes `HTTP_PROXY`/`HTTPS_PROXY` into `openclaw-gateway.service` | Required for OpenClaw to route traffic through ClawVault. Without this, the proxy is installed but inert. | Pass `--no-proxy` at install time to skip this step — you can wire it up manually later. The modification is only applied if the unit file already exists. |\r\n| Installs from pinned package sources | The installer uses the PyPI constraint `clawvault>=0.1.0,<1.0.0` first and falls back to the pinned GitHub tag `v0.1.0` if PyPI is unavailable. | Review the pinned package/tag before installing, or run in a disposable VM for higher assurance. See \"Package Sources\" below. |\r\n\r\nIf any of these trade-offs are unacceptable for your threat model, **do not install this skill.**\r\n\r\n## How ClawVault Works\r\n\r\n### Proxy Architecture\r\n\r\nClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:\r\n\r\n```\r\nAI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs\r\n                    ↓\r\n            Detection Engine\r\n                    ↓\r\n            Dashboard (localhost:8766)\r\n```\r\n\r\n**What This Means:**\r\n- All API requests pass through ClawVault for inspection\r\n- ClawVault can see request/response content including API keys\r\n- This is intentional and necessary for threat detection\r\n- The proxy runs locally on your machine, not on external servers\r\n\r\n### SSL/TLS Verification\r\n\r\n**Default Behavior:**\r\n- ClawVault's default configuration sets `ssl_verify: false` for proxied connections\r\n- This is required for the proxy to inspect HTTPS traffic (MITM-style interception)\r\n\r\n**Security Implications:**\r\n- Disabling SSL verification allows ClawVault to decrypt and inspect encrypted traffic\r\n- This is necessary for detecting threats in API requests/responses\r\n- Traffic between your machine and LLM providers is still encrypted\r\n- The decryption happens locally on your machine, not in transit\r\n\r\n**Recommendation:**\r\n- Only use ClawVault on trusted networks\r\n- The proxy is designed for local development/testing\r\n- For production, consider using ClawVault's detection rules without the proxy\r\n\r\n## Dashboard Security\r\n\r\n### Default Configuration (Secure)\r\n\r\n```bash\r\n# Dashboard binds to localhost only\r\nclawvault start\r\n# Access: http://127.0.0.1:8766 (local machine only)\r\n```\r\n\r\n**This is the recommended configuration** for most users.\r\n\r\n### Remote Access Configuration (Risky)\r\n\r\n```bash\r\n# Dashboard accessible from any IP\r\nclawvault start --dashboard-host 0.0.0.0\r\n# Access: http://<your-ip>:8766 (anyone on network can access)\r\n```\r\n\r\n**⚠️ Security Risks:**\r\n- Dashboard shows sensitive detection data (API keys, PII, etc.)\r\n- No authentication by default\r\n- Anyone on your network can view the dashboard\r\n- Potential data exposure if misconfigured\r\n\r\n**When to Use Remote Access:**\r\n- Only in trusted, isolated networks\r\n- Behind a firewall with strict access controls\r\n- For temporary debugging/demonstration purposes\r\n\r\n**Production Recommendations:**\r\n1. Keep dashboard on localhost (127.0.0.1)\r\n2. Use SSH tunneling for remote access:\r\n   ```bash\r\n   ssh -L 8766:localhost:8766 user@remote-server\r\n   ```\r\n3. Or use a reverse proxy with authentication (nginx + basic auth)\r\n4. Never expose dashboard to public internet without authentication\r\n\r\n## Permissions Explained\r\n\r\nThe skill requires these permissions:\r\n\r\n### `execute_command`\r\n- **Purpose:** Create a Python venv in `~/.clawvault-env/`, install `clawvault>=0.1.0,<1.0.0` from PyPI with pinned GitHub tag `v0.1.0` fallback, and start/stop the proxy + dashboard services. On OpenClaw systems the installer also writes `HTTP_PROXY`/`HTTPS_PROXY` environment variables into `~/.config/systemd/user/openclaw-gateway.service` so the gateway routes AI traffic through ClawVault.\r\n- **Risk:** Can execute arbitrary commands on your system; modifies one OpenClaw unit file when present.\r\n- **Mitigation:** All commands are explicit in `clawvault_manager.py`. Pass `--no-proxy` to skip the systemd modification, or `--no-start` to skip launching services. No command runs without being visible in `clawvault_manager.py:install()`.\r\n\r\n### `write_files`\r\n- **Purpose:** Create configuration files in `~/.ClawVault/`\r\n- **Risk:** Can write to your home directory\r\n- **Mitigation:** Skill only writes to dedicated ClawVault config directory\r\n\r\n### `read_files`\r\n- **Purpose:** Read existing ClawVault configuration\r\n- **Risk:** Can read files on your system\r\n- **Mitigation:** Skill only reads from `~/.ClawVault/` directory\r\n\r\n### `network`\r\n- **Purpose:** Download ClawVault package, proxy API traffic, call local dashboard API\r\n- **Risk:** Can make network requests\r\n- **Mitigation:** Network access is essential for proxy functionality; all traffic is logged\r\n\r\n## Data Handling\r\n\r\n### What Data ClawVault Sees\r\n\r\nClawVault inspects:\r\n- API requests to LLM providers (OpenAI, Anthropic, etc.)\r\n- API responses from LLM providers\r\n- API keys and authentication tokens (in request headers)\r\n- User prompts and AI responses\r\n- Potentially sensitive data (PII, credentials) in prompts/responses\r\n\r\n### Where Data Is Stored\r\n\r\n- **Audit logs:** `~/.ClawVault/audit.db` (SQLite database)\r\n- **Detection logs:** `~/.ClawVault/logs/detection.log`\r\n- **Configuration:** `~/.ClawVault/config.yaml`\r\n\r\n### Data Retention\r\n\r\n- Audit logs are stored indefinitely by default\r\n- You can configure retention policies in `config.yaml`\r\n- To clear logs: `rm ~/.ClawVault/audit.db`\r\n\r\n### Data Privacy\r\n\r\n- All data stays on your local machine\r\n- ClawVault does not send data to external servers (except when proxying to LLM providers)\r\n- No telemetry or analytics are collected\r\n- You control all data through local configuration files\r\n\r\n## Installation Security\r\n\r\n### Package Sources\r\n\r\nThe skill installs ClawVault from pinned package sources. It first tries the PyPI constraint `clawvault>=0.1.0,<1.0.0`; if PyPI installation fails, it falls back to the pinned GitHub tag `v0.1.0`.