{"id":"f1ef2cd0-2d96-409d-8a12-9a8c07d7ba1f","entityType":"agent","slug":"clawhub-zw008-ai-guardian","name":"ai-guardian","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zw008-ai-guardian","canonicalPath":"/agent/clawhub-zw008-ai-guardian","generatedAt":"2026-10-10T10:56:23.960Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:04:33.876Z","emptyReason":null},"description":"Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts). Always use this skill for \"what local models are installed\", \"find shadow / unsanctioned AI models\", \"which model is loaded in VRAM\", \"scan this prompt for secrets/PII before sending\", \"stop secrets leaking into a local model\", \"block a prompt with an API key\", \"detect a jailbreak / prompt injection\", \"set a model allowlist / denylist\", \"detect a tampered / re-pulled model\", \"audit local LLM usage\", \"guard my llama.cpp / LM Studio / local vLLM endpoint\", or \"the complement to IGEL AI Armor\". Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices. Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:ai-guardian","sourceUrl":"https://clawhub.ai/zw008/ai-guardian","homepage":"https://clawhub.ai/zw008/skills/ai-guardian","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/zw008/ai-guardian","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/zw008/skills/ai-guardian","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"ai-guardian technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:04:33.876Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:04:33.876Z","emptyReason":null},"stars":null,"forks":null,"downloads":1571,"packageName":null,"latestVersion":"0.11.3","tractionLabel":"1.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:04:33.876Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T08:04:33.876Z","lastCrawledAt":"2026-10-10T08:04:33.876Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T08:04:33.876Z","lastVerifiedAt":null,"highlights":[{"version":"0.11.3","createdAt":"2026-09-15T05:45:41.277Z","changelog":"ai-guardian v0.11.3 - Removed the file: skill-card.md - No added features or functional changes in this release - The skill continues to provide local LLM observability and governance for Ollama, llama.cpp, LM Studio, and local vLLM environments","fileCount":7,"zipByteSize":18506},{"version":"0.11.2","createdAt":"2026-09-12T13:55:08.442Z","changelog":"- Documentation updated in SKILL.md, including Quick Install and plugin instructions. - References to OpenClaw plugin install updated from clawhub:@aiops-tools/ai-guardian to clawhub:@zw008/ai-guardian. - Skill card (skill-card.md) file removed. - No functional or tool changes; maintenance and documentation cleanup only.","fileCount":7,"zipByteSize":18492},{"version":"0.11.1","createdAt":"2026-09-12T09:54:22.390Z","changelog":"ai-guardian 0.11.1 - Updated documentation in SKILL.md to include plugin-based install instructions for OpenClaw. - Removed redundant or outdated skill-card.md documentation file.","fileCount":7,"zipByteSize":18529},{"version":"0.11.0","createdAt":"2026-09-12T00:43:22.085Z","changelog":"ai-guardian v0.11.0 - Updated metadata: now supports either the ai-guardian or uvx binaries, and requires fewer environment/config fields. - Removed legacy skill-card.md file. - No user-facing changes to tool functionality or compatibility.","fileCount":7,"zipByteSize":18281},{"version":"0.10.0","createdAt":"2026-08-13T00:28:22.697Z","changelog":"ai-guardian 0.10.0 - Added support for an additional tool, increasing the total to 21 MCP tools. - Updated documentation to reflect features for a transparent capture proxy (v0.2 roadmap). - Improved compatibility, feature summaries, and capability details in reference docs. - Removed obsolete skill-card.md documentation file.","fileCount":7,"zipByteSize":18244},{"version":"0.9.0","createdAt":"2026-08-10T06:55:02.547Z","changelog":"- Removed the skill-card.md file. - No feature or functional changes to the skill itself. - Documentation and metadata remain unchanged.","fileCount":7,"zipByteSize":18224},{"version":"0.8.0","createdAt":"2026-08-03T05:55:37.984Z","changelog":"ai-guardian 0.8.0 - Removed the skill-card.md file to streamline documentation. - No user-facing feature changes; all functionality remains the same.","fileCount":7,"zipByteSize":18222},{"version":"0.7.0","createdAt":"2026-08-02T09:37:38.077Z","changelog":"- Removed the file: skill-card.md - No changes to functionality or core documentation. - Internal cleanup: documentation file reduction.","fileCount":7,"zipByteSize":18186}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:ai-guardian","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:ai-guardian` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/ai-guardian before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:56:23.956Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-ai-guardian/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:04:33.876Z","emptyReason":null},"readme":"Skill: ai-guardian\n\nOwner: zw008\n\nSummary: Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts). Always use this skill for \"what local models are installed\", \"find shadow / unsanctioned AI models\", \"which model is loaded in VRAM\", \"scan this prompt for secrets/PII before sending\", \"stop secrets leaking into a local model\", \"block a prompt with an API key\", \"detect a jailbreak / prompt injection\", \"set a model allowlist / denylist\", \"detect a tampered / re-pulled model\", \"audit local LLM usage\", \"guard my llama.cpp / LM Studio / local vLLM endpoint\", or \"the complement to IGEL AI Armor\". Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices. Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.\n\nTags: agent-skills:0.1.0, ai-ops:0.1.0, latest:0.11.3, llm-security:0.1.0, mcp:0.1.0, ollama:0.1.0\n\nVersion history:\n\nv0.11.3 | 2026-09-15T05:45:41.277Z | auto\n\nai-guardian v0.11.3\n\n- Removed the file: skill-card.md\n- No added features or functional changes in this release\n- The skill continues to provide local LLM observability and governance for Ollama, llama.cpp, LM Studio, and local vLLM environments\n\nv0.11.2 | 2026-09-12T13:55:08.442Z | auto\n\n- Documentation updated in SKILL.md, including Quick Install and plugin instructions.\n- References to OpenClaw plugin install updated from clawhub:@aiops-tools/ai-guardian to clawhub:@zw008/ai-guardian.\n- Skill card (skill-card.md) file removed.\n- No functional or tool changes; maintenance and documentation cleanup only.\n\nv0.11.1 | 2026-09-12T09:54:22.390Z | auto\n\nai-guardian 0.11.1\n\n- Updated documentation in SKILL.md to include plugin-based install instructions for OpenClaw.\n- Removed redundant or outdated skill-card.md documentation file.\n\nv0.11.0 | 2026-09-12T00:43:22.085Z | auto\n\nai-guardian v0.11.0\n\n- Updated metadata: now supports either the ai-guardian or uvx binaries, and requires fewer environment/config fields.\n- Removed legacy skill-card.md file.\n- No user-facing changes to tool functionality or compatibility.\n\nv0.10.0 | 2026-08-13T00:28:22.697Z | auto\n\nai-guardian 0.10.0\n\n- Added support for an additional tool, increasing the total to 21 MCP tools.\n- Updated documentation to reflect features for a transparent capture proxy (v0.2 roadmap).\n- Improved compatibility, feature summaries, and capability details in reference docs.\n- Removed obsolete skill-card.md documentation file.\n\nv0.9.0 | 2026-08-10T06:55:02.547Z | auto\n\n- Removed the skill-card.md file.\n- No feature or functional changes to the skill itself.\n- Documentation and metadata remain unchanged.\n\nv0.8.0 | 2026-08-03T05:55:37.984Z | auto\n\nai-guardian 0.8.0\n\n- Removed the skill-card.md file to streamline documentation.\n- No user-facing feature changes; all functionality remains the same.\n\nv0.7.0 | 2026-08-02T09:37:38.077Z | auto\n\n- Removed the file: skill-card.md\n- No changes to functionality or core documentation.\n- Internal cleanup: documentation file reduction.\n\nv0.6.0 | 2026-07-21T09:39:54.701Z | auto\n\n## AI Guardian 0.6.0\n\n- Improved governance harness: risk-tier labels and budget guards are now more descriptive.\n- Clarified tooling docs and usage examples for all 20 tools; removed outdated references.\n- Updated risk-tier write tool logic for improved audit granularity.\n- Refined compatibility and safety notes for single-endpoint/local LLM usage.\n- Minor documentation cleanups; removed obsolete skill-card.md file.\n\nv0.5.0 | 2026-07-20T11:13:59.648Z | auto\n\nai-guardian 0.5.0\n\n- Removed the skill-card.md file from the project.\n- No user-facing or functional changes; project documentation maintenance only.\n\nv0.4.0 | 2026-07-19T03:50:06.185Z | auto\n\nai-guardian v0.4.0\n\n- Adds agent guardrails documentation (references/agent-guardrails.md)\n- New \"undo\" capability and tools (`undo_list`, `undo_apply`) added and documented\n- Expanded toolset: now 20 MCP tools with improved documentation and descriptions\n- Documentation reorganized and streamlined for clarity; removed legacy skill-card.md\n- Updated validation and compatibility notes, including tested Ollama version and scan logic guarantees\n\nv0.3.0 | 2026-07-17T05:56:07.173Z | auto\n\nai-guardian 0.3.0\n\n- Added support for local LLMs beyond Ollama: now covers llama.cpp (llama-server), LM Studio, and single-node vLLM endpoints.\n- Description and usage notes now reflect support for multiple local LLM serving backends.\n- Clarified provenance/drift detection: strong for Ollama/llama.cpp, weaker (ID-only) for LM Studio/vLLM.\n- \"inference-aiops\" referenced as the routing target for cluster/multi-node setups.\n- Removed deprecated skill-card.md file.\n\nv0.2.0 | 2026-07-13T13:09:11.372Z | auto\n\nVersion 0.2.0 of ai-guardian\n\n- Updated package install instructions to use ai-guardian-aiops.\n- Removed skill-card.md.\n- Updated documentation in SKILL.md and setup-guide.md for clarity and installation.\n- No changes to features or compatibility.\n\nv0.1.0 | 2026-07-12T13:13:37.706Z | auto\n\nAI Guardian 0.1.0 (Preview Release)\n\n- Initial preview release focused on governed observability and content governance for single-endpoint local LLMs running on Ollama.