{"id":"7013d158-ae1b-4d5f-b2e3-8c295d67cae3","entityType":"agent","slug":"clawhub-unknown-clawsec-nanoclaw","name":"clawsec-nanoclaw","canonicalUrl":"https://www.xpersona.co/agent/clawhub-unknown-clawsec-nanoclaw","canonicalPath":"/agent/clawhub-unknown-clawsec-nanoclaw","generatedAt":"2026-10-10T07:41:32.468Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T22:38:56.374Z","emptyReason":null},"description":"Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Skill: clawsec-nanoclaw Summary: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Tags: latest:0.0.10 Version history: v0.0.10 | 2026-06-23T08:22:27.400Z | user Release 0.0.10 via CI v0.0.8 | 2026-06-10T14:59:12.174Z | user Release 0.0.8 via CI v0.0.7 | 2026-06-07T10:06:18.365Z | user Release 0.0.7 via CI v0.0.6","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install unknown:clawsec-nanoclaw","sourceUrl":"https://clawhub.ai/unknown/clawsec-nanoclaw","homepage":"https://clawhub.ai/unknown/skills/clawsec-nanoclaw","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/unknown/clawsec-nanoclaw","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/unknown/skills/clawsec-nanoclaw","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":66,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Skill"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:38:56.374Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:38:56.374Z","emptyReason":null},"stars":null,"forks":null,"downloads":1933,"packageName":null,"latestVersion":"0.0.10","tractionLabel":"1.9K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:38:56.341Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T22:38:56.374Z","lastCrawledAt":"2026-10-09T22:38:56.341Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T22:38:56.341Z","lastVerifiedAt":null,"highlights":[{"version":"0.0.10","createdAt":"2026-06-23T08:22:27.400Z","changelog":"Release 0.0.10 via CI","fileCount":24,"zipByteSize":63394},{"version":"0.0.8","createdAt":"2026-06-10T14:59:12.174Z","changelog":"Release 0.0.8 via CI","fileCount":24,"zipByteSize":63269},{"version":"0.0.7","createdAt":"2026-06-07T10:06:18.365Z","changelog":"Release 0.0.7 via CI","fileCount":24,"zipByteSize":63021},{"version":"0.0.6","createdAt":"2026-05-24T18:47:26.870Z","changelog":"Release 0.0.6 via CI","fileCount":24,"zipByteSize":60377},{"version":"0.0.5","createdAt":"2026-05-14T11:43:08.508Z","changelog":"Release 0.0.5 via CI","fileCount":23,"zipByteSize":58791},{"version":"0.0.4","createdAt":"2026-04-16T23:51:05.125Z","changelog":"Release 0.0.4 via CI","fileCount":23,"zipByteSize":57697},{"version":"0.0.3","createdAt":"2026-03-09T17:32:53.949Z","changelog":"Release 0.0.3 via CI","fileCount":22,"zipByteSize":57227},{"version":"0.0.2","createdAt":"2026-03-02T08:32:18.190Z","changelog":"Release 0.0.2 via CI","fileCount":21,"zipByteSize":54830}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install unknown:clawsec-nanoclaw","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T07:41:32.464Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-unknown-clawsec-nanoclaw/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T22:38:56.374Z","emptyReason":null},"readme":"Skill: clawsec-nanoclaw\n\nSummary: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot\n\nTags: latest:0.0.10\n\nVersion history:\n\nv0.0.10 | 2026-06-23T08:22:27.400Z | user\n\nRelease 0.0.10 via CI\n\nv0.0.8 | 2026-06-10T14:59:12.174Z | user\n\nRelease 0.0.8 via CI\n\nv0.0.7 | 2026-06-07T10:06:18.365Z | user\n\nRelease 0.0.7 via CI\n\nv0.0.6 | 2026-05-24T18:47:26.870Z | user\n\nRelease 0.0.6 via CI\n\nv0.0.5 | 2026-05-14T11:43:08.508Z | user\n\nRelease 0.0.5 via CI\n\nv0.0.4 | 2026-04-16T23:51:05.125Z | user\n\nRelease 0.0.4 via CI\n\nv0.0.3 | 2026-03-09T17:32:53.949Z | user\n\nRelease 0.0.3 via CI\n\nv0.0.2 | 2026-03-02T08:32:18.190Z | user\n\nRelease 0.0.2 via CI\n\nv0.0.1 | 2026-02-25T10:20:44.583Z | user\n\nManual republish of 0.0.1 via workflow_dispatch\n\nArchive index:\n\nArchive v0.0.10: 24 files, 63394 bytes\n\nFiles: CHANGELOG.md (3617b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (14939b), guardian/integrity-monitor.ts (21442b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (10995b), host-services/ipc-handlers.ts (3378b), host-services/skill-signature-handler.ts (7632b), INSTALL.md (9616b), lib/advisories.ts (14982b), lib/local_file_io.ts (316b), lib/risk.ts (2501b), lib/signatures.ts (14129b), lib/types.ts (6059b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (7025b), README.md (5416b), skill-card.md (2821b), skill.json (4949b), SKILL.md (8507b), test/security-hardening.test.mjs (7060b), _meta.json (136b)\n\nFile v0.0.10:SKILL.md\n\n---\nname: clawsec-nanoclaw\nversion: 0.0.10\ndescription: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot\n---\n\n# ClawSec for NanoClaw\n\nSecurity advisory monitoring that protects your WhatsApp bot from known vulnerabilities in skills and dependencies.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y\n```\n\n## Overview\n\nClawSec provides MCP tools that check installed skills against a curated feed of security advisories. It prevents installation of vulnerable skills, includes exploitability context for triage, and alerts you to issues in existing ones.\n\n**Core principle:** Check before you install. Monitor what's running.\n\n## When to Use\n\nUse ClawSec tools when:\n- Installing a new skill (check safety first)\n- User asks \"are my skills secure?\"\n- Investigating suspicious behavior\n- Regular security audits\n- After receiving security notifications\n\nDo NOT use for:\n- Code review (use other tools)\n- Performance issues (different concern)\n- General debugging\n\n## MCP Tools Available\n\n### Pre-Installation Check\n\n```typescript\n// Before installing any skill\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'new-skill',\n  skillVersion: '1.0.0'  // optional\n});\n\nif (!safety.safe) {\n  // Show user the risks before proceeding\n  console.warn(`Security issues: ${safety.advisories.map(a => a.id)}`);\n}\n```\n\n### Security Audit\n\n```typescript\n// Check all installed skills (defaults to ~/.claude/skills in the container)\nconst result = await tools.clawsec_check_advisories({\n  installRoot: '/home/node/.claude/skills'  // optional\n});\n\nif (result.matches.some((m) =>\n  m.advisory.severity === 'critical' || m.advisory.exploitability_score === 'high'\n)) {\n  // Alert user immediately\n  console.error('Urgent advisories found!');\n}\n```\n\n### Browse Advisories\n\n```typescript\n// List advisories with filters\nconst advisories = await tools.clawsec_list_advisories({\n  severity: 'high',               // optional\n  exploitabilityScore: 'high'     // optional\n});\n```\n\n## Quick Reference\n\n| Task | Tool | Key Parameter |\n|------|------|---------------|\n| Pre-install check | `clawsec_check_skill_safety` | `skillName` |\n| Audit all skills | `clawsec_check_advisories` | `installRoot` (optional) |\n| Browse feed | `clawsec_list_advisories` | `severity`, `type`, `exploitabilityScore` (optional) |\n| Verify package signature | `clawsec_verify_skill_package` | `packagePath` |\n| Refresh advisory cache | `clawsec_refresh_cache` | (none) |\n| Check file integrity | `clawsec_check_integrity` | `mode`, `autoRestore` (optional) |\n| Approve file change | `clawsec_approve_change` | `path` |\n| View baseline status | `clawsec_integrity_status` | `path` (optional) |\n| Verify audit log | `clawsec_verify_audit` | (none) |\n\n## Common Patterns\n\n### Pattern 1: Safe Skill Installation\n\n```typescript\n// ALWAYS check before installing\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: userRequestedSkill\n});\n\nif (safety.safe) {\n  // Proceed with installation\n  await installSkill(userRequestedSkill);\n} else {\n  // Show user the risks and get confirmation\n  await showSecurityWarning(safety.advisories);\n  if (await getUserConfirmation()) {\n    await installSkill(userRequestedSkill);\n  }\n}\n```\n\n### Pattern 2: Periodic Security Check\n\n```typescript\n// Add to scheduled tasks\nschedule_task({\n  prompt: \"Check advisories using clawsec_check_advisories and alert when critical or high-exploitability matches appear\",\n  schedule_type: \"cron\",\n  schedule_value: \"0 9 * * *\"  // Daily at 9am\n});\n```\n\n### Pattern 3: User Security Query\n\n```\nUser: \"Are my skills secure?\"\n\nYou: I'll check installed skills for known vulnerabilities.\n[Use clawsec_check_advisories]\n\nResponse:\n✅ No urgent issues found.\n- 2 low-severity/low-exploitability advisories\n- All skills up to date\n```\n\n## Common Mistakes\n\n### ❌ Installing without checking\n```typescript\n// DON'T\nawait installSkill('untrusted-skill');\n```\n\n```typescript\n// DO\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'untrusted-skill'\n});\nif (safety.safe) await installSkill('untrusted-skill');\n```\n\n### ❌ Ignoring exploitability context\n```typescript\n// DON'T: Use severity only\nif (advisory.severity === 'high') {\n  notifyNow(advisory);\n}\n```\n\n```typescript\n// DO: Use exploitability + severity\nif (\n  advisory.exploitability_score === 'high' ||\n  advisory.severity === 'critical'\n) {\n  notifyNow(advisory);\n}\n```\n\n### ❌ Skipping critical severity\n```typescript\n// DON'T: Ignore high exploitability in medium severity advisories\nif (advisory.severity === 'critical') alert();\n```\n\n```typescript\n// DO: Prioritize exploitability and severity together\nif (advisory.exploitability_score === 'high' || advisory.severity === 'critical') {\n  // Alert immediately\n}\n```\n\n## Implementation Details\n\n**Feed Source**: https://clawsec.prompt.security/advisories/feed.json\n\nThis signed feed is consolidated. NanoClaw receives NVD CVEs, approved community advisories, and provisional GHSA-without-CVE advisories through the same default URL.\n\n**Update Frequency**: Every 6 hours (automatic)\n\n**Signature Verification**: Ed25519 signed feeds\n**Package Verification Policy**: pinned key only, bounded package/signature paths\n\n**Cache Location**: `/workspace/project/data/clawsec-advisory-cache.json`\n\nSee [INSTALL.md](./INSTALL.md) for setup and [docs/](./docs/) for advanced usage.\n\n## Real-World Impact\n\n- Prevents installation of skills with known RCE vulnerabilities\n- Alerts to supply chain attacks in dependencies\n- Provides actionable remediation steps\n- Zero false positives (curated feed only)\n\n## Release Artifact Verification\n\nFor standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.\n\n```bash\nset -euo pipefail\n\nSKILL_NAME=\"clawsec-nanoclaw\"\nVERSION=\"0.0.10\"\nREPO=\"prompt-security/clawsec\"\nTAG=\"${SKILL_NAME}-v${VERSION}\"\nBASE=\"https://github.com/${REPO}/releases/download/${TAG}\"\nZIP_NAME=\"${SKILL_NAME}-v${VERSION}.zip\"\nTMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP_DIR\"' EXIT\n\nRELEASE_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\"\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\"\ncurl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\"\n\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP_DIR/signing-public.pem\" -outform DER | shasum -a 256 | awk '{print $1}')\"\nif [ \"$ACTUAL_PUBKEY_SHA256\" != \"$RELEASE_PUBKEY_SHA256\" ]; then\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\nfi\n\nopenssl base64 -d -A -in \"$TMP_DIR/checksums.sig\" -out \"$TMP_DIR/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin \\\n  -inkey \"$TMP_DIR/signing-public.pem\" \\\n  -sigfile \"$TMP_DIR/checksums.sig.bin\" \\\n  -in \"$TMP_DIR/checksums.json\" >/dev/null\n\nhash_file() {\n  if command -v shasum >/dev/null 2>&1; then\n    shasum -a 256 \"$1\" | awk '{print $1}'\n  else\n    sha256sum \"$1\" | awk '{print $1}'\n  fi\n}\n\nverify_manifest_file() {\n  asset=\"$1\"\n  path=\"$2\"\n  expected=\"$(jq -r --arg asset \"$asset\" '.files[$asset].sha256 // empty' \"$TMP_DIR/checksums.json\")\"\n  if [ -z \"$expected\" ]; then\n    echo \"ERROR: checksums.json missing $asset\" >&2\n    exit 1\n  fi\n  actual=\"$(hash_file \"$path\")\"\n  if [ \"$actual\" != \"$expected\" ]; then\n    echo \"ERROR: checksum mismatch for $asset\" >&2\n    exit 1\n  fi\n}\n\nexpected_archive=\"$(jq -r '.archive.sha256 // empty' \"$TMP_DIR/checksums.json\")\"\nif [ -z \"$expected_archive\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\nactual_archive=\"$(hash_file \"$TMP_DIR/$ZIP_NAME\")\"\nif [ \"$actual_archive\" != \"$expected_archive\" ]; then\n  echo \"ERROR: archive checksum mismatch\" >&2\n  exit 1\nfi\n\nverify_manifest_file \"SKILL.md\" \"$TMP_DIR/SKILL.md\"\nverify_manifest_file \"skill.json\" \"$TMP_DIR/skill.json\"\n\necho \"Signed release manifest, archive, SKILL.md, and skill.json verified.\"\n```\n\nOnly install or extract the archive after this verification succeeds.\n\nFile v0.0.10:README.md\n\n# ClawSec for NanoClaw\n\nClawSec now supports NanoClaw, a containerized WhatsApp bot powered by Claude agents.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y\n```\n\n## What Changed\n\n### Advisory Feed Monitoring\n- **NVD CVE Pipeline**: Now monitors for NanoClaw-specific keywords\n  - \"NanoClaw\", \"WhatsApp-bot\", \"baileys\" (WhatsApp library)\n  - Container-related vulnerabilities\n- **Platform Targeting**: Advisories can specify `platforms: [\"nanoclaw\"]` for NanoClaw-specific issues\n\n### Keywords Added\nThe CVE monitoring now includes:\n- `NanoClaw` - Direct product name\n- `WhatsApp-bot` - Core functionality\n- `baileys` - WhatsApp client library dependency\n\n## Advisory Schema\n\nAdvisories now support optional `platforms` field:\n\n```json\n{\n  \"id\": \"CVE-2026-XXXXX\",\n  \"platforms\": [\"openclaw\", \"nanoclaw\"],\n  \"severity\": \"critical\",\n  \"type\": \"prompt_injection\",\n  \"affected\": [\"skill-name@1.0.0\"],\n  \"action\": \"Update to version 1.0.1\"\n}\n```\n\n**Platform values:**\n- `\"openclaw\"` - Affects OpenClaw/ClawdBot/MoltBot only\n- `\"nanoclaw\"` - Affects NanoClaw only\n- `[\"openclaw\", \"nanoclaw\"]` - Affects both platforms\n- (empty/missing) - Applies to all platforms (backward compatible)\n\n## ClawSec NanoClaw Skill\n\nClawSec provides a complete security skill for NanoClaw deployments:\n\n**Location**: `skills/clawsec-nanoclaw/`\n\n### Features\n\n- **9 MCP Tools** for agents to manage security:\n  - `clawsec_check_advisories` - Scan installed skills for vulnerabilities\n  - `clawsec_check_skill_safety` - Pre-installation safety checks\n  - `clawsec_list_advisories` - Browse advisory feed with filtering\n  - `clawsec_refresh_cache` - Request immediate advisory cache refresh\n  - `clawsec_verify_skill_package` - Verify Ed25519 signatures on skill packages\n  - `clawsec_check_integrity` - Check protected files for unauthorized changes\n  - `clawsec_approve_change` - Approve intentional file modifications\n  - `clawsec_integrity_status` - View file baseline status\n  - `clawsec_verify_audit` - Verify audit log hash chain\n\n- **Advisory Cache Service**: Host-managed feed fetching with signature validation\n- **Signature Verification**: Ed25519-signed feeds ensure integrity\n- **Exploitability Context**: Surfaces `exploitability_score` and rationale to reduce alert fatigue\n- **IPC Communication**: Container-safe host communication\n\n### Installation\n\n1. Copy the skill to your NanoClaw deployment:\n   ```bash\n   cp -r skills/clawsec-nanoclaw /path/to/nanoclaw/skills/\n   ```\n\n2. Follow the detailed guide at `skills/clawsec-nanoclaw/INSTALL.md`\n\n### Quick Integration\n\nThe skill integrates into three places:\n\n**1. MCP Tools** (container):\n```typescript\n// container/agent-runner/src/ipc-mcp-stdio.ts\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/advisory-tools.js';\n```\n\n**2. IPC Handlers** (host):\n```typescript\n// src/ipc.ts\nimport { handleAdvisoryIpc } from '../skills/clawsec-nanoclaw/host-services/ipc-handlers.js';\n```\n\n**3. Cache Service** (host):\n```typescript\n// src/index.ts\nimport { AdvisoryCacheManager } from '../skills/clawsec-nanoclaw/host-services/advisory-cache.js';\n```\n\n### Advisory Feed\n\nNanoClaw consumes the same feed as OpenClaw:\n```\nhttps://clawsec.prompt.security/advisories/feed.json\n```\n\nThe feed is Ed25519 signed and automatically fetched by the cache service.\n\n## Team Credits\n\nThis integration was developed by a team of 8 specialized agents coordinated to adapt ClawSec for NanoClaw:\n\n- **pioneer-repo-scout** - ClawSec architecture analysis\n- **pioneer-nanoclaw-scout** - NanoClaw architecture analysis\n- **architect** - Integration design and coordination\n- **advisory-specialist** - Advisory feed integration\n- **integrity-specialist** - File integrity design\n- **installer-specialist** - Signature verification implementation\n- **tester** - Test infrastructure and validation\n- **documenter** - Documentation\n\nTotal contribution: 3000+ lines of code and comprehensive design documents.\n\n## What's Included\n\nThe `clawsec-nanoclaw` skill provides:\n\n- **1,730 lines** of production-ready TypeScript code\n- **MCP Tools** (350 lines): Agent-facing vulnerability checking\n- **Advisory Cache** (492 lines): Automatic feed fetching and caching\n- **Signature Verification** (387 lines): Ed25519 signature validation\n- **Advisory Matching** (289 lines): Skill-to-vulnerability correlation\n- **IPC Handlers** (212 lines): Container-to-host communication\n- **Complete Documentation**: Installation guide, usage examples, troubleshooting\n\n## Future Enhancements\n\nPlanned features for future releases:\n- File integrity monitoring (soul-guardian adaptation for containers)\n- Real-time advisory alerts via WebSocket\n- WhatsApp-native security alert formatting\n- Behavioral analysis and anomaly detection\n- Custom/private advisory feed support\n\n## Documentation\n\n- [Skill Documentation](skills/clawsec-nanoclaw/SKILL.md) - Features and architecture\n- [Installation Guide](skills/clawsec-nanoclaw/INSTALL.md) - Detailed setup instructions\n- [ClawSec Main README](README.md) - Overall ClawSec documentation\n- [Security & Signing](../../wiki/security-signing-runbook.md) - Signature verification details\n\n## Support\n\n- **Issues**: https://github.com/prompt-security/clawsec/issues\n- **Security**: security@prompt.security\n- NanoClaw Repository: https://github.com/qwibitai/nanoclaw\n\nFile v0.0.10:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-nanoclaw\",\n  \"version\": \"0.0.10\",\n  \"publishedAt\": 1782202947400\n}\n\nFile v0.0.10:CHANGELOG.md\n\n# Changelog\n\n## [0.0.10] - 2026-06-23\n\n### Changed\n\n- Re-released skill metadata to run through the corrected normal tag publish pipeline without runtime changes.\n\n## [0.0.9] - 2026-06-22\n\n### Changed\n\n- Re-released skill metadata to publish through the updated ClawHub pipeline without runtime changes.\n\n## [0.0.8] - 2026-06-10\n\n### Changed\n\n- Re-released skill package with updated marketplace grouping and signed release trust artifacts for Vercel-compatible skill installation.\n\n## [0.0.7] - 2026-06-07\n\n### Security\n- Added comparator range support for NanoClaw advisory matching and fail-closed handling for malformed affected specifiers.\n- Added strict integrity IPC request ID validation and result path containment before host-side result writes.\n\n## [0.0.6] - 2026-05-24\n\n### Changed\n- Documented that NanoClaw consumes the consolidated signed advisory feed containing NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records.\n- Added advisory metadata typing for GHSA lifecycle fields used by the consolidated feed.\n\n## [0.0.5] - 2026-05-14\n\n### Security\n- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.\n\nAll notable changes to the ClawSec NanoClaw compatibility skill will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.4] - 2026-04-16\n\n### Changed\n\n- Moved signature-related local file reads into `lib/local_file_io.ts` and kept network fetch logic isolated in `lib/signatures.ts`.\n\n### Security\n\n- Reduced static false-positive exfiltration signals by separating local file I/O and remote fetch code paths.\n\n## [0.0.3] - 2026-03-09\n\n### Security\n\n- Removed runtime public-key override from host-side package signature verification; verification now always uses the pinned ClawSec key.\n- Removed unsigned-package override path in host-side verification flow.\n- Added strict package/signature path policy for signature verification (`/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`) with absolute-path, extension, symlink, and realpath boundary checks.\n- Added policy-bound path enforcement for integrity approvals: approvals now require normalized paths that are explicitly present in non-ignored integrity policy targets.\n\n### Changed\n\n- Updated MCP signature verification tool docs and behavior to align with bounded path policy and pinned-key-only verification.