\r\n\r\n```\r\npip install 'clawvault>=0.1.0,<1.0.0'\r\npip install git+https://github.com/tophant-ai/ClawVault.git@v0.1.0\r\n```\r\n\r\nThe installer does **not** perform:\r\n- Checksum verification\r\n- Signature verification\r\n- Dependency-graph auditing\r\n\r\n**Supply-chain risk:** Installing any package from PyPI or GitHub carries supply-chain risk, but the installer avoids tracking an unpinned main branch. Review the package/tag before installing in sensitive environments.\r\n\r\n**How to reduce supply-chain exposure:**\r\n1. Review the repository before installing: https://github.com/tophant-ai/ClawVault\r\n2. Check out a specific commit/tag locally and point `pip` at that path instead\r\n3. Run `./venv/bin/pip install git+https://github.com/tophant-ai/ClawVault.git@<sha>` with an audited commit SHA\r\n4. Run the installer inside a disposable VM or container\r\n5. Subscribe to the repo's security advisories on GitHub\r\n\r\n### Installation Process\r\n\r\nWhat happens, in order, during `install --mode quick`:\r\n\r\n1. Verifies Python version (≥ 3.10)\r\n2. Creates a **dedicated virtual environment** at `~/.clawvault-env/` (isolates ClawVault from system Python — nothing is installed globally)\r\n3. Runs `pip install 'clawvault>=0.1.0,<1.0.0'` inside that venv, with pinned GitHub tag `v0.1.0` fallback\r\n4. Copies `config.example.yaml` from the installed package to `~/.ClawVault/config.yaml`; if the template is unavailable, generates a complete 11-section default config\r\n5. If `~/.config/systemd/user/openclaw-gateway.service` exists, injects `HTTP_PROXY`/`HTTPS_PROXY`/`NO_PROXY`/`NODE_TLS_REJECT_UNAUTHORIZED` into it so OpenClaw routes AI traffic through ClawVault. Skipped if `--no-proxy` is passed or if the service file is absent.\r\n6. Launches the proxy (port 8765) and dashboard (port 8766) via `subprocess.Popen`. Skipped if `--no-start` is passed.\r\n\r\nEverything the skill touches lives under three predictable paths:\r\n- `~/.clawvault-env/` — the Python venv\r\n- `~/.ClawVault/` — config, audit DB, logs, certs, state\r\n- `~/.config/systemd/user/openclaw-gateway.service` — **modified only if it already exists**\r\n\r\n## Threat Model\r\n\r\n### What ClawVault Protects Against\r\n\r\n✅ **Prompt injection attacks** - Detects attempts to manipulate AI behavior\r\n✅ **Data leakage** - Identifies PII, credentials, API keys in prompts/responses\r\n✅ **Dangerous commands** - Flags risky shell commands in AI outputs\r\n✅ **Jailbreak attempts** - Detects attempts to bypass AI safety measures\r\n\r\n### What ClawVault Does NOT Protect Against\r\n\r\n❌ **Malicious ClawVault package** - If the upstream package is compromised, the skill will install it\r\n❌ **Local system compromise** - If your machine is compromised, ClawVault data can be accessed\r\n❌ **Network attacks** - ClawVault does not protect against network-level attacks\r\n❌ **Supply chain attacks** - No verification of package integrity during installation\r\n\r\n## Best Practices\r\n\r\n### For Development/Testing\r\n\r\n```bash\r\n# Safe configuration for local development\r\nclawvault start --dashboard-host 127.0.0.1 --mode interactive\r\n\r\n# Review detection logs regularly\r\ntail -f ~/.ClawVault/logs/detection.log\r\n\r\n# Test with non-sensitive data first\r\nclawvault test --category all\r\n```\r\n\r\n### For Production\r\n\r\n```bash\r\n# Use strict mode for automated blocking\r\nclawvault start --mode strict\r\n\r\n# Keep dashboard local, use SSH tunnel for remote access\r\nssh -L 8766:localhost:8766 user@server\r\n\r\n# Configure audit retention\r\n# Edit ~/.ClawVault/config.yaml:\r\naudit:\r\n  enabled: true\r\n  retention_days: 30\r\n```\r\n\r\n### For Sensitive Environments\r\n\r\n1. **Review the source code** before installation\r\n2. **Run in isolated environment** (VM, container)\r\n3. **Use firewall rules** to restrict network access\r\n4. **Rotate API keys** regularly\r\n5. **Monitor audit logs** for suspicious activity\r\n6. **Disable dashboard** if not needed: `--no-dashboard`\r\n\r\n## Security Checklist\r\n\r\nBefore installing ClawVault skill:\r\n\r\n- [ ] Reviewed ClawVault package source code\r\n- [ ] Understand that ClawVault will see API keys and request content\r\n- [ ] Verified dashboard will bind to localhost (not 0.0.0.0)\r\n- [ ] Understand SSL verification implications\r\n- [ ] Have plan for audit log retention/cleanup\r\n- [ ] Running in appropriate environment (dev/test/prod)\r\n- [ ] Firewall configured if using remote dashboard\r\n- [ ] Understand what permissions the skill requires\r\n\r\n## Reporting Security Issues\r\n\r\nIf you discover a security vulnerability in ClawVault or this skill:\r\n\r\n**For Critical Vulnerabilities (RCE, data exfiltration, credential theft):**\r\n1. Open a [GitHub Security Advisory](https://github.com/tophant-ai/ClawVault/security/advisories/new) (private disclosure)\r\n2. Or email: security@tophant.com\r\n3. Include detailed description and reproduction steps\r\n4. We will respond within 48 hours and work on a fix\r\n\r\n**For Non-Critical Issues (documentation errors, configuration issues, minor bugs):**\r\n1. Open a public [GitHub Issue](https://github.com/tophant-ai/ClawVault/issues/new)\r\n2. Tag with `security` label\r\n3. Community can discuss and contribute fixes\r\n\r\nWe encourage responsible disclosure and will credit security researchers who report vulnerabilities.\r\n\r\n## Additional Resources\r\n\r\n- **ClawVault Documentation:** https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n- **OpenClaw Security:** https://docs.openclaw.ai/gateway/security\r\n- **Threat Model:** https://github.com/tophant-ai/ClawVault/blob/main/doc/architecture.md\r\n\r\n## License\r\n\r\nThis security documentation is part of the ClawVault project.\r\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.9:skill.json\n\n{\n  \"name\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.9\",\n  \"description\": \"AI security system that protects agents from prompt injection, data leakage, and dangerous commands. Operates as local HTTP proxy to inspect traffic. Review SECURITY.md before installing.