\n- Provides passive inventory, policy/provenance checks, VRAM/model status, and prompt scanning for secrets, PII, and jailbreaks.\n- Bundled governance harness enforces audit logging, policy, budgets, undo, and risk tiers; all write tools are governed and auditable.\n- Supports allowlist/denylist, guarded prompt routing, tamper detection, and anomaly reporting; observed usage is logged locally.\n- Designed for standalone use on MacOS/Linux with zero external dependencies; mock-validated only (no real-time proxy).\n\nArchive index:\n\nArchive v0.11.3: 7 files, 18506 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4251b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2755b), SKILL.md (16167b), _meta.json (131b)\n\nFile v0.11.3:SKILL.md\n\n---\nname: ai-guardian\nslug: ai-guardian\ndisplayName: \"AI Guardian\"\nsummary: \"Governed local-LLM observability: model policy, prompt scanner, capture proxy, 21 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/AI-Guardian\ntags: [aiops, mcp, governance, ai-guardian]\ndescription: >\n  Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts).\n  Always use this skill for \"what local models are installed\", \"find shadow / unsanctioned AI models\", \"which model is loaded in VRAM\", \"scan this prompt for secrets/PII before sending\", \"stop secrets leaking into a local model\", \"block a prompt with an API key\", \"detect a jailbreak / prompt injection\", \"set a model allowlist / denylist\", \"detect a tampered / re-pulled model\", \"audit local LLM usage\", \"guard my llama.cpp / LM Studio / local vLLM endpoint\", or \"the complement to IGEL AI Armor\".\n  Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices.\n  Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.\ninstaller:\n  kind: uv\n  package: ai-guardian\nargument-hint: \"[model name, a prompt to scan, or describe your local-LLM task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"ai-guardian\",\"uvx\"]},\"optional\":{\"env\":[\"AI_GUARDIAN_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/AI-Guardian\",\"emoji\":\"🛡️\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed local-LLM (Ollama) observability + content governance. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Every tool call is audited to a local SQLite DB at ~/.ai-guardian/audit.db (relocatable via AI_GUARDIAN_AIOPS_HOME); the OBSERVED local-LLM usage log is a SEPARATE DB at ~/.ai-guardian/usage.db.\n  Zero-config: ai-guardian defaults to the local Ollama at http://localhost:11434 with no token. Ollama endpoints usually run open on a trusted host, so a bearer token is OPTIONAL; when one is supplied it is stored ENCRYPTED in ~/.ai-guardian/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. The store is unlocked by a master password from AI_GUARDIAN_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var AI_GUARDIAN_<TARGET_NAME_UPPER>_TOKEN is still honoured as a fallback with a deprecation warning (migrate with 'ai-guardian secret migrate').\n  The prompt scanner is deterministic and offline (no I/O, no network); route-through guards (guarded_generate/observe_chat) call Ollama only if the prompt's risk band is below block_threshold AND the model is allowed. The raw prompt is never stored — only its length + redacted findings.\n  State-changing operations: remove_model (high, dry-run + double confirm at the CLI, undo re-pull); pull/unload/allowlist/denylist/pin/guarded writes are medium. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label).\n  Webhooks: none — no outbound network calls beyond the configured Ollama REST API.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: the scanner/policy/risk-band are deterministic offline logic; the core Ollama route-through (real generation + policy deny + undo capture) was exercised against a live Ollama 0.24.0 on 2026-07-13, while the remaining runtime API paths and the OpenAI-compatible dialects are exercised against mocked responses (see docs/VERIFICATION.md). Content governance is opt-in route-through in v0.1, a transparent capture proxy is v0.2 roadmap, and IGEL AI Armor interop is doc-level positioning.\n---\n\n# AI Guardian\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Ollama, IGEL, or any AI-security vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian) under the MIT license.\n\nGoverned observability + governance for **on-endpoint local LLMs (Ollama)** —\n**21 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a\nlocal unified audit log under `~/.ai-guardian/`, token/runaway budget guard,\nundo-token recording, and descriptive risk tiers. It is the\n**complement to IGEL AI Armor**: AI Armor governs *whether* a local model may run;\nai-guardian records *what it did* and gates *what leaves in the prompt*.\n\nOllama keeps **no queryable prompt history** (context is client-supplied each\nrequest), so ai-guardian observes on two fronts: **passive inventory / state\nauditing** over `/api/tags`, `/api/ps`, `/api/show`, `/api/version`; and **opt-in\nroute-through content governance** — a caller sends a prompt *through*\n`guarded_generate` / `observe_chat`, which scans + policy-gates + records it and\nonly then calls Ollama.