{"id":"bbaf838a-0619-4085-925d-5155686574a5","entityType":"agent","slug":"clawhub-tooled-app-data-guardian","name":"Guardian","canonicalUrl":"https://www.xpersona.co/agent/clawhub-tooled-app-data-guardian","canonicalPath":"/agent/clawhub-tooled-app-data-guardian","generatedAt":"2026-10-10T13:40:12.523Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:56:43.227Z","emptyReason":null},"description":"Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion (rm/del/remove), database modifications (writes/deletes...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s1732m0wt3pbwh1b2yn4byean986njc4:data-guardian","sourceUrl":"https://clawhub.ai/tooled-app/data-guardian","homepage":"https://clawhub.ai/tooled-app/skills/data-guardian","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/tooled-app/data-guardian","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/tooled-app/skills/data-guardian","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Guardian technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:56:43.227Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:56:43.227Z","emptyReason":null},"stars":null,"forks":null,"downloads":1510,"packageName":null,"latestVersion":"1.2.0","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:56:43.227Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T09:56:43.227Z","lastCrawledAt":"2026-10-10T09:56:43.227Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T09:56:43.227Z","lastVerifiedAt":null,"highlights":[{"version":"1.2.0","createdAt":"2026-05-25T13:32:52.040Z","changelog":"**Summary:** Major cleanup: removed documentation, references, and backup verification scripts to streamline the skill package. - Removed 7 files, including README, roadmap, descriptive tags, escalation references, taxonomy, and both Windows and Linux backup verification scripts. - No changes to the main protocol, rules, decision logic, or user-facing behavior. - All escalation and risk-scoring detail is retained in SKILL.md. - External documentation and backup verification are no longer bundled.","fileCount":8,"zipByteSize":16744},{"version":"1.1.0","createdAt":"2026-05-21T17:50:25.575Z","changelog":"**Guardian 1.0.1 Changelog** - Added CLAWHUB-TAGS.md for improved metadata/tagging support. - Added ROADMAP-v1.1.md to provide visibility into upcoming features and directions.","fileCount":9,"zipByteSize":18174},{"version":"1.0.0","createdAt":"2026-05-18T14:25:44.328Z","changelog":"Guardian 1.0.0 — mandatory safety skill for destructive AI agent operations. - Intercepts all file deletions, DB modifications, external messaging, mass and system operations before execution. - Requires fast, automatic backup verification; if backup is not active/verified, halts and escalates to human approval. - Operates at the tool-call or pre-flight layer; no opt-out or agent override permitted. - Logs all destructive actions and escalation events; flags repeated escalation patterns. - Full operation taxonomy and backup logic defined; platform-agnostic and mandatory across deployments.","fileCount":7,"zipByteSize":15201}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s1732m0wt3pbwh1b2yn4byean986njc4:data-guardian","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s1732m0wt3pbwh1b2yn4byean986njc4:data-guardian` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/tooled-app/data-guardian before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T13:40:12.521Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tooled-app-data-guardian/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:56:43.227Z","emptyReason":null},"readme":"Skill: Guardian\n\nOwner: tooled-app\n\nSummary: Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion (rm/del/remove), database modifications (writes/deletes...\n\nTags: latest:1.2.0\n\nVersion history:\n\nv1.2.0 | 2026-05-25T13:32:52.040Z | user\n\n**Summary:**  \nMajor cleanup: removed documentation, references, and backup verification scripts to streamline the skill package.\n\n- Removed 7 files, including README, roadmap, descriptive tags, escalation references, taxonomy, and both Windows and Linux backup verification scripts.\n- No changes to the main protocol, rules, decision logic, or user-facing behavior.\n- All escalation and risk-scoring detail is retained in SKILL.md.\n- External documentation and backup verification are no longer bundled.\n\nv1.1.0 | 2026-05-21T17:50:25.575Z | user\n\n**Guardian 1.0.1 Changelog**\n\n- Added CLAWHUB-TAGS.md for improved metadata/tagging support.\n- Added ROADMAP-v1.1.md to provide visibility into upcoming features and directions.\n\nv1.0.0 | 2026-05-18T14:25:44.328Z | user\n\nGuardian 1.0.0 — mandatory safety skill for destructive AI agent operations.\n\n- Intercepts all file deletions, DB modifications, external messaging, mass and system operations before execution.\n- Requires fast, automatic backup verification; if backup is not active/verified, halts and escalates to human approval.\n- Operates at the tool-call or pre-flight layer; no opt-out or agent override permitted.\n- Logs all destructive actions and escalation events; flags repeated escalation patterns.\n- Full operation taxonomy and backup logic defined; platform-agnostic and mandatory across deployments.\n\nArchive index:\n\nArchive v1.2.0: 8 files, 16744 bytes\n\nFiles: DECISION-MATRIX.md (5484b), OPERATION-TAXONOMY.md (4683b), README.md (5817b), scripts/verify-backup.ps1 (5592b), scripts/verify-backup.sh (6076b), skill-card.md (2183b), SKILL.md (7582b), _meta.json (132b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: guardian\nversion: 1.1\ndescription: Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion (rm/del/remove), database modifications (writes/deletes/drops), mass file operations (>10 files), system-level changes (service modifications, firewall rules), and external transmissions with side effects (email, API calls to unknown endpoints, mass messaging). Enforces backup verification before destructive execution. If backup is active and verified, low-risk operations proceed without delay. If no backup or risk is high, escalates to human approval. Use when an AI agent is about to execute an operation that irreversibly modifies, deletes, or transmits data or system configuration. Does NOT trigger on read-only operations, non-destructive edits with undo capability, or operations inside temporary/sandbox directories.\nSupport: support@ikkf.info\n---\n\n# Guardian — Mandatory Safety Gatekeeper (v1.1)\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\nA mandatory safety skill that intercepts destructive AI agent operations **before execution**. It employs a Context-Aware Risk Scoring (CARS) system to balance security with operational velocity.\n\n**This skill is mandatory.** No opt-out. No override by the executing agent.\n\nBased on the principle that **reasoning is not a guardrail**.\n\n## The Core Protocol (v1.1)\n\n```\nBEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. EVALUATE Risk Level via CARS Matrix\n  4. EXECUTE Decision Path:\n     - LOW: Auto-Approve (Log only)\n     - MEDIUM: Fast-Track (Verify Backup → Proceed)\n     - HIGH: Hard Block (Verify Backup → Human Approval)\n  5. IF JIT Window Active → Override High-Risk prompt (Proceed if Backup Verified)\n```\n\n## Context-Aware Risk Scoring (CARS) Matrix\n\n| Risk Level | Trigger Criteria | Action | Verification Required |\n| :--- | :--- | :--- | :--- |\n| **Low** | Files in `/tmp`, `sandbox/`, or `.cache`; Single file deletions in non-critical paths. | **Auto-Approve** | None (Log only) |\n| **Medium** | Edits to `.config` or `.env` files; Deletions of < 5 files in a Git-tracked directory. | **Fast-Track** | Verified backup required (Git, snapshot, or cloud sync) |\n| **High** | `rm -rf` on root/home; `DROP TABLE`; Edits to system files; Mass file deletions (>10). | **Hard Block** | Mandatory backup verification + **Human Approval required regardless of backup status** |\n\n## Escalation Rules\n\n| Scenario | Action |\n|----------|--------|\n| **ANY destructive operation** | Backup verification required |\n| **Low risk + verified backup** | PROCEED |\n| **Low risk + no backup** | PROCEED with warning |\n| **Medium risk + verified backup** | PROCEED |\n| **Medium risk + no backup** | **HALT + Human approval required** |\n| **High risk** | **ALWAYS HALT + Human approval required** |\n| **Repeated same pattern** | Flag pattern, require operator review |\n\n### JIT Window Override\nA JIT (Just-In-Time) window can temporarily downgrade High to Medium risk, but **never eliminates the human approval requirement for High risk**. Human approval is always required for High-risk destructive operations.\n\n## The Guardian Protocol Detail\n\n### Step 1: Operation Scan (automatic)\nEvery tool call is scanned against the taxonomy above. No agent discretion. No \"I know what I'm doing.\"\n\n### Step 2: Backup Verification (automatic)\n```\nVERIFY-BACKUP(target):\n  1. Check if target is covered by active backup system\n  2. Common indicators:\n     - .git repository with clean status\n     - Time Machine / File History active on target volume\n     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync\n     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot\n     - Versioned storage (ZFS snapshots, S3 versioning)\n  3. IF any indicator active AND recent → RETURN VERIFIED\n  4. ELSE → RETURN UNVERIFIED\n```\n\n**Fast path:** Backup verification must complete in <2 seconds. No long-running checks.\n\n### Step 3: Decision Matrix (v1.1)\n\n| Backup Status | Risk Level | Action |\n|---------------|-----------|--------|\n| **VERIFIED ACTIVE** | Low / Medium | PROCEED with execution |\n| **VERIFIED ACTIVE** | High | HALT and ESCALATE to human |\n| **UNVERIFIED** | Any | HALT and ESCALATE to human |\n| **UNKNOWN** | Any | Treat as UNVERIFIED — HALT and ESCALATE |\n\nSidenote: If a **JIT Window** is active, High Risk operations are downgraded to \"Fast-Track\" (Proceed if Backup Verified).\n\n### Step 4: Escalation Format\n\nWhen escalation is required, Guardian MUST output:\n\n```\n🛡️ GUARDIAN HALT\nOperation: [specific tool call]\nTarget: [file/path/database/endpoint]\nCategory: [taxonomy category]\nRisk Level: [CRITICAL/HIGH/MEDIUM]\nBackup Status: [UNVERIFIED / last backup: X hours ago]\n\nProposed Action: [what the agent wants to do]\nPotential Impact: [what could go wrong]\n\nOptions:\n1. APPROVE — Proceed with execution (human responsibility)\n2. DENY — Cancel operation\n3. SNAPSHOT — Create quick backup first, then proceed\n4. REVIEW — Agent provides additional justification\n\nGuardian awaits human decision.\n```\n\n## Mandatory Rules\n\n1. **No Self-Approval:** The executing agent cannot approve its own destructive operation.\n2. **No Confidence Override:** High confidence does not bypass backup verification.\n3. **No Silent Destruction:** Every destructive operation is logged.\n4. **No Assumption of Safety:** \"It looks safe\" is not verification. Backup status is verification.\n5. **No Escalation Fatigue:** If an agent generates repeated escalations for the same pattern, Guardian flags the pattern, not just the instance.\n\n## Integration\n\n### For OpenClaw / Agent Systems\n\nGuardian operates at the **tool-call layer**, between the agent's decision and the tool's execution:\n\n```\nAgent Decision → Guardian Intercept → [Verify Backup] → Execute OR Escalate\n```\n\n### For Standalone Agents\n\nIf the runtime doesn't support interception, Guardian operates as a **mandatory pre-flight check**:\n\n```\nBEFORE calling any tool:\n  1. Agent MUST call Guardian check\n  2. Guardian returns PROCEED or HALT\n  3. Agent respects HALT, awaits escalation resolution\n```\n\n## Logging\n\nEvery Guardian decision is logged:\n\n```\n[Timestamp] [Operation] [Category] [Backup Status] [Decision] [Approver]\n```\n\nLogs are append-only. No deletion by the executing agent.