\",\n  \"author\": \"Tophant SPAI Lab\",\n  \"homepage\": \"https://github.com/tophant-ai/ClawVault\",\n  \"repository\": \"https://github.com/tophant-ai/ClawVault\",\n  \"main\": \"clawvault_manager.py\",\n  \"permissions\": [\"execute_command\", \"write_files\", \"read_files\", \"network\"],\n  \"permissions_rationale\": {\n    \"execute_command\": \"Required to run pip install and start/stop ClawVault services\",\n    \"write_files\": \"Creates configuration files in ~/.ClawVault/ directory\",\n    \"read_files\": \"Reads ClawVault configuration from ~/.ClawVault/\",\n    \"network\": \"Downloads ClawVault package and proxies AI traffic for inspection\"\n  },\n  \"tags\": [\"security\", \"ai-protection\", \"proxy\", \"threat-detection\", \"privacy\"],\n  \"requirements\": [\"pyyaml\"],\n  \"python_version\": \">=3.10\",\n  \"commands\": {\n    \"install\": {\n      \"description\": \"Install ClawVault with specified mode. Creates venv, installs from pinned package sources, generates config, integrates proxy, and starts services.\",\n      \"usage\": \"install --mode [quick|standard|advanced] [--no-start] [--no-proxy]\"\n    },\n    \"health\": {\n      \"description\": \"Check ClawVault health status\",\n      \"usage\": \"health\"\n    },\n    \"generate-rule\": {\n      \"description\": \"Generate security rule from natural language or scenario\",\n      \"usage\": \"generate-rule <policy> [--scenario <name>] [--apply]\"\n    },\n    \"test\": {\n      \"description\": \"Run detection tests\",\n      \"usage\": \"test --category [all|sensitive|injection|commands]\"\n    },\n    \"uninstall\": {\n      \"description\": \"Uninstall ClawVault\",\n      \"usage\": \"uninstall [--keep-config]\"\n    }\n  },\n  \"scenarios\": [\"customer_service\", \"development\", \"production\", \"finance\"]\n}\n\nArchive v0.2.8: 6 files, 13966 bytes\n\nFiles: _meta.json (146b), clawvault_manager.py (22164b), README.md (2821b), SECURITY.md (8935b), skill.json (1999b), SKILL.md (3835b)\n\nFile v0.2.8:SKILL.md\n\n---\nname: tophant-clawvault-installer\nversion: 0.2.6\ndescription: AI security system for protecting agents from prompt injection, data leakage, and dangerous commands\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Skill\n\nAI security system for OpenClaw with installation, rule generation, detection, and monitoring.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## Commands\n\n### /clawvault start\n\nStart ClawVault services.\n\n```bash\nclawvault start                  # Default: localhost only (secure)\nclawvault start --mode strict    # Strict mode\n```\n\n### /clawvault install\n\nInstall ClawVault using pinned package sources and secure localhost defaults.\n\n```bash\n/clawvault install --mode quick     # Recommended; installs clawvault>=0.1.0,<1.0.0\n/clawvault install --mode standard  # Interactive\n/clawvault install --mode advanced  # Full control\n```\n\nIf PyPI installation is unavailable, the installer falls back to the pinned GitHub tag `v0.1.0`. Configuration failures are reported as installation failures so agents can recover safely.\n\n### /clawvault health\n\nCheck service health and status.\n\n```bash\n/clawvault health\n```\n\n### /clawvault generate-rule\n\nGenerate security rules from natural language.\n\n```bash\n/clawvault generate-rule \"Block all AWS credentials\"\n/clawvault generate-rule --scenario customer_service --apply\n```\n\n**Scenarios:** `customer_service`, `development`, `production`, `finance`\n\n### /clawvault status\n\nGet running status and statistics.\n\n```bash\n/clawvault status\n```\n\n### /clawvault test\n\nRun detection tests.\n\n```bash\n/clawvault test --category all\n/clawvault test --category sensitive\n```\n\n**Categories:** `all`, `sensitive`, `injection`, `commands`\n\n### /clawvault uninstall\n\nRemove ClawVault.\n\n```bash\n/clawvault uninstall\n/clawvault uninstall --keep-config  # Keep configuration\n```\n\n## Quick Examples\n\n```bash\n# Install\n/clawvault install --mode quick\n\n# Generate rule\n/clawvault generate-rule \"Detect database passwords\" --apply\n\n# Apply scenario\n/clawvault generate-rule --scenario customer_service --apply\n\n# Check health\n/clawvault health\n```\n\n## Requirements\n\n- Python 3.10+\n- Ports 8765, 8766 available\n\n## Permissions\n\n- `execute_command` - Run installation and ClawVault commands\n- `write_files` - Create configuration files\n- `read_files` - Read configurations\n- `network` - Download packages and API calls\n\n## Security Considerations\n\n⚠️ **Important:** ClawVault operates as a local HTTP proxy that inspects AI traffic.\n\n**What This Means:**\n- ClawVault can see API requests, responses, and API keys\n- This is intentional and necessary for threat detection\n- All data stays on your local machine\n\n**Dashboard Security:**\n- Default: Binds to `127.0.0.1` (localhost only) ✅ Secure\n- **For remote access:** Use SSH tunneling instead of exposing dashboard\n- Example: `ssh -L 8766:localhost:8766 user@server`\n\n**Before Installing:**\n- Review the [SECURITY.md](./SECURITY.md) documentation\n- Understand that ClawVault will inspect all proxied traffic\n- Ensure dashboard binding is appropriate for your environment\n- Consider running in isolated environment for sensitive use cases\n\n**For Production:**\n- Use localhost-only dashboard\n- Enable strict mode: `--mode strict`\n- Configure audit log retention\n- Review detection logs regularly\n\nSee [SECURITY.md](./SECURITY.md) for complete security documentation.\n\n## Documentation\n\n- **Full Guide**: https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md\n- **中文文档**: https://github.com/tophant-ai/ClawVault/blob/main/doc/zh/OPENCLAW_SKILL.md\n- **Repository**: https://github.com/tophant-ai/ClawVault\n\n## License\n\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.8:README.md\n\n# ClawVault Skill\n\nAI security system for OpenClaw - protect your AI agents from prompt injection, data leakage, and dangerous commands.\n\n## ⚠️ Security Notice\n\n**Important:** ClawVault operates as a local HTTP proxy that inspects AI traffic.