\n\n> **Standalone**: the governance harness is bundled in the package\n> (`ai_guardian.governance`) — no external skill-family dependency. A\n> transparent capture proxy for other clients' traffic is v0.2 roadmap, and\n> IGEL AI Armor interop is doc-level positioning.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Inventory / state** | `list_models`, `running_models`, `model_details`, `server_status`, `vram_usage` | 5 | read |\n| **Policy / provenance** | `policy_view`, `model_provenance` | 2 | read |\n| **Content governance (read)** | `scan_prompt`, `usage_events`, `anomaly_report` | 3 | read |\n| **Model lifecycle** | `pull_model` (medium), `remove_model` (high), `unload_model` (medium) | 3 | write |\n| **Policy writes** | `set_model_allowlist`, `set_model_denylist`, `pin_model_digest` (all medium) | 3 | write |\n| **Route-through guard** | `guarded_generate`, `observe_chat` (medium) | 2 | write |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n`scan_prompt` is pure (no Ollama call). `guarded_generate` / `observe_chat` block\nwhen the prompt's risk band `>= block_threshold` (default `high`) **or** the model\nis disallowed; blocked calls never reach Ollama and are recorded as blocked.\n\n## Quick Install\n\n```bash\nuv tool install ai-guardian-aiops\nai-guardian doctor          # works zero-config against a local Ollama\nai-guardian init            # optional: endpoint(s) + optional token + model allowlist\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/ai-guardian\nopenclaw skills info ai-guardian          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Inventory local models and **spot shadow AI** (`list_models` / `anomaly_report`): unsanctioned models show `allowed:false`\n- **Scan a prompt before sending it** (`scan_prompt`): secrets / PII / source-code / jailbreak → a weighted risk band, no model call\n- **Stop secrets or PII leaking into a local model** (`guarded_generate` / `observe_chat`): scan + policy-gate + record, then run only if allowed\n- **Detect a tampered / re-pulled model** (`model_provenance`): current digest vs its pin → drift\n- Enforce which models may run (`set_model_allowlist` / `set_model_denylist`) and pin trusted digests (`pin_model_digest`)\n- Inspect VRAM residency (`running_models` / `vram_usage`) and audit observed usage (`usage_events`)\n\n**Do NOT use when** the target is a GPU inference **cluster** (multi-node serving) — that is a different tool in the AIops-tools line. Also not for hypervisors, storage appliances, backup products, container clusters, or network devices.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| On-endpoint local LLM (Ollama): scan prompts, shadow-AI, provenance, policy | **ai-guardian** (this skill) |\n| GPU inference **cluster** serving/ops | another AIops-tools skill for cluster serving |\n| Hypervisor / storage / backup / container / network ops | the matching AIops-tools skill |\n\n## Common Workflows\n\n### 1. Find and shut down shadow (unsanctioned) local models\n\n1. `ai-guardian doctor` → confirm the Ollama endpoint is reachable before you\n   conclude a fleet has \"no models\" when it really has no connectivity\n2. `ai-guardian overview` → endpoint status, model count, and what is loaded\n   right now\n3. `ai-guardian model list` (MCP: `list_models`) → every installed model with its\n   allow/deny verdict; anything `allowed:false` is shadow AI\n4. `ai-guardian guard anomalies` (MCP: `anomaly_report`) → a one-shot rollup of\n   shadow models + digest drift + high-risk / blocked prompts, so you can tell a\n   single stray pull from a pattern\n5. `ai-guardian model running` / `vram_usage` → is the shadow model merely\n   installed, or actually loaded and consuming VRAM right now?\n6. Tighten policy so it cannot recur: `set_model_allowlist([\"llama3.*\", \"qwen*\"])`\n   → future unsanctioned models are refused at `pull_model`. Reversible: the\n   prior list is captured as the undo descriptor\n7. Remove the offender: `ai-guardian model remove <model> --dry-run`, then re-run\n   without `--dry-run` → **high** risk, double confirmation, needs\n   `AI_GUARDIAN_AUDIT_APPROVED_BY`; the undo descriptor records a re-pull\n8. **Failure branch**: if the new allowlist turns out to be too tight and blocks\n   a sanctioned model, `ai-guardian undo list` → `undo apply <id>` restores the\n   **prior** list exactly. If a removal was wrong, replaying the undo re-pulls\n   the model — but the weights come from the registry, so confirm the digest\n   afterwards with workflow 3 rather than assuming it is bit-identical.