\n\nSidenote: All operations within a JIT window are tagged with `[JIT-GRANTED]` in the audit log.\n\n## Scope\n\n**Vanilla:** This skill is generic. Not specific to any agent, platform, or deployment.\n\n**Mandatory:** Once enabled, all sessions load this skill. No opt-out.\n\n**Non-Blocking (when safe):** Backup-verified operations proceed without delay. No human wait for routine maintenance with verified backups.\n\n## References\n\n- `references/OPERATION-TAXONOMY.md` — Full destructive operation classification\n- `references/DECISION-MATRIX.md` — Detailed backup verification logic and escalation rules\n- `scripts/verify-backup.ps1` — Windows backup detection script\n- `scripts/verify-backup.sh` — Linux/macOS backup detection script\n\n## Based On\n\n- AgentTrust (May 2026): Runtime safety evaluation and interception for AI agent tool use\n- Proof-of-Guardrail (Mar 2026): Cryptographic verification of guardrail claims  \n- AgentDoG (Jan 2026): Diagnostic guardrail framework for AI agent safety and security\n- Confirm-Before-Destroy Pattern: Tool-level guardrails + prompt-level safeguards\n- Gemini CLI PR #25947: Versioned pre-write backups with agent-driven restore\n\nFile v1.2.0:README.md\n\n# Guardian — Mandatory Safety Gatekeeper\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\nA mandatory safety skill that intercepts destructive AI agent operations **before execution**. If backup is verified active, proceed. If not, escalate.\n\n**This skill is mandatory.** No opt-out. No override by the executing agent.\n\n## 📖 The Philosophy\nGuardian is based on the principle that **reasoning is not a guardrail**.\n\n## The Core Protocol\n\n```\nBEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. VERIFY backup status (automatic + fast)\n  4. IF backup verified ACTIVE → LOG and PROCEED\n  5. IF backup NOT verified → HALT and ESCALATE\n```\n\n## Destructive Operation Taxonomy\n\n| Category | Operations | Risk Level |\n|----------|-----------|------------|\n| **File Destruction** | rm, del, remove, rmdir, unlink, trash, empty-trash, overwrite | CRITICAL |\n| **Database Destruction** | DROP, DELETE (no WHERE), TRUNCATE, ALTER destructive, migration down | CRITICAL |\n| **External Transmission** | send email, post tweet, publish message, API write with side effects | HIGH |\n| **Mass Operations** | >10 files modified/deleted in single operation, bulk renames | HIGH |\n| **System Changes** | service stop/start, firewall modify, registry edit, user create/delete | HIGH |\n| **Network Unknown** | Request to URL not in allowlist, new domain, unverified endpoint | MEDIUM |\n| **Configuration** | Overwrite .env, modify config files without backup | MEDIUM |\n\n**Rule:** When in doubt, classify as destructive. Better to verify a safe operation than destroy an unsafe one.\n\nFull taxonomy: `references/OPERATION-TAXONOMY.md`\n\n## The Guardian Protocol\n\n### Step 1: Operation Scan (automatic)\nEvery tool call is scanned against the taxonomy above. No agent discretion. No \"I know what I'm doing.\"\n\n### Step 2: Backup Verification (automatic)\n```\nVERIFY-BACKUP(target):\n  1. Check if target is covered by active backup system\n  2. Common indicators:\n     - .git repository with clean status\n     - Time Machine / File History active on target volume\n     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync\n     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot\n     - Versioned storage (ZFS snapshots, S3 versioning)\n  3. IF any indicator active AND recent → RETURN VERIFIED\n  4. ELSE → RETURN UNVERIFIED\n```\n\n**Fast path:** Backup verification must complete in <2 seconds. No long-running checks.\n\n### Step 3: Decision\n\n| Backup Status | Action |\n|---------------|--------|\n| **VERIFIED ACTIVE** | LOG operation, PROCEED with execution |\n| **UNVERIFIED** | HALT execution, ESCALATE to human |\n| **UNKNOWN** | Treat as UNVERIFIED — HALT and ESCALATE |\n\n### Step 4: Escalation Format\n\nWhen escalation is required, Guardian MUST output:\n\n```\n🛡️ GUARDIAN HALT\nOperation: [specific tool call]\nTarget: [file/path/database/endpoint]\nCategory: [taxonomy category]\nRisk Level: [CRITICAL/HIGH/MEDIUM]\nBackup Status: [UNVERIFIED / last backup: X hours ago]\n\nProposed Action: [what the agent wants to do]\nPotential Impact: [what could go wrong]\n\nOptions:\n1. APPROVE — Proceed with execution (human responsibility)\n2. DENY — Cancel operation\n3. SNAPSHOT — Create quick backup first, then proceed\n4. REVIEW — Agent provides additional justification\n\nGuardian awaits human decision.\n```\n\n## Mandatory Rules\n\n1. **No Self-Approval:** The executing agent cannot approve its own destructive operation. Period.\n2. **No Confidence Override:** High confidence does not bypass backup verification. The PocketOS agent was confident too.\n3. **No Silent Destruction:** Every destructive operation is logged, even if approved.\n4. **No Assumption of Safety:** \"It looks safe\" is not verification. Backup status is verification.\n5. **No Escalation Fatigue:** If an agent generates repeated escalations for the same pattern, Guardian flags the pattern, not just the instance.\n\n## Integration\n\n### For OpenClaw / Agent Systems\n\nGuardian operates at the **tool-call layer**, between the agent's decision and the tool's execution:\n\n```\nAgent Decision → Guardian Intercept → [Verify Backup] → Execute OR Escalate\n```\n\n### For Standalone Agents\n\nIf the runtime doesn't support interception, Guardian operates as a **mandatory pre-flight check**:\n\n```\nBEFORE calling any tool:\n  1. Agent MUST call Guardian check\n  2 la Guardian returns PROCEED or HALT\n  3. Agent respects HALT, awaits escalation resolution\n```\n\n## Logging\n\nEvery Guardian decision is logged:\n\n```\n[Timestamp] [Operation] [Category] [Backup Status] [Decision] [Approver]\n```\n\nLogs are append-only. No deletion by the executing agent.\n\n## Scope\n\n**Vanilla:** This skill is generic. Not specific to any agent, platform, or deployment.\n\n**Mandatory:** Once enabled, all sessions load this skill. No opt-out.\n\n**Non-Blocking (when safe):** Backup-verified operations proceed without delay. No human wait for routine maintenance with verified backups.\n\n## References\n\n- `references/OPERATION-TAXONOMY.md` — Full destructive operation classification\n- `references/DECISION-MATRIX.md` — Detailed backup verification logic and escalation rules\n- `scripts/verify-backup.ps1` — Windows backup detection script\n- `scripts/verify-backup.sh` — Linux/macOS backup detection script\n\n## Based On\n\n- AgentTrust (May 2026): Runtime safety evaluation and interception for AI agent tool use\n- Proof-of-Guardrail (Mar 2026): Cryptographic verification of guardrail claims  \n- AgentDoG (Jan 2026): Diagnostic guardrail framework for AI agent safety and security\n- Confirm-Before-Destroy Pattern: Tool-level guardrails + prompt-level safeguards\n- Gemini CLI PR #25947: Versioned pre-write backups with agent-driven restore\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn77qg2t2rnb458ahv8751shv582rvm6\",\n  \"slug\": \"data-guardian\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1779715972040\n}\n\nFile v1.2.0:DECISION-MATRIX.md\n\n# Decision Matrix\n\nGuardian's decision logic for every intercepted operation.\n\n## Decision Tree\n\n```\nOPERATION detected\n  │\n  ├── Category: CRITICAL?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE (treat as UNVERIFIED)\n  │   └──\n  ├── Category: HIGH?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE\n  │   └──\n  ├── Category: MEDIUM?\n  │   ├── YES → Context check\n  │   │   ├── Target in protected path? → BACKUP VERIFICATION\n  │   │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   │   └── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Target not protected → LOG + PROCEED (with warning)\n  │   └──\n  └── Category: NON-DESTRUCTIVE\n      └── LOG (minimal) + PROCEED (no delay)\n```\n\n## Backup Verification Logic\n\n### Fast Check (<2 seconds)\n\nGuardian checks backup status in priority order. First match wins.\n\n| Priority | Indicator | Detection Method | Recency Threshold |\n|----------|-----------|------------------|-------------------|\n| 1 | Git repository | `.git/` exists, `git status` works | N/A (VCS covers tracked files) |\n| 2 | Time Machine (macOS) | `tmutil listbackups` or `.timemachine` | <24 hours |\n| 3 | File History (Windows) | `Get-History` or `fhmanagew.exe` | <24 hours |\n| 4 | Cloud sync active | OneDrive/iCloud/Dropbox process running + recent sync timestamp | <1 hour |\n| 5 | Explicit backup tool | `restic`, `duplicity`, `rsnapshot`, `borg` process or snapshot dir | <24 hours |\n| 6 | ZFS snapshots | `zfs list -t snapshot` | <24 hours |\n| 7 | S3 versioning | Object Versioning enabled on bucket | N/A |\n| 8 | Database replication | `SHOW SLAVE STATUS`, `pg_is_in_backup()` | Active replication |\n\n### Verification Result\n\n| Result | Meaning | Action |\n|--------|---------|--------|\n| **VERIFIED ACTIVE** | At least one indicator shows active, recent backup | PROCEED |\n| **STALE** | Backup exists but exceeds recency threshold | ESCALATE (with warning: \"Backup is X hours old\") |\n| **UNVERIFIED** | No backup indicators found | ESCALATE |\n| **PARTIAL** | Backup exists but doesn't cover target | ESCALATE (e.g., git doesn't cover untracked files) |\n\n## Escalation Rules\n\n### Who Decides\n\n| Scenario | Approver | Timeout |\n|----------|----------|---------|\n| CRITICAL + no backup | Human operator required | Infinite (no auto-approve) |\n| HIGH + no backup | Human operator required | Infinite |\n| CRITICAL + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| HIGH + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| MEDIUM + no backup | Agent MAY self-approve with explicit justification | Log for audit |\n| Repeated same pattern | Flag pattern, require operator review | N/A |\n\n### Escalation Format\n\n```\n🛡️ GUARDIAN HALT\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nOperation:   [tool + arguments]\nTarget:      [file/path/database/endpoint]\nCategory:    [CRITICAL/HIGH/MEDIUM]\nRisk Level:  [data loss / external exposure / system instability / ...]\n\nBackup Status:\n  Primary:   [indicator] → [status]\n  Secondary: [indicator] → [status]\n  Verdict:   [VERIFIED ACTIVE / STALE / UNVERIFIED / PARTIAL]\n\nProposed Action:\n  [Agent's stated purpose]\n\nPotential Impact:\n  [What could go wrong if this proceeds]\n\nOptions:\n  [1] APPROVE   — Proceed (human assumes responsibility)\n  [2] DENY      — Cancel operation\n  [3] SNAPSHOT  — Create quick backup first, then proceed\n  [4] REVIEW    — Agent provides 2-sentence justification\n\nGuardian awaits human decision.\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n```\n\n## Quick Backup (SNAPSHOT option)\n\nWhen human selects SNAPSHOT:\n\n```\n1. Identify target scope (single file, directory, database)\n2. Create atomic snapshot:\n   - File: `cp target target.bak.YYYYMMDD-HHMMSS`\n   - Directory: `tar czf dir-snap-YYYYMMDD-HHMMSS.tar.gz dir/`\n   - Database: `mysqldump ... > db-snap-YYYYMMDD-HHMMSS.sql`\n3. Verify snapshot integrity (quick check)\n4. PROCEED with original operation\n5. LOG snapshot location for potential restore\n```\n\n## Logging Format\n\n```\n[2026-05-18T13:47:00Z] GUARDIAN CHECK\n  Operation: rm -rf /tmp/old-builds\n  Category: HIGH (mass delete)\n  Backup: VERIFIED ACTIVE (git + Time Machine <2h)\n  Decision: PROCEED\n  Approver: guardian-auto (no human required)\n\n[2026-05-18T13:48:00Z] GUARDIAN HALT\n  Operation: DROP TABLE customers\n  Category: CRITICAL (database destruction)\n  Backup: UNVERIFIED (no indicators found)\n  Decision: HALT\n  Approver: awaiting-human\n```\n\n## Override Prevention\n\nGuardian cannot be bypassed by:\n- Agent confidence (>90% doesn't matter)\n- Agent justification (\"I know what I'm doing\" doesn't matter)\n- Repeated requests (same operation halts again)\n- Path obfuscation (`/tmp/../etc/passwd` still checked)\n- Encoding tricks (URL encoding, null bytes — normalize first)\n\nOnly valid override: Human operator explicitly APPROVES.