\n\n- ClawVault can see API requests, responses, and API keys\n- This is intentional and necessary for threat detection\n- All data stays on your local machine\n- **Review [SECURITY.md](./SECURITY.md) before installing**\n\n**Dashboard Security:**\n- Default: Binds to `127.0.0.1` (localhost only) - Secure ✅\n- Remote: `--dashboard-host 0.0.0.0` - Exposes to network ⚠️\n- **Recommendation:** Use SSH tunneling for remote access\n\n## Quick Start\n\n### Installation\n\n**Option 1: Install from ClawHub (Recommended)**\n\n```bash\n# Install from ClawHub\nopenclaw skills install tophant-clawvault\n\n# Or use clawhub CLI\nclawhub install tophant-clawvault\n```\n\n**ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault\n\n**Option 2: Install from Local Repository**\n\n```bash\n# Copy to OpenClaw skills directory\ncp -r skills/tophant-clawvault ~/.openclaw/skills/\n\n# Or create symbolic link\nln -s /path/to/ClawVault/skills/tophant-clawvault ~/.openclaw/skills/tophant-clawvault\n\n# Restart OpenClaw\nopenclaw restart\n```\n\n### Basic Usage\n\n```bash\n# Install ClawVault\n/clawvault install --mode quick\n\n# Check health\n/clawvault health\n\n# Generate security rule\n/clawvault generate-rule \"Block all AWS credentials\" --apply\n\n# Run tests\n/clawvault test --category all\n```\n\n## Features\n\n- **AI-guided installation** - Quick, standard, or advanced setup modes\n- **Pinned install sources** - Uses `clawvault>=0.1.0,<1.0.0` and a pinned GitHub fallback (`v0.1.0`) for safer, repeatable installs\n- **Failure-aware setup** - Reports configuration initialization failures instead of silently continuing\n- **Secure dashboard defaults** - Binds dashboard to `127.0.0.1` by default\n- **Rule generation** - Create security rules from natural language\n- **Scenario templates** - Pre-configured policies (customer_service, development, production, finance)\n- **Detection testing** - Built-in test suites for validation\n- **Health monitoring** - Real-time service status\n\n## Documentation\n\n- **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first**\n- **Skill Reference**: [SKILL.md](./SKILL.md)\n- **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md)\n- **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md)\n\n## Requirements\n\n- Python 3.10+\n- OpenClaw installed\n- Ports 8765, 8766 available\n\n## Support\n\n- **Repository**: https://github.com/tophant-ai/ClawVault\n- **Issues**: https://github.com/tophant-ai/ClawVault/issues\n- **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc\n\n## License\n\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.8:_meta.json\n\n{\n  \"ownerId\": \"kn70av3n6bs6dqfaajr8drm90d82v5tt\",\n  \"slug\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.8\",\n  \"publishedAt\": 1777357162317\n}\n\nFile v0.2.8:SECURITY.md\n\n# Security Documentation\n\n## Overview\n\nClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.\n\n## How ClawVault Works\n\n### Proxy Architecture\n\nClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:\n\n```\nAI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs\n                    ↓\n            Detection Engine\n                    ↓\n            Dashboard (localhost:8766)\n```\n\n**What This Means:**\n- All API requests pass through ClawVault for inspection\n- ClawVault can see request/response content including API keys\n- This is intentional and necessary for threat detection\n- The proxy runs locally on your machine, not on external servers\n\n### SSL/TLS Verification\n\n**Default Behavior:**\n- ClawVault's default configuration sets `ssl_verify: false` for proxied connections\n- This is required for the proxy to inspect HTTPS traffic (MITM-style interception)\n\n**Security Implications:**\n- Disabling SSL verification allows ClawVault to decrypt and inspect encrypted traffic\n- This is necessary for detecting threats in API requests/responses\n- Traffic between your machine and LLM providers is still encrypted\n- The decryption happens locally on your machine, not in transit\n\n**Recommendation:**\n- Only use ClawVault on trusted networks\n- The proxy is designed for local development/testing\n- For production, consider using ClawVault's detection rules without the proxy\n\n## Dashboard Security\n\n### Default Configuration (Secure)\n\n```bash\n# Dashboard binds to localhost only\nclawvault start\n# Access: http://127.0.0.1:8766 (local machine only)\n```\n\n**This is the recommended configuration** for most users.\n\n### Remote Access Configuration (Risky)\n\n```bash\n# Dashboard accessible from any IP\nclawvault start --dashboard-host 0.0.0.0\n# Access: http://<your-ip>:8766 (anyone on network can access)\n```\n\n**⚠️ Security Risks:**\n- Dashboard shows sensitive detection data (API keys, PII, etc.)\n- No authentication by default\n- Anyone on your network can view the dashboard\n- Potential data exposure if misconfigured\n\n**When to Use Remote Access:**\n- Only in trusted, isolated networks\n- Behind a firewall with strict access controls\n- For temporary debugging/demonstration purposes\n\n**Production Recommendations:**\n1. Keep dashboard on localhost (127.0.0.1)\n2. Use SSH tunneling for remote access:\n   ```bash\n   ssh -L 8766:localhost:8766 user@remote-server\n   ```\n3. Or use a reverse proxy with authentication (nginx + basic auth)\n4. Never expose dashboard to public internet without authentication\n\n## Permissions Explained\n\nThe skill requires these permissions:\n\n### `execute_command`\n- **Purpose:** Run `pip install clawvault` and start/stop services\n- **Risk:** Can execute arbitrary commands on your system\n- **Mitigation:** Skill only runs documented installation commands; review clawvault_manager.py source\n\n### `write_files`\n- **Purpose:** Create configuration files in `~/.ClawVault/`\n- **Risk:** Can write to your home directory\n- **Mitigation:** Skill only writes to dedicated ClawVault config directory\n\n### `read_files`\n- **Purpose:** Read existing ClawVault configuration\n- **Risk:** Can read files on your system\n- **Mitigation:** Skill only reads from `~/.ClawVault/` directory\n\n### `network`\n- **Purpose:** Download ClawVault package, proxy API traffic, call local dashboard API\n- **Risk:** Can make network requests\n- **Mitigation:** Network access is essential for proxy functionality; all traffic is logged\n\n## Data Handling\n\n### What Data ClawVault Sees\n\nClawVault inspects:\n- API requests to LLM providers (OpenAI, Anthropic, etc.)