\n- Added regression tests for signature-verification and integrity-approval hardening invariants.\n\n## [0.0.2] - 2026-02-28\n\n### Added\n\n- Exploitability-aware advisory output in NanoClaw MCP tools (`exploitability_score`, `exploitability_rationale`).\n- Exploitability filtering (`exploitabilityScore`) for `clawsec_list_advisories`.\n\n### Changed\n\n- Updated NanoClaw advisory sorting and pre-install safety recommendation logic to prioritize exploitability context.\n- Updated NanoClaw integration docs to match current host/container integration points (`src/ipc.ts`, `src/index.ts`) and current cache schema.\n- Removed duplicate exploitability normalization logic from MCP advisory tools and now reuse `normalizeExploitabilityScore` from `lib/risk.ts`.\n- Reused `matchesAffectedSpecifier` from `lib/advisories.ts` in MCP advisory tools to keep skill/version matching logic centralized and consistent.\n\nFile v0.0.10:docs/INTEGRITY.md\n\n# File Integrity Monitoring for NanoClaw\n\nClawSec's file integrity monitoring protects critical NanoClaw configuration files from unauthorized modification.\n\n## What It Does\n\n**Protects Critical Files:**\n- `registered_groups.json` - Prevents unauthorized group access\n- `CLAUDE.md` files - Protects agent instructions\n- Container/host code - Alerts on unexpected changes\n\n**How It Works:**\n1. **Baseline**: Stores SHA-256 hashes of approved file states\n2. **Monitoring**: Periodically checks files for changes (drift)\n3. **Restore**: Automatically reverts critical files to approved versions\n4. **Audit**: Maintains tamper-evident log of all operations\n\n## Quick Start\n\n### Step 1: Verify Installation\n\nCheck that integrity monitoring is available:\n\n```bash\n# From container\nls /workspace/project/skills/clawsec-nanoclaw/guardian/\n# Should show: policy.json, integrity-monitor.ts\n```\n\n### Step 2: Initialize Baselines\n\nThe first time integrity monitoring runs, it creates baselines automatically:\n\n```typescript\n// Agent calls this (happens automatically on first integrity check)\nawait tools.clawsec_check_integrity();\n```\n\nThis creates:\n```\n/workspace/project/data/soul-guardian/\n├── baselines.json       # SHA-256 hashes\n├── approved/            # File snapshots\n│   ├── registered_groups.json\n│   └── CLAUDE.md\n├── patches/             # Diffs (empty initially)\n├── quarantine/          # Tampered files (empty initially)\n└── audit.jsonl          # Event log\n```\n\n### Step 3: Enable Scheduled Monitoring\n\nAdd to main group's scheduled tasks:\n\n```typescript\nschedule_task({\n  prompt: `\n    Check file integrity with clawsec_check_integrity.\n    If drift detected and files restored, send WhatsApp message:\n    \"⚠️ SECURITY ALERT\n\n    Unauthorized changes detected and automatically reverted:\n    [list files that were restored]\n\n    Review details: /workspace/project/data/soul-guardian/patches/\"\n  `,\n  schedule_type: 'cron',\n  schedule_value: '*/30 * * * *',  // Every 30 minutes\n  context_mode: 'isolated'\n});\n```\n\nThat's it! Integrity monitoring is now active.\n\n## MCP Tools Reference\n\n### 1. `clawsec_check_integrity`\n\nCheck all protected files for unauthorized changes.\n\n**Parameters:**\n- `mode` (optional): `'check'` (default) or `'status'`\n  - `check`: Detect drift and auto-restore\n  - `status`: View baselines only (no drift detection)\n- `autoRestore` (optional): `true` (default) or `false`\n  - If `false`, drift is detected but not auto-fixed\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"timestamp\": \"2026-02-25T12:00:00Z\",\n  \"drift_detected\": false,\n  \"files\": [\n    {\n      \"path\": \"/workspace/project/data/registered_groups.json\",\n      \"status\": \"ok\",\n      \"mode\": \"restore\",\n      \"expected_sha\": \"abc123...\",\n      \"found_sha\": \"abc123...\"\n    }\n  ],\n  \"summary\": {\n    \"total\": 3,\n    \"ok\": 3,\n    \"drifted\": 0,\n    \"restored\": 0,\n    \"alerted\": 0,\n    \"errors\": 0\n  }\n}\n```\n\n**Example:**\n```typescript\nconst result = await tools.clawsec_check_integrity();\n\nif (result.drift_detected) {\n  console.log('⚠️ Drift detected!');\n  for (const file of result.files) {\n    if (file.status === 'restored') {\n      console.log(`✅ Restored: ${file.path}`);\n      console.log(`  Diff: ${file.patch_path}`);\n    } else if (file.status === 'drifted') {\n      console.log(`⚠️ Changed: ${file.path} (alert only)`);\n    }\n  }\n}\n```\n\n### 2. `clawsec_approve_change`\n\nApprove an intentional file modification as the new baseline.\n\n**When to use:**\n- After legitimately updating CLAUDE.md\n- After adding/removing groups in registered_groups.json\n- After any intentional change to protected files\n\n**Parameters:**\n- `path` (required): Absolute path to file\n- `note` (optional): Explanation for audit log\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"path\": \"/workspace/group/CLAUDE.md\",\n  \"approved_at\": \"2026-02-25T12:00:00Z\",\n  \"approved_by\": \"agent\",\n  \"note\": \"Added new skill instructions\"\n}\n```\n\n**Example:**\n```typescript\n// After editing CLAUDE.md\nawait tools.clawsec_approve_change({\n  path: '/workspace/group/CLAUDE.md',\n  note: 'Updated agent instructions for new skill'\n});\n\nconsole.log('✅ Change approved - new baseline created');\n```\n\n### 3. `clawsec_integrity_status`\n\nView current baseline status without checking for drift.\n\n**Parameters:**\n- `path` (optional): Specific file, or all if omitted\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"baseline_age\": \"2026-02-25T10:00:00Z\",\n  \"files\": [\n    {\n      \"path\": \"/workspace/project/data/registered_groups.json\",\n      \"mode\": \"restore\",\n      \"priority\": \"critical\",\n      \"has_baseline\": true,\n      \"baseline_sha\": \"abc123...\",\n      \"approved_at\": \"2026-02-25T10:00:00Z\",\n      \"snapshot_exists\": true\n    }\n  ]\n}\n```\n\n**Example:**\n```typescript\nconst status = await tools.clawsec_integrity_status();\n\nconsole.log('Protected files:');\nfor (const file of status.files) {\n  console.log(`- ${file.path} (${file.mode}, ${file.priority})`);\n  console.log(`  Last approved: ${file.approved_at}`);\n}\n```\n\n### 4. `clawsec_verify_audit`\n\nVerify audit log hash chain integrity.\n\n**No parameters.**\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"valid\": true,\n  \"entries\": 42,\n  \"errors\": []\n}\n```\n\n**Example:**\n```typescript\nconst verification = await tools.clawsec_verify_audit();\n\nif (!verification.valid) {\n  console.log('🚨 CRITICAL: Audit log has been tampered with!');\n  console.log('Errors:', verification.errors);\n} else {\n  console.log(`✅ Audit log verified (${verification.entries} entries)`);\n}\n```\n\n## Protected Files Policy\n\n### Critical Priority (Auto-Restore)\n\n**`/workspace/project/data/registered_groups.json`**\n- **Risk**: Tampering grants unauthorized group access\n- **Action**: Immediate auto-restore + alert\n\n**`/workspace/group/CLAUDE.md`**\n- **Risk**: Modifies agent behavior\n- **Action**: Immediate auto-restore + alert\n\n**`/workspace/project/groups/global/CLAUDE.md`**\n- **Risk**: Affects all groups\n- **Action**: Immediate auto-restore + alert\n\n### Medium Priority (Alert Only)\n\n**Container code** (`/workspace/project/container/**/*.ts`)\n- **Risk**: Unexpected code changes\n- **Action**: Alert for review (no auto-restore)\n\n**Host code** (`/workspace/project/host/**/*.ts`)\n- **Risk**: Unexpected code changes\n- **Action**: Alert for review (no auto-restore)\n\n### Ignored\n\n**IPC files** (`/workspace/ipc/**/*`)\n- Changes are expected and frequent\n\n**Conversations** (`/workspace/group/conversations/**/*`)\n- Changes are expected and frequent\n\n## Workflow Examples\n\n### Scenario 1: Scheduled Monitoring\n\n**Setup:**\n```typescript\nschedule_task({\n  prompt: 'Run clawsec_check_integrity and alert on drift',\n  schedule_type: 'cron',\n  schedule_value: '*/30 * * * *'\n});\n```\n\n**What happens:**\n1. Every 30 minutes, agent checks integrity\n2. If drift detected in critical files:\n   - Files auto-restored to baseline\n   - Tampered versions quarantined\n   - Diff patch generated\n   - User alerted via WhatsApp\n3. If drift in non-critical files:\n   - Alert only, no auto-restore\n\n### Scenario 2: Updating Agent Instructions\n\n**Workflow:**\n```typescript\n// 1. Edit CLAUDE.md\nfs.writeFileSync('/workspace/group/CLAUDE.md', newInstructions);\n\n// 2. Test changes\n// ... verify agent behaves correctly ...\n\n// 3. Approve changes\nawait tools.clawsec_approve_change({\n  path: '/workspace/group/CLAUDE.md',\n  note: 'Added instructions for new weather skill'\n});\n\n// 4. Future integrity checks will use this new baseline\n```\n\n### Scenario 3: Adding a New Group\n\n**Workflow:**\n```typescript\n// 1. Add group to registered_groups.json\nconst groups = JSON.parse(fs.readFileSync('/workspace/project/data/registered_groups.json'));\ngroups['new-jid'] = { name: 'Family', folder: 'family', trigger: '@Andy' };\nfs.writeFileSync('/workspace/project/data/registered_groups.json', JSON.stringify(groups, null, 2));\n\n// 2. Approve the change\nawait tools.clawsec_approve_change({\n  path: '/workspace/project/data/registered_groups.json',\n  note: 'Added family group'\n});\n```\n\n### Scenario 4: Investigating Drift\n\n**When drift is detected:**\n```typescript\nconst result = await tools.clawsec_check_integrity();\n\nif (result.drift_detected) {\n  for (const file of result.files) {\n    if (file.status === 'restored') {\n      // Critical file was auto-restored\n      console.log(`🔧 Auto-restored: ${file.path}`);\n      console.log(`📄 Diff: ${file.patch_path}`);\n      console.log(`📦 Quarantine: ${file.quarantine_path}`);\n\n      // Review the diff\n      const diff = fs.readFileSync(file.patch_path, 'utf-8');\n      console.log('Changes that were reverted:');\n      console.log(diff);\n    }\n  }\n}\n```\n\n## Security Model\n\n### Threat Model\n\n**Protects Against:**\n- Unauthorized file modifications\n- Group hijacking (via registered_groups.json tampering)\n- Agent instruction poisoning (via CLAUDE.md changes)\n- Accidental file corruption\n\n**Does NOT Protect Against:**\n- Attacker with full host access (can modify baselines)\n- Simultaneous baseline + file modification\n- Malicious scheduled tasks that approve their own changes\n\n### Baseline Storage\n\n**Location:** `/workspace/project/data/soul-guardian/`\n\n**Access Control:**\n- Baselines written only by host process\n- Containers access via IPC only\n- No container can modify its own baselines\n\n**Integrity:**\n- SHA-256 hashes (industry standard)\n- Hash-chained audit log (tamper-evident)\n- Atomic file operations (safe restores)\n\n### Audit Log\n\n**Format:** JSONL with hash chaining\n\n**Each entry includes:**\n```json\n{\n  \"ts\": \"2026-02-25T12:00:00Z\",\n  \"event\": \"drift\",\n  \"actor\": \"agent\",\n  \"path\": \"/workspace/group/CLAUDE.md\",\n  \"expected_sha\": \"abc123...\",\n  \"found_sha\": \"def456...\",\n  \"chain\": {\n    \"prev\": \"previous_entry_hash\",\n    \"hash\": \"this_entry_hash\"\n  }\n}\n```\n\n**Chain calculation:**\n```\nhash = SHA-256(prev_hash + '\\n' + canonical_json(entry_without_chain))\n```\n\nThis makes tampering detectable: changing any entry breaks the chain.\n\n## Troubleshooting\n\n### Integrity Check Fails\n\n**Symptom:** `clawsec_check_integrity` returns `success: false`\n\n**Causes:**\n1. IntegrityService not initialized\n2. Policy file missing\n3. Baselines corrupted\n\n**Solution:**\n```bash\n# Check service status\nls /workspace/project/data/soul-guardian/\n\n# If missing, reinitialize\nrm -rf /workspace/project/data/soul-guardian/\n# Next integrity check will recreate baselines\n```\n\n### False Positives (Legitimate Changes Flagged)\n\n**Symptom:** File keeps getting restored even though changes are legitimate\n\n**Cause:** Baseline not updated after intentional changes\n\n**Solution:**\n```typescript\nawait tools.clawsec_approve_change({\n  path: '/path/to/file',\n  note: 'Legitimate change'\n});\n```\n\n### Audit Chain Broken\n\n**Symptom:** `clawsec_verify_audit` returns `valid: false`\n\n**Causes:**\n1. Audit log manually edited\n2. Filesystem corruption\n3. Security breach\n\n**Solution:**\n```typescript\nconst verification = await tools.clawsec_verify_audit();\nconsole.log('Errors:', verification.errors);\n\n// If corruption, backup and reset\ncp /workspace/project/data/soul-guardian/audit.jsonl /tmp/audit-backup.jsonl\nrm /workspace/project/data/soul-guardian/audit.jsonl\n// Audit log will restart on next operation\n```\n\n### High Disk Usage\n\n**Symptom:** `/workspace/project/data/soul-guardian/` grows large\n\n**Causes:**\n- Many drift events generate patches\n- Quarantine files accumulate\n\n**Solution:**\n```bash\n# Clean old patches (older than 30 days)\nfind /workspace/project/data/soul-guardian/patches/ -mtime +30 -delete\n\n# Clean quarantine (after review)\nrm /workspace/project/data/soul-guardian/quarantine/*\n```\n\n## Performance\n\n**Overhead:**\n- Baseline check: ~10ms per file\n- SHA-256 computation: ~1ms per KB\n- Restore operation: ~20ms per file\n\n**Typical deployment:**\n- 3-5 protected files\n- 30-minute check interval\n- < 0.1% CPU usage\n- < 5MB disk usage\n\n## Advanced Topics\n\n### Custom Policy\n\nWhile the default policy is pinned by the skill, you can fork it:\n\n```bash\ncp /workspace/project/skills/clawsec-nanoclaw/guardian/policy.json /workspace/project/data/custom-policy.json\n```\n\nEdit and reinitialize:\n```typescript\n// Update IntegrityMonitor initialization\nnew IntegrityMonitor({\n  policyPath: '/workspace/project/data/custom-policy.json',\n  stateDir: '/workspace/project/data/soul-guardian'\n});\n```\n\n### Manual Baseline Export\n\n```bash\n# Export current baselines\ncp /workspace/project/data/soul-guardian/baselines.json /tmp/baselines-backup.json\n\n# Export approved snapshots\ntar -czf /tmp/approved-snapshots.tar.gz /workspace/project/data/soul-guardian/approved/\n```\n\n### Baseline Import (Disaster Recovery)\n\n```bash\n# Restore baselines\ncp /tmp/baselines-backup.json /workspace/project/data/soul-guardian/baselines.json\n\n# Restore snapshots\ntar -xzf /tmp/approved-snapshots.tar.gz -C /workspace/project/data/soul-guardian/\n```\n\n## FAQ\n\n**Q: Can I disable auto-restore for testing?**\n\nA: Yes, use `autoRestore: false`:\n```typescript\nawait tools.clawsec_check_integrity({ autoRestore: false });\n```\n\n**Q: How do I protect additional files?**\n\nA: Edit `policy.json` and add targets:\n```json\n{\n  \"path\": \"/workspace/group/my-config.json\",\n  \"mode\": \"restore\",\n  \"priority\": \"high\",\n  \"description\": \"My custom config\"\n}\n```\n\n**Q: What happens if both baseline and file are modified?**\n\nA: The most recent baseline wins. Always approve legitimate changes immediately.\n\n**Q: Can I run integrity checks on-demand?**\n\nA: Yes, just call `clawsec_check_integrity` from any agent.\n\n**Q: Is the audit log encrypted?**\n\nA: No, but it's hash-chained for tamper detection. Encryption can be added in Phase 3.\n\n## Support\n\n- **Documentation**: https://clawsec.prompt.security/\n- **Issues**: https://github.com/prompt-security/clawsec/issues\n- **Security Reports**: security@prompt.security\n\n---\n\n**Ready to protect your NanoClaw deployment? Start with the [Quick Start](#quick-start) guide above.**\n\nFile v0.0.10:docs/SKILL_SIGNING.md\n\n# Skill Package Signing and Verification\n\nThis document explains how ClawSec signs skill packages and how NanoClaw agents verify signatures before installation.\n\n---\n\n## Table of Contents\n\n1. [Overview](#overview)\n2. [For Skill Publishers: How to Sign Packages](#for-skill-publishers-how-to-sign-packages)\n3. [For NanoClaw Agents: How to Verify Signatures](#for-nanoclaw-agents-how-to-verify-signatures)\n4. [Security Properties](#security-properties)\n5. [Key Management](#key-management)\n6. [Troubleshooting](#troubleshooting)\n\n---\n\n## Overview\n\nSkill signature verification prevents **supply chain attacks** by ensuring skill packages haven't been tampered with during distribution. ClawSec uses **Ed25519 digital signatures** to sign skill packages, and NanoClaw agents verify these signatures before installation.\n\n### Why Signature Verification?\n\nWithout signature verification, an attacker could:\n- **Replace** a legitimate skill package with a malicious one during download\n- **Modify** package contents to inject backdoors or steal data\n- **Distribute** trojan skills that appear legitimate but contain malware\n\nSignature verification ensures:\n- ✅ **Authenticity**: Package comes from ClawSec (or trusted publisher)\n- ✅ **Integrity**: Package hasn't been modified since signing\n- ✅ **Non-repudiation**: Signer can't deny signing the package\n\n---\n\n## For Skill Publishers: How to Sign Packages\n\n### Prerequisites\n\n- OpenSSL 1.1.1+ (for Ed25519 support)\n- Private Ed25519 signing key (generate once, keep secure)\n- Skill package ready for distribution\n\n### Step 1: Generate Ed25519 Keypair (One-Time Setup)\n\n```bash\n# Generate private key (KEEP THIS SECRET!)\nopenssl genpkey -algorithm ED25519 -out clawsec-signing-private.pem\n\n# Extract public key (share this with users)\nopenssl pkey -in clawsec-signing-private.pem -pubout -out clawsec-signing-public.pem\n\n# Secure the private key\nchmod 600 clawsec-signing-private.pem\n```\n\n**⚠️ CRITICAL**: Never commit the private key to version control! Store it securely:\n- Local machine: `~/.ssh/clawsec-signing-private.pem` with `chmod 600`\n- CI/CD: GitHub Secrets, AWS Secrets Manager, or similar\n- Team: 1Password, Vault, or hardware security module (HSM)\n\n### Step 2: Package Your Skill\n\n```bash\n# Create skill package (tarball or zip)\ntar -czf my-skill-1.0.0.tar.gz -C skills/my-skill .\n\n# Or as a zip file\nzip -r my-skill-1.0.0.zip skills/my-skill/\n```\n\n### Step 3: Sign the Package\n\n```bash\n# Create detached Ed25519 signature\nopenssl dgst -sha512 -sign clawsec-signing-private.pem \\\n  -out my-skill-1.0.0.tar.gz.sig \\\n  my-skill-1.0.0.tar.gz\n\n# Verify the signature was created\nls -lh my-skill-1.0.0.tar.gz.sig\n# Should show a ~64-byte file\n```\n\n**Signature Format**: Detached Ed25519 signature, base64-encoded, stored in `.sig` file.\n\n### Step 4: Distribute Package + Signature\n\nDistribute **both** files together:\n- `my-skill-1.0.0.tar.gz` (the skill package)\n- `my-skill-1.0.0.tar.gz.sig` (the signature)\n\nUsers will verify the signature against your public key before installation.