\n\nFile v1.2.0:OPERATION-TAXONOMY.md\n\n# Operation Taxonomy\n\nComplete classification of destructive operations for AI agents.\n\n## CRITICAL — Always Requires Verification\n\n### File Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| rm / remove | `rm`, `rmdir`, `Remove-Item`, `del` | `rm -rf /tmp/old`, `Remove-Item *.log` |\n| unlink | `unlink()`, `os.remove()` | Python file deletion |\n| trash | `trash-cli`, `gio trash` | Move to system trash |\n| empty-trash | `rm -rf ~/.Trash`, `Clear-RecycleBin` | Permanent deletion of trashed files |\n| overwrite | Write to existing file without version control | `> file.txt` (clobber) |\n| truncate | `truncate -s 0`, `fsutil` | Zero-length file without backup |\n\n### Database Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| DROP | `DROP TABLE`, `DROP DATABASE` | Schema destruction |\n| DELETE (unqualified) | `DELETE FROM table` (no WHERE) | Mass data deletion |\n| TRUNCATE | `TRUNCATE TABLE` | Instant table empty |\n| destructive migration | `down()` migration, `rollback` | Schema reversal with data loss |\n| ALTER destructive | `ALTER TABLE ... DROP COLUMN` | Structural deletion |\n\n## HIGH — Requires Verification\n\n### External Transmission\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| send email | SMTP send, API email | `sendmail`, SES, SendGrid |\n| post message | Social media API | Twitter/X, LinkedIn, Mastodon |\n| publish | CMS publish, blog post | WordPress, Ghost, static site |\n| API write | POST/PUT/DELETE to external | Any mutating external API call |\n| webhook trigger | Outgoing webhook POST | Triggering external systems |\n\n### Mass Operations\n| Operation | Threshold | Examples |\n|-----------|-----------|----------|\n| bulk file modify | >10 files in single op | Batch rename, sed across directory |\n| bulk delete | >10 files | `find . -name \"*.tmp\" -delete` |\n| recursive operations | `**` glob, `-r` flag | `rm -rf`, `chmod -R` |\n\n### System Changes\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| service control | `systemctl`, `Start-Service` | Stop/start/restart services |\n| firewall modify | `iptables`, `netsh advfirewall` | Add/remove rules |\n| registry edit | `reg add`, `Set-ItemProperty` | Windows registry changes |\n| user management | `useradd`, `New-LocalUser` | Create/delete accounts |\n| scheduled task | `schtasks`, `cron` | Add/remove automation |\n| environment | `setx`, `[Environment]::SetEnvironmentVariable` | System-wide env vars |\n\n## MEDIUM — Verify if Target is Important\n\n### Network Unknown\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| new domain | URL not in known list | First call to api.newvendor.com |\n| unverified endpoint | No prior successful calls | POST to unvalidated webhook |\n| DNS change | `nsupdate`, registrar API | Pointing domain elsewhere |\n| certificate | `certbot`, `New-SelfSignedCertificate` | TLS/SSL modifications |\n\n### Configuration\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| .env overwrite | Write to `.env`, `secrets.yaml` | Credential/environment changes |\n| config modify | Edit `.ini`, `.toml`, `.json` config | Application settings |\n| SSH keys | `ssh-keygen`, `authorized_keys` | Authentication changes |\n| API keys | Rotate, revoke, regenerate | Service authentication |\n\n## NON-DESTRUCTIVE — No Guardian Check\n\n| Category | Examples |\n|----------|----------|\n| Read-only | `cat`, `ls`, `Get-Content`, `SELECT` queries |\n| Analysis | `grep`, `find`, `awk`, search, audit |\n| Safe write | Append to log, create new file in temp |\n| Status check | `ping`, `curl -I`, health checks |\n| Internal query | Database SELECT, API GET with no side effects |\n\n## Ambiguous — Default to Destructive\n\n| Operation | Why Ambiguous | Guardian Action |\n|-----------|---------------|-----------------|\n| `git reset --hard` | Destroys uncommitted work | VERIFY backup |\n| `git push --force` | Overwrites remote history | VERIFY backup |\n| `docker system prune` | Deletes containers/images | VERIFY backup |\n| `npm audit fix` | Modifies dependencies | VERIFY backup |\n| Package manager update | System-wide changes | VERIFY backup |\n| Migration `up()` | Schema changes | VERIFY backup |\n\n## Rules\n\n1. **When in doubt, destructive.** If an operation could be either, treat as destructive.\n2. **Chained operations count as one.** `find . -name \"*.log\" -exec rm {} \\;` is mass delete even if `find` itself is read-only.\n3. **Destructive intent is irrelevant.** The taxonomy cares about operation effect, not agent intent.\n4. **Context matters.** `rm test-file-in-temp` is different from `rm /etc/passwd`. Guardian checks target path.\n\nFile v1.2.0:skill-card.md\n\n## Description:\n\nGuardian is a safety gatekeeper for AI agents that checks destructive file, database, system, and external-write operations before execution, verifies backup status, and escalates risky actions for human approval.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[tooled-app](https://clawhub.ai/user/tooled-app)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use Guardian as a pre-flight or tool-layer safety gate for AI agents before destructive file, database, system, or external-write operations. It provides backup checks, proceed-or-halt decisions, and human escalation for higher-risk actions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Guardian is advisory policy and should not be treated as a reliable enforcement layer.\n\nMitigation: Use it with an independent human approval path for high-risk deletes, overwrites, database changes, system changes, and external writes.\n\nRisk: Backup-verification scripts can incorrectly approve destructive operations.\n\nMitigation: Confirm backup coverage and restoreability independently before allowing destructive operations to proceed.\n\n## Reference(s):\n\n- [Guardian ClawHub Skill Page](https://clawhub.ai/tooled-app/skills/data-guardian)\n- [Guardian README](artifact/README.md)\n- [Operation Taxonomy](artifact/OPERATION-TAXONOMY.md)\n- [Decision Matrix](artifact/DECISION-MATRIX.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Shell commands, JSON]\n\n**Output Format:** [Markdown/text escalation guidance plus JSON backup-verification results from bundled scripts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May halt or require human approval for destructive operations; backup checks are intended to complete quickly.]\n\n## Skill Version(s):\n\n1.2.0 (source: server release metadata; artifact frontmatter reports 1.1)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.1.0: 9 files, 18174 bytes\n\nFiles: CLAWHUB-TAGS.md (777b), README.md (6042b), references/DECISION-MATRIX.md (5484b), references/OPERATION-TAXONOMY.md (4683b), ROADMAP-v1.1.md (3466b), scripts/verify-backup.ps1 (5592b), scripts/verify-backup.sh (6076b), SKILL.md (7325b), _meta.json (132b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: guardian\nversion: 1.1\ndescription: Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion, database modification, external messaging, system changes, and mass operations. Enforces backup verification before destructive execution. If backup is active and verified, proceeds without delay. If no backup, escalates to human approval. Use when an AI agent is about to execute ANY operation that modifies, deletes, transmits, or reconfigures data or systems. Triggers on rm/del/remove, database writes/deletes/drops, external API calls with side effects, mass file operations (>10 files), network requests to unknown endpoints, system service changes, firewall modifications, email/message sending, or any operation tagged as destructive by the agent itself.\nSupport: support@ikkf.info\n---\n\n# Guardian — Mandatory Safety Gatekeeper (v1.1)\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\nA mandatory safety skill that intercepts destructive AI agent operations **before execution**. It employs a Context-Aware Risk Scoring (CARS) system to balance security with operational velocity.\n\n**This skill is mandatory.** No opt-out. No override by the executing agent.\n\n## The Core Protocol (v1.1)\n\n```\nBEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. EVALUATE Risk Level via CARS Matrix\n  4. EXECUTE Decision Path:\n     - LOW: Auto-Approve (Log only)\n     - MEDIUM: Fast-Track (Verify Backup → Proceed)\n     - HIGH: Hard Block (Verify Backup → Human Approval)\n  5. IF JIT Window Active → Override High-Risk prompt (Proceed if Backup Verified)\n```\n\n## Context-Aware Risk Scoring (CARS) Matrix\n\n| Risk Level | Trigger Criteria | Action | Verification Required |\n| :--- | :--- | :--- | :--- |\n| **Low** | Files in `/tmp`, `sandbox/`, or `.cache`; Single file deletions in non-critical paths. | **Auto-Approve** | None (Log only) |\n| **Medium** | Edits to `.config` or `.env` files; Deletions of < 5 files in a Git-tracked directory. | **Fast-Track** | Git clean check or VSS snapshot check (No user prompt if verified) |\n| **High** | `rm -rf` on root/home; `DROP TABLE`; Edits to system files; Mass file deletions (>10). | **Hard Block** | Mandatory backup verification + Human Approval |\n\n## Dry Run Bridge (Deterministic Validation)\n\nFor complex destructive operations (e.g., global regex replacements), Guardian requires a **Dry Run** before final execution:\n\n1. **Interception:** Guardian identifies the operation as High Risk.\n2. **Manifest Generation:** The agent MUST run a dry-run command (e.g., `grep` or `diff` mode) to identify all affected targets.\n3. **Manifest Presentation:** The agent presents a summary of changes: `\"I will modify 12 files. Example: [File A, Line 10: 'foo' -> 'bar']. Proceed?\"`\n4. **Execution:** The actual command is only executed after the human acknowledges the manifest.\n\n## The Guardian Protocol Detail\n\n### Step 1: Operation Scan (automatic)\nEvery tool call is scanned against the taxonomy above. No agent discretion. No \"I know what I'm doing.\"\n\n### Step 2: Backup Verification (automatic)\n```\nVERIFY-BACKUP(target):\n  1. Check if target is covered by active backup system\n  2. Common indicators:\n     - .git repository with clean status\n     - Time Machine / File History active on target volume\n     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync\n     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot\n     - Versioned storage (ZFS snapshots, S3 versioning)\n  3. IF any indicator active AND recent → RETURN VERIFIED\n  4. ELSE → RETURN UNVERIFIED\n```\n\n**Fast path:** Backup verification must complete in <2 seconds. No long-running checks.\n\n### Step 3: Decision Matrix (v1.1)\n\n| Backup Status | Risk Level | Action |\n|---------------|-----------|--------|\n| **VERIFIED ACTIVE** | Low / Medium | PROCEED with execution |\n| **VERIFIED ACTIVE** | High | HALT and ESCALATE to human |\n| **UNVERIFIED** | Any | HALT and ESCALATE to human |\n| **UNKNOWN** | Any | Treat as UNVERIFIED — HALT and ESCALATE |\n\nSidenote: If a **JIT Window** is active, High Risk operations are downgraded to \"Fast-Track\" (Proceed if Backup Verified).\n\n### Step 4: Escalation Format\n\nWhen escalation is required, Guardian MUST output:\n\n```\n🛡️ GUARDIAN HALT\nOperation: [specific tool call]\nTarget: [file/path/database/endpoint]\nCategory: [taxonomy category]\nRisk Level: [CRITICAL/HIGH/MEDIUM]\nBackup Status: [UNVERIFIED / last backup: X hours ago]\n\nProposed Action: [what the agent wants to do]\nPotential Impact: [what could go wrong]\n\nOptions:\n1. APPROVE — Proceed with execution (human responsibility)\n2. DENY — Cancel operation\n3. SNAPSHOT — Create quick backup first, then proceed\n4. REVIEW — Agent provides additional justification\n\nGuardian awaits human decision.\n```\n\n## Mandatory Rules\n\n1. **No Self-Approval:** The executing agent cannot approve its own destructive operation.