\n- API responses from LLM providers\n- API keys and authentication tokens (in request headers)\n- User prompts and AI responses\n- Potentially sensitive data (PII, credentials) in prompts/responses\n\n### Where Data Is Stored\n\n- **Audit logs:** `~/.ClawVault/audit.db` (SQLite database)\n- **Detection logs:** `~/.ClawVault/logs/detection.log`\n- **Configuration:** `~/.ClawVault/config.yaml`\n\n### Data Retention\n\n- Audit logs are stored indefinitely by default\n- You can configure retention policies in `config.yaml`\n- To clear logs: `rm ~/.ClawVault/audit.db`\n\n### Data Privacy\n\n- All data stays on your local machine\n- ClawVault does not send data to external servers (except when proxying to LLM providers)\n- No telemetry or analytics are collected\n- You control all data through local configuration files\n\n## Installation Security\n\n### Package Sources\n\nThe skill installs ClawVault from:\n1. **Primary:** PyPI (`pip install clawvault`)\n2. **Fallback:** GitHub (`git+https://github.com/tophant-ai/ClawVault.git`)\n\n**Security Considerations:**\n- PyPI packages can be updated by maintainers\n- No version pinning or checksum verification in the skill\n- Installing from GitHub uses the latest main branch code\n\n**Recommendations:**\n1. Review the ClawVault package source before installing:\n   - PyPI: https://pypi.org/project/clawvault/\n   - GitHub: https://github.com/tophant-ai/ClawVault\n2. Pin to specific version: `pip install clawvault==0.1.0`\n3. Verify package integrity if concerned about supply chain attacks\n\n### Installation Process\n\nWhat happens during installation:\n1. Checks Python version (requires 3.10+)\n2. Runs `pip install clawvault`\n3. Creates `~/.ClawVault/` directory\n4. Generates default `config.yaml`\n5. Optionally starts services on ports 8765, 8766\n\n## Threat Model\n\n### What ClawVault Protects Against\n\n✅ **Prompt injection attacks** - Detects attempts to manipulate AI behavior\n✅ **Data leakage** - Identifies PII, credentials, API keys in prompts/responses\n✅ **Dangerous commands** - Flags risky shell commands in AI outputs\n✅ **Jailbreak attempts** - Detects attempts to bypass AI safety measures\n\n### What ClawVault Does NOT Protect Against\n\n❌ **Malicious ClawVault package** - If the upstream package is compromised, the skill will install it\n❌ **Local system compromise** - If your machine is compromised, ClawVault data can be accessed\n❌ **Network attacks** - ClawVault does not protect against network-level attacks\n❌ **Supply chain attacks** - No verification of package integrity during installation\n\n## Best Practices\n\n### For Development/Testing\n\n```bash\n# Safe configuration for local development\nclawvault start --dashboard-host 127.0.0.1 --mode interactive\n\n# Review detection logs regularly\ntail -f ~/.ClawVault/logs/detection.log\n\n# Test with non-sensitive data first\nclawvault test --category all\n```\n\n### For Production\n\n```bash\n# Use strict mode for automated blocking\nclawvault start --mode strict\n\n# Keep dashboard local, use SSH tunnel for remote access\nssh -L 8766:localhost:8766 user@server\n\n# Configure audit retention\n# Edit ~/.ClawVault/config.yaml:\naudit:\n  enabled: true\n  retention_days: 30\n```\n\n### For Sensitive Environments\n\n1. **Review the source code** before installation\n2. **Run in isolated environment** (VM, container)\n3. **Use firewall rules** to restrict network access\n4. **Rotate API keys** regularly\n5. **Monitor audit logs** for suspicious activity\n6. **Disable dashboard** if not needed: `--no-dashboard`\n\n## Security Checklist\n\nBefore installing ClawVault skill:\n\n- [ ] Reviewed ClawVault package source code\n- [ ] Understand that ClawVault will see API keys and request content\n- [ ] Verified dashboard will bind to localhost (not 0.0.0.0)\n- [ ] Understand SSL verification implications\n- [ ] Have plan for audit log retention/cleanup\n- [ ] Running in appropriate environment (dev/test/prod)\n- [ ] Firewall configured if using remote dashboard\n- [ ] Understand what permissions the skill requires\n\n## Reporting Security Issues\n\nIf you discover a security vulnerability in ClawVault or this skill:\n\n**For Critical Vulnerabilities (RCE, data exfiltration, credential theft):**\n1. Open a [GitHub Security Advisory](https://github.com/tophant-ai/ClawVault/security/advisories/new) (private disclosure)\n2. Or email: security@tophant.com\n3. Include detailed description and reproduction steps\n4. We will respond within 48 hours and work on a fix\n\n**For Non-Critical Issues (documentation errors, configuration issues, minor bugs):**\n1. Open a public [GitHub Issue](https://github.com/tophant-ai/ClawVault/issues/new)\n2. Tag with `security` label\n3. Community can discuss and contribute fixes\n\nWe encourage responsible disclosure and will credit security researchers who report vulnerabilities.\n\n## Additional Resources\n\n- **ClawVault Documentation:** https://github.com/tophant-ai/ClawVault/tree/main/doc\n- **OpenClaw Security:** https://docs.openclaw.ai/gateway/security\n- **Threat Model:** https://github.com/tophant-ai/ClawVault/blob/main/doc/architecture.md\n\n## License\n\nThis security documentation is part of the ClawVault project.\nMIT © 2026 Tophant SPAI Lab\n\nFile v0.2.8:skill.json\n\n{\n  \"name\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.6\",\n  \"description\": \"AI security system that protects agents from prompt injection, data leakage, and dangerous commands. Operates as local HTTP proxy to inspect traffic. Review SECURITY.md before installing.