\n\n### Step 5: Publish Public Key\n\nShare your public key with users via:\n- **Pinned in repository**: Commit `clawsec-signing-public.pem` to your repo\n- **Website**: Host at `https://yoursite.com/clawsec-signing-public.pem`\n- **DNS TXT record**: Publish as base64-encoded TXT record\n- **Skill metadata**: Embed in `skill.json`\n\n---\n\n## For NanoClaw Agents: How to Verify Signatures\n\n### Quick Start\n\n```typescript\n// Verify a downloaded skill package before installation\nconst verification = await tools.clawsec_verify_skill_package({\n  packagePath: '/tmp/my-skill-1.0.0.tar.gz'\n  // signaturePath auto-detected as /tmp/my-skill-1.0.0.tar.gz.sig\n});\n\nconst result = JSON.parse(verification.content[0].text);\n\nif (!result.valid) {\n  console.log('⚠️ SIGNATURE VERIFICATION FAILED!');\n  console.log(`Reason: ${result.reason || result.error}`);\n  console.log('DO NOT install this package.');\n  return;\n}\n\nconsole.log(`✓ Signature valid (signer: ${result.signer})`);\nconsole.log(`Package hash: ${result.packageInfo.sha256}`);\nconsole.log('Safe to proceed with installation.');\n```\n\n### MCP Tool: `clawsec_verify_skill_package`\n\n**Parameters:**\n- `packagePath` (required): Absolute path to skill package (`.tar.gz`, `.tar`, `.tgz`, or `.zip`)\n- `signaturePath` (optional): Path to signature file (auto-detects `.sig` if omitted)\n\nPath policy:\n- Files must be under one of: `/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`\n- Symlinks are rejected\n- Signatures must use `.sig`\n\n**Returns:**\n```typescript\n{\n  success: boolean,           // Operation completed without errors\n  valid: boolean,             // Signature is cryptographically valid\n  recommendation: string,     // \"install\" | \"block\" | \"review\"\n  signer: string,             // \"clawsec\"\n  algorithm: \"Ed25519\",       // Signature algorithm\n  verifiedAt: string,         // ISO timestamp\n  packageInfo: {\n    size: number,             // Package file size in bytes\n    sha256: string            // SHA-256 hash of package\n  },\n  error?: string              // Error message if failed\n}\n```\n\n### Usage Patterns\n\n#### Pattern 1: Basic Pre-Installation Check\n\n```typescript\nasync function installSkill(packagePath: string) {\n  // Verify signature first\n  const verification = await tools.clawsec_verify_skill_package({ packagePath });\n  const result = JSON.parse(verification.content[0].text);\n\n  if (result.recommendation === 'block') {\n    throw new Error(`Cannot install: ${result.reason || result.error}`);\n  }\n\n  // Signature valid - proceed with extraction\n  extractPackage(packagePath, '/workspace/project/skills/');\n}\n```\n\n#### Pattern 2: Combined Security Checks\n\n```typescript\nasync function installSkillSafely(packagePath: string, skillName: string) {\n  // Step 1: Verify signature\n  const sigVerify = await tools.clawsec_verify_skill_package({ packagePath });\n  const sigResult = JSON.parse(sigVerify.content[0].text);\n\n  if (!sigResult.valid) {\n    throw new Error(`Signature invalid: ${sigResult.reason}`);\n  }\n\n  // Step 2: Check advisories\n  const advisory = await tools.clawsec_check_skill_safety({ skillName });\n  const advResult = JSON.parse(advisory.content[0].text);\n\n  if (!advResult.safe) {\n    throw new Error(`Known vulnerabilities: ${advResult.advisories.map(a => a.id).join(', ')}`);\n  }\n\n  // Both checks passed - safe to install\n  extractPackage(packagePath, '/workspace/project/skills/');\n  console.log(`✓ Installed ${skillName} (verified + no advisories)`);\n}\n```\n\n#### Pattern 3: Download and Verify Workflow\n\n```typescript\nasync function downloadAndInstallSkill(url: string) {\n  const packagePath = `/tmp/${Date.now()}-skill.tar.gz`;\n  const signaturePath = `${packagePath}.sig`;\n\n  // Download package\n  await fetch(url).then(r => r.arrayBuffer()).then(buf => {\n    fs.writeFileSync(packagePath, Buffer.from(buf));\n  });\n\n  // Download signature\n  await fetch(`${url}.sig`).then(r => r.text()).then(sig => {\n    fs.writeFileSync(signaturePath, sig);\n  });\n\n  // Verify before installation\n  const verification = await tools.clawsec_verify_skill_package({\n    packagePath,\n    signaturePath\n  });\n\n  const result = JSON.parse(verification.content[0].text);\n\n  if (!result.valid) {\n    fs.unlinkSync(packagePath);     // Delete tampered file\n    fs.unlinkSync(signaturePath);\n    throw new Error('Signature verification failed');\n  }\n\n  // Install verified package\n  extractPackage(packagePath, '/workspace/project/skills/');\n\n  // Cleanup\n  fs.unlinkSync(packagePath);\n  fs.unlinkSync(signaturePath);\n}\n```\n\n### Error Handling\n\n```typescript\nconst verification = await tools.clawsec_verify_skill_package({ packagePath });\nconst result = JSON.parse(verification.content[0].text);\n\n// Check result.success first (operation completed)\nif (!result.success) {\n  console.error('Verification operation failed:', result.error);\n  // Reasons: file not found, service unavailable, timeout\n  return;\n}\n\n// Then check result.valid (signature cryptographically valid)\nif (!result.valid) {\n  console.error('Invalid signature:', result.reason);\n  // Reasons: signature mismatch, tampered package, invalid format\n  return;\n}\n\n// Finally check recommendation\nswitch (result.recommendation) {\n  case 'install':\n    console.log('✓ Safe to install');\n    break;\n  case 'block':\n    console.error('⛔ Installation blocked');\n    break;\n  case 'review':\n    console.warn('⚠️ Manual review recommended');\n    break;\n}\n```\n\n---\n\n## Security Properties\n\n### What Signature Verification Prevents\n\n✅ **Prevents:**\n- **Tampering**: Detecting if package contents were modified after signing\n- **MITM attacks**: Detecting if package was swapped during download\n- **Malicious mirrors**: Ensuring package comes from trusted source\n- **Accidental corruption**: Detecting file corruption during transfer\n\n### What Signature Verification Does NOT Prevent\n\n❌ **Does Not Prevent:**\n- **Malicious signed packages**: If the publisher's key is compromised\n- **Zero-day vulnerabilities**: Bugs unknown to the publisher\n- **Social engineering**: Convincing users to trust malicious publishers\n- **Time-of-check-to-time-of-use**: Package modified after verification\n\n**Defense in Depth**: Combine signature verification with:\n1. **Advisory checking** (`clawsec_check_skill_safety`)\n2. **Code review** (manual inspection of skill code)\n3. **Sandboxing** (run skills in isolated containers)\n4. **Monitoring** (detect suspicious behavior at runtime)\n\n### Trust Model\n\nSignature verification relies on **trust in the public key**:\n\n```\n┌─────────────────────────────────────────────────┐\n│ You trust ClawSec's public key                  │\n│          ↓                                      │\n│ ClawSec signs package with private key          │\n│          ↓                                      │\n│ You verify signature with ClawSec's public key  │\n│          ↓                                      │\n│ Signature valid → Package is authentic         │\n└─────────────────────────────────────────────────┘\n```\n\n**Key Question**: How do you establish trust in the public key?\n- **Pinned in repository**: Public key committed to ClawSec repo (trust GitHub)\n- **HTTPS website**: Download from `https://clawsec.prompt.security/` (trust TLS/CA)\n- **Out-of-band verification**: Compare key fingerprint via phone, Signal, etc.\n- **Web of Trust**: Multiple trusted sources publish the same key\n\n---\n\n## Key Management\n\n### ClawSec's Pinned Public Key\n\n**Location**: `/workspace/project/skills/clawsec-nanoclaw/advisories/feed-signing-public.pem`\n\nThis is the **same key** used for advisory feed verification, providing a single trust anchor for all ClawSec security operations.\n\n**Key Fingerprint** (for manual verification):\n```bash\n# Compute fingerprint of pinned key\nopenssl pkey -pubin -in feed-signing-public.pem -outform DER | \\\n  openssl dgst -sha256 -binary | base64\n# Expected: <will be filled in after key generation>\n```\n\n### Public Key Policy\n\nThe verifier always uses the pinned ClawSec public key from this skill package.\nRuntime public-key overrides are intentionally not supported.\n\n### Key Rotation\n\nIf ClawSec's signing key is compromised or needs rotation:\n\n1. **Generate new keypair** (keep private key secure)\n2. **Sign all packages** with new key\n3. **Publish new public key** to all distribution channels\n4. **Update pinned key** in `/workspace/project/skills/clawsec-nanoclaw/advisories/`\n5. **Deprecate old key** after transition period (e.g., 90 days)\n\nDuring transition, support **dual signatures**:\n- `package.tar.gz.sig` (old key)\n- `package.tar.gz.sig2` (new key)\n\nAgents can verify with either key during the overlap period.\n\n---\n\n## Troubleshooting\n\n### Error: \"Signature file not found\"\n\n**Cause**: Missing `.sig` file or incorrect path.\n\n**Solution**:\n```bash\n# Check if signature exists\nls -l /tmp/skill.tar.gz.sig\n\n# If missing, download signature\ncurl -o /tmp/skill.tar.gz.sig https://example.com/skill.tar.gz.sig\n\n# Or specify explicit path\nclawsec_verify_skill_package({\n  packagePath: '/tmp/skill.tar.gz',\n  signaturePath: '/tmp/custom-signature.sig'\n})\n```\n\n### Error: \"Signature verification failed\"\n\n**Cause**: Package was tampered with, or signature doesn't match package.\n\n**Solution**:\n```bash\n# Re-download package and signature\ncurl -o /tmp/skill.tar.gz https://example.com/skill.tar.gz\ncurl -o /tmp/skill.tar.gz.sig https://example.com/skill.tar.gz.sig\n\n# Verify manually with OpenSSL\nopenssl dgst -sha512 -verify clawsec-signing-public.pem \\\n  -signature /tmp/skill.tar.gz.sig /tmp/skill.tar.gz\n# Should output: \"Verified OK\"\n```\n\n### Error: \"Invalid PEM format\"\n\n**Cause**: Public key file is corrupted or not in PEM format.\n\n**Solution**:\n```bash\n# Check public key format\nhead -1 /path/to/public-key.pem\n# Should output: \"-----BEGIN PUBLIC KEY-----\"\n\n# Re-download public key\ncurl -o clawsec-signing-public.pem \\\n  https://clawsec.prompt.security/clawsec-signing-public.pem\n```\n\n### Error: \"Package file not found\"\n\n**Cause**: Incorrect path or file doesn't exist.\n\n**Solution**:\n```bash\n# Use absolute paths (required)\nclawsec_verify_skill_package({\n  packagePath: '/tmp/skill.tar.gz'  // ✓ Absolute\n  // packagePath: './skill.tar.gz' // ✗ Relative (won't work)\n})\n\n# Verify file exists\nstat /tmp/skill.tar.gz\n```\n\n### Verification Times Out (>5s)\n\n**Cause**: Large package (>50MB) or slow disk I/O.\n\n**Solution**:\n```bash\n# Check package size\nls -lh /tmp/skill.tar.gz\n\n# For very large packages, verification can take time\n# Consider splitting into smaller skill modules\n```\n\n---\n\n## Appendix: Signature File Format\n\nClawSec uses **Ed25519 detached signatures** in raw binary format, base64-encoded.\n\n**File Structure**:\n```\nmy-skill-1.0.0.tar.gz.sig:\n  Line 1: base64-encoded signature (88 characters)\n```\n\n**Example**:\n```\nMEQCIDxyz...ABC123==\n```\n\n**Properties**:\n- Algorithm: Ed25519 (EdDSA with Curve25519)\n- Signature size: 64 bytes (88 characters base64)\n- Hash function: SHA-512 (internal to Ed25519)\n- Format: Raw binary, base64-encoded\n\n**Verification Algorithm**:\n1. Decode base64 signature → 64-byte binary\n2. Hash package with SHA-512\n3. Verify Ed25519 signature(hash, publicKey) → boolean\n\n---\n\n## References\n\n- [Ed25519 Specification (RFC 8032)](https://tools.ietf.org/html/rfc8032)\n- [OpenSSL Ed25519 Documentation](https://www.openssl.org/docs/man3.0/man7/Ed25519.html)\n- [ClawSec Security Architecture](https://clawsec.prompt.security/docs/architecture)\n- [Supply Chain Attack Prevention](https://owasp.org/www-community/attacks/Supply_Chain_Attack)\n\n---\n\n**Document Version**: 1.0.0\n**Last Updated**: 2026-02-25\n**Maintainer**: ClawSec Security Team\n\nFile v0.0.10:INSTALL.md\n\n# ClawSec for NanoClaw - Installation Guide\n\nThis guide shows how to add ClawSec security monitoring to your NanoClaw deployment.\n\n## Overview\n\nClawSec provides security advisory monitoring for NanoClaw through:\n- **MCP Tools**: Agents can check for vulnerabilities via `clawsec_check_advisories`\n- **Advisory Feed**: Automatic monitoring of https://clawsec.prompt.security/advisories/feed.json\n- **Signature Verification**: Ed25519-signed feeds ensure integrity\n- **Exploitability Context**: Advisories include exploitability score and rationale for triage\n\n## Prerequisites\n\n- NanoClaw >= 0.1.0\n- Node.js >= 18.0.0\n- Write access to NanoClaw installation directory\n\n## Installation Steps\n\n### 1. Copy Skill Files\n\nCopy the `clawsec-nanoclaw` skill directory to your NanoClaw installation:\n\n```bash\n# From the ClawSec repository\ncp -r skills/clawsec-nanoclaw /path/to/your/nanoclaw/skills/\n```\n\n### 2. Integrate MCP Tools\n\nAdd the ClawSec MCP tools to your NanoClaw container agent runner.\n\n**File**: `container/agent-runner/src/ipc-mcp-stdio.ts`\n\n```typescript\n// Add these imports at the top to register all ClawSec MCP tools:\n\n// Advisory tools: clawsec_check_advisories, clawsec_check_skill_safety,\n//                 clawsec_list_advisories, clawsec_refresh_cache\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/advisory-tools.js';\n\n// Signature verification: clawsec_verify_skill_package\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/signature-verification.js';\n\n// Integrity monitoring: clawsec_check_integrity, clawsec_approve_change,\n//                       clawsec_integrity_status, clawsec_verify_audit\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/integrity-tools.js';\n```\n\nEach file calls `server.tool()` directly to register its tools. The `server`,\n`writeIpcFile`, `TASKS_DIR`, and `groupFolder` variables must be available in\nthe scope where these files are imported (they are declared as ambient globals\nin each tool file).\n\n### 3. Integrate IPC Handlers\n\nAdd the host-side IPC handlers for ClawSec operations.\n\n**File**: `src/ipc.ts`\n\n```typescript\n// Add these imports at the top\nimport { handleAdvisoryIpc } from '../skills/clawsec-nanoclaw/host-services/ipc-handlers.js';\nimport { AdvisoryCacheManager } from '../skills/clawsec-nanoclaw/host-services/advisory-cache.js';\nimport { SkillSignatureVerifier } from '../skills/clawsec-nanoclaw/host-services/skill-signature-handler.js';\n\n// Initialize these once in host startup and pass through deps\nconst advisoryCacheManager = new AdvisoryCacheManager('/workspace/project/data', logger);\nconst signatureVerifier = new SkillSignatureVerifier();\n\n// In processTaskIpc switch:\ncase 'refresh_advisory_cache':\ncase 'verify_skill_signature':\n  await handleAdvisoryIpc(\n    data,\n    { advisoryCacheManager, signatureVerifier },\n    logger,\n    sourceGroup\n  );\n  break;\ndefault:\n  // existing task handling\n}\n```\n\n### 4. Start Advisory Cache Service\n\nAdd the advisory cache manager to your host services.\n\n**File**: `src/index.ts` (or your main entry point)\n\n```typescript\nimport { AdvisoryCacheManager } from '../skills/clawsec-nanoclaw/host-services/advisory-cache.js';\n\n// Start the service when your host process starts\nasync function main() {\n  // ... your existing initialization ...\n\n  // Initialize cache manager and prime it at startup\n  const advisoryCacheManager = new AdvisoryCacheManager('/workspace/project/data', logger);\n  await advisoryCacheManager.initialize();\n\n  // Recommended refresh cadence (6h)\n  setInterval(() => {\n    advisoryCacheManager.refresh().catch((error) => {\n      logger.error({ error }, 'Periodic advisory cache refresh failed');\n    });\n  }, 6 * 60 * 60 * 1000);\n\n  // ... rest of your startup ...\n}\n```\n\n### 5. Restart NanoClaw\n\nRestart your NanoClaw instance to load the new MCP tools and services:\n\n```bash\n# Stop NanoClaw\ndocker-compose down\n\n# Start with new configuration\ndocker-compose up -d\n```\n\n## Verification\n\nTest that ClawSec is working:\n\n### 1. Check MCP Tools Available\n\nFrom within a NanoClaw agent session, the following tools should be available:\n\n**Advisory Tools** (mcp-tools/advisory-tools.ts):\n- `clawsec_check_advisories` - Scan installed skills for vulnerabilities\n- `clawsec_check_skill_safety` - Pre-installation safety check\n- `clawsec_list_advisories` - List all advisories with filtering\n- `clawsec_refresh_cache` - Request immediate advisory cache refresh\n\n**Signature Verification** (mcp-tools/signature-verification.ts):\n- `clawsec_verify_skill_package` - Verify Ed25519 signature on skill packages\n  - Uses pinned ClawSec public key (no runtime key override)\n  - Accepts staged package/signature paths only under `/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`\n\n**Integrity Monitoring** (mcp-tools/integrity-tools.ts):\n- `clawsec_check_integrity` - Check protected files for unauthorized changes\n- `clawsec_approve_change` - Approve intentional file modification as new baseline\n- `clawsec_integrity_status` - View current baseline status\n- `clawsec_verify_audit` - Verify audit log hash chain integrity\n\n### 2. Test Advisory Checking\n\nAsk your NanoClaw agent:\n```\nCheck if any of my installed skills have security advisories\n```\n\nThe agent should use the `clawsec_check_advisories` tool and report results.\n\n### 3. Check Advisory Cache\n\nVerify the cache file was created:\n```bash\ncat /workspace/project/data/clawsec-advisory-cache.json\n```\n\nYou should see:\n- `feed`: Array of advisories\n- `fetchedAt`: Timestamp of last update\n- `verified`: Should be `true`\n- `publicKeyFingerprint`: SHA-256 fingerprint of the pinned signing key\n\n## Usage Examples\n\n### Agent Commands\n\nOnce installed, your NanoClaw agents can:\n\n**Check for vulnerabilities:**\n```\nScan my installed skills for security issues\n```\n\n**Pre-installation check:**\n```\nIs it safe to install skill-name@1.0.0?\n```\n\n**List all advisories:**\n```\nShow me all ClawSec security advisories\n```\n\n### Manual Tool Invocation\n\nYou can also call the MCP tools directly from agent code:\n\n```typescript\n// Check all installed skills\nconst result = await tools.clawsec_check_advisories({\n  installRoot: '/home/node/.claude/skills'\n});\n\n// Check specific skill before installation\nconst safetyCheck = await tools.clawsec_check_skill_safety({\n  skillName: 'risky-skill',\n  skillVersion: '1.0.0'\n});\n```\n\n## Configuration\n\n### Cache Location\n\nDefault: `/workspace/project/data/clawsec-advisory-cache.json`\n\nTo change, pass a different data directory path to `new AdvisoryCacheManager(dataDir, logger)`.\n\n### Refresh Interval\n\nDefault: 6 hours\n\nTo change, update the `setInterval(...)` duration (in milliseconds) in host startup.\n\n### Feed URL\n\nDefault: `https://clawsec.prompt.security/advisories/feed.json`\n\nTo use a mirror or custom feed, update `FEED_URL` in `skills/clawsec-nanoclaw/host-services/advisory-cache.ts`.\n\n## Platform-Specific Advisories\n\nClawSec advisories can target specific platforms:\n\n- **`platforms: [\"nanoclaw\"]`**: Only affects NanoClaw\n- **`platforms: [\"openclaw\"]`**: Only affects OpenClaw/MoltBot\n- **`platforms: [\"openclaw\", \"nanoclaw\"]`**: Affects both\n- **No `platforms` field**: Applies to all platforms\n\nPlatform metadata is preserved in advisory records and can be filtered by your policy layer.\n\n## Security\n\n### Signature Verification\n\nAll advisory feeds are Ed25519 signed. The public key is pinned in:\n```\nskills/clawsec-nanoclaw/advisories/feed-signing-public.pem\n```\n\nFeeds failing signature verification are rejected.\n\n### Cache Integrity\n\nThe advisory cache includes:\n- Cryptographic signature of feed contents\n- Verification status\n- Timestamp of last successful fetch\n\nNever manually edit the cache file - it will break signature verification.\n\n## Troubleshooting\n\n### Tools Not Appearing\n\n**Problem**: MCP tools not showing up in agent\n\n**Solution**:\n1. Check that you added the import and registration in `ipc-mcp-stdio.ts`\n2. Restart the container\n3. Check container logs for import errors\n\n### Cache Not Updating\n\n**Problem**: Advisory cache is empty or stale\n\n**Solution**:\n1. Check that `AdvisoryCacheManager.initialize()` is called in your host entry point\n2. Verify network access to `clawsec.prompt.security`\n3. Check host logs for fetch errors\n4. Manually trigger: `curl https://clawsec.prompt.security/advisories/feed.json`\n\n### Signature Verification Failing\n\n**Problem**: Cache shows `\"verified\": false`\n\n**Solution**:\n1. Ensure public key file exists at correct path\n2. Check file permissions (should be readable)\n3. Verify feed URL is correct (not using HTTP instead of HTTPS)\n4. Check for corrupted downloads (try clearing cache and refetching)\n\n### IPC Communication Issues\n\n**Problem**: Tools return errors about IPC\n\n**Solution**:\n1. Verify IPC handlers are registered in `src/ipc.ts`\n2. Check that IPC directory exists and is writable\n3. Ensure host process is running\n4. Check host logs for handler errors\n\n## Uninstallation\n\nTo remove ClawSec from NanoClaw:\n\n1. Remove MCP tool registration from `ipc-mcp-stdio.ts`\n2. Remove IPC handler registration from `src/ipc.ts`\n3. Remove `AdvisoryCacheManager` initialization from host entry point\n4. Delete the skill directory: `rm -rf skills/clawsec-nanoclaw`\n5. Delete the cache file: `rm /workspace/project/data/clawsec-advisory-cache.json`\n6. Restart NanoClaw\n\n## Support\n\n- **Documentation**: https://clawsec.prompt.security/\n- **Issues**: https://github.com/prompt-security/clawsec/issues\n- **Security**: security@prompt.security\n\n## License\n\nAGPL-3.0-or-later\n\n---\n\n**Questions?** Open an issue or check the main ClawSec documentation.\n\nFile v0.0.10:skill-card.md\n\n## Description:\n\nUse when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[davida-ps](https://clawhub.ai/user/davida-ps)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and NanoClaw operators use this skill to check installed or candidate skills against ClawSec security advisories, verify skill package signatures, and monitor protected bot files for unauthorized changes.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Agents receive host-side integrity tools that can approve protected-file changes or restore critical bot files.\n\nMitigation: Require separate human or administrator approval before exposing integrity approval or auto-restore for global instructions or group registration files.\n\nRisk: Production installs could trust a modified release package or unpinned installation path.\n\nMitigation: Use a pinned installer or the documented signed release verification path before installing or extracting the release.\n\nRisk: Advisory scans may inspect an unintended skills directory if broad paths are supplied.\n\nMitigation: Restrict advisory scans to the intended NanoClaw skills directory and review scan scope during deployment.