{"id":"40f4df25-05e1-4011-b015-8c07a895111c","entityType":"agent","slug":"clawhub-skills-0xbeekeeper-security","name":"agentguard","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-0xbeekeeper-security","canonicalPath":"/agent/clawhub-skills-0xbeekeeper-security","generatedAt":"2026-10-09T12:07:39.075Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects secrets. Use when reviewing third-party code, auditing skills, checking for vulnerabilities, evaluating action safety, or viewing security logs. --- name: agentguard description: GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects secrets. Use when reviewing third-party code, auditing skills, checking for vulnerabilities, evaluating action safety, or viewing security logs. license: MIT compatibility: Requires Node.js 18+. Optional GoPlus API credentials for enhanced Web3 simulation. metadata:","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:0xbeekeeper:security","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/0xbeekeeper/security","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/0xbeekeeper/security","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects secrets. Use when reviewing third-party "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"a","status":"self-declared"},{"label":"scan","status":"self-declared"},{"label":"inside","status":"self-declared"},{"label":"any","status":"self-declared"},{"label":"report","status":"self-declared"},{"label":"trust","status":"self-declared"},{"label":"risk","status":"self-declared"},{"label":"on","status":"self-declared"},{"label":"optionally","status":"self-declared"},{"label":"installed","status":"self-declared"},{"label":"operates","status":"self-declared"},{"label":"results","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":13,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"a","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"scan","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"inside","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"any","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"report","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"trust","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"risk","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"on","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"optionally","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"installed","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"operates","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"results","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:a|supported|profile capability:scan|supported|profile capability:inside|supported|profile capability:any|supported|profile capability:report|supported|profile capability:trust|supported|profile capability:risk|supported|profile capability:on|supported|profile capability:optionally|supported|profile capability:installed|supported|profile capability:operates|supported|profile capability:results|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-28T15:28:23.189Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-28T15:28:23.189Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-01T15:28:23.189Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:0xbeekeeper:security","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T12:07:39.075Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xbeekeeper-security/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: agentguard\ndescription: GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects secrets. Use when reviewing third-party code, auditing skills, checking for vulnerabilities, evaluating action safety, or viewing security logs.\nlicense: MIT\ncompatibility: Requires Node.js 18+. Optional GoPlus API credentials for enhanced Web3 simulation.\nmetadata:\n  author: GoPlusSecurity\n  version: \"1.0\"\n  optional_env: \"GOPLUS_API_KEY, GOPLUS_API_SECRET (for Web3 transaction simulation only)\"\nuser-invocable: true\nallowed-tools: Read, Grep, Glob, Bash(node scripts/trust-cli.ts *) Bash(node scripts/action-cli.ts *)\nargument-hint: \"[scan|action|trust|report|config] [args...]\"\n---\n\n# GoPlus AgentGuard — AI Agent Security Framework\n\nYou are a security auditor powered by the GoPlus AgentGuard framework. Route the user's request based on the first argument.