\",\n  \"author\": \"Tophant SPAI Lab\",\n  \"homepage\": \"https://github.com/tophant-ai/ClawVault\",\n  \"repository\": \"https://github.com/tophant-ai/ClawVault\",\n  \"main\": \"clawvault_manager.py\",\n  \"permissions\": [\n    \"execute_command\",\n    \"write_files\",\n    \"read_files\",\n    \"network\"\n  ],\n  \"permissions_rationale\": {\n    \"execute_command\": \"Required to run pip install and start/stop ClawVault services\",\n    \"write_files\": \"Creates configuration files in ~/.ClawVault/ directory\",\n    \"read_files\": \"Reads ClawVault configuration from ~/.ClawVault/\",\n    \"network\": \"Downloads ClawVault package and proxies AI traffic for inspection\"\n  },\n  \"tags\": [\n    \"security\",\n    \"ai-protection\",\n    \"proxy\",\n    \"threat-detection\",\n    \"privacy\"\n  ],\n  \"requirements\": [\n    \"pyyaml\",\n    \"requests\"\n  ],\n  \"python_version\": \">=3.10\",\n  \"commands\": {\n    \"install\": {\n      \"description\": \"Install ClawVault with specified mode\",\n      \"usage\": \"install --mode [quick|standard|advanced]\"\n    },\n    \"health\": {\n      \"description\": \"Check ClawVault health status\",\n      \"usage\": \"health\"\n    },\n    \"generate-rule\": {\n      \"description\": \"Generate security rule from natural language or scenario\",\n      \"usage\": \"generate-rule <policy> [--scenario <name>] [--apply]\"\n    },\n    \"status\": {\n      \"description\": \"Get ClawVault running status and statistics\",\n      \"usage\": \"status\"\n    },\n    \"test\": {\n      \"description\": \"Run detection tests\",\n      \"usage\": \"test --category [all|sensitive|injection|commands]\"\n    },\n    \"uninstall\": {\n      \"description\": \"Uninstall ClawVault\",\n      \"usage\": \"uninstall [--keep-config]\"\n    }\n  },\n  \"scenarios\": [\n    \"customer_service\",\n    \"development\",\n    \"production\",\n    \"finance\"\n  ]\n}\n\nArchive v0.2.7: 6 files, 13966 bytes\n\nFiles: _meta.json (146b), clawvault_manager.py (22164b), README.md (2821b), SECURITY.md (8935b), skill.json (1999b), SKILL.md (3835b)\n\nFile v0.2.7:SKILL.md\n\n---\nname: tophant-clawvault-installer\nversion: 0.2.6\ndescription: AI security system for protecting agents from prompt injection, data leakage, and dangerous commands\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Skill\n\nAI security system for OpenClaw with installation, rule generation, detection, and monitoring.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## Commands\n\n### /clawvault start\n\nStart ClawVault services.\n\n```bash\nclawvault start                  # Default: localhost only (secure)\nclawvault start --mode strict    # Strict mode\n```\n\n### /clawvault install\n\nInstall ClawVault using pinned package sources and secure localhost defaults.\n\n```bash\n/clawvault install --mode quick     # Recommended; installs clawvault>=0.1.0,<1.0.0\n/clawvault install --mode standard  # Interactive\n/clawvault install --mode advanced  # Full control\n```\n\nIf PyPI installation is unavailable, the installer falls back to the pinned GitHub tag `v0.1.0`. Configuration failures are reported as installation failures so agents can recover safely.\n\n### /clawvault health\n\nCheck service health and status.\n\n```bash\n/clawvault health\n```\n\n### /clawvault generate-rule\n\nGenerate security rules from natural language.\n\n```bash\n/clawvault generate-rule \"Block all AWS credentials\"\n/clawvault generate-rule --scenario customer_service --apply\n```\n\n**Scenarios:** `customer_service`, `development`, `production`, `finance`\n\n### /clawvault status\n\nGet running status and statistics.\n\n```bash\n/clawvault status\n```\n\n### /clawvault test\n\nRun detection tests.\n\n```bash\n/clawvault test --category all\n/clawvault test --category sensitive\n```\n\n**Categories:** `all`, `sensitive`, `injection`, `commands`\n\n### /clawvault uninstall\n\nRemove ClawVault.\n\n```bash\n/clawvault uninstall\n/clawvault uninstall --keep-config  # Keep configuration\n```\n\n## Quick Examples\n\n```bash\n# Install\n/clawvault install --mode quick\n\n# Generate rule\n/clawvault generate-rule \"Detect database passwords\" --apply\n\n# Apply scenario\n/clawvault generate-rule --scenario customer_service --apply\n\n# Check health\n/clawvault health\n```\n\n## Requirements\n\n- Python 3.10+\n- Ports 8765, 8766 available\n\n## Permissions\n\n- `execute_command` - Run installation and ClawVault commands\n- `write_files` - Create configuration files\n- `read_files` - Read configurations\n- `network` - Download packages and API calls\n\n## Security Consi\n\nArchive v0.2.6: 6 files, 13966 bytes\n\nFiles: clawvault_manager.py (22164b), README.md (2821b), SECURITY.md (8935b), skill.json (1999b), SKILL.md (3835b), _meta.json (146b)\n\nArchive v0.2.5: 6 files, 18655 bytes\n\nFiles: clawvault_manager.py (35992b), README.md (2408b), SECURITY.md (13264b), skill.json (1958b), SKILL.md (4498b), _meta.json (146b)\n\nArchive v0.2.4: 6 files, 18841 bytes\n\nFiles: clawvault_manager.py (36244b), README.md (2408b), SECURITY.md (13538b), skill.json (1958b), SKILL.md (4498b), _meta.json (146b)","readmeExcerpt":"Skill: Tophant Clawvault Installer Owner: martin2877 Summary: Install, configure, test, and uninstall ClawVault AI security proxy Tags: ai-protection:0.2.5, installer:0.2.6, latest:0.2.13, privacy:0.2.5, proxy:0.2.5, security:0.2.6, threat-detection:0.2.5 Version history: v0.2.13 | 2026-05-19T09:56:14.409Z | user Add OpenClaw plugin installation and acceptance flow v0.2.12 | 2026-04-30T07:40:56.987Z | user Package an","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python3 SKILL_DIR/clawvault_manager.py <command> [options]"},{"language":"bash","snippet":"# Default: write OpenClaw gateway proxy config and start ClawVault web dashboard,\n# but do not restart openclaw-gateway.\n# ClawVault web dashboard starts at http://localhost:8766.