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/davida-ps/skills/clawsec-nanoclaw)\n- [ClawSec Advisory Feed](https://clawsec.prompt.security/advisories/feed.json)\n- [Installation Guide](INSTALL.md)\n- [File Integrity Monitoring for NanoClaw](docs/INTEGRITY.md)\n- [Skill Package Signing and Verification](docs/SKILL_SIGNING.md)\n- [ClawSec Security Architecture](https://clawsec.prompt.security/docs/architecture)\n- [Ed25519 Specification (RFC 8032)](https://tools.ietf.org/html/rfc8032)\n- [OpenSSL Ed25519 Documentation](https://www.openssl.org/docs/man3.0/man7/Ed25519.html)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown and JSON-oriented tool results with inline TypeScript and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Agent-facing MCP tool output can include advisory matches, safety recommendations, signature verification results, integrity status, audit verification, and remediation guidance.]\n\n## Skill Version(s):\n\n0.0.10 (source: SKILL.md frontmatter, artifact/skill.json, CHANGELOG, ClawHub release evidence; released 2026-06-23)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.0.10:guardian/policy.json\n\n{\n  \"version\": 1,\n  \"description\": \"NanoClaw file integrity monitoring policy\",\n  \"nanoclaw_version\": \"0.1.0\",\n  \"targets\": [\n    {\n      \"path\": \"/workspace/project/data/registered_groups.json\",\n      \"mode\": \"restore\",\n      \"priority\": \"critical\",\n      \"description\": \"Group registration config - prevents unauthorized group access\"\n    },\n    {\n      \"path\": \"/workspace/group/CLAUDE.md\",\n      \"mode\": \"restore\",\n      \"priority\": \"high\",\n      \"description\": \"Group-specific agent instructions\"\n    },\n    {\n      \"path\": \"/workspace/project/groups/global/CLAUDE.md\",\n      \"mode\": \"restore\",\n      \"priority\": \"high\",\n      \"description\": \"Global agent instructions shared across all groups\"\n    },\n    {\n      \"pattern\": \"/workspace/project/container/**/*.ts\",\n      \"mode\": \"alert\",\n      \"priority\": \"medium\",\n      \"description\": \"Container runtime code - alert on changes for awareness\"\n    },\n    {\n      \"pattern\": \"/workspace/project/host/**/*.ts\",\n      \"mode\": \"alert\",\n      \"priority\": \"medium\",\n      \"description\": \"Host process code - alert on changes for awareness\"\n    },\n    {\n      \"pattern\": \"/workspace/ipc/**/*\",\n      \"mode\": \"ignore\",\n      \"priority\": \"low\",\n      \"description\": \"IPC files change constantly - ignore\"\n    },\n    {\n      \"pattern\": \"/workspace/group/conversations/**/*\",\n      \"mode\": \"ignore\",\n      \"priority\": \"low\",\n      \"description\": \"Chat history - expected to change frequently\"\n    }\n  ],\n  \"notes\": [\n    \"Mode 'restore': Auto-restore file to approved baseline on drift + alert user\",\n    \"Mode 'alert': Alert user about drift but do not auto-restore\",\n    \"Mode 'ignore': No monitoring, file changes are expected\",\n    \"Patterns use glob syntax with ** for recursive matching\"\n  ]\n}\n\nFile v0.0.10:skill.json\n\n{\n  \"name\": \"clawsec-nanoclaw\",\n  \"version\": \"0.0.10\",\n  \"description\": \"ClawSec security suite for NanoClaw - Advisory feed monitoring, MCP tools for vulnerability checking, and Ed25519 signature verification for containerized WhatsApp bot agents\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"keywords\": [\n    \"security\",\n    \"nanoclaw\",\n    \"whatsapp-bot\",\n    \"mcp-tools\",\n    \"advisory\",\n    \"feed\",\n    \"threat-intel\",\n    \"containers\",\n    \"signature-verification\",\n    \"vulnerability-scanning\",\n    \"agents\",\n    \"ai\"\n  ],\n  \"platform\": \"nanoclaw\",\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"NanoClaw skill documentation\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and release notes\"\n      },\n      {\n        \"path\": \"INSTALL.md\",\n        \"required\": true,\n        \"description\": \"Installation guide for NanoClaw deployments\"\n      },\n      {\n        \"path\": \"mcp-tools/advisory-tools.ts\",\n        \"required\": true,\n        \"description\": \"MCP tools for advisory checking in container context\"\n      },\n      {\n        \"path\": \"host-services/advisory-cache.ts\",\n        \"required\": true,\n        \"description\": \"Host-side advisory cache manager with periodic feed fetching\"\n      },\n      {\n        \"path\": \"host-services/ipc-handlers.ts\",\n        \"required\": true,\n        \"description\": \"IPC handlers for MCP tool requests\"\n      },\n      {\n        \"path\": \"lib/signatures.ts\",\n        \"required\": true,\n        \"description\": \"Ed25519 signature verification utilities\"\n      },\n      {\n        \"path\": \"lib/local_file_io.ts\",\n        \"required\": true,\n        \"description\": \"Local file access helpers used by signature verification routines\"\n      },\n      {\n        \"path\": \"lib/advisories.ts\",\n        \"required\": true,\n        \"description\": \"Advisory matching and vulnerability detection\"\n      },\n      {\n        \"path\": \"lib/types.ts\",\n        \"required\": true,\n        \"description\": \"TypeScript type definitions\"\n      },\n      {\n        \"path\": \"lib/risk.ts\",\n        \"required\": true,\n        \"description\": \"Shared advisory risk evaluation logic for host and MCP tools\"\n      },\n      {\n        \"path\": \"advisories/feed-signing-public.pem\",\n        \"required\": true,\n        \"description\": \"Pinned Ed25519 public key for feed signature verification\"\n      },\n      {\n        \"path\": \"mcp-tools/signature-verification.ts\",\n        \"required\": true,\n        \"description\": \"Phase 1: MCP tool for skill package signature verification\"\n      },\n      {\n        \"path\": \"host-services/skill-signature-handler.ts\",\n        \"required\": true,\n        \"description\": \"Phase 1: Host-side signature verification service\"\n      },\n      {\n        \"path\": \"docs/SKILL_SIGNING.md\",\n        \"required\": true,\n        \"description\": \"Phase 1: Documentation for skill signing and verification\"\n      },\n      {\n        \"path\": \"mcp-tools/integrity-tools.ts\",\n        \"required\": true,\n        \"description\": \"Phase 2: MCP tools for file integrity monitoring\"\n      },\n      {\n        \"path\": \"host-services/integrity-handler.ts\",\n        \"required\": true,\n        \"description\": \"Phase 2: Host-side integrity monitoring service\"\n      },\n      {\n        \"path\": \"guardian/integrity-monitor.ts\",\n        \"required\": true,\n        \"description\": \"Phase 2: Core file integrity monitoring engine\"\n      },\n      {\n        \"path\": \"guardian/policy.json\",\n        \"required\": true,\n        \"description\": \"Phase 2: NanoClaw-specific file protection policy\"\n      },\n      {\n        \"path\": \"docs/INTEGRITY.md\",\n        \"required\": true,\n        \"description\": \"Phase 2: Documentation for file integrity monitoring\"\n      }\n    ]\n  },\n  \"capabilities\": [\n    \"Advisory feed monitoring from clawsec.prompt.security\",\n    \"MCP tools for agent-initiated vulnerability scans\",\n    \"Exploitability-aware advisory prioritization for agent environments\",\n    \"Pre-installation skill safety checks\",\n    \"Ed25519 signature verification for advisory feeds\",\n    \"Platform metadata preserved in advisory records for downstream filtering\",\n    \"Containerized agent support with IPC communication\"\n  ],\n  \"nanoclaw\": {\n    \"mcp_tools\": [\n      \"clawsec_check_advisories\",\n      \"clawsec_check_skill_safety\",\n      \"clawsec_list_advisories\",\n      \"clawsec_refresh_cache\",\n      \"clawsec_verify_skill_package\",\n      \"clawsec_check_integrity\",\n      \"clawsec_approve_change\",\n      \"clawsec_integrity_status\",\n      \"clawsec_verify_audit\"\n    ],\n    \"requires\": {\n      \"node\": \">=18.0.0\",\n      \"nanoclaw\": \">=0.1.0\"\n    },\n    \"integration\": {\n      \"mcp_tools_file\": \"container/agent-runner/src/ipc-mcp-stdio.ts\",\n      \"ipc_handlers_file\": \"src/ipc.ts\",\n      \"cache_location\": \"/workspace/project/data/clawsec-advisory-cache.json\"\n    }\n  }\n}\n\nArchive v0.0.8: 24 files, 63269 bytes\n\nFiles: CHANGELOG.md (3325b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (14939b), guardian/integrity-monitor.ts (21442b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (10995b), host-services/ipc-handlers.ts (3378b), host-services/skill-signature-handler.ts (7632b), INSTALL.md (9616b), lib/advisories.ts (14982b), lib/local_file_io.ts (316b), lib/risk.ts (2501b), lib/signatures.ts (14129b), lib/types.ts (6059b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (7025b), README.md (5416b), skill-card.md (2770b), skill.json (4948b), SKILL.md (8505b), test/security-hardening.test.mjs (7060b), _meta.json (135b)\n\nFile v0.0.8:SKILL.md\n\n---\nname: clawsec-nanoclaw\nversion: 0.0.8\ndescription: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot\n---\n\n# ClawSec for NanoClaw\n\nSecurity advisory monitoring that protects your WhatsApp bot from known vulnerabilities in skills and dependencies.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y\n```\n\n## Overview\n\nClawSec provides MCP tools that check installed skills against a curated feed of security advisories. It prevents installation of vulnerable skills, includes exploitability context for triage, and alerts you to issues in existing ones.\n\n**Core principle:** Check before you install. Monitor what's running.\n\n## When to Use\n\nUse ClawSec tools when:\n- Installing a new skill (check safety first)\n- User asks \"are my skills secure?\"\n- Investigating suspicious behavior\n- Regular security audits\n- After receiving security notifications\n\nDo NOT use for:\n- Code review (use other tools)\n- Performance issues (different concern)\n- General debugging\n\n## MCP Tools Available\n\n### Pre-Installation Check\n\n```typescript\n// Before installing any skill\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'new-skill',\n  skillVersion: '1.0.0'  // optional\n});\n\nif (!safety.safe) {\n  // Show user the risks before proceeding\n  console.warn(`Security issues: ${safety.advisories.map(a => a.id)}`);\n}\n```\n\n### Security Audit\n\n```typescript\n// Check all installed skills (defaults to ~/.claude/skills in the container)\nconst result = await tools.clawsec_check_advisories({\n  installRoot: '/home/node/.claude/skills'  // optional\n});\n\nif (result.matches.some((m) =>\n  m.advisory.severity === 'critical' || m.advisory.exploitability_score === 'high'\n)) {\n  // Alert user immediately\n  console.error('Urgent advisories found!');\n}\n```\n\n### Browse Advisories\n\n```typescript\n// List advisories with filters\nconst advisories = await tools.clawsec_list_advisories({\n  severity: 'high',               // optional\n  exploitabilityScore: 'high'     // optional\n});\n```\n\n## Quick Reference\n\n| Task | Tool | Key Parameter |\n|------|------|---------------|\n| Pre-install check | `clawsec_check_skill_safety` | `skillName` |\n| Audit all skills | `clawsec_check_advisories` | `installRoot` (optional) |\n| Browse feed | `clawsec_list_advisories` | `severity`, `type`, `exploitabilityScore` (optional) |\n| Verify package signature | `clawsec_verify_skill_package` | `packagePath` |\n| Refresh advisory cache | `clawsec_refresh_cache` | (none) |\n| Check file integrity | `clawsec_check_integrity` | `mode`, `autoRestore` (optional) |\n| Approve file change | `clawsec_approve_change` | `path` |\n| View baseline status | `clawsec_integrity_status` | `path` (optional) |\n| Verify audit log | `clawsec_verify_audit` | (none) |\n\n## Common Patterns\n\n### Pattern 1: Safe Skill Installation\n\n```typescript\n// ALWAYS check before installing\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: userRequestedSkill\n});\n\nif (safety.safe) {\n  // Proceed with installation\n  await installSkill(userRequestedSkill);\n} else {\n  // Show user the risks and get confirmation\n  await showSecurityWarning(safety.advisories);\n  if (await getUserConfirmation()) {\n    await installSkill(userRequestedSkill);\n  }\n}\n```\n\n### Pattern 2: Periodic Security Check\n\n```typescript\n// Add to scheduled tasks\nschedule_task({\n  prompt: \"Check advisories using clawsec_check_advisories and alert when critical or high-exploitability matches appear\",\n  schedule_type: \"cron\",\n  schedule_value: \"0 9 * * *\"  // Daily at 9am\n});\n```\n\n### Pattern 3: User Security Query\n\n```\nUser: \"Are my skills secure?\"\n\nYou: I'll check installed skills for known vulnerabilities.\n[Use clawsec_check_advisories]\n\nResponse:\n✅ No urgent issues found.\n- 2 low-severity/low-exploitability advisories\n- All skills up to date\n```\n\n## Common Mistakes\n\n### ❌ Installing without checking\n```typescript\n// DON'T\nawait installSkill('untrusted-skill');\n```\n\n```typescript\n// DO\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'untrusted-skill'\n});\nif (safety.safe) await installSkill('untrusted-skill');\n```\n\n### ❌ Ignoring exploitability context\n```typescript\n// DON'T: Use severity only\nif (advisory.severity === 'high') {\n  notifyNow(advisory);\n}\n```\n\n```typescript\n// DO: Use exploitability + severity\nif (\n  advisory.exploitability_score === 'high' ||\n  advisory.severity === 'critical'\n) {\n  notifyNow(advisory);\n}\n```\n\n### ❌ Skipping critical severity\n```typescript\n// DON'T: Ignore high exploitability in medium severity advisories\nif (advisory.severity === 'critical') alert();\n```\n\n```typescript\n// DO: Prioritize exploitability and severity together\nif (advisory.exploitability_score === 'high' || advisory.severity === 'critical') {\n  // Alert immediately\n}\n```\n\n## Implementation Details\n\n**Feed Source**: https://clawsec.prompt.security/advisories/feed.json\n\nThis signed feed is consolidated. NanoClaw receives NVD CVEs, approved community advisories, and provisional GHSA-without-CVE advisories through the same default URL.\n\n**Update Frequency**: Every 6 hours (automatic)\n\n**Signature Verification**: Ed25519 signed feeds\n**Package Verification Policy**: pinned key only, bounded package/signature paths\n\n**Cache Location**: `/workspace/project/data/clawsec-advisory-cache.json`\n\nSee [INSTALL.md](./INSTALL.md) for setup and [docs/](./docs/) for advanced usage.\n\n## Real-World Impact\n\n- Prevents installation of skills with known RCE vulnerabilities\n- Alerts to supply chain attacks in dependencies\n- Provides actionable remediation steps\n- Zero false positives (curated feed only)\n\n## Release Artifact Verification\n\nFor standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.\n\n```bash\nset -euo pipefail\n\nSKILL_NAME=\"clawsec-nanoclaw\"\nVERSION=\"0.0.6\"\nREPO=\"prompt-security/clawsec\"\nTAG=\"${SKILL_NAME}-v${VERSION}\"\nBASE=\"https://github.com/${REPO}/releases/download/${TAG}\"\nZIP_NAME=\"${SKILL_NAME}-v${VERSION}.zip\"\nTMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP_DIR\"' EXIT\n\nRELEASE_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\"\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\"\ncurl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\"\n\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP_DIR/signing-public.pem\" -outform DER | shasum -a 256 | awk '{print $1}')\"\nif [ \"$ACTUAL_PUBKEY_SHA256\" != \"$RELEASE_PUBKEY_SHA256\" ]; then\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\nfi\n\nopenssl base64 -d -A -in \"$TMP_DIR/checksums.sig\" -out \"$TMP_DIR/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin \\\n  -inkey \"$TMP_DIR/signing-public.pem\" \\\n  -sigfile \"$TMP_DIR/checksums.sig.bin\" \\\n  -in \"$TMP_DIR/checksums.json\" >/dev/null\n\nhash_file() {\n  if command -v shasum >/dev/null 2>&1; then\n    shasum -a 256 \"$1\" | awk '{print $1}'\n  else\n    sha256sum \"$1\" | awk '{print $1}'\n  fi\n}\n\nverify_manifest_file() {\n  asset=\"$1\"\n  path=\"$2\"\n  expected=\"$(jq -r --arg asset \"$asset\" '.files[$asset].sha256 // empty' \"$TMP_DIR/checksums.json\")\"\n  if [ -z \"$expected\" ]; then\n    echo \"ERROR: checksums.json missing $asset\" >&2\n    exit 1\n  fi\n  actual=\"$(hash_file \"$path\")\"\n  if [ \"$actual\" != \"$expected\" ]; then\n    echo \"ERROR: checksum mismatch for $asset\" >&2\n    exit 1\n  fi\n}\n\nexpected_archive=\"$(jq -r '.archive.sha256 // empty' \"$TMP_DIR/checksums.json\")\"\nif [ -z \"$expected_archive\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\nactual_archive=\"$(hash_file \"$TMP_DIR/$ZIP_NAME\")\"\nif [ \"$actual_archive\" != \"$expected_archive\" ]; then\n  echo \"ERROR: archive checksum mismatch\" >&2\n  exit 1\nfi\n\nverify_manifest_file \"SKILL.md\" \"$TMP_DIR/SKILL.md\"\nverify_manifest_file \"skill.json\" \"$TMP_DIR/skill.json\"\n\necho \"Signed release manifest, archive, SKILL.md, and skill.json verified.\"\n```\n\nOnly install or extract the archive after this verification succeeds.\n\nFile v0.0.8:README.md\n\n# ClawSec for NanoClaw\n\nClawSec now supports NanoClaw, a containerized WhatsApp bot powered by Claude agents.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y\n```\n\n## What Changed\n\n### Advisory Feed Monitoring\n- **NVD CVE Pipeline**: Now monitors for NanoClaw-specific keywords\n  - \"NanoClaw\", \"WhatsApp-bot\", \"baileys\" (WhatsApp library)\n  - Container-related vulnerabilities\n- **Platform Targeting**: Advisories can specify `platforms: [\"nanoclaw\"]` for NanoClaw-specific issues\n\n### Keywords Added\nThe CVE monitoring now includes:\n- `NanoClaw` - Direct product name\n- `WhatsApp-bot` - Core functionality\n- `baileys` - WhatsApp client library dependency\n\n## Advisory Schema\n\nAdvisories now support optional `platforms` field:\n\n```json\n{\n  \"id\": \"CVE-2026-XXXXX\",\n  \"platforms\": [\"openclaw\", \"nanoclaw\"],\n  \"severity\": \"critical\",\n  \"type\": \"prompt_injection\",\n  \"affected\": [\"skill-name@1.0.0\"],\n  \"action\": \"Update to version 1.0.1\"\n}\n```\n\n**Platform values:**\n- `\"openclaw\"` - Affects OpenClaw/ClawdBot/MoltBot only\n- `\"nanoclaw\"` - Affects NanoClaw only\n- `[\"openclaw\", \"nanoclaw\"]` - Affects both platforms\n- (empty/missing) - Applies to all platforms (backward compatible)\n\n## ClawSec NanoClaw Skill\n\nClawSec provides a complete security skill for NanoClaw deployments:\n\n**Location**: `skills/clawsec-nanoclaw/`\n\n### Features\n\n- **9 MCP Tools** for agents to manage security:\n  - `clawsec_check_advisories` - Scan installed skills for vulnerabilities\n  - `clawsec_check_skill_safety` - Pre-installation safety checks\n  - `clawsec_list_advisories` - Browse advisory feed with filtering\n  - `clawsec_refresh_cache` - Request immediate advisory cache refresh\n  - `clawsec_verify_skill_package` - Verify Ed25519 signatures on skill packages\n  - `clawsec_check_integrity` - Check protected files for unauthorized changes\n  - `clawsec_approve_change` - Approve intentional file modifications\n  - `clawsec_integrity_status` - View file baseline status\n  - `clawsec_verify_audit` - Verify audit log hash chain\n\n- **Advisory Cache Service**: Host-managed feed fetching with signature validation\n- **Signature Verification**: Ed25519-signed feeds ensure integrity\n- **Exploitability Context**: Surfaces `exploitability_score` and rationale to reduce alert fatigue\n- **IPC Communication**: Container-safe host communication\n\n### Installation\n\n1. Copy the skill to your NanoClaw deployment:\n   ```bash\n   cp -r skills/clawsec-nanoclaw /path/to/nanoclaw/skills/\n   ```\n\n2. Follow the detailed guide at `skills/clawsec-nanoclaw/INSTALL.md`\n\n### Quick Integration\n\nThe skill integrates into three places:\n\n**1. MCP Tools** (container):\n```typescript\n// container/agent-runner/src/ipc-mcp-stdio.ts\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/advisory-tools.js';\n```\n\n**2. IPC Handlers** (host):\n```typescript\n// src/ipc.ts\nimport { handleAdvisoryIpc } from '../skills/clawsec-nanoclaw/host-services/ipc-handlers.js';\n```\n\n**3. Cache Service** (host):\n```typescript\n// src/index.ts\nimport { AdvisoryCacheManager } from '../skills/clawsec-nanoclaw/host-services/advisory-cache.js';\n```\n\n### Advisory Feed\n\nNanoClaw consumes the same feed as OpenClaw:\n```\nhttps://clawsec.prompt.security/advisories/feed.json\n```\n\nThe feed is Ed25519 signed and automatically fetched by the cache service.\n\n## Team Credits\n\nThis integration was developed by a team of 8 specialized agents coordinated to adapt ClawSec for NanoClaw:\n\n- **pioneer-repo-scout** - ClawSec architecture analysis\n- **pioneer-nanoclaw-scout** - NanoClaw architecture analysis\n- **architect** - Integration design and coordination\n- **advisory-specialist** - Advisory feed integration\n- **integrity-specialist** - File integrity design\n- **installer-specialist** - Signature verification implementation\n- **tester** - Test infrastructure and validation\n- **documenter** - Documentation\n\nTotal contribution: 3000+ lines of code and comprehensive design documents.