\n\n### 2. Stop secrets and PII leaking into a local model\n\n1. `ai-guardian guard scan \"…text…\"` (MCP: `scan_prompt`) → a **pure** call, no\n   model involved: deterministic findings (secrets / PII / code / jailbreak) plus\n   a weighted risk band. Use it to pre-check content offline before it ever\n   reaches a model\n2. `ai-guardian guard policy` (MCP: `policy_view`) → confirm which models are\n   permitted and what the current thresholds are\n3. Route real calls through the guard:\n   `guarded_generate(model, prompt, block_threshold=\"high\")` → the guard scans,\n   records to the usage log, and **blocks before Ollama** if the risk band is\n   `>= high` or the model is disallowed\n4. `ai-guardian guard usage` (MCP: `usage_events(allowed=False)`) → review what\n   was caught. The raw prompt is **never stored** — only its length and redacted\n   findings, so reviewing the log cannot itself leak the secret\n5. `ai-guardian guard anomalies` → confirm the rate of blocked prompts is falling\n   after you educate the user or fix the calling integration\n6. **Failure branch**: route-through is **opt-in** — anything that calls Ollama\n   directly bypasses the guard entirely. If `usage_events` is suspiciously empty\n   while `running_models` shows activity, you are looking at un-routed traffic,\n   not a clean fleet. A transparent capture proxy is a v0.2 roadmap item; until\n   then, treat guard coverage as coverage of what was routed, and say so.\n\n### 3. Detect tampered or silently re-pulled model weights\n\n1. `ai-guardian model list` / `model_details <model>` → read the current digest\n   for the models you sanction\n2. `pin_model_digest(model, digest)` → pin the trusted digest once, while you\n   still trust it. Pinning after a suspected compromise pins the compromise\n3. Later (or on a schedule): `ai-guardian guard provenance` (MCP:\n   `model_provenance`) → any model whose current digest differs from its pin\n   reports `status: DRIFT` — re-pulled or tampered weights\n4. `usage_events` around the drift timestamp → was the drifted model used, and\n   for what, before you noticed?\n5. **Failure branch**: `DRIFT` is a statement about the digest, not about intent\n   — a legitimate upgrade drifts identically to tampering. Investigate before\n   removing: check whether a `pull_model` appears in the audit trail at\n   `~/.ai-guardian/audit.db`. If it does not, treat it as untrusted and remove\n   under workflow 1. Re-pin only once you have re-established what the digest\n   *should* be.\n\n### 4. Fleet hygiene review before a rollout\n\n1. `ai-guardian overview` → the endpoint's current state at a glance\n2. `ai-guardian model list` → the full inventory with allow/deny verdicts\n3. `ai-guardian guard provenance` → every pinned model still matching its digest\n4. `vram_usage` + `running_models` → what is resident and whether the endpoint\n   has headroom for the model you are about to roll out\n5. `unload_model <model>` → free VRAM from an idle model without removing it\n   (reversible in practice — it reloads on next use)\n6. `ai-guardian model pull <model>` → the pull is checked against the allowlist,\n   so an unsanctioned rollout is refused rather than merely logged\n7. `ai-guardian guard anomalies` → a clean rollup is the exit criterion for the\n   review\n8. **Failure branch**: if `pull_model` is refused, the model is not on the\n   allowlist — widen the policy deliberately with `set_model_allowlist`\n   (audited, reversible) rather than working around the guard. If the pull fails\n   on VRAM, `unload_model` an idle model first; the audit trail records the\n   failed attempt with `status=error` and no undo token.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the host and account you run it under (point it at a runtime the account\ncannot administer, or hand the agent only the scan/observe tools). There is no\nread-only switch, deny-rules file, or approval gate — content governance (the\nmodel allow/deny policy and the `guarded_generate` block threshold) is a\nseparate, product-level control that stays.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.ai-guardian/audit.db` (relocatable via `AI_GUARDIAN_AIOPS_HOME`): params, result, status, duration, and the risk tier. Observed local-LLM usage lives in a **separate** `~/.ai-guardian/usage.db`.\n- `AI_GUARDIAN_AUDIT_APPROVED_BY` / `AI_GUARDIAN_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `AI_GUARDIAN_RUNAWAY_MAX=0`.\n- `remove_model` supports `--dry-run` + double confirmation at the CLI and records an undo (re-pull); allowlist/denylist writes record an undo → the prior list.\n- The scanner is deterministic and offline; findings are redacted so a secret is never re-emitted.\n\n## References\n\n- `references/capabilities.md` — full 21-tool + endpoint reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, optional token, and connectivity\n\nFile v0.11.3:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"ai-guardian\",\n  \"version\": \"0.11.3\",\n  \"publishedAt\": 1789451141277\n}\n\nFile v0.11.3:references/agent-guardrails.md\n\n# Agent guardrails — running ai-guardian with a smaller / local model\n\nThere is a pleasing recursion here: ai-guardian governs local LLMs, and this page\nis about driving ai-guardian *with* one. The same weaknesses this tool exists to\nobserve — a model that answers confidently without checking, that cannot tell\n\"unknown\" from \"none\", that reports a truncated view as complete — are the ones\nyou will hit while operating it.