\n2. **No Confidence Override:** High confidence does not bypass backup verification.\n3. **No Silent Destruction:** Every destructive operation is logged.\n4. **No Assumption of Safety:** \"It looks safe\" is not verification. Backup status is verification.\n5. **No Escalation Fatigue:** If an agent generates repeated escalations for the same pattern, Guardian flags the pattern, not just the instance.\n\n## Integration\n\n### For OpenClaw / Agent Systems\n\nGuardian operates at the **tool-call layer**, between the agent's decision and the tool's execution:\n\n```\nAgent Decision → Guardian Intercept → [Verify Backup] → Execute OR Escalate\n```\n\n### For Standalone Agents\n\nIf the runtime doesn't support interception, Guardian operates as a **mandatory pre-flight check**:\n\n```\nBEFORE calling any tool:\n  1. Agent MUST call Guardian check\n  2. Guardian returns PROCEED or HALT\n  3. Agent respects HALT, awaits escalation resolution\n```\n\n## Logging\n\nEvery Guardian decision is logged:\n\n```\n[Timestamp] [Operation] [Category] [Backup Status] [Decision] [Approver]\n```\n\nLogs are append-only. No deletion by the executing agent.\n\nSidenote: All operations within a JIT window are tagged with `[JIT-GRANTED]` in the audit log.\n\n## Scope\n\n**Vanilla:** This skill is generic. Not specific to any agent, platform, or deployment.\n\n**Mandatory:** Once enabled, all sessions load this skill. No opt-out.\n\n**Non-Blocking (when safe):** Backup-verified operations proceed without delay. No human wait for routine maintenance with verified backups.\n\n## References\n\n- `references/OPERATION-TAXONOMY.md` — Full destructive operation classification\n- `references/DECISION-MATRIX.md` — Detailed backup verification logic and escalation rules\n- `scripts/verify-backup.ps1` — Windows backup detection script\n- `scripts/verify-backup.sh` — Linux/macOS backup detection script\n\n## Based On\n\n- AgentTrust (May 2026): Runtime safety evaluation and interception for AI agent tool use\n- Proof-of-Guardrail (Mar 2026): Cryptographic verification of guardrail claims  \n- AgentDoG (Jan 2026): Diagnostic guardrail framework for AI agent safety and security\n- Confirm-Before-Destroy Pattern: Tool-level guardrails + prompt-level safeguards\n- Gemini CLI PR #25947: Versioned pre-write backups with agent-driven restore\n\nFile v1.1.0:README.md\n\n# Guardian — Mandatory Safety Gatekeeper\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\nA mandatory safety skill that intercepts destructive AI agent operations **before execution**. If backup is verified active, proceed. If not, escalate.\n\n**This skill is mandatory.** No opt-out. No override by the executing agent.\n\n## 📖 The Philosophy\nGuardian is based on the principle that **reasoning is not a guardrail**. Read the full story behind its creation: [The Bouncer in the Machine](C:\\Users\\Clawdette\\iCloudDrive\\DemystifyPosts\\writing-services\\c3-drafts\\day-48-the-bouncer-in-the-machine.md) (Pending publication to demystify.website).\n\n## The Core Protocol\n\n```\nBEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. VERIFY backup status (automatic + fast)\n  4. IF backup verified ACTIVE → LOG and PROCEED\n  5. IF backup NOT verified → HALT and ESCALATE\n```\n\n## Destructive Operation Taxonomy\n\n| Category | Operations | Risk Level |\n|----------|-----------|------------|\n| **File Destruction** | rm, del, remove, rmdir, unlink, trash, empty-trash, overwrite | CRITICAL |\n| **Database Destruction** | DROP, DELETE (no WHERE), TRUNCATE, ALTER destructive, migration down | CRITICAL |\n| **External Transmission** | send email, post tweet, publish message, API write with side effects | HIGH |\n| **Mass Operations** | >10 files modified/deleted in single operation, bulk renames | HIGH |\n| **System Changes** | service stop/start, firewall modify, registry edit, user create/delete | HIGH |\n| **Network Unknown** | Request to URL not in allowlist, new domain, unverified endpoint | MEDIUM |\n| **Configuration** | Overwrite .env, modify config files without backup | MEDIUM |\n\n**Rule:** When in doubt, classify as destructive. Better to verify a safe operation than destroy an unsafe one.\n\nFull taxonomy: `references/OPERATION-TAXONOMY.md`\n\n## The Guardian Protocol\n\n### Step 1: Operation Scan (automatic)\nEvery tool call is scanned against the taxonomy above. No agent discretion. No \"I know what I'm doing.\"\n\n### Step 2: Backup Verification (automatic)\n```\nVERIFY-BACKUP(target):\n  1. Check if target is covered by active backup system\n  2. Common indicators:\n     - .git repository with clean status\n     - Time Machine / File History active on target volume\n     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync\n     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot\n     - Versioned storage (ZFS snapshots, S3 versioning)\n  3. IF any indicator active AND recent → RETURN VERIFIED\n  4. ELSE → RETURN UNVERIFIED\n```\n\n**Fast path:** Backup verification must complete in <2 seconds. No long-running checks.\n\n### Step 3: Decision\n\n| Backup Status | Action |\n|---------------|--------|\n| **VERIFIED ACTIVE** | LOG operation, PROCEED with execution |\n| **UNVERIFIED** | HALT execution, ESCALATE to human |\n| **UNKNOWN** | Treat as UNVERIFIED — HALT and ESCALATE |\n\n### Step 4: Escalation Format\n\nWhen escalation is required, Guardian MUST output:\n\n```\n🛡️ GUARDIAN HALT\nOperation: [specific tool call]\nTarget: [file/path/database/endpoint]\nCategory: [taxonomy category]\nRisk Level: [CRITICAL/HIGH/MEDIUM]\nBackup Status: [UNVERIFIED / last backup: X hours ago]\n\nProposed Action: [what the agent wants to do]\nPotential Impact: [what could go wrong]\n\nOptions:\n1. APPROVE — Proceed with execution (human responsibility)\n2. DENY — Cancel operation\n3. SNAPSHOT — Create quick backup first, then proceed\n4. REVIEW — Agent provides additional justification\n\nGuardian awaits human decision.\n```\n\n## Mandatory Rules\n\n1. **No Self-Approval:** The executing agent cannot approve its own destructive operation. Period.\n2. **No Confidence Override:** High confidence does not bypass backup verification. The PocketOS agent was confident too.\n3. **No Silent Destruction:** Every destructive operation is logged, even if approved.\n4. **No Assumption of Safety:** \"It looks safe\" is not verification. Backup status is verification.\n5. **No Escalation Fatigue:** If an agent generates repeated escalations for the same pattern, Guardian flags the pattern, not just the instance.\n\n## Integration\n\n### For OpenClaw / Agent Systems\n\nGuardian operates at the **tool-call layer**, between the agent's decision and the tool's execution:\n\n```\nAgent Decision → Guardian Intercept → [Verify Backup] → Execute OR Escalate\n```\n\n### For Standalone Agents\n\nIf the runtime doesn't support interception, Guardian operates as a **mandatory pre-flight check**:\n\n```\nBEFORE calling any tool:\n  1. Agent MUST call Guardian check\n  2 la Guardian returns PROCEED or HALT\n  3. Agent respects HALT, awaits escalation resolution\n```\n\n## Logging\n\nEvery Guardian decision is logged:\n\n```\n[Timestamp] [Operation] [Category] [Backup Status] [Decision] [Approver]\n```\n\nLogs are append-only. No deletion by the executing agent.\n\n## Scope\n\n**Vanilla:** This skill is generic. Not specific to any agent, platform, or deployment.\n\n**Mandatory:** Once enabled, all sessions load this skill. No opt-out.\n\n**Non-Blocking (when safe):** Backup-verified operations proceed without delay. No human wait for routine maintenance with verified backups.\n\n## References\n\n- `references/OPERATION-TAXONOMY.md` — Full destructive operation classification\n- `references/DECISION-MATRIX.md` — Detailed backup verification logic and escalation rules\n- `scripts/verify-backup.ps1` — Windows backup detection script\n- `scripts/verify-backup.sh` — Linux/macOS backup detection script\n\n## Based On\n\n- AgentTrust (May 2026): Runtime safety evaluation and interception for AI agent tool use\n- Proof-of-Guardrail (Mar 2026): Cryptographic verification of guardrail claims  \n- AgentDoG (Jan 2026): Diagnostic guardrail framework for AI agent safety and security\n- Confirm-Before-Destroy Pattern: Tool-level guardrails + prompt-level safeguards\n- Gemini CLI PR #25947: Versioned pre-write backups with agent-driven restore\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn77qg2t2rnb458ahv8751shv582rvm6\",\n  \"slug\": \"data-guardian\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1779385825575\n}\n\nFile v1.1.0:references/DECISION-MATRIX.md\n\n# Decision Matrix\n\nGuardian's decision logic for every intercepted operation.\n\n## Decision Tree\n\n```\nOPERATION detected\n  │\n  ├── Category: CRITICAL?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE (treat as UNVERIFIED)\n  │   └──\n  ├── Category: HIGH?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE\n  │   └──\n  ├── Category: MEDIUM?\n  │   ├── YES → Context check\n  │   │   ├── Target in protected path? → BACKUP VERIFICATION\n  │   │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   │   └── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Target not protected → LOG + PROCEED (with warning)\n  │   └──\n  └── Category: NON-DESTRUCTIVE\n      └── LOG (minimal) + PROCEED (no delay)\n```\n\n## Backup Verification Logic\n\n### Fast Check (<2 seconds)\n\nGuardian checks backup status in priority order. First match wins.\n\n| Priority | Indicator | Detection Method | Recency Threshold |\n|----------|-----------|------------------|-------------------|\n| 1 | Git repository | `.git/` exists, `git status` works | N/A (VCS covers tracked files) |\n| 2 | Time Machine (macOS) | `tmutil listbackups` or `.timemachine` | <24 hours |\n| 3 | File History (Windows) | `Get-History` or `fhmanagew.exe` | <24 hours |\n| 4 | Cloud sync active | OneDrive/iCloud/Dropbox process running + recent sync timestamp | <1 hour |\n| 5 | Explicit backup tool | `restic`, `duplicity`, `rsnapshot`, `borg` process or snapshot dir | <24 hours |\n| 6 | ZFS snapshots | `zfs list -t snapshot` | <24 hours |\n| 7 | S3 versioning | Object Versioning enabled on bucket | N/A |\n| 8 | Database replication | `SHOW SLAVE STATUS`, `pg_is_in_backup()` | Active replication |\n\n### Verification Result\n\n| Result | Meaning | Action |\n|--------|---------|--------|\n| **VERIFIED ACTIVE** | At least one indicator shows active, recent backup | PROCEED |\n| **STALE** | Backup exists but exceeds recency threshold | ESCALATE (with warning: \"Backup is X hours old\") |\n| **UNVERIFIED** | No backup indicators found | ESCALATE |\n| **PARTIAL** | Backup exists but doesn't cover target | ESCALATE (e.g., git doesn't cover untracked files) |\n\n## Escalation Rules\n\n### Who Decides\n\n| Scenario | Approver | Timeout |\n|----------|----------|---------|\n| CRITICAL + no backup | Human operator required | Infinite (no auto-approve) |\n| HIGH + no backup | Human operator required | Infinite |\n| CRITICAL + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| HIGH + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| MEDIUM + no backup | Agent MAY self-approve with explicit justification | Log for audit |\n| Repeated same pattern | Flag pattern, require operator review | N/A |\n\n### Escalation Format\n\n```\n🛡️ GUARDIAN HALT\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nOperation:   [tool + arguments]\nTarget:      [file/path/database/endpoint]\nCategory:    [CRITICAL/HIGH/MEDIUM]\nRisk Level:  [data loss / external exposure / system instability / ...]\n\nBackup Status:\n  Primary:   [indicator] → [status]\n  Secondary: [indicator] → [status]\n  Verdict:   [VERIFIED ACTIVE / STALE / UNVERIFIED / PARTIAL]\n\nProposed Action:\n  [Agent's stated purpose]\n\nPotential Impact:\n  [What could go wrong if this proceeds]\n\nOptions:\n  [1] APPROVE   — Proceed (human assumes responsibility)\n  [2] DENY      — Cancel operation\n  [3] SNAPSHOT  — Create quick backup first, then proceed\n  [4] REVIEW    — Agent provides 2-sentence justification\n\nGuardian awaits human decision.