\n\n## What's Included\n\nThe `clawsec-nanoclaw` skill provides:\n\n- **1,730 lines** of production-ready TypeScript code\n- **MCP Tools** (350 lines): Agent-facing vulnerability checking\n- **Advisory Cache** (492 lines): Automatic feed fetching and caching\n- **Signature Verification** (387 lines): Ed25519 signature validation\n- **Advisory Matching** (289 lines): Skill-to-vulnerability correlation\n- **IPC Handlers** (212 lines): Container-to-host communication\n- **Complete Documentation**: Installation guide, usage examples, troubleshooting\n\n## Future Enhancements\n\nPlanned features for future releases:\n- File integrity monitoring (soul-guardian adaptation for containers)\n- Real-time advisory alerts via WebSocket\n- WhatsApp-native security alert formatting\n- Behavioral analysis and anomaly detection\n- Custom/private advisory feed support\n\n## Documentation\n\n- [Skill Documentation](skills/clawsec-nanoclaw/SKILL.md) - Features and architecture\n- [Installation Guide](skills/clawsec-nanoclaw/INSTALL.md) - Detailed setup instructions\n- [ClawSec Main README](README.md) - Overall ClawSec documentation\n- [Security & Signing](../../wiki/security-signing-runbook.md) - Signature verification details\n\n## Support\n\n- **Issues**: https://github.com/prompt-security/clawsec/issues\n- **Security**: security@prompt.security\n- NanoClaw Repository: https://github.com/qwibitai/nanoclaw\n\nFile v0.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-nanoclaw\",\n  \"version\": \"0.0.8\",\n  \"publishedAt\": 1781103552174\n}\n\nFile v0.0.8:CHANGELOG.md\n\n# Changelog\n\n## [0.0.8] - 2026-06-10\n\n### Changed\n\n- Re-released skill package with updated marketplace grouping and signed release trust artifacts for Vercel-compatible skill installation.\n\n## [0.0.7] - 2026-06-07\n\n### Security\n- Added comparator range support for NanoClaw advisory matching and fail-closed handling for malformed affected specifiers.\n- Added strict integrity IPC request ID validation and result path containment before host-side result writes.\n\n## [0.0.6] - 2026-05-24\n\n### Changed\n- Documented that NanoClaw consumes the consolidated signed advisory feed containing NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records.\n- Added advisory metadata typing for GHSA lifecycle fields used by the consolidated feed.\n\n## [0.0.5] - 2026-05-14\n\n### Security\n- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.\n\nAll notable changes to the ClawSec NanoClaw compatibility skill will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.4] - 2026-04-16\n\n### Changed\n\n- Moved signature-related local file reads into `lib/local_file_io.ts` and kept network fetch logic isolated in `lib/signatures.ts`.\n\n### Security\n\n- Reduced static false-positive exfiltration signals by separating local file I/O and remote fetch code paths.\n\n## [0.0.3] - 2026-03-09\n\n### Security\n\n- Removed runtime public-key override from host-side package signature verification; verification now always uses the pinned ClawSec key.\n- Removed unsigned-package override path in host-side verification flow.\n- Added strict package/signature path policy for signature verification (`/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`) with absolute-path, extension, symlink, and realpath boundary checks.\n- Added policy-bound path enforcement for integrity approvals: approvals now require normalized paths that are explicitly present in non-ignored integrity policy targets.\n\n### Changed\n\n- Updated MCP signature verification tool docs and behavior to align with bounded path policy and pinned-key-only verification.\n- Added regression tests for signature-verification and integrity-approval hardening invariants.\n\n## [0.0.2] - 2026-02-28\n\n### Added\n\n- Exploitability-aware advisory output in NanoClaw MCP tools (`exploitability_score`, `exploitability_rationale`).\n- Exploitability filtering (`exploitabilityScore`) for `clawsec_list_advisories`.\n\n### Changed\n\n- Updated NanoClaw advisory sorting and pre-install safety recommendation logic to prioritize exploitability context.\n- Updated NanoClaw integration docs to match current host/container integration points (`src/ipc.ts`, `src/index.ts`) and current cache schema.\n- Removed duplicate exploitability normalization logic from MCP advisory tools and now reuse `normalizeExploitabilityScore` from `lib/risk.ts`.\n- Reused `matchesAffectedSpecifier` from `lib/advisories.ts` in MCP advisory tools to keep skill/version matching logic centralized and consistent.\n\nFile v0.0.8:docs/INTEGRITY.md\n\n# File Integrity Monitoring for NanoClaw\n\nClawSec's file integrity monitoring protects critical NanoClaw configuration files from unauthorized modification.\n\n## What It Does\n\n**Protects Critical Files:**\n- `registered_groups.json` - Prevents unauthorized group access\n- `CLAUDE.md` files - Protects agent instructions\n- Container/host code - Alerts on unexpected changes\n\n**How It Works:**\n1. **Baseline**: Stores SHA-256 hashes of approved file states\n2. **Monitoring**: Periodically checks files for changes (drift)\n3. **Restore**: Automatically reverts critical files to approved versions\n4. **Audit**: Maintains tamper-evident log of all operations\n\n## Quick Start\n\n### Step 1: Verify Installation\n\nCheck that integrity monitoring is available:\n\n```bash\n# From container\nls /workspace/project/skills/clawsec-nanoclaw/guardian/\n# Should show: policy.json, integrity-monitor.ts\n```\n\n### Step 2: Initialize Baselines\n\nThe first time integrity monitoring runs, it creates baselines automatically:\n\n```typescript\n// Agent calls this (happens automatically on first integrity check)\nawait tools.clawsec_check_integrity();\n```\n\nThis creates:\n```\n/workspace/project/data/soul-guardian/\n├── baselines.json       # SHA-256 hashes\n├── approved/            # File snapshots\n│   ├── registered_groups.json\n│   └── CLAUDE.md\n├── patches/             # Diffs (empty initially)\n├── quarantine/          # Tampered files (empty initially)\n└── audit.jsonl          # Event log\n```\n\n### Step 3: Enable Scheduled Monitoring\n\nAdd to main group's scheduled tasks:\n\n```typescript\nschedule_task({\n  prompt: `\n    Check file integrity with clawsec_check_integrity.\n    If drift detected and files restored, send WhatsApp message:\n    \"⚠️ SECURITY ALERT\n\n    Unauthorized changes detected and automatically reverted:\n    [list files that were restored]\n\n    Review details: /workspace/project/data/soul-guardian/patches/\"\n  `,\n  schedule_type: 'cron',\n  schedule_value: '*/30 * * * *',  // Every 30 minutes\n  context_mode: 'isolated'\n});\n```\n\nThat's it! Integrity monitoring is now active.\n\n## MCP Tools Reference\n\n### 1. `clawsec_check_integrity`\n\nCheck all protected files for unauthorized changes.\n\n**Parameters:**\n- `mode` (optional): `'check'` (default) or `'status'`\n  - `check`: Detect drift and auto-restore\n  - `status`: View baselines only (no drift detection)\n- `autoRestore` (optional): `true` (default) or `false`\n  - If `false`, drift is detected but not auto-fixed\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"timestamp\": \"2026-02-25T12:00:00Z\",\n  \"drift_detected\": false,\n  \"files\": [\n    {\n      \"path\": \"/workspace/project/data/registered_groups.json\",\n      \"status\": \"ok\",\n      \"mode\": \"restore\",\n      \"expected_sha\": \"abc123...\",\n      \"found_sha\": \"abc123...\"\n    }\n  ],\n  \"summary\": {\n    \"total\": 3,\n    \"ok\": 3,\n    \"drifted\": 0,\n    \"restored\": 0,\n    \"alerted\": 0,\n    \"errors\": 0\n  }\n}\n```\n\n**Example:**\n```typescript\nconst result = await tools.clawsec_check_integrity();\n\nif (result.drift_detected) {\n  console.log('⚠️ Drift detected!');\n  for (const file of result.files) {\n    if (file.status === 'restored') {\n      console.log(`✅ Restored: ${file.path}`);\n      console.log(`  Diff: ${file.patch_path}`);\n    } else if (file.status === 'drifted') {\n      console.log(`⚠️ Changed: ${file.path} (alert only)`);\n    }\n  }\n}\n```\n\n### 2. `clawsec_approve_change`\n\nApprove an intentional file modification as the new baseline.\n\n**When to use:**\n- After legitimately updating CLAUDE.md\n- After adding/removing groups in registered_groups.json\n- After any intentional change to protected files\n\n**Parameters:**\n- `path` (required): Absolute path to file\n- `note` (optional): Explanation for audit log\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"path\": \"/workspace/group/CLAUDE.md\",\n  \"approved_at\": \"2026-02-25T12:00:00Z\",\n  \"approved_by\": \"agent\",\n  \"note\": \"Added new skill instructions\"\n}\n```\n\n**Example:**\n```typescript\n// After editing CLAUDE.md\nawait tools.clawsec_approve_change({\n  path: '/workspace/group/CLAUDE.md',\n  note: 'Updated agent instructions for new skill'\n});\n\nconsole.log('✅ Change approved - new baseline created');\n```\n\n### 3. `clawsec_integrity_status`\n\nView current baseline status without checking for drift.\n\n**Parameters:**\n- `path` (optional): Specific file, or all if omitted\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"baseline_age\": \"2026-02-25T10:00:00Z\",\n  \"files\": [\n    {\n      \"path\": \"/workspace/project/data/registered_groups.json\",\n      \"mode\": \"restore\",\n      \"priority\": \"critical\",\n      \"has_baseline\": true,\n      \"baseline_sha\": \"abc123...\",\n      \"approved_at\": \"2026-02-25T10:00:00Z\",\n      \"snapshot_exists\": true\n    }\n  ]\n}\n```\n\n**Example:**\n```typescript\nconst status = await tools.clawsec_integrity_status();\n\nconsole.log('Protected files:');\nfor (const file of status.files) {\n  console.log(`- ${file.path} (${file.mode}, ${file.priority})`);\n  console.log(`  Last approved: ${file.approved_at}`);\n}\n```\n\n### 4. `clawsec_verify_audit`\n\nVerify audit log hash chain integrity.\n\n**No parameters.**\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"valid\": true,\n  \"entries\": 42,\n  \"errors\": []\n}\n```\n\n**Example:**\n```typescript\nconst verification = await tools.clawsec_verify_audit();\n\nif (!verification.valid) {\n  console.log('🚨 CRITICAL: Audit log has been tampered with!');\n  console.log('Errors:', verification.errors);\n} else {\n  console.log(`✅ Audit log verified (${verification.entries} entries)`);\n}\n```\n\n## Protected Files Policy\n\n### Critical Priority (Auto-Restore)\n\n**`/workspace/project/data/registered_groups.json`**\n- **Risk**: Tampering grants unauthorized group access\n- **Action**: Immediate auto-restore + alert\n\n**`/workspace/group/CLAUDE.md`**\n- **Risk**: Modifies agent behavior\n- **Action**: Immediate auto-restore + alert\n\n**`/workspace/project/groups/global/CLAUDE.md`**\n- **Risk**: Affects all groups\n- **Action**: Immediate auto-restore + alert\n\n### Medium Priority (Alert Only)\n\n**Container code** (`/workspace/project/container/**/*.ts`)\n- **Risk**: Unexpected code changes\n- **Action**: Alert for review (no auto-restore)\n\n**Host code** (`/workspace/project/host/**/*.ts`)\n- **Risk**: Unexpected code changes\n- **Action**: Alert for review (no auto-restore)\n\n### Ignored\n\n**IPC files** (`/workspace/ipc/**/*`)\n- Changes are expected and frequent\n\n**Conversations** (`/workspace/group/conversations/**/*`)\n- Changes are expected and frequent\n\n## Workflow Examples\n\n### Scenario 1: Scheduled Monitoring\n\n**Setup:**\n```typescript\nschedule_task({\n  prompt: 'Run clawsec_check_integrity and alert on drift',\n  schedule_type: 'cron',\n  schedule_value: '*/30 * * * *'\n});\n```\n\n**What happens:**\n1. Every 30 minutes, agent checks integrity\n2. If drift detected in critical files:\n   - Files auto-restored to baseline\n   - Tampered versions quarantined\n   - Diff patch generated\n   - User alerted via WhatsApp\n3. If drift in non-critical files:\n   - Alert only, no auto-restore\n\n### Scenario 2: Updating Agent Instructions\n\n**Workflow:**\n```typescript\n// 1. Edit CLAUDE.md\nfs.writeFileSync('/workspace/group/CLAUDE.md', newInstructions);\n\n// 2. Test changes\n// ... verify agent behaves correctly ...\n\n// 3. Approve changes\nawait tools.clawsec_approve_change({\n  path: '/workspace/group/CLAUDE.md',\n  note: 'Added instructions for new weather skill'\n});\n\n// 4. Future integrity checks will use this new baseline\n```\n\n### Scenario 3: Adding a New Group\n\n**Workflow:**\n```typescript\n// 1. Add group to registered_groups.json\nconst groups = JSON.parse(fs.readFileSync('/workspace/project/data/registered_groups.json'));\ngroups['new-jid'] = { name: 'Family', folder: 'family', trigger: '@Andy' };\nfs.writeFileSync('/workspace/project/data/registered_groups.json', JSON.stringify(groups, null, 2));\n\n// 2. Approve the change\nawait tools.clawsec_approve_change({\n  path: '/workspace/project/data/registered_groups.json',\n  note: 'Added family group'\n});\n```\n\n### Scenario 4: Investigating Drift\n\n**When drift is detected:**\n```typescript\nconst result = await tools.clawsec_check_integrity();\n\nif (result.drift_detected) {\n  for (const file of result.files) {\n    if (file.status === 'restored') {\n      // Critical file was auto-restored\n      console.log(`🔧 Auto-restored: ${file.path}`);\n      console.log(`📄 Diff: ${file.patch_path}`);\n      console.log(`📦 Quarantine: ${file.quarantine_path}`);\n\n      // Review the diff\n      const diff = fs.readFileSync(file.patch_path, 'utf-8');\n      console.log('Changes that were reverted:');\n      console.log(diff);\n    }\n  }\n}\n```\n\n## Security Model\n\n### Threat Model\n\n**Protects Against:**\n- Unauthorized file modifications\n- Group hijacking (via registered_groups.json tampering)\n- Agent instruction poisoning (via CLAUDE.md changes)\n- Accidental file corruption\n\n**Does NOT Protect Against:**\n- Attacker with full host access (can modify baselines)\n- Simultaneous baseline + file modification\n- Malicious scheduled tasks that approve their own changes\n\n### Baseline Storage\n\n**Location:** `/workspace/project/data/soul-guardian/`\n\n**Access Control:**\n- Baselines written only by host process\n- Containers access via IPC only\n- No container can modify its own baselines\n\n**Integrity:**\n- SHA-256 hashes (industry standard)\n- Hash-chained audit log (tamper-evident)\n- Atomic file operations (safe restores)\n\n### Audit Log\n\n**Format:** JSONL with hash chaining\n\n**Each entry includes:**\n```json\n{\n  \"ts\": \"2026-02-25T12:00:00Z\",\n  \"event\": \"drift\",\n  \"actor\": \"agent\",\n  \"path\": \"/workspace/group/CLAUDE.md\",\n  \"expected_sha\": \"abc123...\",\n  \"found_sha\": \"def456...\",\n  \"chain\": {\n    \"prev\": \"previous_entry_hash\",\n    \"hash\": \"this_entry_hash\"\n  }\n}\n```\n\n**Chain calculation:**\n```\nhash = SHA-256(prev_hash + '\\n' + canonical_json(entry_without_chain))\n```\n\nThis makes tampering detectable: changing any entry breaks the chain.\n\n## Troubleshooting\n\n### Integrity Check Fails\n\n**Symptom:** `clawsec_check_integrity` returns `success: false`\n\n**Causes:**\n1. IntegrityService not initialized\n2. Policy file missing\n3. Baselines corrupted\n\n**Solution:**\n```bash\n# Check service status\nls /workspace/project/data/soul-guardian/\n\n# If missing, reinitialize\nrm -rf /workspace/project/data/soul-guardian/\n# Next integrity check will recreate baselines\n```\n\n### False Positives (Legitimate Changes Flagged)\n\n**Symptom:** File keeps getting restored even though changes are legitimate\n\n**Cause:** Baseline not updated after intentional changes\n\n**Solution:**\n```typescript\nawait tools.clawsec_approve_change({\n  path: '/path/to/file',\n  note: 'Legitimate change'\n});\n```\n\n### Audit Chain Broken\n\n**Symptom:** `clawsec_verify_audit` returns `valid: false`\n\n**Causes:**\n1. Audit log manually edited\n2. Filesystem corruption\n3. Security breach\n\n**Solution:**\n```typescript\nconst verification = await tools.clawsec_verify_audit();\nconsole.log('Errors:', verification.errors);\n\n// If corruption, backup and reset\ncp /workspace/project/data/soul-guardian/audit.jsonl /tmp/audit-backup.jsonl\nrm /workspace/project/data/soul-guardian/audit.jsonl\n// Audit log will restart on next operation\n```\n\n### High Disk Usage\n\n**Symptom:** `/workspace/project/data/soul-guardian/` grows large\n\n**Causes:**\n- Many drift events generate patches\n- Quarantine files accumulate\n\n**Solution:**\n```bash\n# Clean old patches (older than 30 days)\nfind /workspace/project/data/soul-guardian/patches/ -mtime +30 -delete\n\n# Clean quarantine (after review)\nrm /workspace/project/data/soul-guardian/quarantine/*\n```\n\n## Performance\n\n**Overhead:**\n- Baseline check: ~10ms per file\n- SHA-256 computation: ~1ms per KB\n- Restore operation: ~20ms per file\n\n**Typical deployment:**\n- 3-5 protected files\n- 30-minute check interval\n- < 0.1% CPU usage\n- < 5MB disk usage\n\n## Advanced Topics\n\n### Custom Policy\n\nWhile the default policy is pinned by the skill, you can fork it:\n\n```bash\ncp /workspace/project/skills/clawsec-nanoclaw/guardian/policy.json /workspace/project/data/custom-policy.json\n```\n\nEdit and reinitialize:\n```typescript\n// Update IntegrityMonitor initialization\nnew IntegrityMonitor({\n  policyPath: '/workspace/project/data/custom-policy.json',\n  stateDir: '/workspace/project/data/soul-guardian'\n});\n```\n\n### Manual Baseline Export\n\n```bash\n# Export current baselines\ncp /workspace/project/data/soul-guardian/baselines.json /tmp/baselines-backup.json\n\n# Export approved snapshots\ntar -czf /tmp/approved-snapshots.tar.gz /workspace/project/data/soul-guardian/approved/\n```\n\n### Baseline Import (Disaster Recovery)\n\n```bash\n# Restore baselines\ncp /tmp/baselines-backup.json /workspace/project/data/soul-guardian/baselines.json\n\n# Restore snapshots\ntar -xzf /tmp/approved-snapshots.tar.gz -C /workspace/project/data/soul-guardian/\n```\n\n## FAQ\n\n**Q: Can I disable auto-restore for testing?**\n\nA: Yes, use `autoRestore: false`:\n```typescript\nawait tools.clawsec_check_integrity({ autoRestore: false });\n```\n\n**Q: How do I protect additional files?**\n\nA: Edit `policy.json` and add targets:\n```json\n{\n  \"path\": \"/workspace/group/my-config.json\",\n  \"mode\": \"restore\",\n  \"priority\": \"high\",\n  \"description\": \"My custom config\"\n}\n```\n\n**Q: What happens if both baseline and file are modified?**\n\nA: The most recent baseline wins. Always approve legitimate changes immediately.\n\n**Q: Can I run integrity checks on-demand?**\n\nA: Yes, just call `clawsec_check_integrity` from any agent.\n\n**Q: Is the audit log encrypted?**\n\nA: No, but it's hash-chained for tamper detection. Encryption can be added in Phase 3.\n\n## Support\n\n- **Documentation**: https://clawsec.prompt.security/\n- **Issues**: https://github.com/prompt-security/clawsec/issues\n- **Security Reports**: security@prompt.security\n\n---\n\n**Ready to protect your NanoClaw deployment? Start with the [Quick Start](#quick-start) guide above.**\n\nFile v0.0.8:docs/SKILL_SIGNING.md\n\n# Skill Package Signing and Verification\n\nThis document explains how ClawSec signs skill packages and how NanoClaw agents verify signatures before installation.\n\n---\n\n## Table of Contents\n\n1. [Overview](#overview)\n2. [For Skill Publishers: How to Sign Packages](#for-skill-publishers-how-to-sign-packages)\n3. [For NanoClaw Agents: How to Verify Signatures](#for-nanoclaw-agents-how-to-verify-signatures)\n4. [Security Properties](#security-properties)\n5. [Key Management](#key-management)\n6. [Troubleshooting](#troubleshooting)\n\n---\n\n## Overview\n\nSkill signature verification prevents **supply chain attacks** by ensuring skill packages haven't been tampered with during distribution. ClawSec uses **Ed25519 digital signatures** to sign skill packages, and NanoClaw agents verify these signatures before installation.\n\n### Why Signature Verification?\n\nWithout signature verification, an attacker could:\n- **Replace** a legitimate skill package with a malicious one during download\n- **Modify** package contents to inject backdoors or steal data\n- **Distribute** trojan skills that appear legitimate but contain malware\n\nSignature verification ensures:\n- ✅ **Authenticity**: Package comes from ClawSec (or trusted publisher)\n- ✅ **Integrity**: Package hasn't been modified since signing\n- ✅ **Non-repudiation**: Signer can't deny signing the package\n\n---\n\n## For Skill Publishers: How to Sign Packages\n\n### Prerequisites\n\n- OpenSSL 1.1.1+ (for Ed25519 support)\n- Private Ed25519 signing key (generate once, keep secure)\n- Skill package ready for distribution\n\n### Step 1: Generate Ed25519 Keypair (One-Time Setup)\n\n```bash\n# Generate private key (KEEP THIS SECRET!)