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The host and account you run under.** Point the tool at a runtime the account\n  cannot administer — an Ollama daemon whose model store the user can't modify —\n  so a `remove_model` or `pull_model` fails at the runtime, the only place the\n  permission actually lives. A revoked permission cannot be argued around by a\n  model; a skill-side flag can.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`), or hand\n  it only the scan/observe tools.\n\nContent governance is different, and it stays: `guarded_generate` still scans and\ngates each prompt against the allow/deny model policy and the block threshold\nbefore the model runs. That is a product control over *what a model is asked to\ndo*, not an authorization gate over *which tools an agent may call*.\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.ai-guardian/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. Observed local-LLM usage lives in a separate `~/.ai-guardian/usage.db`. |\n| \"Don't invent a digest / version / license\" | A field the runtime cannot report comes back as `null`, never as `\"\"`. This is load-bearing: Ollama and llama.cpp expose a pinnable identity, while LM Studio and vLLM expose only a model id. |\n| \"Don't call it tampering when you just can't tell\" | `model_provenance` reports a pinned model with no obtainable digest as `unverifiable`, never as `DRIFT`. Only a digest that is present **and** different is drift. |\n| \"Tell me if the output was cut off\" | `usage_events` returns `{\"events\": [...], \"count\": N, \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured (one extra row is fetched), not guessed. An under-reported usage log otherwise looks exactly like an absence of risky prompts. |\n| \"Never log the prompt text itself\" | The route-through path stores only the prompt's length, its risk band, and the redacted findings. The raw prompt is never written to the usage log. |\n| \"Redact secrets before showing me\" | The scanner's findings are already redacted; matched secrets and PII are reported by type and location, not by value. |\n| \"Confirm before anything destructive\" | `remove_model` is high-risk, requires a `--dry-run`-able preview + double confirmation at the CLI, and captures the model manifest for an undo (re-pull). |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate ai-guardian, which observes and governs local LLM runtimes (Ollama,\nllama.cpp, LM Studio, vLLM) on this machine.\n\nTOOL USE\n- Before answering any question about which models are installed, running,\n  sanctioned, or what has been observed, you MUST call a tool. Never answer from\n  memory — you are not a reliable witness to the machine you are running on.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreachable runtime\n  means unknown state, not \"no models installed\".\n\nREPORTING WHAT CAN AND CANNOT BE KNOWN\n- A null digest means the runtime cannot identify the weights. Report that as\n  \"unverifiable\" — never as clean, and never as drift.\n- A null version or license means the API does not expose it, not that the model\n  has none.\n- If usage_events returns truncated: true, say so. Never conclude \"no risky\n  prompts were observed\" from a truncated log.\n- A shadow model is a model present but not sanctioned by policy. That is a\n  policy finding, not evidence of malice. Report what the policy says, not what\n  you infer about intent.\n- scan_prompt results are heuristic. A \"none\" risk band means no pattern matched,\n  which is not the same as \"this prompt is safe\". Say which one you mean.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not recommend removing a model on the basis of it being unsanctioned alone —\n  surface it and let a human decide. remove_model deletes local weights.\n- Do not confuse the identifier kinds: a model name (llama3:8b) carries a tag, a\n  base name (llama3) does not, and a digest identifies the weights. A pinned\n  digest belongs to an exact model name.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — `remove_model` deletes local model\nweights, and re-pulling them is a large download rather than a quick undo:\n\n```bash\n# e.g. point ai-guardian at a runtime/account that can't administer the model\n# store, or hand the agent only the scan/observe tools. Then:\nai-guardian doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport AI_GUARDIAN_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport AI_GUARDIAN_AUDIT_RATIONALE=\"removing unsanctioned model per policy review\"\n```\n\nContent governance is independent of all this: `guarded_generate` / `observe_chat`\nscan each prompt, gate it against the allow/deny model policy and the block\nthreshold, record it to the usage log, and only then call the model. That is what\nkeeps secrets and jailbreaks out of a local model regardless of how read vs write\nis controlled.\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model reports \"no drift\" for an unverifiable runtime.