\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n```\n\n## Quick Backup (SNAPSHOT option)\n\nWhen human selects SNAPSHOT:\n\n```\n1. Identify target scope (single file, directory, database)\n2. Create atomic snapshot:\n   - File: `cp target target.bak.YYYYMMDD-HHMMSS`\n   - Directory: `tar czf dir-snap-YYYYMMDD-HHMMSS.tar.gz dir/`\n   - Database: `mysqldump ... > db-snap-YYYYMMDD-HHMMSS.sql`\n3. Verify snapshot integrity (quick check)\n4. PROCEED with original operation\n5. LOG snapshot location for potential restore\n```\n\n## Logging Format\n\n```\n[2026-05-18T13:47:00Z] GUARDIAN CHECK\n  Operation: rm -rf /tmp/old-builds\n  Category: HIGH (mass delete)\n  Backup: VERIFIED ACTIVE (git + Time Machine <2h)\n  Decision: PROCEED\n  Approver: guardian-auto (no human required)\n\n[2026-05-18T13:48:00Z] GUARDIAN HALT\n  Operation: DROP TABLE customers\n  Category: CRITICAL (database destruction)\n  Backup: UNVERIFIED (no indicators found)\n  Decision: HALT\n  Approver: awaiting-human\n```\n\n## Override Prevention\n\nGuardian cannot be bypassed by:\n- Agent confidence (>90% doesn't matter)\n- Agent justification (\"I know what I'm doing\" doesn't matter)\n- Repeated requests (same operation halts again)\n- Path obfuscation (`/tmp/../etc/passwd` still checked)\n- Encoding tricks (URL encoding, null bytes — normalize first)\n\nOnly valid override: Human operator explicitly APPROVES.\n\nFile v1.1.0:references/OPERATION-TAXONOMY.md\n\n# Operation Taxonomy\n\nComplete classification of destructive operations for AI agents.\n\n## CRITICAL — Always Requires Verification\n\n### File Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| rm / remove | `rm`, `rmdir`, `Remove-Item`, `del` | `rm -rf /tmp/old`, `Remove-Item *.log` |\n| unlink | `unlink()`, `os.remove()` | Python file deletion |\n| trash | `trash-cli`, `gio trash` | Move to system trash |\n| empty-trash | `rm -rf ~/.Trash`, `Clear-RecycleBin` | Permanent deletion of trashed files |\n| overwrite | Write to existing file without version control | `> file.txt` (clobber) |\n| truncate | `truncate -s 0`, `fsutil` | Zero-length file without backup |\n\n### Database Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| DROP | `DROP TABLE`, `DROP DATABASE` | Schema destruction |\n| DELETE (unqualified) | `DELETE FROM table` (no WHERE) | Mass data deletion |\n| TRUNCATE | `TRUNCATE TABLE` | Instant table empty |\n| destructive migration | `down()` migration, `rollback` | Schema reversal with data loss |\n| ALTER destructive | `ALTER TABLE ... DROP COLUMN` | Structural deletion |\n\n## HIGH — Requires Verification\n\n### External Transmission\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| send email | SMTP send, API email | `sendmail`, SES, SendGrid |\n| post message | Social media API | Twitter/X, LinkedIn, Mastodon |\n| publish | CMS publish, blog post | WordPress, Ghost, static site |\n| API write | POST/PUT/DELETE to external | Any mutating external API call |\n| webhook trigger | Outgoing webhook POST | Triggering external systems |\n\n### Mass Operations\n| Operation | Threshold | Examples |\n|-----------|-----------|----------|\n| bulk file modify | >10 files in single op | Batch rename, sed across directory |\n| bulk delete | >10 files | `find . -name \"*.tmp\" -delete` |\n| recursive operations | `**` glob, `-r` flag | `rm -rf`, `chmod -R` |\n\n### System Changes\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| service control | `systemctl`, `Start-Service` | Stop/start/restart services |\n| firewall modify | `iptables`, `netsh advfirewall` | Add/remove rules |\n| registry edit | `reg add`, `Set-ItemProperty` | Windows registry changes |\n| user management | `useradd`, `New-LocalUser` | Create/delete accounts |\n| scheduled task | `schtasks`, `cron` | Add/remove automation |\n| environment | `setx`, `[Environment]::SetEnvironmentVariable` | System-wide env vars |\n\n## MEDIUM — Verify if Target is Important\n\n### Network Unknown\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| new domain | URL not in known list | First call to api.newvendor.com |\n| unverified endpoint | No prior successful calls | POST to unvalidated webhook |\n| DNS change | `nsupdate`, registrar API | Pointing domain elsewhere |\n| certificate | `certbot`, `New-SelfSignedCertificate` | TLS/SSL modifications |\n\n### Configuration\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| .env overwrite | Write to `.env`, `secrets.yaml` | Credential/environment changes |\n| config modify | Edit `.ini`, `.toml`, `.json` config | Application settings |\n| SSH keys | `ssh-keygen`, `authorized_keys` | Authentication changes |\n| API keys | Rotate, revoke, regenerate | Service authentication |\n\n## NON-DESTRUCTIVE — No Guardian Check\n\n| Category | Examples |\n|----------|----------|\n| Read-only | `cat`, `ls`, `Get-Content`, `SELECT` queries |\n| Analysis | `grep`, `find`, `awk`, search, audit |\n| Safe write | Append to log, create new file in temp |\n| Status check | `ping`, `curl -I`, health checks |\n| Internal query | Database SELECT, API GET with no side effects |\n\n## Ambiguous — Default to Destructive\n\n| Operation | Why Ambiguous | Guardian Action |\n|-----------|---------------|-----------------|\n| `git reset --hard` | Destroys uncommitted work | VERIFY backup |\n| `git push --force` | Overwrites remote history | VERIFY backup |\n| `docker system prune` | Deletes containers/images | VERIFY backup |\n| `npm audit fix` | Modifies dependencies | VERIFY backup |\n| Package manager update | System-wide changes | VERIFY backup |\n| Migration `up()` | Schema changes | VERIFY backup |\n\n## Rules\n\n1. **When in doubt, destructive.** If an operation could be either, treat as destructive.\n2. **Chained operations count as one.** `find . -name \"*.log\" -exec rm {} \\;` is mass delete even if `find` itself is read-only.\n3. **Destructive intent is irrelevant.** The taxonomy cares about operation effect, not agent intent.\n4. **Context matters.** `rm test-file-in-temp` is different from `rm /etc/passwd`. Guardian checks target path.\n\nFile v1.1.0:CLAWHUB-TAGS.md\n\n# Guardian — Tags for ClawHub Post\n\n## Primary Tags\nai-safety\nagent-guardrails\ndestructive-operations\nbackup-verification\nsafety-skill\nmandatory-skill\n\n## Secondary Tags\ntamper-evident\naudit-trail\ncompliance\ncross-platform\npowershell\nbash\nopen-source\npocketos\nai-agent-security\ndata-protection\nprevent-data-loss\nnon-blocking\nvanilla-skill\nproduction-ready\n\n## ClawHub Category Tags\nskill\nsecurity\nguardian\nsafety\n\n## Description Tags (for search)\nAI agent safety guardrail that intercepts destructive operations before execution. Verifies backups automatically. If backup active, proceeds without delay. If not, halts and escalates. Cross-platform PowerShell + Bash scripts. Based on the PocketOS incident. 68 downloads. Pairs with Guardian Audit for tamper-evident logging.\n\nFile v1.1.0:ROADMAP-v1.1.md\n\n# Guardian v1.1 Roadmap\n\nBased on download velocity (140 Guardian + 99 Guardian Audit, day one) and expected feedback patterns from the agent safety community.\n\n## P1 — Critical (Do First)\n\n### 1.1 Windows File History Detection Improvements\n**Why:** Current WMI check (`Win32_FileHistoryConfiguration`) is unreliable on Windows 11 24H2+. Multiple users will report false negatives.\n**Fix:** Add registry-based detection (`HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\FileHistory`) and Known Folders API check.\n**Effort:** Small. 2 hours.\n\n### 1.2 Docker Volume / Container Detection\n**Why:** Agents increasingly operate in Docker contexts. `rm -rf /app/data` inside a container is destructive but not covered by host-level backup detection.\n**Fix:** Check for Docker bind mounts, volume labels, and `docker volume inspect` metadata.\n**Effort:** Medium. 4 hours.\n\n### 1.3 WSL Path Detection\n**Why:** WSL2 paths (`\\\\wsl$\\Ubuntu\\home\\...`) are common for dev agents. Current scripts don't detect git repos or backups inside WSL from Windows side.\n**Fix:** Add WSL path normalization + `wsl git status` fallback.\n**Effort:** Small. 2 hours.\n\n## P2 — Important (Do Next)\n\n### 1.4 Configurable Mass Operation Threshold\n**Why:** Current >10 files threshold is arbitrary. Some users want >50, some want >5.\n**Fix:** Add `guardian.conf` or environment variable `GUARDIAN_MASS_THRESHOLD`.\n**Effort:** Small. 1 hour.\n\n### 1.5 Database Backup Detection Expansion\n**Why:** Currently only checks replication. Users will want `pg_dump` presence, SQLite `.dump`, MySQL `mysqldump` scheduled task detection.\n**Fix:** Add process and file-based detection for common database backup tools.\n**Effort:** Medium. 3 hours.\n\n### 1.6 Cloud Sync Deep Integration\n**Why:** Current check only verifies client is running. Doesn't verify sync status (paused, error, offline).\n**Fix:** Read sync state from OneDrive status icon, Dropbox `.dropbox.cache`, iCloud BRCL files.\n**Effort:** Medium. 4 hours.\n\n### 1.7 Dry-Run Mode\n**Why:** Users want to test Guardian without actual halts. Useful for CI/CD pipelines and onboarding.\n**Fix:** Add `GUARDIAN_DRY_RUN=1` environment variable. Logs decisions without blocking.\n**Effort:** Small. 2 hours.\n\n## P3 — Nice to Have\n\n### 1.8 Integration with AutoGen / LangChain / CrewAI\n**Why:** These frameworks have tool-call middleware. Guardian could be a native middleware layer.\n**Fix:** Provide Python wrapper classes for each framework.\n**Effort:** Large. 8 hours.\n\n### 1.9 Webhook Notifications\n**Why:** Teams want Slack/Discord alerts when Guardian halts something in production.\n**Fix:** Optional webhook URL in config. POST on HALT events.\n**Effort:** Small. 2 hours.\n\n### 1.10 GUI Dashboard (Optional)\n**Why:** Visual overview of halt history, approval rates, backup coverage gaps.\n**Fix:** Lightweight web dashboard reading the audit log.\n**Effort:** Large. 12 hours.\n\n## v1.1 Scope Recommendation\n\n**Ship P1 + P2 (items 1.1–1.7) as v1.1.** That's 18 hours of focused work, addresses the most common failure modes, and keeps the skill lightweight. P3 items can wait for v1.2 based on actual demand.\n\n## Release Timeline\n\n| Phase | Items | Target |\n|-------|-------|--------|\n| v1.1-alpha | 1.1, 1.4, 1.7 | 3 days |\n| v1.1-beta | +1.2, 1.3, 1.5 | 1 week |\n| v1.1-stable | +1.6 | 2 weeks |\n\n## Feedback-Driven Priorities\n\nIf `support@ikkf.info` reveals different patterns, reprioritize. The roadmap is a hypothesis. User pain is the truth.\n\nArchive v1.0.0: 7 files, 15201 bytes\n\nFiles: README.md (5534b), references/DECISION-MATRIX.md (5484b), references/OPERATION-TAXONOMY.md (4683b), scripts/verify-backup.ps1 (5592b), scripts/verify-backup.sh (6076b), SKILL.md (6528b), _meta.json (132b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: guardian\ndescription: Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion, database modification, external messaging, system changes, and mass operations. Enforces backup verification before destructive execution. If backup is active and verified, proceeds without delay. If no backup, escalates to human approval. Use when an AI agent is about to execute ANY operation that modifies, deletes, transmits, or reconfigures data or systems. Triggers on rm/del/remove, database writes/deletes/drops, external API calls with side effects, mass file operations (>10 files), network requests to unknown endpoints, system service changes, firewall modifications, email/message sending, or any operation tagged as destructive by the agent itself.\n---\n\n# Guardian — Mandatory Safety Gatekeeper\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\nA mandatory safety skill that intercepts destructive AI agent operations **before execution**. If backup is verified active, proceed. If not, escalate.