\n# To activate OpenClaw proxy later, manually run:\n#   systemctl --user restart openclaw-gateway\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --install-plugin --json\n\n# Interactive setup\npython3 SKILL_DIR/clawvault_manager.py install --mode standard --json\n\n# Full control (strict mode)\npython3 SKILL_DIR/clawvault_manager.py install --mode advanced --json\n\n# Install without starting services\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json\n\n# Deprecated compatibility flag: proxy config is already written by default\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --json\n\n# Dangerous: restart gateway immediately; may disconnect or hang OpenClaw\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --restart-gateway --json\n\n# Skip OpenClaw proxy integration explicitly\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json"},{"language":"bash","snippet":"python3 SKILL_DIR/clawvault_manager.py health --json"},{"language":"bash","snippet":"python3 SKILL_DIR/clawvault_manager.py generate-rule \"Block all AWS credentials\" --json\npython3 SKILL_DIR/clawvault_manager.py generate-rule --scenario customer_service --apply --json"},{"language":"bash","snippet":"python3 SKILL_DIR/clawvault_manager.py test --category all --json\npython3 SKILL_DIR/clawvault_manager.py test --category sensitive --json"},{"language":"bash","snippet":"python3 SKILL_DIR/clawvault_manager.py unconfigure-proxy --json"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: tophant-clawvault-installer\nversion: 0.2.13\ndescription: Install, configure, test, and uninstall ClawVault AI security proxy\nhomepage: https://github.com/tophant-ai/ClawVault\nuser-invocable: true\ndisable-model-invocation: false\n---\n\n# ClawVault Installer\n\nInstall, configure, test, and uninstall ClawVault — the AI security proxy that protects agents from prompt injection, data leakage, and dangerous commands.\n\n**Protection Against:**\n- Prompt injection attacks\n- Data leakage (PII, credentials, API keys)\n- Dangerous command execution\n- Jailbreak attempts\n\n## What This Skill Does\n\nInstalls ClawVault into a dedicated venv at `~/.clawvault-env/` and writes config under `~/.ClawVault/`. See `SECURITY.md` for the full capability, risk, and design-intent disclosure.\n\n## How to Run\n\n**IMPORTANT: All commands MUST be executed using the Python script bundled with this skill.**\n\nDo NOT run `pip install`, `clawvault`, or any other command directly. Always use:\n\n```bash\npython3 SKILL_DIR/clawvault_manager.py <command> [options]\n```\n\nWhere `SKILL_DIR` is the directory containing this SKILL.md file (typically `~/.openclaw/workspace/skills/tophant-clawvault-installer/` or `~/.openclaw/skills/tophant-clawvault-installer/`).\n\nAdd `--json` to any command for machine-readable JSON output.\n\n## Commands\n\n### /tophant-clawvault-installer install\n\nInstall ClawVault. The script creates a Python virtual environment, temporarily installs the latest GitHub repository code from `main` instead of PyPI or a fixed tag, generates config, writes OpenClaw gateway proxy config when the gateway service exists, and starts ClawVault services. By default it does **not** restart `openclaw-gateway`, because recent OpenClaw versions may disconnect or hang after a gateway restart. **No pip or system package manager needed.**\n\n```bash\n# Default: write OpenClaw gateway proxy config and start ClawVault web dashboard,\n# but do not restart openclaw-gateway.\n# ClawVault web dashboard starts at http://localhost:8766.\n# To activate OpenClaw proxy later, manually run:\n#   systemctl --user restart openclaw-gateway\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --install-plugin --json\n\n# Interactive setup\npython3 SKILL_DIR/clawvault_manager.py install --mode standard --json\n\n# Full control (strict mode)\npython3 SKILL_DIR/clawvault_manager.py install --mode advanced --json\n\n# Install without starting services\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-start --json\n\n# Deprecated compatibility flag: proxy config is already written by default\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --json\n\n# Dangerous: restart gateway immediately; may disconnect or hang OpenClaw\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --configure-gateway-proxy --restart-gateway --json\n\n# Skip OpenClaw proxy integration explicitly\npython3 SKILL_DIR/clawvault_manager.py install --mode quick --no-proxy --json\n```\n\n### OpenClaw plugi"},{"path":"README.md","content":"# ClawVault Installer Skill\r\n\r\nAI security system for OpenClaw — protect your AI agents from prompt injection, data leakage, and dangerous commands.\r\n\r\n## Before Installing\r\n\r\nThis skill installs and operates a local HTTPS-inspection proxy. Capabilities, defaults, and risks are documented in [SECURITY.md](./SECURITY.md) — please review it before installing.\r\n\r\n## Quick Start\r\n\r\n### Installation\r\n\r\n**Option 1: Install from ClawHub (Recommended)**\r\n\r\n```bash\r\n# Install from ClawHub\r\nopenclaw skills install tophant-clawvault-installer\r\n\r\n# Or use clawhub CLI\r\nclawhub install tophant-clawvault-installer\r\n```\r\n\r\n**ClawHub:** https://clawhub.ai/Martin2877/tophant-clawvault-installer\r\n\r\n**Option 2: Install from Local Repository**\r\n\r\n```bash\r\n# Copy to OpenClaw skills directory\r\ncp -r skills/tophant-clawvault-installer ~/.openclaw/skills/\r\n\r\n# Or create symbolic link\r\nln -s /path/to/ClawVault/skills/tophant-clawvault-installer ~/.openclaw/skills/tophant-clawvault-installer\r\n\r\n# Restart OpenClaw\r\nopenclaw restart\r\n```\r\n\r\n### Basic Usage\r\n\r\n```bash\r\n# Install ClawVault and link the OpenClaw file-guard plugin\r\n/tophant-clawvault-installer install --mode quick --install-plugin\r\n\r\n# Check health\r\n/tophant-clawvault-installer health\r\n\r\n# Generate security rule\r\n/tophant-clawvault-installer generate-rule \"Block all AWS credentials\" --apply\r\n\r\n# Run tests\r\n/tophant-clawvault-installer test --category all\r\n```\r\n\r\n## Features\r\n\r\n- **AI-guided installation** - Quick, standard, or advanced setup modes\r\n- **Dedicated virtualenv** - Installs into `~/.clawvault-env` instead of the system Python\r\n- **Latest GitHub install source** - Temporarily installs from the latest GitHub `main` code instead of PyPI or a fixed tag\r\n- **Failure-aware setup** - Reports configuration initialization failures as installation failures\r\n- **Secure dashboard defaults** - Binds the dashboard to `127.0.0.1` by default\r\n- **OpenClaw proxy integration and validation** - Can configure OpenClaw gateway proxy settings and verify the normal prompt path that triggers file-guard plugin interception\r\n- **Rule generation** - Create security rules from natural language\r\n- **Scenario templates** - Pre-configured policies (customer_service, development, production, finance)\r\n- **Detection testing** - Built-in test suites for validation\r\n- **Health monitoring** - Real-time service status\r\n\r\n## Documentation\r\n\r\n- **Security