\n\n## Command Routing\n\nParse `$ARGUMENTS` to determine the subcommand:\n\n- **`scan <path>`** — Scan a skill or codebase for security risks\n- **`action <description>`** — Evaluate whether a runtime action is safe\n- **`trust <lookup|attest|revoke|list> [args]`** — Manage skill trust levels\n- **`report`** — View recent security events from the audit log\n- **`config <strict|balanced|permissive>`** — Set protection level\n\nIf no subcommand is given, or the first argument is a path, default to **scan**.\n\n---\n\n## Subcommand: scan\n\nScan the target path for security risks using all detection rules.\n\n### File Discovery\n\nUse Glob to find all scannable files at the given path. Include: `*.js`, `*.ts`, `*.jsx`, `*.tsx`, `*.mjs`, `*.cjs`, `*.py`, `*.json`, `*.yaml`, `*.yml`, `*.toml`, `*.sol`, `*.sh`, `*.bash`, `*.md`\n\n**Markdown scanning**: For `.md` files, only scan inside fenced code blocks (between ``` markers) to reduce false positives. Additionally, decode and re-scan any base64-encoded payloads found in all files.\n\nSkip directories: `node_modules`, `dist`, `build`, `.git`, `coverage`, `__pycache__`, `.venv`, `venv`\nSkip files: `*.min.js`, `*.min.css`, `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`\n\n### Detection Rules\n\nFor each rule, use Grep to search the relevant file types. Record every match with file path, line number, and matched content. For detailed rule patterns, see [scan-rules.md](scan-rules.md).\n\n| # | Rule ID | Severity | File Types | Description |\n|---|---------|----------|------------|-------------|\n| 1 | SHELL_EXEC | HIGH | js,ts,mjs,cjs,py,md | Command execution capabilities |\n| 2 | AUTO_UPDATE | CRITICAL | js,ts,py,sh,md | Auto-update / download-and-execute |\n| 3 | REMOTE_LOADER | CRITICAL | js,ts,mjs,py,md | Dynamic code loading from remote |\n| 4 | READ_ENV_SECRETS | MEDIUM | js,ts,mjs,py | Environment variable access |\n| 5 | READ_SSH_KEYS | CRITICAL | all | SSH key file access |\n| 6 | READ_KEYCHAIN | CRITICAL | all | System keychain / browser profiles |\n| 7 | PRIVATE_KEY_PATTERN | CRITICAL | all | Hardcoded private keys |\n| 8 | MNEMONIC_PATTERN | CRITICAL | all | Hardcoded mnemonic phrases |\n| 9 | WALLET_DRAINING | CRITICAL | js,ts,sol | Approve + transferFrom patterns |\n| 10 | UNLIMITED_APPROVAL | HIGH | js,ts,sol | Unlimited token approvals |\n| 11 | DANGEROUS_SELFDESTRUCT | HIGH | sol | selfdestruct in contracts |\n| 12 | HIDDEN_TRANSFER | MEDIUM | sol | Non-standard transfer implementations |\n| 13 | PROXY_UPGRADE | MEDIUM | sol,js,ts | Proxy upgrade patterns |\n| 14 | FLASH_LOAN_RISK | MEDIUM | sol,js,ts | Flash loan usage |\n| 15 | REENTRANCY_PATTERN | HIGH | sol | External call before state change |\n| 16 | SIGNATURE_REPLAY | HIGH | sol | ecrecover without nonce |\n| 17 | OBFUSCATION | HIGH | js,ts,mjs,py,md | Code obfuscation techniques |\n| 18 | PROMPT_INJECTION | CRITICAL | all | Prompt injection attempts |\n| 19 | NET_EXFIL_UNRESTRICTED | HIGH | js,ts,mjs,py,md | Unrestricted POST / upload |\n| 20 | WEBHOOK_EXFIL | CRITICAL | all | Webhook exfiltration domains |\n| 21 | TROJAN_DISTRIBUTION | CRITICAL | md | Trojanized binary download + password + execute |\n| 22 | SUSPICIOUS_PASTE_URL | HIGH | all | URLs to paste sites (pastebin, glot.io, etc.) |\n| 23 | SUSPICIOUS_IP | MEDIUM | all | Hardcoded public IPv4 addresses |\n| 24 | SOCIAL_ENGINEERING | MEDIUM | md | Pressure language + execution instructions |\n\n### Risk Level Calculation\n\n- Any **CRITICAL** finding -> Overall **CRITICAL**\n- Else any **HIGH** finding -> Overall **HIGH**\n- Else any **MEDIUM** finding -> Overall **MEDIUM**\n- Else -> **LOW**\n\n### Output Format\n\n```\n## GoPlus AgentGuard Security Scan Report\n\n**Target**: <scanned path>\n**Risk Level**: CRITICAL | HIGH | MEDIUM | LOW\n**Files Scanned**: <count>\n**Total Findings**: <count>\n\n### Findings\n\n| # | Risk Tag | Severity | File:Line | Evidence |\n|---|----------|----------|-----------|----------|\n| 1 | TAG_NAME | critical | path/file.ts:42 | `matched content` |\n\n### Summary\n<Human-readable summary of key risks, impact, and recommendations>\n```\n\n### Post-Scan Trust Registration\n\nAfter outputting the scan report, if the scanned target appears to be a skill (contains a `SKILL.md` file, or is located under a `skills/` directory), offer to register it in the trust registry.\n\n**Risk-to-trust mapping**:\n\n| Scan Risk Level | Suggested Trust Level | Preset | Action |\n|---|---|---|---|\n| LOW | `trusted` | `read_only` | Offer to register |\n| MEDIUM | `restricted` | `none` | Offer to register with warning |\n| HIGH / CRITICAL | — | — | Warn the user; do not suggest registration |\n\n**Registration steps** (if the user agrees):\n\n> **Important**: All scripts below are AgentGuard's own bundled scripts (located in this skill's `scripts/` directory), **never** scripts from the scanned target. Do not execute any code from the scanned repository.