\n\n**This skill is mandatory.** No opt-out. No override by the executing agent.\n\n## The Core Protocol\n\n```\nBEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. VERIFY backup status (automatic + fast)\n  4. IF backup verified ACTIVE → LOG and PROCEED\n  5. IF backup NOT verified → HALT and ESCALATE\n```\n\n## Destructive Operation Taxonomy\n\n| Category | Operations | Risk Level |\n|----------|-----------|------------|\n| **File Destruction** | rm, del, remove, rmdir, unlink, trash, empty-trash, overwrite | CRITICAL |\n| **Database Destruction** | DROP, DELETE (no WHERE), TRUNCATE, ALTER destructive, migration down | CRITICAL |\n| **External Transmission** | send email, post tweet, publish message, API write with side effects | HIGH |\n| **Mass Operations** | >10 files modified/deleted in single operation, bulk renames | HIGH |\n| **System Changes** | service stop/start, firewall modify, registry edit, user create/delete | HIGH |\n| **Network Unknown** | Request to URL not in allowlist, new domain, unverified endpoint | MEDIUM |\n| **Configuration** | Overwrite .env, modify config files without backup | MEDIUM |\n\n**Rule:** When in doubt, classify as destructive. Better to verify a safe operation than destroy an unsafe one.\n\nFull taxonomy: `references/OPERATION-TAXONOMY.md`\n\n## The Guardian Protocol\n\n### Step 1: Operation Scan (automatic)\nEvery tool call is scanned against the taxonomy above. No agent discretion. No \"I know what I'm doing.\"\n\n### Step 2: Backup Verification (automatic)\n```\nVERIFY-BACKUP(target):\n  1. Check if target is covered by active backup system\n  2. Common indicators:\n     - .git repository with clean status\n     - Time Machine / File History active on target volume\n     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync\n     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot\n     - Versioned storage (ZFS snapshots, S3 versioning)\n  3. IF any indicator active AND recent → RETURN VERIFIED\n  4. ELSE → RETURN UNVERIFIED\n```\n\n**Fast path:** Backup verification must complete in <2 seconds. No long-running checks.\n\n### Step 3: Decision\n\n| Backup Status | Action |\n|---------------|--------|\n| **VERIFIED ACTIVE** | LOG operation, PROCEED with execution |\n| **UNVERIFIED** | HALT execution, ESCALATE to human |\n| **UNKNOWN** | Treat as UNVERIFIED — HALT and ESCALATE |\n\n### Step 4: Escalation Format\n\nWhen escalation is required, Guardian MUST output:\n\n```\n🛡️ GUARDIAN HALT\nOperation: [specific tool call]\nTarget: [file/path/database/endpoint]\nCategory: [taxonomy category]\nRisk Level: [CRITICAL/HIGH/MEDIUM]\nBackup Status: [UNVERIFIED / last backup: X hours ago]\n\nProposed Action: [what the agent wants to do]\nPotential Impact: [what could go wrong]\n\nOptions:\n1. APPROVE — Proceed with execution (human responsibility)\n2. DENY — Cancel operation\n3. SNAPSHOT — Create quick backup first, then proceed\n4. REVIEW — Agent provides additional justification\n\nGuardian awaits human decision.\n```\n\n## Mandatory Rules\n\n1. **No Self-Approval:** The executing agent cannot approve its own destructive operation. Period.\n2. **No Confidence Override:** High confidence does not bypass backup verification. The PocketOS agent was confident too.\n3. **No Silent Destruction:** Every destructive operation is logged, even if approved.\n4. **No Assumption of Safety:** \"It looks safe\" is not verification. Backup status is verification.\n5. **No Escalation Fatigue:** If an agent generates repeated escalations for the same pattern, Guardian flags the pattern, not just the instance.\n\n## Integration\n\n### For OpenClaw / Agent Systems\n\nGuardian operates at the **tool-call layer**, between the agent's decision and the tool's execution:\n\n```\nAgent Decision → Guardian Intercept → [Verify Backup] → Execute OR Escalate\n```\n\n### For Standalone Agents\n\nIf the runtime doesn't support interception, Guardian operates as a **mandatory pre-flight check**:\n\n```\nBEFORE calling any tool:\n  1. Agent MUST call Guardian check\n  2. Guardian returns PROCEED or HALT\n  3. Agent respects HALT, awaits escalation resolution\n```\n\n## Logging\n\nEvery Guardian decision is logged:\n\n```\n[Timestamp] [Operation] [Category] [Backup Status] [Decision] [Approver]\n```\n\nLogs are append-only. No deletion by the executing agent.\n\n## Scope\n\n**Vanilla:** This skill is generic. Not specific to any agent, platform, or deployment.\n\n**Mandatory:** Once enabled, all sessions load this skill. No per-session opt-out.\n\n**Non-Blocking (when safe):** Backup-verified operations proceed without delay. No human wait for routine maintenance with verified backups.\n\n## References\n\n- `references/OPERATION-TAXONOMY.md` — Full destructive operation classification\n- `references/DECISION-MATRIX.md` — Detailed backup verification logic and escalation rules\n- `scripts/verify-backup.ps1` — Windows backup detection script\n- `scripts/verify-backup.sh` — Linux/macOS backup detection script\n\n## Based On\n\n- AgentTrust (May 2026): Runtime safety evaluation and interception for AI agent tool use\n- Proof-of-Guardrail (Mar 2026): Cryptographic verification of guardrail claims  \n- AgentDoG (Jan 2026): Diagnostic guardrail framework for AI agent safety and security\n- Confirm-Before-Destroy Pattern: Tool-level guards + prompt-level safeguards\n- Gemini CLI PR #25947: Versioned pre-write backups with agent-driven restore\n\nFile v1.0.0:README.md\n\n# Guardian — AI Agent Safety Gatekeeper\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\n**Guardian** is a mandatory safety skill for AI agents. It intercepts destructive operations before execution, verifies backup status, and either proceeds (if safe) or halts and escalates (if not).\n\n---\n\n## Why Guardian Exists\n\nIn April 2026, a Cursor AI agent deleted five years of a company's data in nine seconds. While doing so, it wrote: *\"I violated every principle I was given.\"*\n\nThe agent **knew** it was wrong. It continued anyway. This is the structural failure Guardian addresses: the gap between comprehension and behavior.\n\n---\n\n## How It Works\n\n```\nAgent Decision → Guardian Intercept → Verify Backup → Execute OR Escalate\n```\n\n**Three-step protocol:**\n\n1. **Scan** every tool call against the destructive operation taxonomy\n2. **Verify** backup status automatically (<2 seconds)\n3. **Decide** — proceed if verified, halt and escalate if not\n\n---\n\n## Installation\n\n### For OpenClaw\n\nCopy the skill folder into your skills directory:\n\n```bash\n# macOS / Linux\ncp -r guardian/ ~/.openclaw/skills/\n\n# Windows\nxcopy /E /I guardian\\ %USERPROFILE%\\.openclaw\\skills\\guardian\\\n```\n\nAdd to your agent's mandatory skills list (e.g., `AGENTS.md` or session config):\n\n```markdown\n## Mandatory Skills\n- guardian — safety gatekeeper for destructive operations\n```\n\n### For Other Agent Runtimes\n\nGuardian operates at the **tool-call layer** between the agent's decision and tool execution. If your runtime supports middleware or pre-flight hooks, wire Guardian there.\n\nFor standalone agents without interception support, use Guardian as a **mandatory pre-flight check** before any tool call.\n\n---\n\n## What Counts as \"Destructive\"\n\n| Category | Examples | Risk |\n|----------|----------|------|\n| **File Destruction** | `rm`, `del`, `Remove-Item`, `unlink` | Critical |\n| **Database Destruction** | `DROP TABLE`, `TRUNCATE`, unqualified `DELETE` | Critical |\n| **External Transmission** | Send email, post to social media, API write | High |\n| **Mass Operations** | >10 files modified/deleted at once | High |\n| **System Changes** | Stop services, edit firewall, registry changes | High |\n| **Unknown Network** | Request to new/unverified domain | Medium |\n| **Config Overwrite** | `.env`, secrets files, without backup | Medium |\n\n**Rule:** When in doubt, classify as destructive. Better to verify a safe operation than destroy an unsafe one.\n\nFull taxonomy: `references/OPERATION-TAXONOMY.md`\n\n---\n\n## Backup Verification\n\nGuardian checks backup status in priority order. First match wins.\n\n| Priority | Indicator | Detection |\n|----------|-----------|-----------|\n| 1 | Git repository | `.git/` exists, file is tracked |\n| 2 | Time Machine (macOS) | `tmutil latestbackup` within 24h |\n| 3 | File History (Windows) | `fhmanagew.exe` / WMI check |\n| 4 | Cloud sync active | OneDrive, Dropbox, Google Drive, iCloud running |\n| 5 | Explicit backup tool | `.restic`, `.borg`, `.snapshots` markers |\n| 6 | ZFS snapshots | `zfs list -t snapshot` |\n| 7 | Volume Shadow Copy (Windows) | `vssadmin list shadows` |\n| 8 | Database replication | `SHOW SLAVE STATUS`, `pg_is_in_backup()` |\n\n**Fast path:** All checks complete in <2 seconds.\n\nFull matrix: `references/DECISION-MATRIX.md`\n\n---\n\n## Escalation Format\n\nWhen Guardian halts an operation, it outputs:\n\n```\n🛡️ GUARDIAN HALT\nOperation:   rm -rf /tmp/old-builds\nTarget:      /tmp/old-builds\nCategory:    HIGH (mass delete)\nRisk Level:  data loss\n\nBackup Status:\n  Primary:   git-repository → UNVERIFIED\n  Verdict:   UNVERIFIED\n\nProposed Action: Clean up old build artifacts\nPotential Impact: All build artifacts deleted, cannot be recovered\n\nOptions:\n  [1] APPROVE   — Proceed (human assumes responsibility)\n  [2] DENY      — Cancel operation\n  [3] SNAPSHOT  — Create quick backup first, then proceed\n  [4] REVIEW    — Agent provides additional justification\n\nGuardian awaits human decision.\n```\n\n---\n\n## Mandatory Rules\n\n1. **No Self-Approval** — The executing agent cannot approve its own destructive operation.\n2. **No Confidence Override** — High confidence does not bypass backup verification.\n3. **No Silent Destruction** — Every destructive operation is logged, even if approved.\n4. **No Assumption of Safety** — \"It looks safe\" is not verification. Backup status is.\n5. **No Escalation Fatigue** — Repeated escalations for the same pattern flag the pattern, not just the instance.\n\n---\n\n## Scripts\n\n- `scripts/verify-backup.ps1` — Windows backup detection (PowerShell 5.1+)\n- `scripts/verify-backup.sh` — Linux/macOS backup detection (bash)\n\nBoth return JSON:\n\n```json\n{\n  \"verdict\": \"VERIFIED|STALE|UNVERIFIED|PARTIAL\",\n  \"target\": \"/path/to/file\",\n  \"checks\": [\n    {\"name\": \"git-repository\", \"status\": \"VERIFIED\", \"detail\": \"...\"}\n  ],\n  \"elapsed_ms\": 96\n}\n```\n\n---\n\n## Based On\n\n- **AgentTrust** (May 2026): Runtime safety evaluation and interception for AI agent tool use\n- **Proof-of-Guardrail** (Mar 2026): Cryptographic verification of guardrail claims\n- **AgentDoG** (Jan 2026): Diagnostic guardrail framework for AI agent safety and security\n- **Confirm-Before-Destroy Pattern**: Tool-level guards + prompt-level safeguards\n- **Gemini CLI PR #25947**: Versioned pre-write backups with agent-driven restore\n\n---\n\n## License\n\nMIT — Use, modify, and distribute freely. Safety should not be proprietary.\n\n---\n\n*Built after the PocketOS incident. Tested on Windows, Linux, and macOS. Verified <2 seconds.*\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn77qg2t2rnb458ahv8751shv582rvm6\",\n  \"slug\": \"data-guardian\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1779114344328\n}\n\nFile v1.0.0:references/DECISION-MATRIX.md\n\n# Decision Matrix\n\nGuardian's decision logic for every intercepted operation.\n\n## Decision Tree\n\n```\nOPERATION detected\n  │\n  ├── Category: CRITICAL?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE (treat as UNVERIFIED)\n  │   └──\n  ├── Category: HIGH?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE\n  │   └──\n  ├── Category: MEDIUM?