Guide**: [SECURITY.md](./SECURITY.md) ⚠️ **Read this first**\r\n- **Skill Reference**: [SKILL.md](./SKILL.md)\r\n- **Complete Guide**: [../../doc/OPENCLAW_SKILL.md](../../doc/OPENCLAW_SKILL.md)\r\n- **中文文档**: [../../doc/zh/OPENCLAW_SKILL.md](../../doc/zh/OPENCLAW_SKILL.md)\r\n\r\n## Requirements\r\n\r\n- Python 3.10+\r\n- OpenClaw installed\r\n- Ports 8765, 8766 available\r\n\r\n## Support\r\n\r\n- **Repository**: https://github.com/tophant-ai/ClawVault\r\n- **Issues**: https://github.com/tophant-ai/ClawVault/issues\r\n- **Documentation**: https://github.com/tophant-ai/ClawVault/tree/main/doc\r\n\r\n## License\r\n\r\nMIT © 2"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn70av3n6bs6dqfaajr8drm90d82v5tt\",\n  \"slug\": \"tophant-clawvault-installer\",\n  \"version\": \"0.2.13\",\n  \"publishedAt\": 1779184574409\n}"},{"path":"SECURITY.md","content":"# Security Documentation\r\n\r\n## Overview\r\n\r\nClawVault is a security-focused AI protection system that operates as a local HTTP proxy to inspect and protect AI agent traffic. This document explains the security model, potential risks, and best practices for safe deployment.\r\n\r\n## Design Intent — Why Several Defaults Look Permissive\r\n\r\nClawVault is a **man-in-the-middle (MITM) inspection proxy for AI traffic**. To do its job, it necessarily exhibits behaviors that automated security scanners flag as high-risk. Every one of these is intentional. This section documents them up-front so there is no ambiguity between \"intentional capability\" and \"bug.\"\r\n\r\n| Behavior | Why it's required | How to constrain it |\r\n|---|---|---|\r\n| `ssl_verify: false` in default config | Decrypts HTTPS so detectors can scan request/response bodies. Without this, ClawVault cannot see the AI traffic it is meant to protect. | MITM only applies to hosts listed in `proxy.intercept_hosts`. Non-AI traffic passes through untouched. Limit the list if you only want specific providers inspected. |\r\n| Dashboard has no authentication by default | Default bind is `127.0.0.1` (localhost only); anyone with a shell on the machine already has more access than the dashboard exposes. | **Never** start with `--dashboard-host 0.0.0.0` on untrusted networks. Use SSH port-forwarding for remote viewing. |\r\n| The skill sees your API keys and prompts | API keys travel inside the HTTPS requests being inspected. A proxy that inspects requests will see them. | All traffic stays on `localhost`. Nothing is uploaded. Audit logs in `~/.ClawVault/audit.db` are local-only. |\r\n| Installer writes `HTTP_PROXY`/`HTTPS_PROXY` into `openclaw-gateway.service` | Routes OpenClaw traffic through ClawVault when the gateway is restarted later. The installer does not restart the gateway by default because recent OpenClaw versions may disconnect or hang after gateway restart. | Pass `--no-proxy` to skip the unit-file change. Restart `openclaw-gateway` manually only when safe to reconnect. Use `unconfigure-proxy` to remove the injected env lines. |\r\n| Installs from latest GitHub source | Temporary behavior: PyPI and fixed-tag installs are disabled so users get the newest repository code. | Review the repository before installing or run in a disposable VM for higher assurance. See \"Package Sources\" below. |\r\n\r\nIf any of these trade-offs are unacceptable for your threat model, **do not install this skill.**\r\n\r\n## How ClawVault Works\r\n\r\n### Proxy Architecture\r\n\r\nClawVault runs as a **local HTTP proxy** that intercepts traffic between AI agents and LLM providers:\r\n\r\n```\r\nAI Agent → ClawVault Proxy (localhost:8765) → LLM Provider APIs\r\n                    ↓\r\n            Detection Engine\r\n                    ↓\r\n            Dashboard (localhost:8766)\r\n```\r\n\r\n**What This Means:**\r\n- All API requests pass through ClawVault for inspection\r\n- ClawVault can see request/response content including API keys\r\n- This is intentional and neces"},{"path":"skill-card.md","content":"## Description:\n\nInstall, configure, test, and uninstall ClawVault AI security proxy.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[martin2877](https://clawhub.ai/user/martin2877)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and OpenClaw operators use this skill to install and manage ClawVault as a local AI security proxy, generate security rules, run detection tests, and remove proxy configuration when needed.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Default setup can inspect API prompts, responses, and credentials through a local HTTPS inspection proxy.\n\nMitigation: Review before installing on a machine with real credentials and prefer a disposable VM or container for initial evaluation.\n\nRisk: The installer uses mutable remote code from the ClawVault main branch rather than a pinned release.\n\nMitigation: Install only from an audited pinned ClawVault commit for sensitive environments.\n\nRisk: Proxy integration can make persistent OpenClaw gateway changes and gateway restart may affect active sessions.\n\nMitigation: Use --no-proxy and --no-start unless proxy activation is intentional, and avoid --restart-gateway until the TLS and connectivity impact is understood.\n\n## Reference(s):\n\n- [ClawVault repository](https://github.com/tophant-ai/ClawVault)\n- [ClawVault OpenClaw skill guide](https://github.com/tophant-ai/ClawVault/blob/main/doc/OPENCLAW_SKILL.md)\n- [ClawVault documentation](https://github.com/tophant-ai/ClawVault/tree/main/doc)\n- [ClawHub skill page](https://clawhub.ai/martin2877/skills/tophant-clawvault-installer)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown instructions with bash command examples and JSON-capable command output.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands support --json for machine-readable output.]\n\n## Skill Version(s):\n\n0.2.13 (source: server release, SKILL.md frontmatter, skill.json)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1677,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T03:28:29.472Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T03:28:29.472Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:35:20.161Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}