** Ask it to quote\n  the `status` field per model rather than summarising; `unverifiable` and `ok`\n  are visually similar in a rollup but mean opposite things about confidence.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` or\n  `anomaly_report` — they fold inventory, policy verdicts, and usage stats into\n  one call.\n- **The model ignores later tool results in a long context.** Ask about one model\n  at a time with `model_details` rather than dumping the whole inventory.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.3:references/capabilities.md\n\n# ai-guardian capabilities\n\n> 21 MCP tools (11 read, 8 write, 2 undo) over Ollama's REST API\n> (default `http://localhost:11434`, usually no auth). The scanner / policy /\n> risk-band are pure deterministic offline logic; the Ollama paths need live\n> verification.\n\n## Read tools (10)\n\n| Tool | Ollama endpoint / pure | Returns |\n|------|------------------------|---------|\n| `list_models` | `GET /api/tags` | per-model: name, digest, sizeBytes, family, parameterSize, quantization, modifiedAt, **allowed** (allow/deny verdict — shadow → `false`) |\n| `running_models` | `GET /api/ps` | per-loaded-model: name, digest, sizeVramBytes, expiresAt, allowed |\n| `model_details` | `POST /api/show` | model, license, family, parameterSize, quantization, capabilities[] |\n| `server_status` | `GET /api/version` | reachable, version (or error) |\n| `vram_usage` | `GET /api/ps` | loadedModels, totalVramBytes, budgetBytes, overBudget, models[] |\n| `policy_view` | pure (reads config) | allowedModels, deniedModels, pinnedDigests, note |\n| `model_provenance` | `GET /api/tags` + config | driftCount, pinnedCount, models[]{model, currentDigest, pinnedDigest, status: ok/DRIFT/unpinned} |\n| `scan_prompt` | **pure** (no model call) | riskBand, findingCount, byCategory, findings[]{category, kind, severity, preview(redacted)} |\n| `usage_events` | reads `usage.db` | count, events[] (filter by model / risk_level / allowed / since / limit) |\n| `anomaly_report` | `GET /api/tags` + `usage.db` | shadowModels[], digestDrift[], highRiskPrompts, blockedPrompts, totalObserved |\n\n## Write tools (8)\n\n| Tool | Risk | Ollama endpoint / effect | Undo / safety |\n|------|------|--------------------------|---------------|\n| `pull_model` | medium | `POST /api/pull` | **refused if it violates the deny/allow policy** |\n| `remove_model` | **high** | `DELETE /api/delete` | captures the model manifest; records an undo (`pull_model` re-pull); CLI `--dry-run` + double confirm |\n| `unload_model` | medium | `POST /api/generate` `keep_alive:0` | evict from VRAM; no undo |\n| `set_model_allowlist` | medium | writes `config.yaml` | undo → prior allowlist (immutable replace, not append) |\n| `set_model_denylist` | medium | writes `config.yaml` | undo → prior denylist (deny patterns always win) |\n| `pin_model_digest` | medium | writes `config.yaml` | pin a model's expected provenance digest; undo → prior pin |\n| `guarded_generate` | medium | scan → policy-gate → record → `POST /api/generate` if allowed | blocks when risk band `>= block_threshold` (default `high`) OR model disallowed; blocked never reaches Ollama; raw prompt never stored |\n| `observe_chat` | medium | scan → policy-gate → record → `POST /api/chat` if allowed | same, for OpenAI-style `[{role,content}]` messages |\n\n## The deterministic scanner (behind `scan_prompt` / the route-through guards)\n\nPure, offline, no network. Categories and weighted risk band:\n\n- **secrets** — AWS access key (`AKIA…`, critical), private-key blocks (critical),\n  GitHub token (critical), OpenAI `sk-…` (critical), Slack token (high), JWT\n  (high), Google API key (high), assigned `api_key=…` / high-entropy fallback\n  (medium).\n- **pii** — email (low), US SSN (high), credit card **with a Luhn check** (high).\n- **code_leak** — source/config heuristics (fires on >= 2 signals, medium).\n- **jailbreak** — ignore-instructions / DAN / developer-mode / system-prompt-leak\n  signatures (medium).\n- **risk band** — weighted sum (low=1, medium=3, high=7, critical=15); bands\n  low 0-2, medium 3-6, high 7-14, critical >=15 — and **any single critical\n  dominates**. Findings are **redacted** (short masked preview only).\n\n## Out of scope (by design)\n\n- GPU inference-**cluster** serving/ops (multi-node) — a different AIops-tools tool\n- Model training / fine-tuning\n- Non-Ollama local-LLM runtimes\n- ~~A transparent capture proxy for other clients' traffic~~ — **shipped**:\n  `ai-guardian proxy serve` (CLI-only; it blocks while listening, so an MCP tool\n  that started it would hang the caller). `proxy_guidance` composes the command\n  and states the caveat: it is a **chokepoint, not an enforcement boundary**\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n\nFile v0.11.3:references/cli-reference.md\n\n# ai-guardian CLI reference\n\n> The CLI is a convenience subset; the full 21-tool surface\n> is via MCP (`ai-guardian mcp`). Works zero-config against a local Ollama\n> (`http://localhost:11434`).