\nopenssl genpkey -algorithm ED25519 -out clawsec-signing-private.pem\n\n# Extract public key (share this with users)\nopenssl pkey -in clawsec-signing-private.pem -pubout -out clawsec-signing-public.pem\n\n# Secure the private key\nchmod 600 clawsec-signing-private.pem\n```\n\n**⚠️ CRITICAL**: Never commit the private key to version control! Store it securely:\n- Local machine: `~/.ssh/clawsec-signing-private.pem` with `chmod 600`\n- CI/CD: GitHub Secrets, AWS Secrets Manager, or similar\n- Team: 1Password, Vault, or hardware security module (HSM)\n\n### Step 2: Package Your Skill\n\n```bash\n# Create skill package (tarball or zip)\ntar -czf my-skill-1.0.0.tar.gz -C skills/my-skill .\n\n# Or as a zip file\nzip -r my-skill-1.0.0.zip skills/my-skill/\n```\n\n### Step 3: Sign the Package\n\n```bash\n# Create detached Ed25519 signature\nopenssl dgst -sha512 -sign clawsec-signing-private.pem \\\n  -out my-skill-1.0.0.tar.gz.sig \\\n  my-skill-1.0.0.tar.gz\n\n# Verify the signature was created\nls -lh my-skill-1.0.0.tar.gz.sig\n# Should show a ~64-byte file\n```\n\n**Signature Format**: Detached Ed25519 signature, base64-encoded, stored in `.sig` file.\n\n### Step 4: Distribute Package + Signature\n\nDistribute **both** files together:\n- `my-skill-1.0.0.tar.gz` (the skill package)\n- `my-skill-1.0.0.tar.gz.sig` (the signature)\n\nUsers will verify the signature against your public key before installation.\n\n### Step 5: Publish Public Key\n\nShare your public key with users via:\n- **Pinned in repository**: Commit `clawsec-signing-public.pem` to your repo\n- **Website**: Host at `https://yoursite.com/clawsec-signing-public.pem`\n- **DNS TXT record**: Publish as base64-encoded TXT record\n- **Skill metadata**: Embed in `skill.json`\n\n---\n\n## For NanoClaw Agents: How to Verify Signatures\n\n### Quick Start\n\n```typescript\n// Verify a downloaded skill package before installation\nconst verification = await tools.clawsec_verify_skill_package({\n  packagePath: '/tmp/my-skill-1.0.0.tar.gz'\n  // signaturePath auto-detected as /tmp/my-skill-1.0.0.tar.gz.sig\n});\n\nconst result = JSON.parse(verification.content[0].text);\n\nif (!result.valid) {\n  console.log('⚠️ SIGNATURE VERIFICATION FAILED!');\n  console.log(`Reason: ${result.reason || result.error}`);\n  console.log('DO NOT install this package.');\n  return;\n}\n\nconsole.log(`✓ Signature valid (signer: ${result.signer})`);\nconsole.log(`Package hash: ${result.packageInfo.sha256}`);\nconsole.log('Safe to proceed with installation.');\n```\n\n### MCP Tool: `clawsec_verify_skill_package`\n\n**Parameters:**\n- `packagePath` (required): Absolute path to skill package (`.tar.gz`, `.tar`, `.tgz`, or `.zip`)\n- `signaturePath` (optional): Path to signature file (auto-detects `.sig` if omitted)\n\nPath policy:\n- Files must be under one of: `/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`\n- Symlinks are rejected\n- Signatures must use `.sig`\n\n**Returns:**\n```typescript\n{\n  success: boolean,           // Operation completed without errors\n  valid: boolean,             // Signature is cryptographically valid\n  recommendation: string,     // \"install\" | \"block\" | \"review\"\n  signer: string,             // \"clawsec\"\n  algorithm: \"Ed25519\",       // Signature algorithm\n  verifiedAt: string,         // ISO timestamp\n  packageInfo: {\n    size: number,             // Package file size in bytes\n    sha256: string            // SHA-256 hash of package\n  },\n  error?: string              // Error message if failed\n}\n```\n\n### Usage Patterns\n\n#### Pattern 1: Basic Pre-Installation Check\n\n```typescript\nasync function installSkill(packagePath: string) {\n  // Verify signature first\n  const verification = await tools.clawsec_verify_skill_package({ packagePath });\n  const result = JSON.parse(verification.content[0].text);\n\n  if (result.recommendation === 'block') {\n    throw new Error(`Cannot install: ${result.reason || result.error}`);\n  }\n\n  // Signature valid - proceed with extraction\n  extractPackage(packagePath, '/workspace/project/skills/');\n}\n```\n\n#### Pattern 2: Combined Security Checks\n\n```typescript\nasync function installSkillSafely(packagePath: string, skillName: string) {\n  // Step 1: Verify signature\n  const sigVerify = await tools.clawsec_verify_skill_package({ packagePath });\n  const sigResult = JSON.parse(sigVerify.content[0].text);\n\n  if (!sigResult.valid) {\n    throw new Error(`Signature invalid: ${sigResult.reason}`);\n  }\n\n  // Step 2: Check advisories\n  const advisory = await tools.clawsec_check_skill_safety({ skillName });\n  const advResult = JSON.parse(advisory.content[0].text);\n\n  if (!advResult.safe) {\n    throw new Error(`Known vulnerabilities: ${advResult.advisories.map(a => a.id).join(', ')}`);\n  }\n\n  // Both checks passed - safe to install\n  extractPackage(packagePath, '/workspace/project/skills/');\n  console.log(`✓ Installed ${skillName} (verified + no advisories)`);\n}\n```\n\n#### Pattern 3: Download and Verify Workflow\n\n```typescript\nasync function downloadAndInstallSkill(url: string) {\n  const packagePath = `/tmp/${Date.now()}-skill.tar.gz`;\n  const signaturePath = `${packagePath}.sig`;\n\n  // Download package\n  await fetch(url).then(r => r.arrayBuffer()).then(buf => {\n    fs.writeFileSync(packagePath, Buffer.from(buf));\n  });\n\n  // Download signature\n  await fetch(`${url}.sig`).then(r => r.text()).then(sig => {\n    fs.writeFileSync(signaturePath, sig);\n  });\n\n  // Verify before installation\n  const verification = await tools.clawsec_verify_skill_package({\n    packagePath,\n    signaturePath\n  });\n\n  const result = JSON.parse(verification.content[0].text);\n\n  if (!result.valid) {\n    fs.unlinkSync(packagePath);     // Delete tampered file\n    fs.unlinkSync(signaturePath);\n    throw new Error('Signature verification failed');\n  }\n\n  // Install verified package\n  extractPackage(packagePath, '/workspace/project/skills/');\n\n  // Cleanup\n  fs.unlinkSync(packagePath);\n  fs.unlinkSync(signaturePath);\n}\n```\n\n### Error Handling\n\n```typescript\nconst verification = await tools.clawsec_verify_skill_package({ packagePath });\nconst result = JSON.parse(verification.content[0].text);\n\n// Check result.success first (operation completed)\nif (!result.success) {\n  console.error('Verification operation failed:', result.error);\n  // Reasons: file not found, service unavailable, timeout\n  return;\n}\n\n// Then check result.valid (signature cryptographically valid)\nif (!result.valid) {\n  console.error('Invalid signature:', result.reason);\n  // Reasons: signature mismatch, tampered package, invalid format\n  return;\n}\n\n// Finally check recommendation\nswitch (result.recommendation) {\n  case 'install':\n    console.log('✓ Safe to install');\n    break;\n  case 'block':\n    console.error('⛔ Installation blocked');\n    break;\n  case 'review':\n    console.warn('⚠️ Manual review recommended');\n    break;\n}\n```\n\n---\n\n## Security Properties\n\n### What Signature Verification Prevents\n\n✅ **Prevents:**\n- **Tampering**: Detecting if package contents were modified after signing\n- **MITM attacks**: Detecting if package was swapped during download\n- **Malicious mirrors**: Ensuring package comes from trusted source\n- **Accidental corruption**: Detecting file corruption during transfer\n\n### What Signature Verification Does NOT Prevent\n\n❌ **Does Not Prevent:**\n- **Malicious signed packages**: If the publisher's key is compromised\n- **Zero-day vulnerabilities**: Bugs unknown to the publisher\n- **Social engineering**: Convincing users to trust malicious publishers\n- **Time-of-check-to-time-of-use**: Package modified after verification\n\n**Defense in Depth**: Combine signature verification with:\n1. **Advisory checking** (`clawsec_check_skill_safety`)\n2. **Code review** (manual inspection of skill code)\n3. **Sandboxing** (run skills in isolated containers)\n4. **Monitoring** (detect suspicious behavior at runtime)\n\n### Trust Model\n\nSignature verification relies on **trust in the public key**:\n\n```\n┌─────────────────────────────────────────────────┐\n│ You trust ClawSec's public key                  │\n│          ↓                                      │\n│ ClawSec signs package with private key          │\n│          ↓                                      │\n│ You verify signature with ClawSec's public key  │\n│          ↓                                      │\n│ Signature valid → Package is authentic         │\n└─────────────────────────────────────────────────┘\n```\n\n**Key Question**: How do you establish trust in the public key?\n- **Pinned in repository**: Public key committed to ClawSec repo (trust GitHub)\n- **HTTPS website**: Download from `https://clawsec.prompt.security/` (trust TLS/CA)\n- **Out-of-band verification**: Compare key fingerprint via phone, Signal, etc.\n- **Web of Trust**: Multiple trusted sources publish the same key\n\n---\n\n## Key Management\n\n### ClawSec's Pinned Public Key\n\n**Location**: `/workspace/project/skills/clawsec-nanoclaw/advisories/feed-signing-public.pem`\n\nThis is the **same key** used for advisory feed verification, providing a single trust anchor for all ClawSec security operations.\n\n**Key Fingerprint** (for manual verification):\n```bash\n# Compute fingerprint of pinned key\nopenssl pkey -pubin -in feed-signing-public.pem -outform DER | \\\n  openssl dgst -sha256 -binary | base64\n# Expected: <will be filled in after key generation>\n```\n\n### Public Key Policy\n\nThe verifier always uses the pinned ClawSec public key from this skill package.\nRuntime public-key overrides are intentionally not supported.\n\n### Key Rotation\n\nIf ClawSec's signing key is compromised or needs rotation:\n\n1. **Generate new keypair** (keep private key secure)\n2. **Sign all packages** with new key\n3. **Publish new public key** to all distribution channels\n4. **Update pinned key** in `/workspace/project/skills/clawsec-nanoclaw/advisories/`\n5. **Deprecate old key** after transition period (e.g., 90 days)\n\nDuring transition, support **dual signatures**:\n- `package.tar.gz.sig` (old key)\n- `package.tar.gz.sig2` (new key)\n\nAgents can verify with either key during the overlap period.\n\n---\n\n## Troubleshooting\n\n### Error: \"Signature file not found\"\n\n**Cause**: Missing `.sig` file or incorrect path.\n\n**Solution**:\n```bash\n# Check if signature exists\nls -l /tmp/skill.tar.gz.sig\n\n# If missing, download signature\ncurl -o /tmp/skill.tar.gz.sig https://example.com/skill.tar.gz.sig\n\n# Or specify explicit path\nclawsec_verify_skill_package({\n  packagePath: '/tmp/skill.tar.gz',\n  signaturePath: '/tmp/custom-signature.sig'\n})\n```\n\n### Error: \"Signature verification failed\"\n\n**Cause**: Package was tampered with, or signature doesn't match package.\n\n**Solution**:\n```bash\n# Re-download package and signature\ncurl -o /tmp/skill.tar.gz https://example.com/skill.tar.gz\ncurl -o /tmp/skill.tar.gz.sig https://example.com/skill.tar.gz.sig\n\n# Verify manually with OpenSSL\nopenssl dgst -sha512 -verify clawsec-signing-public.pem \\\n  -signature /tmp/skill.tar.gz.sig /tmp/skill.tar.gz\n# Should output: \"Verified OK\"\n```\n\n### Error: \"Invalid PEM format\"\n\n**Cause**: Public key file is corrupted or not in PEM format.\n\n**Solution**:\n```bash\n# Check public key format\nhead -1 /path/to/public-key.pem\n# Should output: \"-----BEGIN PUBLIC KEY-----\"\n\n# Re-download public key\ncurl -o clawsec-signing-public.pem \\\n  https://clawsec.prompt.security/clawsec-signing-public.pem\n```\n\n### Error: \"Package file not found\"\n\n**Cause**: Incorrect path or file doesn't exist.\n\n**Solution**:\n```bash\n# Use absolute paths (required)\nclawsec_verify_skill_package({\n  packagePath: '/tmp/skill.tar.gz'  // ✓ Absolute\n  // packagePath: './skill.tar.gz' // ✗ Relative (won't work)\n})\n\n# Verify file exists\nstat /tmp/skill.tar.gz\n```\n\n### Verification Times Out (>5s)\n\n**Cause**: Large package (>50MB) or slow disk I/O.\n\n**Solution**:\n```bash\n# Check package size\nls -lh /tmp/skill.tar.gz\n\n# For very large packages, verification can take time\n# Consider splitting into smaller skill modules\n```\n\n---\n\n## Appendix: Signature File Format\n\nClawSec uses **Ed25519 detached signatures** in raw binary format, base64-encoded.\n\n**File Structure**:\n```\nmy-skill-1.0.0.tar.gz.sig:\n  Line 1: base64-encoded signature (88 characters)\n```\n\n**Example**:\n```\nMEQCIDxyz...ABC123==\n```\n\n**Properties**:\n- Algorithm: Ed25519 (EdDSA with Curve25519)\n- Signature size: 64 bytes (88 characters base64)\n- Hash function: SHA-512 (internal to Ed25519)\n- Format: Raw binary, base64-encoded\n\n**Verification Algorithm**:\n1. Decode base64 signature → 64-byte binary\n2. Hash package with SHA-512\n3. Verify Ed25519 signature(hash, publicKey) → boolean\n\n---\n\n## References\n\n- [Ed25519 Specification (RFC 8032)](https://tools.ietf.org/html/rfc8032)\n- [OpenSSL Ed25519 Documentation](https://www.openssl.org/docs/man3.0/man7/Ed25519.html)\n- [ClawSec Security Architecture](https://clawsec.prompt.security/docs/architecture)\n- [Supply Chain Attack Prevention](https://owasp.org/www-community/attacks/Supply_Chain_Attack)\n\n---\n\n**Document Version**: 1.0.0\n**Last Updated**: 2026-02-25\n**Maintainer**: ClawSec Security Team\n\nFile v0.0.8:INSTALL.md\n\n# ClawSec for NanoClaw - Installation Guide\n\nThis guide shows how to add ClawSec security monitoring to your NanoClaw deployment.\n\n## Overview\n\nClawSec provides security advisory monitoring for NanoClaw through:\n- **MCP Tools**: Agents can check for vulnerabilities via `clawsec_check_advisories`\n- **Advisory Feed**: Automatic monitoring of https://clawsec.prompt.security/advisories/feed.json\n- **Signature Verification**: Ed25519-signed feeds ensure integrity\n- **Exploitability Context**: Advisories include exploitability score and rationale for triage\n\n## Prerequisites\n\n- NanoClaw >= 0.1.0\n- Node.js >= 18.0.0\n- Write access to NanoClaw installation directory\n\n## Installation Steps\n\n### 1. Copy Skill Files\n\nCopy the `clawsec-nanoclaw` skill directory to your NanoClaw installation:\n\n```bash\n# From the ClawSec repository\ncp -r skills/clawsec-nanoclaw /path/to/your/nanoclaw/skills/\n```\n\n### 2. Integrate MCP Tools\n\nAdd the ClawSec MCP tools to your NanoClaw container agent runner.\n\n**File**: `container/agent-runner/src/ipc-mcp-stdio.ts`\n\n```typescript\n// Add these imports at the top to register all ClawSec MCP tools:\n\n// Advisory tools: clawsec_check_advisories, clawsec_check_skill_safety,\n//                 clawsec_list_advisories, clawsec_refresh_cache\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/advisory-tools.js';\n\n// Signature verification: clawsec_verify_skill_package\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/signature-verification.js';\n\n// Integrity monitoring: clawsec_check_integrity, clawsec_approve_change,\n//                       clawsec_integrity_status, clawsec_verify_audit\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/integrity-tools.js';\n```\n\nEach file calls `server.tool()` directly to register its tools. The `server`,\n`writeIpcFile`, `TASKS_DIR`, and `groupFolder` variables must be available in\nthe scope where these files are imported (they are declared as ambient globals\nin each tool file).\n\n### 3. Integrate IPC Handlers\n\nAdd the host-side IPC handlers for ClawSec operations.\n\n**File**: `src/ipc.ts`\n\n```typescript\n// Add these imports at the top\nimport { handleAdvisoryIpc } from '../skills/clawsec-nanoclaw/host-services/ipc-handlers.js';\nimport { AdvisoryCacheManager } from '../skills/clawsec-nanoclaw/host-services/advisory-cache.js';\nimport { SkillSignatureVerifier } from '../skills/clawsec-nanoclaw/host-services/skill-signature-handler.js';\n\n// Initialize these once in host startup and pass through deps\nconst advisoryCacheManager = new AdvisoryCacheManager('/workspace/project/data', logger);\nconst signatureVerifier = new SkillSignatureVerifier();\n\n// In processTaskIpc switch:\ncase 'refresh_advisory_cache':\ncase 'verify_skill_signature':\n  await handleAdvisoryIpc(\n    data,\n    { advisoryCacheManager, signatureVerifier },\n    logger,\n    sourceGroup\n  );\n  break;\ndefault:\n  // existing task handling\n}\n```\n\n### 4. Start Advisory Cache Service\n\nAdd the advisory cache manager to your host services.\n\n**File**: `src/index.ts` (or your main entry point)\n\n```typescript\nimport { AdvisoryCacheManager } from '../skills/clawsec-nanoclaw/host-services/advisory-cache.js';\n\n// Start the service when your host process starts\nasync function main() {\n  // ... your existing initialization ...\n\n  // Initialize cache manager and prime it at startup\n  const advisoryCacheManager = new AdvisoryCacheManager('/workspace/project/data', logger);\n  await advisoryCacheManager.initialize();\n\n  // Recommended refresh cadence (6h)\n  setInterval(() => {\n    advisoryCacheManager.refresh().catch((error) => {\n      logger.error({ error }, 'Periodic advisory cache refresh failed');\n    });\n  }, 6 * 60 * 60 * 1000);\n\n  // ... rest of your startup ...\n}\n```\n\n### 5. Restart NanoClaw\n\nRestart your NanoClaw instance to load the new MCP tools and services:\n\n```bash\n# Stop NanoClaw\ndocker-compose down\n\n# Start with new configuration\ndocker-compose up -d\n```\n\n## Verification\n\nTest that ClawSec is working:\n\n### 1. Check MCP Tools Available\n\nFrom within a NanoClaw agent session, the following tools should be available:\n\n**Advisory Tools** (mcp-tools/advisory-tools.ts):\n- `clawsec_check_advisories` - Scan installed skills for vulnerabilities\n- `clawsec_check_skill_safety` - Pre-installation safety check\n- `clawsec_list_advisories` - List all advisories with filtering\n- `clawsec_refresh_cache` - Request immediate advisory cache refresh\n\n**Signature Verification** (mcp-tools/signature-verification.ts):\n- `clawsec_verify_skill_package` - Verify Ed25519 signature on skill packages\n  - Uses pinned ClawSec public key (no runtime key override)\n  - Accepts staged package/signature paths only under `/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`\n\n**Integrity Monitoring** (mcp-tools/integrity-tools.ts):\n- `clawsec_check_integrity` - Check protected files for unauthorized changes\n- `clawsec_approve_change` - Approve intentional file modification as new baseline\n- `clawsec_integrity_status` - View current baseline status\n- `clawsec_verify_audit` - Verify audit log hash chain integrity\n\n### 2. Test Advisory Checking\n\nAsk your NanoClaw agent:\n```\nCheck if any of my installed skills have security advisories\n```\n\nThe agent should use the `clawsec_check_advisories` tool and report results.\n\n### 3. Check Advisory Cache\n\nVerify the cache file was created:\n```bash\ncat /workspace/project/data/clawsec-advisory-cache.json\n```\n\nYou should see:\n- `feed`: Array of advisories\n- `fetchedAt`: Timestamp of last update\n- `verified`: Should be `true`\n- `publicKeyFingerprint`: SHA-256 fingerprint of the pinned signing key\n\n## Usage Examples\n\n### Agent Commands\n\nOnce installed, your NanoClaw agents can:\n\n**Check for vulnerabilities:**\n```\nScan my installed skills for security issues\n```\n\n**Pre-installation check:**\n```\nIs it safe to install skill-name@1.0.0?\n```\n\n**List all advisories:**\n```\nShow me all ClawSec security advisories\n```\n\n### Manual Tool Invocation\n\nYou can also call the MCP tools directly from agent code:\n\n```typescript\n// Check all installed skills\nconst result = await tools.clawsec_check_advisories({\n  installRoot: '/home/node/.claude/skills'\n});\n\n// Check specific skill before installation\nconst safetyCheck = await tools.clawsec_check_skill_safety({\n  skillName: 'risky-skill',\n  skillVersion: '1.0.0'\n});\n```\n\n## Configuration\n\n### Cache Location\n\nDefault: `/workspace/project/data/clawsec-advisory-cache.json`\n\nTo change, pass a different data directory path to `new AdvisoryCacheManager(dataDir, logger)`.\n\n### Refresh Interval\n\nDefault: 6 hours\n\nTo change, update the `setInterval(...)` duration (in milliseconds) in host startup.\n\n### Feed URL\n\nDefault: `https://clawsec.prompt.security/advisories/feed.json`\n\nTo use a mirror or custom feed, update `FEED_URL` in `skills/clawsec-nanoclaw/host-services/advisory-cache.ts`.