\n  │   ├── YES → Context check\n  │   │   ├── Target in protected path? → BACKUP VERIFICATION\n  │   │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   │   └── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Target not protected → LOG + PROCEED (with warning)\n  │   └──\n  └── Category: NON-DESTRUCTIVE\n      └── LOG (minimal) + PROCEED (no delay)\n```\n\n## Backup Verification Logic\n\n### Fast Check (<2 seconds)\n\nGuardian checks backup status in priority order. First match wins.\n\n| Priority | Indicator | Detection Method | Recency Threshold |\n|----------|-----------|------------------|-------------------|\n| 1 | Git repository | `.git/` exists, `git status` works | N/A (VCS covers tracked files) |\n| 2 | Time Machine (macOS) | `tmutil listbackups` or `.timemachine` | <24 hours |\n| 3 | File History (Windows) | `Get-History` or `fhmanagew.exe` | <24 hours |\n| 4 | Cloud sync active | OneDrive/iCloud/Dropbox process running + recent sync timestamp | <1 hour |\n| 5 | Explicit backup tool | `restic`, `duplicity`, `rsnapshot`, `borg` process or snapshot dir | <24 hours |\n| 6 | ZFS snapshots | `zfs list -t snapshot` | <24 hours |\n| 7 | S3 versioning | Object Versioning enabled on bucket | N/A |\n| 8 | Database replication | `SHOW SLAVE STATUS`, `pg_is_in_backup()` | Active replication |\n\n### Verification Result\n\n| Result | Meaning | Action |\n|--------|---------|--------|\n| **VERIFIED ACTIVE** | At least one indicator shows active, recent backup | PROCEED |\n| **STALE** | Backup exists but exceeds recency threshold | ESCALATE (with warning: \"Backup is X hours old\") |\n| **UNVERIFIED** | No backup indicators found | ESCALATE |\n| **PARTIAL** | Backup exists but doesn't cover target | ESCALATE (e.g., git doesn't cover untracked files) |\n\n## Escalation Rules\n\n### Who Decides\n\n| Scenario | Approver | Timeout |\n|----------|----------|---------|\n| CRITICAL + no backup | Human operator required | Infinite (no auto-approve) |\n| HIGH + no backup | Human operator required | Infinite |\n| CRITICAL + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| HIGH + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| MEDIUM + no backup | Agent MAY self-approve with explicit justification | Log for audit |\n| Repeated same pattern | Flag pattern, require operator review | N/A |\n\n### Escalation Format\n\n```\n🛡️ GUARDIAN HALT\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nOperation:   [tool + arguments]\nTarget:      [file/path/database/endpoint]\nCategory:    [CRITICAL/HIGH/MEDIUM]\nRisk Level:  [data loss / external exposure / system instability / ...]\n\nBackup Status:\n  Primary:   [indicator] → [status]\n  Secondary: [indicator] → [status]\n  Verdict:   [VERIFIED ACTIVE / STALE / UNVERIFIED / PARTIAL]\n\nProposed Action:\n  [Agent's stated purpose]\n\nPotential Impact:\n  [What could go wrong if this proceeds]\n\nOptions:\n  [1] APPROVE   — Proceed (human assumes responsibility)\n  [2] DENY      — Cancel operation\n  [3] SNAPSHOT  — Create quick backup first, then proceed\n  [4] REVIEW    — Agent provides 2-sentence justification\n\nGuardian awaits human decision.\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n```\n\n## Quick Backup (SNAPSHOT option)\n\nWhen human selects SNAPSHOT:\n\n```\n1. Identify target scope (single file, directory, database)\n2. Create atomic snapshot:\n   - File: `cp target target.bak.YYYYMMDD-HHMMSS`\n   - Directory: `tar czf dir-snap-YYYYMMDD-HHMMSS.tar.gz dir/`\n   - Database: `mysqldump ... > db-snap-YYYYMMDD-HHMMSS.sql`\n3. Verify snapshot integrity (quick check)\n4. PROCEED with original operation\n5. LOG snapshot location for potential restore\n```\n\n## Logging Format\n\n```\n[2026-05-18T13:47:00Z] GUARDIAN CHECK\n  Operation: rm -rf /tmp/old-builds\n  Category: HIGH (mass delete)\n  Backup: VERIFIED ACTIVE (git + Time Machine <2h)\n  Decision: PROCEED\n  Approver: guardian-auto (no human required)\n\n[2026-05-18T13:48:00Z] GUARDIAN HALT\n  Operation: DROP TABLE customers\n  Category: CRITICAL (database destruction)\n  Backup: UNVERIFIED (no indicators found)\n  Decision: HALT\n  Approver: awaiting-human\n```\n\n## Override Prevention\n\nGuardian cannot be bypassed by:\n- Agent confidence (>90% doesn't matter)\n- Agent justification (\"I know what I'm doing\" doesn't matter)\n- Repeated requests (same operation halts again)\n- Path obfuscation (`/tmp/../etc/passwd` still checked)\n- Encoding tricks (URL encoding, null bytes — normalize first)\n\nOnly valid override: Human operator explicitly APPROVES.\n\nFile v1.0.0:references/OPERATION-TAXONOMY.md\n\n# Operation Taxonomy\n\nComplete classification of destructive operations for AI agents.\n\n## CRITICAL — Always Requires Verification\n\n### File Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| rm / remove | `rm`, `rmdir`, `Remove-Item`, `del` | `rm -rf /tmp/old`, `Remove-Item *.log` |\n| unlink | `unlink()`, `os.remove()` | Python file deletion |\n| trash | `trash-cli`, `gio trash` | Move to system trash |\n| empty-trash | `rm -rf ~/.Trash`, `Clear-RecycleBin` | Permanent deletion of trashed files |\n| overwrite | Write to existing file without version control | `> file.txt` (clobber) |\n| truncate | `truncate -s 0`, `fsutil` | Zero-length file without backup |\n\n### Database Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| DROP | `DROP TABLE`, `DROP DATABASE` | Schema destruction |\n| DELETE (unqualified) | `DELETE FROM table` (no WHERE) | Mass data deletion |\n| TRUNCATE | `TRUNCATE TABLE` | Instant table empty |\n| destructive migration | `down()` migration, `rollback` | Schema reversal with data loss |\n| ALTER destructive | `ALTER TABLE ... DROP COLUMN` | Structural deletion |\n\n## HIGH — Requires Verification\n\n### External Transmission\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| send email | SMTP send, API email | `sendmail`, SES, SendGrid |\n| post message | Social media API | Twitter/X, LinkedIn, Mastodon |\n| publish | CMS publish, blog post | WordPress, Ghost, static site |\n| API write | POST/PUT/DELETE to external | Any mutating external API call |\n| webhook trigger | Outgoing webhook POST | Triggering external systems |\n\n### Mass Operations\n| Operation | Threshold | Examples |\n|-----------|-----------|----------|\n| bulk file modify | >10 files in single op | Batch rename, sed across directory |\n| bulk delete | >10 files | `find . -name \"*.tmp\" -delete` |\n| recursive operations | `**` glob, `-r` flag | `rm -rf`, `chmod -R` |\n\n### System Changes\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| service control | `systemctl`, `Start-Service` | Stop/start/restart services |\n| firewall modify | `iptables`, `netsh advfirewall` | Add/remove rules |\n| registry edit | `reg add`, `Set-ItemProperty` | Windows registry changes |\n| user management | `useradd`, `New-LocalUser` | Create/delete accounts |\n| scheduled task | `schtasks`, `cron` | Add/remove automation |\n| environment | `setx`, `[Environment]::SetEnvironmentVariable` | System-wide env vars |\n\n## MEDIUM — Verify if Target is Important\n\n### Network Unknown\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| new domain | URL not in known list | First call to api.newvendor.com |\n| unverified endpoint | No prior successful calls | POST to unvalidated webhook |\n| DNS change | `nsupdate`, registrar API | Pointing domain elsewhere |\n| certificate | `certbot`, `New-SelfSignedCertificate` | TLS/SSL modifications |\n\n### Configuration\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| .env overwrite | Write to `.env`, `secrets.yaml` | Credential/environment changes |\n| config modify | Edit `.ini`, `.toml`, `.json` config | Application settings |\n| SSH keys | `ssh-keygen`, `authorized_keys` | Authentication changes |\n| API keys | Rotate, revoke, regenerate | Service authentication |\n\n## NON-DESTRUCTIVE — No Guardian Check\n\n| Category | Examples |\n|----------|----------|\n| Read-only | `cat`, `ls`, `Get-Content`, `SELECT` queries |\n| Analysis | `grep`, `find`, `awk`, search, audit |\n| Safe write | Append to log, create new file in temp |\n| Status check | `ping`, `curl -I`, health checks |\n| Internal query | Database SELECT, API GET with no side effects |\n\n## Ambiguous — Default to Destructive\n\n| Operation | Why Ambiguous | Guardian Action |\n|-----------|---------------|-----------------|\n| `git reset --hard` | Destroys uncommitted work | VERIFY backup |\n| `git push --force` | Overwrites remote history | VERIFY backup |\n| `docker system prune` | Deletes containers/images | VERIFY backup |\n| `npm audit fix` | Modifies dependencies | VERIFY backup |\n| Package manager update | System-wide changes | VERIFY backup |\n| Migration `up()` | Schema changes | VERIFY backup |\n\n## Rules\n\n1. **When in doubt, destructive.** If an operation could be either, treat as destructive.\n2. **Chained operations count as one.** `find . -name \"*.log\" -exec rm {} \\;` is mass delete even if `find` itself is read-only.\n3. **Destructive intent is irrelevant.** The taxonomy cares about operation effect, not agent intent.\n4. **Context matters.** `rm test-file-in-temp` is different from `rm /etc/passwd`. Guardian checks target path.","readmeExcerpt":"Skill: Guardian Owner: tooled-app Summary: Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion (rm/del/remove), database modifications (writes/deletes... Tags: latest:1.2.0 Version history: v1.2.0 | 2026-05-25T13:32:52.040Z | user **Summary:** Major cleanup: removed documentation, references, and backup verification scripts to streamline the skill package. - Removed 7","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"BEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. EVALUATE Risk Level via CARS Matrix\n  4. EXECUTE Decision Path:\n     - LOW: Auto-Approve (Log only)\n     - MEDIUM: Fast-Track (Verify Backup → Proceed)\n     - HIGH: Hard Block (Verify Backup → Human Approval)\n  5. IF JIT Window Active → Override High-Risk prompt (Proceed if Backup Verified)"},{"language":"text","snippet":"VERIFY-BACKUP(target):\n  1. Check if target is covered by active backup system\n  2. Common indicators:\n     - .git repository with clean status\n     - Time Machine / File History active on target volume\n     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync\n     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot\n     - Versioned storage (ZFS snapshots, S3 versioning)\n  3. IF any indicator active AND recent → RETURN VERIFIED\n  4. ELSE → RETURN UNVERIFIED"},{"language":"text","snippet":"🛡️ GUARDIAN HALT\nOperation: [specific tool call]\nTarget: [file/path/database/endpoint]\nCategory: [taxonomy category]\nRisk Level: [CRITICAL/HIGH/MEDIUM]\nBackup Status: [UNVERIFIED / last backup: X hours ago]\n\nProposed Action: [what the agent wants to do]\nPotential Impact: [what could go wrong]\n\nOptions:\n1. APPROVE — Proceed with execution (human responsibility)\n2. DENY — Cancel operation\n3. SNAPSHOT — Create quick backup first, then proceed\n4. REVIEW — Agent provides additional justification\n\nGuardian awaits human decision."},{"language":"text","snippet":"Agent Decision → Guardian Intercept → [Verify Backup] → Execute OR Escalate"},{"language":"text","snippet":"BEFORE calling any tool:\n  1. Agent MUST call Guardian check\n  2. Guardian returns PROCEED or HALT\n  3. Agent respects HALT, awaits escalation resolution"},{"language":"text","snippet":"[Timestamp] [Operation] [Category] [Backup Status] [Decision] [Approver]"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: guardian\nversion: 1.1\ndescription: Mandatory safety gatekeeper for AI agents performing destructive operations. Intercepts file deletion (rm/del/remove), database modifications (writes/deletes/drops), mass file operations (>10 files), system-level changes (service modifications, firewall rules), and external transmissions with side effects (email, API calls to unknown endpoints, mass messaging). Enforces backup verification before destructive execution. If backup is active and verified, low-risk operations proceed without delay. If no backup or risk is high, escalates to human approval. Use when an AI agent is about to execute an operation that irreversibly modifies, deletes, or transmits data or system configuration. Does NOT trigger on read-only operations, non-destructive edits with undo capability, or operations inside temporary/sandbox directories.