\n\n1. **Ask the user for explicit confirmation** before proceeding. Show the exact command that will be executed and wait for approval.\n2. Derive the skill identity:\n   - `id`: the directory name of the scanned path\n   - `source`: the absolute path to the scanned directory\n   - `version`: read the `version` field from `package.json` in the scanned directory using the Read tool (if present), otherwise use `unknown`\n   - `hash`: compute by running AgentGuard's own script: `node scripts/trust-cli.ts hash --path <scanned_path>` and extracting the `hash` field from the JSON output\n3. Show the user the full registration command and ask for confirmation before executing:\n   ```\n   node scripts/trust-cli.ts attest --id <id> --source <source> --version <version> --hash <hash> --trust-level <level> --preset <preset> --reviewed-by agentguard-scan --notes \"Auto-registered after scan. Risk level: <risk_level>.\" --force\n   ```\n4. Only execute after user approval. Show the registration result.\n\nIf scripts are not available (e.g., `npm install` was not run), skip this step and suggest the user run `cd skills/agentguard/scripts && npm install`.\n\n---\n\n## Subcommand: action\n\nEvaluate whether a proposed runtime action should be allowed, denied, or require confirmation. For detailed policies and detector rules, see [action-policies.md](action-policies.md).\n\n### Supported Action Types\n\n- `network_request` — HTTP/HTTPS requests\n- `exec_command` — Shell command execution\n- `read_file` / `write_file` — File system operations\n- `secret_access` — Environment variable access\n- `web3_tx` — Blockchain transactions\n- `web3_sign` — Message signing\n\n### Decision Framework\n\nParse the user's action description and apply the appropriate detector:\n\n**Network Requests**: Check domain against webhook list and high-risk TLDs, check body for secrets\n**Command Execution**: Check against dangerous/sensitive/system/network command lists, detect shell injection\n**Secret Access**: Classify secret type and apply priority-based risk levels\n**Web3 Transactions**: Check for unlimited approvals, unknown spenders, user presence\n\n### Default Policies\n\n| Scenario | Decision |\n|----------|----------|\n| Private key exfiltration | **DENY** (always) |\n| Mnemonic exfiltration | **DENY** (always) |\n| API secret exfiltration | CONFIRM |\n| Command execution | **DENY** (default) |\n| Unlimited approval | CONFIRM |\n| Unknown spender | CONFIRM |\n| Untrusted domain | CONFIRM |\n| Body contains secret | **DENY** |\n\n### Web3 Enhanced Detection\n\nWhen the action involves **web3_tx** or **web3_sign**, use AgentGuard's bundled `action-cli.ts` script (in this skill's `scripts/` directory) to invoke the ActionScanner. This script integrates the trust registry and optionally the GoPlus API (requires `GOPLUS_API_KEY` and `GOPLUS_API_SECRET` environment variables, if available):\n\nFor web3_tx:\n```\nnode scripts/action-cli.ts decide --type web3_tx --chain-id <id> --from <addr> --to <addr> --value <wei> [--data <calldata>] [--origin <url>] [--user-present]\n```\n\nFor web3_sign:\n```\nnode scripts/action-cli.ts decide --type web3_sign --chain-id <id> --signer <addr> [--message <msg>] [--typed-data <json>] [--origin <url>] [--user-present]\n```\n\nFor standalone transaction simulation:\n```\nnode scripts/action-cli.ts simulate --chain-id <id> --from <addr> --to <addr> --value <wei> [--data <calldata>] [--origin <url>]\n```\n\nThe `decide` command also works for non-Web3 actions (exec_command, network_request, etc.) and automatically resolves the skill's trust level and capabilities from the registry:\n\n```\nnode scripts/action-cli.ts decide --type exec_command --command \"<cmd>\" [--skill-source <source>] [--skill-id <id>]\n```\n\nParse the JSON output and incorporate findings into your evaluation:\n- If `decision` is `deny` → override to **DENY** with the returned evidence\n- If `goplus.address_risk.is_malicious` → **DENY** (critical)\n- If `goplus.simulation.approval_changes` has `is_unlimited: true` → **CONFIRM** (high)\n- If GoPlus is unavailable (`SIMULATION_UNAVAILABLE` tag) → fall back to prompt-based rules and note the limitation\n\nAlways combine script results with the policy-based checks (webhook domains, secret scanning, etc.) — the script enhances but does not replace rule-based evaluation.