\n\n## Platform-Specific Advisories\n\nClawSec advisories can target specific platforms:\n\n- **`platforms: [\"nanoclaw\"]`**: Only affects NanoClaw\n- **`platforms: [\"openclaw\"]`**: Only affects OpenClaw/MoltBot\n- **`platforms: [\"openclaw\", \"nanoclaw\"]`**: Affects both\n- **No `platforms` field**: Applies to all platforms\n\nPlatform metadata is preserved in advisory records and can be filtered by your policy layer.\n\n## Security\n\n### Signature Verification\n\nAll advisory feeds are Ed25519 signed. The public key is pinned in:\n```\nskills/clawsec-nanoclaw/advisories/feed-signing-public.pem\n```\n\nFeeds failing signature verification are rejected.\n\n### Cache Integrity\n\nThe advisory cache includes:\n- Cryptographic signature of feed contents\n- Verification status\n- Timestamp of last successful fetch\n\nNever manually edit the cache file - it will break signature verification.\n\n## Troubleshooting\n\n### Tools Not Appearing\n\n**Problem**: MCP tools not showing up in agent\n\n**Solution**:\n1. Check that you added the import and registration in `ipc-mcp-stdio.ts`\n2. Restart the container\n3. Check container logs for import errors\n\n### Cache Not Updating\n\n**Problem**: Advisory cache is empty or stale\n\n**Solution**:\n1. Check that `AdvisoryCacheManager.initialize()` is called in your host entry point\n2. Verify network access to `clawsec.prompt.security`\n3. Check host logs for fetch errors\n4. Manually trigger: `curl https://clawsec.prompt.security/advisories/feed.json`\n\n### Signature Verification Failing\n\n**Problem**: Cache shows `\"verified\": false`\n\n**Solution**:\n1. Ensure public key file exists at correct path\n2. Check file permissions (should be readable)\n3. Verify feed URL is correct (not using HTTP instead of HTTPS)\n4. Check for corrupted downloads (try clearing cache and refetching)\n\n### IPC Communication Issues\n\n**Problem**: Tools return errors about IPC\n\n**Solution**:\n1. Verify IPC handlers are registered in `src/ipc.ts`\n2. Check that IPC directory exists and is writable\n3. Ensure host process is running\n4. Check host logs for handler errors\n\n## Uninstallation\n\nTo remove ClawSec from NanoClaw:\n\n1. Remove MCP tool registration from `ipc-mcp-stdio.ts`\n2. Remove IPC handler registration from `src/ipc.ts`\n3. Remove `AdvisoryCacheManager` initialization from host entry point\n4. Delete the skill directory: `rm -rf skills/clawsec-nanoclaw`\n5. Delete the cache file: `rm /workspace/project/data/clawsec-advisory-cache.json`\n6. Restart NanoClaw\n\n## Support\n\n- **Documentation**: https://clawsec.prompt.security/\n- **Issues**: https://github.com/prompt-security/clawsec/issues\n- **Security**: security@prompt.security\n\n## License\n\nAGPL-3.0-or-later\n\n---\n\n**Questions?** Open an issue or check the main ClawSec documentation.\n\nFile v0.0.8:skill-card.md\n\n## Description: <br>\nUse when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[davida-ps](https://clawhub.ai/user/davida-ps) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators of NanoClaw deployments use this skill to check installed or requested skills against security advisories, verify signed packages, and monitor protected files for integrity drift. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Agents can exercise integrity-management authority over protected files such as CLAUDE.md and registered_groups.json. <br>\nMitigation: Install only when that authority is intended, restrict access to integrity MCP tools and IPC handlers, and require human approval before baseline changes. <br>\nRisk: Automatic restoration of protected files can overwrite changes before they are reviewed. <br>\nMitigation: Start with `autoRestore: false`, review `guardian/policy.json`, and preserve audit, patch, and quarantine data before cleanup. <br>\nRisk: Incorrect or stale baselines can make legitimate changes appear suspicious or make unwanted content the approved state. <br>\nMitigation: Review baseline approvals carefully and use documented approval workflows only after confirming the intended file contents. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/davida-ps/clawsec-nanoclaw) <br>\n- [ClawSec advisory feed](https://clawsec.prompt.security/advisories/feed.json) <br>\n- [Installation guide](artifact/INSTALL.md) <br>\n- [File integrity monitoring](artifact/docs/INTEGRITY.md) <br>\n- [Skill package signing and verification](artifact/docs/SKILL_SIGNING.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands, configuration] <br>\n**Output Format:** [Markdown with TypeScript and shell command examples; MCP tools return JSON-like results for advisory, signature, and integrity checks.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Outputs may include advisory matches, exploitability context, signature verification status, file integrity status, audit verification results, and remediation guidance.] <br>\n\n## Skill Version(s): <br>\n0.0.8 (source: server release evidence, SKILL.md frontmatter, CHANGELOG) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.0.8:guardian/policy.json\n\n{\n  \"version\": 1,\n  \"description\": \"NanoClaw file integrity monitoring policy\",\n  \"nanoclaw_version\": \"0.1.0\",\n  \"targets\": [\n    {\n      \"path\": \"/workspace/project/data/registered_groups.json\",\n      \"mode\": \"restore\",\n      \"priority\": \"critical\",\n      \"description\": \"Group registration config - prevents unauthorized group access\"\n    },\n    {\n      \"path\": \"/workspace/group/CLAUDE.md\",\n      \"mode\": \"restore\",\n      \"priority\": \"high\",\n      \"description\": \"Group-specific agent instructions\"\n    },\n    {\n      \"path\": \"/workspace/project/groups/global/CLAUDE.md\",\n      \"mode\": \"restore\",\n      \"priority\": \"high\",\n      \"description\": \"Global agent instructions shared across all groups\"\n    },\n    {\n      \"pattern\": \"/workspace/project/container/**/*.ts\",\n      \"mode\": \"alert\",\n      \"priority\": \"medium\",\n      \"description\": \"Container runtime code - alert on changes for awareness\"\n    },\n    {\n      \"pattern\": \"/workspace/project/host/**/*.ts\",\n      \"mode\": \"alert\",\n      \"priority\": \"medium\",\n      \"description\": \"Host process code - alert on changes for awareness\"\n    },\n    {\n      \"pattern\": \"/workspace/ipc/**/*\",\n      \"mode\": \"ignore\",\n      \"priority\": \"low\",\n      \"description\": \"IPC files change constantly - ignore\"\n    },\n    {\n      \"pattern\": \"/workspace/group/conversations/**/*\",\n      \"mode\": \"ignore\",\n      \"priority\": \"low\",\n      \"description\": \"Chat history - expected to change frequently\"\n    }\n  ],\n  \"notes\": [\n    \"Mode 'restore': Auto-restore file to approved baseline on drift + alert user\",\n    \"Mode 'alert': Alert user about drift but do not auto-restore\",\n    \"Mode 'ignore': No monitoring, file changes are expected\",\n    \"Patterns use glob syntax with ** for recursive matching\"\n  ]\n}\n\nFile v0.0.8:skill.json\n\n{\n  \"name\": \"clawsec-nanoclaw\",\n  \"version\": \"0.0.8\",\n  \"description\": \"ClawSec security suite for NanoClaw - Advisory feed monitoring, MCP tools for vulnerability checking, and Ed25519 signature verification for containerized WhatsApp bot agents\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"keywords\": [\n    \"security\",\n    \"nanoclaw\",\n    \"whatsapp-bot\",\n    \"mcp-tools\",\n    \"advisory\",\n    \"feed\",\n    \"threat-intel\",\n    \"containers\",\n    \"signature-verification\",\n    \"vulnerability-scanning\",\n    \"agents\",\n    \"ai\"\n  ],\n  \"platform\": \"nanoclaw\",\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"NanoClaw skill documentation\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and release notes\"\n      },\n      {\n        \"path\": \"INSTALL.md\",\n        \"required\": true,\n        \"description\": \"Installation guide for NanoClaw deployments\"\n      },\n      {\n        \"path\": \"mcp-tools/advisory-tools.ts\",\n        \"required\": true,\n        \"description\": \"MCP tools for advisory checking in container context\"\n      },\n      {\n        \"path\": \"host-services/advisory-cache.ts\",\n        \"required\": true,\n        \"description\": \"Host-side advisory cache manager with periodic feed fetching\"\n      },\n      {\n        \"path\": \"host-services/ipc-handlers.ts\",\n        \"required\": true,\n        \"description\": \"IPC handlers for MCP tool requests\"\n      },\n      {\n        \"path\": \"lib/signatures.ts\",\n        \"required\": true,\n        \"description\": \"Ed25519 signature verification utilities\"\n      },\n      {\n        \"path\": \"lib/local_file_io.ts\",\n        \"required\": true,\n        \"description\": \"Local file access helpers used by signature verification routines\"\n      },\n      {\n        \"path\": \"lib/advisories.ts\",\n        \"required\": true,\n        \"description\": \"Advisory matching and vulnerability detection\"\n      },\n      {\n        \"path\": \"lib/types.ts\",\n        \"required\": true,\n        \"description\": \"TypeScript type definitions\"\n      },\n      {\n        \"path\": \"lib/risk.ts\",\n        \"required\": true,\n        \"description\": \"Shared advisory risk evaluation logic for host and MCP tools\"\n      },\n      {\n        \"path\": \"advisories/feed-signing-public.pem\",\n        \"required\": true,\n        \"description\": \"Pinned Ed25519 public key for feed signature verification\"\n      },\n      {\n        \"path\": \"mcp-tools/signature-verification.ts\",\n        \"required\": true,\n        \"description\": \"Phase 1: MCP tool for skill package signature verification\"\n      },\n      {\n        \"path\": \"host-services/skill-signature-handler.ts\",\n        \"required\": true,\n        \"description\": \"Phase 1: Host-side signature verification service\"\n      },\n      {\n        \"path\": \"docs/SKILL_SIGNING.md\",\n        \"required\": true,\n        \"description\": \"Phase 1: Documentation for skill signing and verification\"\n      },\n      {\n        \"path\": \"mcp-tools/integrity-tools.ts\",\n        \"required\": true,\n        \"description\": \"Phase 2: MCP tools for file integrity monitoring\"\n      },\n      {\n        \"path\": \"host-services/integrity-handler.ts\",\n        \"required\": true,\n        \"description\": \"Phase 2: Host-side integrity monitoring service\"\n      },\n      {\n        \"path\": \"guardian/integrity-monitor.ts\",\n        \"required\": true,\n        \"description\": \"Phase 2: Core file integrity monitoring engine\"\n      },\n      {\n        \"path\": \"guardian/policy.json\",\n        \"required\": true,\n        \"description\": \"Phase 2: NanoClaw-specific file protection policy\"\n      },\n      {\n        \"path\": \"docs/INTEGRITY.md\",\n        \"required\": true,\n        \"description\": \"Phase 2: Documentation for file integrity monitoring\"\n      }\n    ]\n  },\n  \"capabilities\": [\n    \"Advisory feed monitoring from clawsec.prompt.security\",\n    \"MCP tools for agent-initiated vulnerability scans\",\n    \"Exploitability-aware advisory prioritization for agent environments\",\n    \"Pre-installation skill safety checks\",\n    \"Ed25519 signature verification for advisory feeds\",\n    \"Platform metadata preserved in advisory records for downstream filtering\",\n    \"Containerized agent support with IPC communication\"\n  ],\n  \"nanoclaw\": {\n    \"mcp_tools\": [\n      \"clawsec_check_advisories\",\n      \"clawsec_check_skill_safety\",\n      \"clawsec_list_advisories\",\n      \"clawsec_refresh_cache\",\n      \"clawsec_verify_skill_package\",\n      \"clawsec_check_integrity\",\n      \"clawsec_approve_change\",\n      \"clawsec_integrity_status\",\n      \"clawsec_verify_audit\"\n    ],\n    \"requires\": {\n      \"node\": \">=18.0.0\",\n      \"nanoclaw\": \">=0.1.0\"\n    },\n    \"integration\": {\n      \"mcp_tools_file\": \"container/agent-runner/src/ipc-mcp-stdio.ts\",\n      \"ipc_handlers_file\": \"src/ipc.ts\",\n      \"cache_location\": \"/workspace/project/data/clawsec-advisory-cache.json\"\n    }\n  }\n}\n\nArchive v0.0.7: 24 files, 63021 bytes\n\nFiles: CHANGELOG.md (3147b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (14939b), guardian/integrity-monitor.ts (21442b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (10995b), host-services/ipc-handlers.ts (3378b), host-services/skill-signature-handler.ts (7632b), INSTALL.md (9616b), lib/advisories.ts (14982b), lib/local_file_io.ts (316b), lib/risk.ts (2501b), lib/signatures.ts (14129b), lib/types.ts (6059b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (7025b), README.md (5239b), skill-card.md (2687b), skill.json (4948b), SKILL.md (8329b), test/security-hardening.test.mjs (7060b), _meta.json (135b)\n\nFile v0.0.7:SKILL.md\n\n---\nname: clawsec-nanoclaw\nversion: 0.0.7\ndescription: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot\n---\n\n# ClawSec for NanoClaw\n\nSecurity advisory monitoring that protects your WhatsApp bot from known vulnerabilities in skills and dependencies.\n\n## Overview\n\nClawSec provides MCP tools that check installed skills against a curated feed of security advisories. It prevents installation of vulnerable skills, includes exploitability context for triage, and alerts you to issues in existing ones.\n\n**Core principle:** Check before you install. Monitor what's running.\n\n## When to Use\n\nUse ClawSec tools when:\n- Installing a new skill (check safety first)\n- User asks \"are my skills secure?\"\n- Investigating suspicious behavior\n- Regular security audits\n- After receiving security notifications\n\nDo NOT use for:\n- Code review (use other tools)\n- Performance issues (different concern)\n- General debugging\n\n## MCP Tools Available\n\n### Pre-Installation Check\n\n```typescript\n// Before installing any skill\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'new-skill',\n  skillVersion: '1.0.0'  // optional\n});\n\nif (!safety.safe) {\n  // Show user the risks before proceeding\n  console.warn(`Security issues: ${safety.advisories.map(a => a.id)}`);\n}\n```\n\n### Security Audit\n\n```typescript\n// Check all installed skills (defaults to ~/.claude/skills in the container)\nconst result = await tools.clawsec_check_advisories({\n  installRoot: '/home/node/.claude/skills'  // optional\n});\n\nif (result.matches.some((m) =>\n  m.advisory.severity === 'critical' || m.advisory.exploitability_score === 'high'\n)) {\n  // Alert user immediately\n  console.error('Urgent advisories found!');\n}\n```\n\n### Browse Advisories\n\n```typescript\n// List advisories with filters\nconst advisories = await tools.clawsec_list_advisories({\n  severity: 'high',               // optional\n  exploitabilityScore: 'high'     // optional\n});\n```\n\n## Quick Reference\n\n| Task | Tool | Key Parameter |\n|------|------|---------------|\n| Pre-install check | `clawsec_check_skill_safety` | `skillName` |\n| Audit all skills | `clawsec_check_advisories` | `installRoot` (optional) |\n| Browse feed | `clawsec_list_advisories` | `severity`, `type`, `exploitabilityScore` (optional) |\n| Verify package signature | `clawsec_verify_skill_package` | `packagePath` |\n| Refresh advisory cache | `clawsec_refresh_cache` | (none) |\n| Check file integrity | `clawsec_check_integrity` | `mode`, `autoRestore` (optional) |\n| Approve file change | `clawsec_approve_change` | `path` |\n| View baseline status | `clawsec_integrity_status` | `path` (optional) |\n| Verify audit log | `clawsec_verify_audit` | (none) |\n\n## Common Patterns\n\n### Pattern 1: Safe Skill Installation\n\n```typescript\n// ALWAYS check before installing\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: userRequestedSkill\n});\n\nif (safety.safe) {\n  // Proceed with installation\n  await installSkill(userRequestedSkill);\n} else {\n  // Show user the risks and get confirmation\n  await showSecurityWarning(safety.advisories);\n  if (await getUserConfirmation()) {\n    await installSkill(userRequestedSkill);\n  }\n}\n```\n\n### Pattern 2: Periodic Security Check\n\n```typescript\n// Add to scheduled tasks\nschedule_task({\n  prompt: \"Check advisories using clawsec_check_advisories and alert when critical or high-exploitability matches appear\",\n  schedule_type: \"cron\",\n  schedule_value: \"0 9 * * *\"  // Daily at 9am\n});\n```\n\n### Pattern 3: User Security Query\n\n```\nUser: \"Are my skills secure?\"\n\nYou: I'll check installed skills for known vulnerabilities.\n[Use clawsec_check_advisories]\n\nResponse:\n✅ No urgent issues found.\n- 2 low-severity/low-exploitability advisories\n- All skills up to date\n```\n\n## Common Mistakes\n\n### ❌ Installing without checking\n```typescript\n// DON'T\nawait installSkill('untrusted-skill');\n```\n\n```typescript\n// DO\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'untrusted-skill'\n});\nif (safety.safe) await installSkill('untrusted-skill');\n```\n\n### ❌ Ignoring exploitability context\n```typescript\n// DON'T: Use severity only\nif (advisory.severity === 'high') {\n  notifyNow(advisory);\n}\n```\n\n```typescript\n// DO: Use exploitability + severity\nif (\n  advisory.exploitability_score === 'high' ||\n  advisory.severity === 'critical'\n) {\n  notifyNow(advisory);\n}\n```\n\n### ❌ Skipping critical severity\n```typescript\n// DON'T: Ignore high exploitability in medium severity advisories\nif (advisory.severity === 'critical') alert();\n```\n\n```typescript\n// DO: Prioritize exploitability and severity together\nif (advisory.exploitability_score === 'high' || advisory.severity === 'critical') {\n  // Alert immediately\n}\n```\n\n## Implementation Details\n\n**Feed Source**: https://clawsec.prompt.security/advisories/feed.json\n\nThis signed feed is consolidated. NanoClaw receives NVD CVEs, approved community advisories, and provisional GHSA-without-CVE advisories through the same default URL.\n\n**Update Frequency**: Every 6 hours (automatic)\n\n**Signature Verification**: Ed25519 signed feeds\n**Package Verification Policy**: pinned key only, bounded package/signature paths\n\n**Cache Location**: `/workspace/project/data/clawsec-advisory-cache.json`\n\nSee [INSTALL.md](./INSTALL.md) for setup and [docs/](./docs/) for advanced usage.\n\n## Real-World Impact\n\n- Prevents installation of skills with known RCE vulnerabilities\n- Alerts to supply chain attacks in dependencies\n- Provides actionable remediation steps\n- Zero false positives (curated feed only)\n\n\n## Release Artifact Verification\n\nFor standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.\n\n```bash\nset -euo pipefail\n\nSKILL_NAME=\"clawsec-nanoclaw\"\nVERSION=\"0.0.6\"\nREPO=\"prompt-security/clawsec\"\nTAG=\"${SKILL_NAME}-v${VERSION}\"\nBASE=\"https://github.com/${REPO}/releases/download/${TAG}\"\nZIP_NAME=\"${SKILL_NAME}-v${VERSION}.zip\"\nTMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TMP_DIR\"' EXIT\n\nRELEASE_PUBKEY_SHA256=\"711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\"\n\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TMP_DIR/checksums.sig\"\ncurl -fsSL \"$BASE/signing-public.pem\" -o \"$TMP_DIR/signing-public.pem\"\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/SKILL.md\" -o \"$TMP_DIR/SKILL.md\"\ncurl -fsSL \"$BASE/skill.json\" -o \"$TMP_DIR/skill.json\"\n\nACTUAL_PUBKEY_SHA256=\"$(openssl pkey -pubin -in \"$TMP_DIR/signing-public.pem\" -outform DER | shasum -a 256 | awk '{print $1}')\"\nif [ \"$ACTUAL_PUBKEY_SHA256\" != \"$RELEASE_PUBKEY_SHA256\" ]; then\n  echo \"ERROR: signing-public.pem fingerprint mismatch\" >&2\n  exit 1\nfi\n\nopenssl base64 -d -A -in \"$TMP_DIR/checksums.sig\" -out \"$TMP_DIR/checksums.sig.bin\"\nopenssl pkeyutl -verify -rawin -pubin \\\n  -inkey \"$TMP_DIR/signing-public.pem\" \\\n  -sigfile \"$TMP_DIR/checksums.sig.bin\" \\\n  -in \"$TMP_DIR/checksums.json\" >/dev/null\n\nhash_file() {\n  if command -v shasum >/dev/null 2>&1; then\n    shasum -a 256 \"$1\" | awk '{print $1}'\n  else\n    sha256sum \"$1\" | awk '{print $1}'\n  fi\n}\n\nverify_manifest_file() {\n  asset=\"$1\"\n  path=\"$2\"\n  expected=\"$(jq -r --arg asset \"$asset\" '.files[$asset].sha256 // empty' \"$TMP_DIR/checksums.json\")\"\n  if [ -z \"$expected\" ]; then\n    echo \"ERROR: checksums.json missing $asset\" >&2\n    exit 1\n  fi\n  actual=\"$(hash_file \"$path\")\"\n  if [ \"$actual\" != \"$expected\" ]; then\n    echo \"ERROR: checksum mismatch for $asset\" >&2\n    exit 1\n  fi\n}\n\nexpected_archive=\"$(jq -r '.archive.sha256 // empty' \"$TMP_DIR/checksums.json\")\"\nif [ -z \"$expected_archive\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\nactual_archive=\"$(hash_file \"$TMP_DIR/$ZIP_NAME\")\"\nif [ \"$actual_archive\" != \"$expected_archive\" ]; then\n  echo \"ERROR: archive checksum mismatch\" >&2\n  exit 1\nfi\n\nverify_manifest_file \"SKILL.md\" \"$TMP_DIR/SKILL.md\"\nverify_manifest_file \"skill.json\" \"$TMP_DIR/skill.json\"\n\necho \"Signed release manifest, archive, SKILL.md, and skill.json verified.