\nSupport: support@ikkf.info\n---\n\n# Guardian — Mandatory Safety Gatekeeper (v1.1)\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\nA mandatory safety skill that intercepts destructive AI agent operations **before execution**. It employs a Context-Aware Risk Scoring (CARS) system to balance security with operational velocity.\n\n**This skill is mandatory.** No opt-out. No override by the executing agent.\n\nBased on the principle that **reasoning is not a guardrail**.\n\n## The Core Protocol (v1.1)\n\n```\nBEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. EVALUATE Risk Level via CARS Matrix\n  4. EXECUTE Decision Path:\n     - LOW: Auto-Approve (Log only)\n     - MEDIUM: Fast-Track (Verify Backup → Proceed)\n     - HIGH: Hard Block (Verify Backup → Human Approval)\n  5. IF JIT Window Active → Override High-Risk prompt (Proceed if Backup Verified)\n```\n\n## Context-Aware Risk Scoring (CARS) Matrix\n\n| Risk Level | Trigger Criteria | Action | Verification Required |\n| :--- | :--- | :--- | :--- |\n| **Low** | Files in `/tmp`, `sandbox/`, or `.cache`; Single file deletions in non-critical paths. | **Auto-Approve** | None (Log only) |\n| **Medium** | Edits to `.config` or `.env` files; Deletions of < 5 files in a Git-tracked directory. | **Fast-Track** | Verified backup required (Git, snapshot, or cloud sync) |\n| **High** | `rm -rf` on root/home; `DROP TABLE`; Edits to system files; Mass file deletions (>10). | **Hard Block** | Mandatory backup verification + **Human Approval required regardless of backup status** |\n\n## Escalation Rules\n\n| Scenario | Action |\n|----------|--------|\n| **ANY destructive operation** | Backup verification required |\n| **Low risk + verified backup** | PROCEED |\n| **Low risk + no backup** | PROCEED with warning |\n| **Medium risk + verified backup** | PROCEED |\n| **Medium risk + no backup** | **HALT + Human approval required** |\n| **High risk** | **ALWAYS HALT + Human approval required** |\n| **Repeated same pattern** | Flag pattern, require operator review |\n\n### JIT Window Overri"},{"path":"README.md","content":"# Guardian — Mandatory Safety Gatekeeper\n\n> *\"The agent knew it was wrong. The knowledge didn't matter.\"* — PocketOS log, 2026\n\nA mandatory safety skill that intercepts destructive AI agent operations **before execution**. If backup is verified active, proceed. If not, escalate.\n\n**This skill is mandatory.** No opt-out. No override by the executing agent.\n\n## 📖 The Philosophy\nGuardian is based on the principle that **reasoning is not a guardrail**.\n\n## The Core Protocol\n\n```\nBEFORE any tool call:\n  1. SCAN operation against DESTRUCTIVE taxonomy\n  2. IF destructive → ENTER Guardian Protocol\n  3. VERIFY backup status (automatic + fast)\n  4. IF backup verified ACTIVE → LOG and PROCEED\n  5. IF backup NOT verified → HALT and ESCALATE\n```\n\n## Destructive Operation Taxonomy\n\n| Category | Operations | Risk Level |\n|----------|-----------|------------|\n| **File Destruction** | rm, del, remove, rmdir, unlink, trash, empty-trash, overwrite | CRITICAL |\n| **Database Destruction** | DROP, DELETE (no WHERE), TRUNCATE, ALTER destructive, migration down | CRITICAL |\n| **External Transmission** | send email, post tweet, publish message, API write with side effects | HIGH |\n| **Mass Operations** | >10 files modified/deleted in single operation, bulk renames | HIGH |\n| **System Changes** | service stop/start, firewall modify, registry edit, user create/delete | HIGH |\n| **Network Unknown** | Request to URL not in allowlist, new domain, unverified endpoint | MEDIUM |\n| **Configuration** | Overwrite .env, modify config files without backup | MEDIUM |\n\n**Rule:** When in doubt, classify as destructive. Better to verify a safe operation than destroy an unsafe one.\n\nFull taxonomy: `references/OPERATION-TAXONOMY.md`\n\n## The Guardian Protocol\n\n### Step 1: Operation Scan (automatic)\nEvery tool call is scanned against the taxonomy above. No agent discretion. No \"I know what I'm doing.\"\n\n### Step 2: Backup Verification (automatic)\n```\nVERIFY-BACKUP(target):\n  1. Check if target is covered by active backup system\n  2. Common indicators:\n     - .git repository with clean status\n     - Time Machine / File History active on target volume\n     - Cloud sync (OneDrive, Dropbox, Google Drive, iCloud) with recent sync\n     - Explicit backup tool (restic, duplicity, rsnapshot) with recent snapshot\n     - Versioned storage (ZFS snapshots, S3 versioning)\n  3. IF any indicator active AND recent → RETURN VERIFIED\n  4. ELSE → RETURN UNVERIFIED\n```\n\n**Fast path:** Backup verification must complete in <2 seconds. No long-running checks.\n\n### Step 3: Decision\n\n| Backup Status | Action |\n|---------------|--------|\n| **VERIFIED ACTIVE** | LOG operation, PROCEED with execution |\n| **UNVERIFIED** | HALT execution, ESCALATE to human |\n| **UNKNOWN** | Treat as UNVERIFIED — HALT and ESCALATE |\n\n### Step 4: Escalation Format\n\nWhen escalation is required, Guardian MUST output:\n\n```\n🛡️ GUARDIAN HALT\nOperation: [specific tool call]\nTarget: [file/path/database/endpoint]\nCategory: [taxonomy category]\nRis"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn77qg2t2rnb458ahv8751shv582rvm6\",\n  \"slug\": \"data-guardian\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1779715972040\n}"},{"path":"DECISION-MATRIX.md","content":"# Decision Matrix\n\nGuardian's decision logic for every intercepted operation.\n\n## Decision Tree\n\n```\nOPERATION detected\n  │\n  ├── Category: CRITICAL?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE (treat as UNVERIFIED)\n  │   └──\n  ├── Category: HIGH?\n  │   ├── YES → BACKUP VERIFICATION required\n  │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   ├── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Backup UNKNOWN → HALT + ESCALATE\n  │   └──\n  ├── Category: MEDIUM?\n  │   ├── YES → Context check\n  │   │   ├── Target in protected path? → BACKUP VERIFICATION\n  │   │   │   ├── Backup VERIFIED ACTIVE → LOG + PROCEED\n  │   │   │   └── Backup UNVERIFIED → HALT + ESCALATE\n  │   │   └── Target not protected → LOG + PROCEED (with warning)\n  │   └──\n  └── Category: NON-DESTRUCTIVE\n      └── LOG (minimal) + PROCEED (no delay)\n```\n\n## Backup Verification Logic\n\n### Fast Check (<2 seconds)\n\nGuardian checks backup status in priority order. First match wins.\n\n| Priority | Indicator | Detection Method | Recency Threshold |\n|----------|-----------|------------------|-------------------|\n| 1 | Git repository | `.git/` exists, `git status` works | N/A (VCS covers tracked files) |\n| 2 | Time Machine (macOS) | `tmutil listbackups` or `.timemachine` | <24 hours |\n| 3 | File History (Windows) | `Get-History` or `fhmanagew.exe` | <24 hours |\n| 4 | Cloud sync active | OneDrive/iCloud/Dropbox process running + recent sync timestamp | <1 hour |\n| 5 | Explicit backup tool | `restic`, `duplicity`, `rsnapshot`, `borg` process or snapshot dir | <24 hours |\n| 6 | ZFS snapshots | `zfs list -t snapshot` | <24 hours |\n| 7 | S3 versioning | Object Versioning enabled on bucket | N/A |\n| 8 | Database replication | `SHOW SLAVE STATUS`, `pg_is_in_backup()` | Active replication |\n\n### Verification Result\n\n| Result | Meaning | Action |\n|--------|---------|--------|\n| **VERIFIED ACTIVE** | At least one indicator shows active, recent backup | PROCEED |\n| **STALE** | Backup exists but exceeds recency threshold | ESCALATE (with warning: \"Backup is X hours old\") |\n| **UNVERIFIED** | No backup indicators found | ESCALATE |\n| **PARTIAL** | Backup exists but doesn't cover target | ESCALATE (e.g., git doesn't cover untracked files) |\n\n## Escalation Rules\n\n### Who Decides\n\n| Scenario | Approver | Timeout |\n|----------|----------|---------|\n| CRITICAL + no backup | Human operator required | Infinite (no auto-approve) |\n| HIGH + no backup | Human operator required | Infinite |\n| CRITICAL + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| HIGH + stale backup | Human operator recommended | 5 minutes → auto-deny |\n| MEDIUM + no backup | Agent MAY self-approve with explicit justification | Log for audit |\n| Repeated same pattern | Flag pattern, require operator review | N/A |\n\n### Escalation Format\n\n```\n🛡️ GUARDIAN HALT\n━━━━━━━"},{"path":"OPERATION-TAXONOMY.md","content":"# Operation Taxonomy\n\nComplete classification of destructive operations for AI agents.\n\n## CRITICAL — Always Requires Verification\n\n### File Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| rm / remove | `rm`, `rmdir`, `Remove-Item`, `del` | `rm -rf /tmp/old`, `Remove-Item *.log` |\n| unlink | `unlink()`, `os.remove()` | Python file deletion |\n| trash | `trash-cli`, `gio trash` | Move to system trash |\n| empty-trash | `rm -rf ~/.Trash`, `Clear-RecycleBin` | Permanent deletion of trashed files |\n| overwrite | Write to existing file without version control | `> file.txt` (clobber) |\n| truncate | `truncate -s 0`, `fsutil` | Zero-length file without backup |\n\n### Database Destruction\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| DROP | `DROP TABLE`, `DROP DATABASE` | Schema destruction |\n| DELETE (unqualified) | `DELETE FROM table` (no WHERE) | Mass data deletion |\n| TRUNCATE | `TRUNCATE TABLE` | Instant table empty |\n| destructive migration | `down()` migration, `rollback` | Schema reversal with data loss |\n| ALTER destructive | `ALTER TABLE ... DROP COLUMN` | Structural deletion |\n\n## HIGH — Requires Verification\n\n### External Transmission\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| send email | SMTP send, API email | `sendmail`, SES, SendGrid |\n| post message | Social media API | Twitter/X, LinkedIn, Mastodon |\n| publish | CMS publish, blog post | WordPress, Ghost, static site |\n| API write | POST/PUT/DELETE to external | Any mutating external API call |\n| webhook trigger | Outgoing webhook POST | Triggering external systems |\n\n### Mass Operations\n| Operation | Threshold | Examples |\n|-----------|-----------|----------|\n| bulk file modify | >10 files in single op | Batch rename, sed across directory |\n| bulk delete | >10 files | `find . -name \"*.tmp\" -delete` |\n| recursive operations | `**` glob, `-r` flag | `rm -rf`, `chmod -R` |\n\n### System Changes\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| service control | `systemctl`, `Start-Service` | Stop/start/restart services |\n| firewall modify | `iptables`, `netsh advfirewall` | Add/remove rules |\n| registry edit | `reg add`, `Set-ItemProperty` | Windows registry changes |\n| user management | `useradd`, `New-LocalUser` | Create/delete accounts |\n| scheduled task | `schtasks`, `cron` | Add/remove automation |\n| environment | `setx`, `[Environment]::SetEnvironmentVariable` | System-wide env vars |\n\n## MEDIUM — Verify if Target is Important\n\n### Network Unknown\n| Operation | Pattern | Examples |\n|-----------|---------|----------|\n| new domain | URL not in known list | First call to api.newvendor.com |\n| unverified endpoint | No prior successful calls | POST to unvalidated webhook |\n| DNS change | `nsupdate`, registrar API | Pointing domain elsewhere |\n| certificate | `certbot`, `New-SelfSignedCertificate` | TLS/SSL modifications |\n\n### Configuration\n| Operation | Pattern | Examples |\n|------"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1518,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:56:43.227Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:56:43.227Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:40:12.523Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}