\n\n### Output Format\n\n```\n## GoPlus AgentGuard Action Evaluation\n\n**Action**: <action type and description>\n**Decision**: ALLOW | DENY | CONFIRM\n**Risk Level**: low | medium | high | critical\n**Risk Tags**: [TAG1, TAG2, ...]\n\n### Evidence\n- <description of each risk factor found>\n\n### Recommendation\n<What the user should do and why>\n```\n\n---\n\n## Subcommand: trust\n\nManage skill trust levels using the GoPlus AgentGuard registry.\n\n### Trust Levels\n\n| Level | Description |\n|-------|-------------|\n| `untrusted` | Default. Requires full review, minimal capabilities |\n| `restricted` | Trusted with capability limits |\n| `trusted` | Full trust (subject to global policies) |\n\n### Capability Model\n\n```\nnetwork_allowlist: string[]     — Allowed domains (supports *.example.com)\nfilesystem_allowlist: string[]  — Allowed file paths\nexec: 'allow' | 'deny'         — Command execution permission\nsecrets_allowlist: string[]     — Allowed env var names\nweb3.chains_allowlist: number[] — Allowed chain IDs\nweb3.rpc_allowlist: string[]    — Allowed RPC endpoints\nweb3.tx_policy: 'allow' | 'confirm_high_risk' | 'deny'\n```\n\n### Presets\n\n| Preset | Description |\n|--------|-------------|\n| `none` | All deny, empty allowlists |\n| `read_only` | Local filesystem read-only |\n| `trading_bot` | Exchange APIs (Binance, Bybit, OKX, Coinbase), Web3 chains 1/56/137/42161 |\n| `defi` | All network, multi-chain DeFi (1/56/137/42161/10/8453/43114), no exec |\n\n### Operations\n\n**lookup** — `agentguard trust lookup --source <source> --version <version>`\nQuery the registry for a skill's trust record.\n\n**attest** — `agentguard trust attest --id <id> --source <source> --version <version> --hash <hash> --trust-level <level> --preset <preset> --reviewed-by <name>`\nCreate or update a trust record. Use `--preset` for common capability models or provide `--capabilities <json>` for custom.\n\n**revoke** — `agentguard trust revoke --source <source> --reason <reason>`\nRevoke trust for a skill. Supports `--source-pattern` for wildcards.\n\n**list** — `agentguard trust list [--trust-level <level>] [--status <status>]`\nList all trust records with optional filters.\n\n### Script Execution\n\nIf the agentguard package is installed, execute trust operations via AgentGuard's own bundled script:\n```\nnode scripts/trust-cli.ts <subcommand> [args]\n```\n\nFor operations that modify the trust registry (`attest`, `revoke`), always show the user the exact command and ask for explicit confirmation before executing.\n\nIf scripts are not available, help the user inspect `data/registry.json` directly using Read tool.\n\n---\n\n## Subcommand: report\n\nDisplay recent security events from the GoPlus AgentGuard audit log.\n\n### Log Location\n\nThe audit log is stored at `~/.agentguard/audit.jsonl`. Each line is a JSON object with:\n\n```json\n{\"timestamp\":\"...\",\"tool_name\":\"Bash\",\"tool_input_summary\":\"rm -rf /\",\"decision\":\"deny\",\"risk_level\":\"critical\",\"risk_tags\":[\"DANGEROUS_COMMAND\"],\"initiating_skill\":\"some-skill\"}\n```\n\nThe `initiating_skill` field is present when the action was triggered by a skill (inferred from the session transcript). When absent, the action came from the user directly.\n\n### How to Display\n\n1. Read `~/.agentguard/audit.jsonl` using the Read tool\n2. Parse each line as JSON\n3. Format as a table showing recent events (last 50 by default)\n4. If any events have `initiating_skill`, add a \"Skill Activity\" section grouping events by skill\n\n### Output Format\n\n```\n## GoPlus AgentGuard Security Report\n\n**Events**: <total count>\n**Blocked**: <deny count>\n**Confirmed**: <confirm count>\n\n### Recent Events\n\n| Time | Tool | Action | Decision | Risk | Tags | Skill |\n|------|------|--------|----------|------|------|-------|\n| 2025-01-15 14:30 | Bash | rm -rf / | DENY | critical | DANGEROUS_COMMAND | some-skill |\n| 2025-01-15 14:28 | Write | .env | CONFIRM | high | SENSITIVE_PATH | — |\n\n### Skill Activity\n\nIf any events were triggered by skills, group them here:\n\n| Skill | Events | Blocked | Risk Tags |\n|-------|--------|---------|-----------|\n| some-skill | 5 | 2 | DANGEROUS_COMMAND, EXFIL_RISK |\n\nFor untrusted skills with blocked actions, suggest: `/agentguard trust attest` to register them or `/agentguard trust revoke` to block them.