\"\n```\n\nOnly install or extract the archive after this verification succeeds.\n\nFile v0.0.7:README.md\n\n# ClawSec for NanoClaw\n\nClawSec now supports NanoClaw, a containerized WhatsApp bot powered by Claude agents.\n\n## What Changed\n\n### Advisory Feed Monitoring\n- **NVD CVE Pipeline**: Now monitors for NanoClaw-specific keywords\n  - \"NanoClaw\", \"WhatsApp-bot\", \"baileys\" (WhatsApp library)\n  - Container-related vulnerabilities\n- **Platform Targeting**: Advisories can specify `platforms: [\"nanoclaw\"]` for NanoClaw-specific issues\n\n### Keywords Added\nThe CVE monitoring now includes:\n- `NanoClaw` - Direct product name\n- `WhatsApp-bot` - Core functionality\n- `baileys` - WhatsApp client library dependency\n\n## Advisory Schema\n\nAdvisories now support optional `platforms` field:\n\n```json\n{\n  \"id\": \"CVE-2026-XXXXX\",\n  \"platforms\": [\"openclaw\", \"nanoclaw\"],\n  \"severity\": \"critical\",\n  \"type\": \"prompt_injection\",\n  \"affected\": [\"skill-name@1.0.0\"],\n  \"action\": \"Update to version 1.0.1\"\n}\n```\n\n**Platform values:**\n- `\"openclaw\"` - Affects OpenClaw/ClawdBot/MoltBot only\n- `\"nanoclaw\"` - Affects NanoClaw only\n- `[\"openclaw\", \"nanoclaw\"]` - Affects both platforms\n- (empty/missing) - Applies to all platforms (backward compatible)\n\n## ClawSec NanoClaw Skill\n\nClawSec provides a complete security skill for NanoClaw deployments:\n\n**Location**: `skills/clawsec-nanoclaw/`\n\n### Features\n\n- **9 MCP Tools** for agents to manage security:\n  - `clawsec_check_advisories` - Scan installed skills for vulnerabilities\n  - `clawsec_check_skill_safety` - Pre-installation safety checks\n  - `clawsec_list_advisories` - Browse advisory feed with filtering\n  - `clawsec_refresh_cache` - \n\nArchive v0.0.6: 24 files, 60377 bytes\n\nFiles: CHANGELOG.md (2873b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (14939b), guardian/integrity-monitor.ts (21442b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (9848b), host-services/ipc-handlers.ts (3378b), host-services/skill-signature-handler.ts (7632b), INSTALL.md (9616b), lib/advisories.ts (11207b), lib/local_file_io.ts (316b), lib/risk.ts (2501b), lib/signatures.ts (14129b), lib/types.ts (6059b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (7025b), README.md (5239b), skill-card.md (2596b), skill.json (4948b), SKILL.md (8329b), test/security-hardening.test.mjs (2847b), _meta.json (135b)\n\nArchive v0.0.5: 23 files, 58791 bytes\n\nFiles: CHANGELOG.md (2577b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (14939b), guardian/integrity-monitor.ts (21442b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (9848b), host-services/ipc-handlers.ts (3378b), host-services/skill-signature-handler.ts (7632b), INSTALL.md (9616b), lib/advisories.ts (11207b), lib/local_file_io.ts (316b), lib/risk.ts (2501b), lib/signatures.ts (14129b), lib/types.ts (5831b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (7025b), README.md (5239b), skill.json (4948b), SKILL.md (8161b), test/security-hardening.test.mjs (2847b), _meta.json (135b)\n\nArchive v0.0.4: 23 files, 57697 bytes\n\nFiles: CHANGELOG.md (2307b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (14939b), guardian/integrity-monitor.ts (21442b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (9848b), host-services/ipc-handlers.ts (3378b), host-services/skill-signature-handler.ts (7632b), INSTALL.md (9616b), lib/advisories.ts (11207b), lib/local_file_io.ts (316b), lib/risk.ts (2501b), lib/signatures.ts (14129b), lib/types.ts (5831b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (7025b), README.md (5239b), skill.json (4948b), SKILL.md (5460b), test/security-hardening.test.mjs (2847b), _meta.json (135b)\n\nArchive v0.0.3: 22 files, 57227 bytes\n\nFiles: CHANGELOG.md (2009b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (14939b), guardian/integrity-monitor.ts (21442b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (9848b), host-services/ipc-handlers.ts (3378b), host-services/skill-signature-handler.ts (7632b), INSTALL.md (9616b), lib/advisories.ts (11207b), lib/risk.ts (2501b), lib/signatures.ts (14102b), lib/types.ts (5831b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (7025b), README.md (5239b), skill.json (4774b), SKILL.md (5460b), test/security-hardening.test.mjs (2847b), _meta.json (135b)\n\nArchive v0.0.2: 21 files, 54830 bytes\n\nFiles: CHANGELOG.md (1082b), docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (15123b), guardian/integrity-monitor.ts (20678b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11102b), host-services/integrity-handler.ts (9848b), host-services/ipc-handlers.ts (3480b), host-services/skill-signature-handler.ts (6254b), INSTALL.md (9379b), lib/advisories.ts (11207b), lib/risk.ts (2501b), lib/signatures.ts (14102b), lib/types.ts (5986b), mcp-tools/advisory-tools.ts (13249b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (5194b), README.md (5239b), skill.json (4774b), SKILL.md (5378b), _meta.json (135b)\n\nArchive v0.0.1: 19 files, 52729 bytes\n\nFiles: docs/INTEGRITY.md (13850b), docs/SKILL_SIGNING.md (15123b), guardian/integrity-monitor.ts (20678b), guardian/policy.json (1745b), host-services/advisory-cache.ts (11891b), host-services/integrity-handler.ts (9848b), host-services/ipc-handlers.ts (3480b), host-services/skill-signature-handler.ts (6254b), INSTALL.md (8702b), lib/advisories.ts (10548b), lib/signatures.ts (14102b), lib/types.ts (5885b), mcp-tools/advisory-tools.ts (12958b), mcp-tools/integrity-tools.ts (8318b), mcp-tools/signature-verification.ts (5194b), README.md (5185b), skill.json (4401b), SKILL.md (5155b), _meta.json (135b)","readmeExcerpt":"Skill: clawsec-nanoclaw Summary: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Tags: latest:0.0.10 Version history: v0.0.10 | 2026-06-23T08:22:27.400Z | user Release 0.0.10 via CI v0.0.8 | 2026-06-10T14:59:12.174Z | user Release 0.0.8 via CI v0.0.7 | 2026-06-07T10:06:18.365Z | user Release 0.0.7 via CI v0.0.6 ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y"},{"language":"typescript","snippet":"// Before installing any skill\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'new-skill',\n  skillVersion: '1.0.0'  // optional\n});\n\nif (!safety.safe) {\n  // Show user the risks before proceeding\n  console.warn(`Security issues: ${safety.advisories.map(a => a.id)}`);\n}"},{"language":"typescript","snippet":"// Check all installed skills (defaults to ~/.claude/skills in the container)\nconst result = await tools.clawsec_check_advisories({\n  installRoot: '/home/node/.claude/skills'  // optional\n});\n\nif (result.matches.some((m) =>\n  m.advisory.severity === 'critical' || m.advisory.exploitability_score === 'high'\n)) {\n  // Alert user immediately\n  console.error('Urgent advisories found!');\n}"},{"language":"typescript","snippet":"// List advisories with filters\nconst advisories = await tools.clawsec_list_advisories({\n  severity: 'high',               // optional\n  exploitabilityScore: 'high'     // optional\n});"},{"language":"typescript","snippet":"// ALWAYS check before installing\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: userRequestedSkill\n});\n\nif (safety.safe) {\n  // Proceed with installation\n  await installSkill(userRequestedSkill);\n} else {\n  // Show user the risks and get confirmation\n  await showSecurityWarning(safety.advisories);\n  if (await getUserConfirmation()) {\n    await installSkill(userRequestedSkill);\n  }\n}"},{"language":"typescript","snippet":"// Add to scheduled tasks\nschedule_task({\n  prompt: \"Check advisories using clawsec_check_advisories and alert when critical or high-exploitability matches appear\",\n  schedule_type: \"cron\",\n  schedule_value: \"0 9 * * *\"  // Daily at 9am\n});"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: clawsec-nanoclaw\nversion: 0.0.10\ndescription: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot\n---\n\n# ClawSec for NanoClaw\n\nSecurity advisory monitoring that protects your WhatsApp bot from known vulnerabilities in skills and dependencies.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y\n```\n\n## Overview\n\nClawSec provides MCP tools that check installed skills against a curated feed of security advisories. It prevents installation of vulnerable skills, includes exploitability context for triage, and alerts you to issues in existing ones.\n\n**Core principle:** Check before you install. Monitor what's running.\n\n## When to Use\n\nUse ClawSec tools when:\n- Installing a new skill (check safety first)\n- User asks \"are my skills secure?\"\n- Investigating suspicious behavior\n- Regular security audits\n- After receiving security notifications\n\nDo NOT use for:\n- Code review (use other tools)\n- Performance issues (different concern)\n- General debugging\n\n## MCP Tools Available\n\n### Pre-Installation Check\n\n```typescript\n// Before installing any skill\nconst safety = await tools.clawsec_check_skill_safety({\n  skillName: 'new-skill',\n  skillVersion: '1.0.0'  // optional\n});\n\nif (!safety.safe) {\n  // Show user the risks before proceeding\n  console.warn(`Security issues: ${safety.advisories.map(a => a.id)}`);\n}\n```\n\n### Security Audit\n\n```typescript\n// Check all installed skills (defaults to ~/.claude/skills in the container)\nconst result = await tools.clawsec_check_advisories({\n  installRoot: '/home/node/.claude/skills'  // optional\n});\n\nif (result.matches.some((m) =>\n  m.advisory.severity === 'critical' || m.advisory.exploitability_score === 'high'\n)) {\n  // Alert user immediately\n  console.error('Urgent advisories found!');\n}\n```\n\n### Browse Advisories\n\n```typescript\n// List advisories with filters\nconst advisories = await tools.clawsec_list_advisories({\n  severity: 'high',               // optional\n  exploitabilityScore: 'high'     // optional\n});\n```\n\n## Quick Reference\n\n| Task | Tool | Key Parameter |\n|------|------|---------------|\n| Pre-install check | `clawsec_check_skill_safety` | `skillName` |\n| Audit all skills | `clawsec_check_advisories` | `installRoot` (optional) |\n| Browse feed | `clawsec_list_advisories` | `severity`, `type`, `exploitabilityScore` (optional) |\n| Verify package signature | `clawsec_verify_skill_package` | `packagePath` |\n| Refresh advisory cache | `clawsec_refresh_cache` | (none) |\n| Check file integrity | `clawsec_check_integrity` | `mode`, `autoRestore` (optional) |\n| Approve file change | `clawsec_approve_change` | `path` |\n| View baseline status | `clawsec_integrity_status` | `path` (optional) |\n| Verify audit log | `clawsec_verify_audit` | (none) |\n\n## Common Patterns\n\n### Pattern 1: Safe Skill In"},{"path":"README.md","content":"# ClawSec for NanoClaw\n\nClawSec now supports NanoClaw, a containerized WhatsApp bot powered by Claude agents.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y\n```\n\n## What Changed\n\n### Advisory Feed Monitoring\n- **NVD CVE Pipeline**: Now monitors for NanoClaw-specific keywords\n  - \"NanoClaw\", \"WhatsApp-bot\", \"baileys\" (WhatsApp library)\n  - Container-related vulnerabilities\n- **Platform Targeting**: Advisories can specify `platforms: [\"nanoclaw\"]` for NanoClaw-specific issues\n\n### Keywords Added\nThe CVE monitoring now includes:\n- `NanoClaw` - Direct product name\n- `WhatsApp-bot` - Core functionality\n- `baileys` - WhatsApp client library dependency\n\n## Advisory Schema\n\nAdvisories now support optional `platforms` field:\n\n```json\n{\n  \"id\": \"CVE-2026-XXXXX\",\n  \"platforms\": [\"openclaw\", \"nanoclaw\"],\n  \"severity\": \"critical\",\n  \"type\": \"prompt_injection\",\n  \"affected\": [\"skill-name@1.0.0\"],\n  \"action\": \"Update to version 1.0.1\"\n}\n```\n\n**Platform values:**\n- `\"openclaw\"` - Affects OpenClaw/ClawdBot/MoltBot only\n- `\"nanoclaw\"` - Affects NanoClaw only\n- `[\"openclaw\", \"nanoclaw\"]` - Affects both platforms\n- (empty/missing) - Applies to all platforms (backward compatible)\n\n## ClawSec NanoClaw Skill\n\nClawSec provides a complete security skill for NanoClaw deployments:\n\n**Location**: `skills/clawsec-nanoclaw/`\n\n### Features\n\n- **9 MCP Tools** for agents to manage security:\n  - `clawsec_check_advisories` - Scan installed skills for vulnerabilities\n  - `clawsec_check_skill_safety` - Pre-installation safety checks\n  - `clawsec_list_advisories` - Browse advisory feed with filtering\n  - `clawsec_refresh_cache` - Request immediate advisory cache refresh\n  - `clawsec_verify_skill_package` - Verify Ed25519 signatures on skill packages\n  - `clawsec_check_integrity` - Check protected files for unauthorized changes\n  - `clawsec_approve_change` - Approve intentional file modifications\n  - `clawsec_integrity_status` - View file baseline status\n  - `clawsec_verify_audit` - Verify audit log hash chain\n\n- **Advisory Cache Service**: Host-managed feed fetching with signature validation\n- **Signature Verification**: Ed25519-signed feeds ensure integrity\n- **Exploitability Context**: Surfaces `exploitability_score` and rationale to reduce alert fatigue\n- **IPC Communication**: Container-safe host communication\n\n### Installation\n\n1. Copy the skill to your NanoClaw deployment:\n   ```bash\n   cp -r skills/clawsec-nanoclaw /path/to/nanoclaw/skills/\n   ```\n\n2. Follow the detailed guide at `skills/clawsec-nanoclaw/INSTALL.md`\n\n### Quick Integration\n\nThe skill integrates into three places:\n\n**1. MCP Tools** (container):\n```typescript\n// container/agent-runner/src/ipc-mcp-stdio.ts\nimport '../../../skills/clawsec-nanoclaw/mcp-tools/advisory-tools.js';\n```\n\n**2. IPC Handlers** (host):\n```typescript\n// src/ipc.ts\nimport { handleAdvisoryIpc } from '../skills/clawsec-na"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-nanoclaw\",\n  \"version\": \"0.0.10\",\n  \"publishedAt\": 1782202947400\n}"},{"path":"CHANGELOG.md","content":"# Changelog\n\n## [0.0.10] - 2026-06-23\n\n### Changed\n\n- Re-released skill metadata to run through the corrected normal tag publish pipeline without runtime changes.\n\n## [0.0.9] - 2026-06-22\n\n### Changed\n\n- Re-released skill metadata to publish through the updated ClawHub pipeline without runtime changes.\n\n## [0.0.8] - 2026-06-10\n\n### Changed\n\n- Re-released skill package with updated marketplace grouping and signed release trust artifacts for Vercel-compatible skill installation.\n\n## [0.0.7] - 2026-06-07\n\n### Security\n- Added comparator range support for NanoClaw advisory matching and fail-closed handling for malformed affected specifiers.\n- Added strict integrity IPC request ID validation and result path containment before host-side result writes.\n\n## [0.0.6] - 2026-05-24\n\n### Changed\n- Documented that NanoClaw consumes the consolidated signed advisory feed containing NVD CVEs, approved community advisories, and provisional GHSA-without-CVE records.\n- Added advisory metadata typing for GHSA lifecycle fields used by the consolidated feed.\n\n## [0.0.5] - 2026-05-14\n\n### Security\n- Added explicit signed release artifact verification instructions for standalone installs, including `checksums.json`, `checksums.sig`, `signing-public.pem`, archive hash verification, and `SKILL.md`/`skill.json` checksum checks.\n\nAll notable changes to the ClawSec NanoClaw compatibility skill will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.4] - 2026-04-16\n\n### Changed\n\n- Moved signature-related local file reads into `lib/local_file_io.ts` and kept network fetch logic isolated in `lib/signatures.ts`.\n\n### Security\n\n- Reduced static false-positive exfiltration signals by separating local file I/O and remote fetch code paths.\n\n## [0.0.3] - 2026-03-09\n\n### Security\n\n- Removed runtime public-key override from host-side package signature verification; verification now always uses the pinned ClawSec key.\n- Removed unsigned-package override path in host-side verification flow.\n- Added strict package/signature path policy for signature verification (`/tmp`, `/var/tmp`, `/workspace/ipc`, `/workspace/project/data`, `/workspace/project/tmp`, `/workspace/project/downloads`) with absolute-path, extension, symlink, and realpath boundary checks.\n- Added policy-bound path enforcement for integrity approvals: approvals now require normalized paths that are explicitly present in non-ignored integrity policy targets.\n\n### Changed\n\n- Updated MCP signature verification tool docs and behavior to align with bounded path policy and pinned-key-only verification.\n- Added regression tests for signature-verification and integrity-approval hardening invariants.\n\n## [0.0.2] - 2026-02-28\n\n### Added\n\n- Exploitability-aware advisory output in NanoClaw MCP tools (`exploitability_score`, `exploitability_rationale`).\n- Exploitability filtering (`expl"},{"path":"docs/INTEGRITY.md","content":"# File Integrity Monitoring for NanoClaw\n\nClawSec's file integrity monitoring protects critical NanoClaw configuration files from unauthorized modification.\n\n## What It Does\n\n**Protects Critical Files:**\n- `registered_groups.json` - Prevents unauthorized group access\n- `CLAUDE.md` files - Protects agent instructions\n- Container/host code - Alerts on unexpected changes\n\n**How It Works:**\n1. **Baseline**: Stores SHA-256 hashes of approved file states\n2. **Monitoring**: Periodically checks files for changes (drift)\n3. **Restore**: Automatically reverts critical files to approved versions\n4. **Audit**: Maintains tamper-evident log of all operations\n\n## Quick Start\n\n### Step 1: Verify Installation\n\nCheck that integrity monitoring is available:\n\n```bash\n# From container\nls /workspace/project/skills/clawsec-nanoclaw/guardian/\n# Should show: policy.json, integrity-monitor.ts\n```\n\n### Step 2: Initialize Baselines\n\nThe first time integrity monitoring runs, it creates baselines automatically:\n\n```typescript\n// Agent calls this (happens automatically on first integrity check)\nawait tools.clawsec_check_integrity();\n```\n\nThis creates:\n```\n/workspace/project/data/soul-guardian/\n├── baselines.json       # SHA-256 hashes\n├── approved/            # File snapshots\n│   ├── registered_groups.json\n│   └── CLAUDE.md\n├── patches/             # Diffs (empty initially)\n├── quarantine/          # Tampered files (empty initially)\n└── audit.jsonl          # Event log\n```\n\n### Step 3: Enable Scheduled Monitoring\n\nAdd to main group's scheduled tasks:\n\n```typescript\nschedule_task({\n  prompt: `\n    Check file integrity with clawsec_check_integrity.\n    If drift detected and files restored, send WhatsApp message:\n    \"⚠️ SECURITY ALERT\n\n    Unauthorized changes detected and automatically reverted:\n    [list files that were restored]\n\n    Review details: /workspace/project/data/soul-guardian/patches/\"\n  `,\n  schedule_type: 'cron',\n  schedule_value: '*/30 * * * *',  // Every 30 minutes\n  context_mode: 'isolated'\n});\n```\n\nThat's it! Integrity monitoring is now active.\n\n## MCP Tools Reference\n\n### 1. `clawsec_check_integrity`\n\nCheck all protected files for unauthorized changes.\n\n**Parameters:**\n- `mode` (optional): `'check'` (default) or `'status'`\n  - `check`: Detect drift and auto-restore\n  - `status`: View baselines only (no drift detection)\n- `autoRestore` (optional): `true` (default) or `false`\n  - If `false`, drift is detected but not auto-fixed\n\n**Output:**\n```json\n{\n  \"success\": true,\n  \"timestamp\": \"2026-02-25T12:00:00Z\",\n  \"drift_detected\": false,\n  \"files\": [\n    {\n      \"path\": \"/workspace/project/data/registered_groups.json\",\n      \"status\": \"ok\",\n      \"mode\": \"restore\",\n      \"expected_sha\": \"abc123...\",\n      \"found_sha\": \"abc123...\"\n    }\n  ],\n  \"summary\": {\n    \"total\": 3,\n    \"ok\": 3,\n    \"drifted\": 0,\n    \"restored\": 0,\n    \"alerted\": 0,\n    \"errors\": 0\n  }\n}\n```\n\n**Example:**\n```typescript\nconst result = await tools.clawsec_check_integrity();\n\nif (result.drift_de"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Skill: clawsec-nanoclaw Summary: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot Tags: latest:0.0.10 Version history: v0.0.10 | 2026-06-23T08:22:27.400Z | user Release 0.0.10 via CI v0.0.8 | 2026-06-10T14:59:12.174Z | user Release 0.0.8 via CI v0.0.7 | 2026-06-07T10:06:18.365Z | user Release 0.0.7 via CI v0.0.6","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1105,"uniquenessScore":50,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T22:38:56.374Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T22:38:56.374Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T07:41:32.468Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}