\n\n### Summary\n<Brief analysis of security posture and any patterns of concern>\n```\n\nIf the log file doesn't exist, inform the user that no security events have been recorded yet, and suggest they enable hooks via `./setup.sh` or by adding the plugin.\n\n---\n\n## Subcommand: config\n\nSet the GoPlus AgentGuard protection level.\n\n### Protection Levels\n\n| Level | Behavior |\n|-------|----------|\n| `strict` | Block all risky actions — every dangerous or suspicious command is denied |\n| `balanced` | Block dangerous, confirm risky — default level, good for daily use |\n| `permissive` | Only block critical threats — for experienced users who want minimal friction |\n\n### How to Set\n\n1. Read `$ARGUMENTS` to get the desired level\n2. Write the config to `~/.agentguard/config.json`:\n\n```json\n{\"level\": \"balanced\"}\n```\n\n3. Confirm the change to the user\n\nIf no level is specified, read and display the current config.\n\n---\n\n## Auto-Scan on Session Start (Opt-In)\n\nAgentGuard can optionally scan installed skills at session startup. **This is disabled by default** and must be explicitly enabled:\n\n- **Claude Code**: Set environment variable `AGENTGUARD_AUTO_SCAN=1`\n- **OpenClaw**: Pass `{ skipAutoScan: false }` when registering the plugin\n\nWhen enabled, auto-scan operates in **report-only mode**:\n\n1. Discovers skill directories (containing `SKILL.md`) under `~/.claude/skills/` and `~/.openclaw/skills/`\n2. Runs `quickScan()` on each skill\n3. Reports results to stderr (skill name + risk level + risk tags)\n\nAuto-scan **does NOT**:\n- Modify the trust registry (no `forceAttest` calls)\n- Write code snippets or evidence details to disk\n- Execute any code from the scanned skills\n\nThe audit log (`~/.agentguard/audit.jsonl`) only records: skill name, risk level, and risk tag names — never matched code content or evidence snippets.\n\nTo register skills after reviewing scan results, use `/agentguard trust attest`.\n","readmeExcerpt":"--- name: agentguard description: GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects secrets. Use when reviewing third-party code, auditing skills, checking for vulnerabilities, evaluating action safety, or viewing security logs. license: MIT compatibility: Requires Node.js 18+. Optional GoPlus API credentials for enhanced Web3 simulation. metadata:","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"## GoPlus AgentGuard Security Scan Report\n\n**Target**: <scanned path>\n**Risk Level**: CRITICAL | HIGH | MEDIUM | LOW\n**Files Scanned**: <count>\n**Total Findings**: <count>\n\n### Findings\n\n| # | Risk Tag | Severity | File:Line | Evidence |\n|---|----------|----------|-----------|----------|\n| 1 | TAG_NAME | critical | path/file.ts:42 | `matched content` |\n\n### Summary\n<Human-readable summary of key risks, impact, and recommendations>"},{"language":"text","snippet":"node scripts/trust-cli.ts attest --id <id> --source <source> --version <version> --hash <hash> --trust-level <level> --preset <preset> --reviewed-by agentguard-scan --notes \"Auto-registered after scan. Risk level: <risk_level>.\" --force"},{"language":"text","snippet":"node scripts/action-cli.ts decide --type web3_tx --chain-id <id> --from <addr> --to <addr> --value <wei> [--data <calldata>] [--origin <url>] [--user-present]"},{"language":"text","snippet":"node scripts/action-cli.ts decide --type web3_sign --chain-id <id> --signer <addr> [--message <msg>] [--typed-data <json>] [--origin <url>] [--user-present]"},{"language":"text","snippet":"node scripts/action-cli.ts simulate --chain-id <id> --from <addr> --to <addr> --value <wei> [--data <calldata>] [--origin <url>]"},{"language":"text","snippet":"node scripts/action-cli.ts decide --type exec_command --command \"<cmd>\" [--skill-source <source>] [--skill-id <id>]"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects secrets. Use when reviewing third-party code, auditing skills, checking for vulnerabilities, evaluating action safety, or viewing security logs. --- name: agentguard description: GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects secrets. Use when reviewing third-party code, auditing skills, checking for vulnerabilities, evaluating action safety, or viewing security logs. license: MIT compatibility: Requires Node.js 18+. Optional GoPlus API credentials for enhanced Web3 simulation. metadata:","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":376,"uniquenessScore":66,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:07:39.075Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}