\n\n## Setup & diagnostics\n\n```bash\nai-guardian init                      # interactive wizard: Ollama endpoint(s) + optional token + model allowlist\nai-guardian doctor [--skip-auth]      # config + policy summary + Ollama reachability (/api/version)\nai-guardian mcp                       # start the MCP server (stdio transport)\n```\n\n## Overview\n\n```bash\nai-guardian overview [--target <t>]   # models installed/running, shadow count, observed-usage stats\n```\n\n## Models (inventory + guarded lifecycle)\n\n```bash\nai-guardian model list [--target <t>]         # installed models with allow/deny verdicts\nai-guardian model running [--target <t>]      # loaded models (VRAM + expiry)\nai-guardian model details <model>             # license / parameters / capabilities\nai-guardian model pull <model>                # pull a model (refused if it violates policy)\nai-guardian model remove <model> [--dry-run]  # (high) delete a local model; dry-run + double confirm; undo re-pull\nai-guardian model unload <model>              # (medium) evict from VRAM (keep_alive:0)\n```\n\n## Guard (policy, provenance, prompt scanning, usage, anomalies)\n\n```bash\nai-guardian guard policy                      # current model allow/deny policy + digest pins\nai-guardian guard provenance [--target <t>]   # installed digests vs their pins (drift detection)\nai-guardian guard scan \"<text>\"               # deterministic scan → findings + risk band (no model call)\nai-guardian guard usage [--limit 50]          # query the observed-usage log\nai-guardian guard anomalies [--target <t>]    # rollup: shadow models, digest drift, high-risk + blocked prompts\n```\n\n## Secrets (encrypted store ~/.ai-guardian/secrets.enc)\n\nA bearer token is optional (rare for local Ollama).\n\n```bash\nai-guardian secret set <target> [--value <token>]  # store a token (hidden prompt if no --value)\nai-guardian secret list                            # names only — values never shown\nai-guardian secret rm <target>\nai-guardian secret migrate                         # import legacy plaintext .env (AI_GUARDIAN_<T>_TOKEN)\nai-guardian secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Common options & notes\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target, i.e. the local Ollama)\n- `--dry-run` (on `model remove`) — print the API call that would be made, change nothing\n- `model remove` requires two confirmations; set `AI_GUARDIAN_AUDIT_APPROVED_BY` (+ `AI_GUARDIAN_AUDIT_RATIONALE`) to record who/why on the audit row (optional)\n- The route-through guards (`guarded_generate` / `observe_chat`) are MCP-only; use `guard scan` on the CLI to pre-check text without a model call\n\nFile v0.11.3:references/setup-guide.md\n\n# ai-guardian setup & security guide\n\n> The scanner / policy / risk-band are deterministic offline logic; the Ollama\n> API paths need live verification (see `docs/VERIFICATION.md`).\n\n## 1. Install\n\n```bash\nuv tool install ai-guardian-aiops\n```\n\n## 2. Zero-config default\n\nai-guardian works **out of the box** against the local Ollama at\n`http://localhost:11434` with **no token** — Ollama endpoints usually run open on\na trusted host. You can go straight to:\n\n```bash\nai-guardian doctor        # Ollama reachability + policy summary\nai-guardian overview\n```\n\nRun `init` only if you want to name multiple endpoints, add a token, or set a\nmodel allowlist.\n\n## 3. Onboard (optional)\n\n```bash\nai-guardian init\n```\n\nThe wizard records (non-secret) connection details and the optional model policy\ninto `~/.ai-guardian/config.yaml`. If the endpoint requires a bearer token (rare\nfor local Ollama), it is stored **encrypted** into `~/.ai-guardian/secrets.enc`.\nExample config:\n\n```yaml\ntargets:\n  - name: local\n    host: localhost\n    port: 11434\n    scheme: http\n    verify_ssl: false          # self-signed HTTPS lab certs only\nallowed_models:                # shell globs; empty = allow-all\n  - \"llama3.*\"\n  - \"qwen*\"\ndenied_models: []              # deny patterns always win\npinned_digests: {}             # model -> expected provenance digest (drift detection)\n```\n\nThe **policy** (`allowed_models` / `denied_models` / `pinned_digests`) is\n**non-secret** config — it lives in `config.yaml`, not the encrypted store.\n\n## 4. Optional bearer token\n\nMost local Ollama setups need no token. If yours does:\n\n```bash\nai-guardian secret set local        # hidden prompt for the token\n```\n\nFor non-interactive use (MCP server / CI / cron), export the master password so\nthe encrypted store can be unlocked without a prompt:\n\n```bash\nexport AI_GUARDIAN_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n### Token security\n\n- A token is **never** written to disk in plaintext. It lives only in\n  `~/.ai-guardian/secrets.enc`, encrypted with Fernet (AES-128-CBC + HMAC), the\n  key derived from your master password via scrypt. Only a per-store random salt\n  and the ciphertext are on disk (chmod 600); the master password is never stored.\n- A legacy plaintext env var `AI_GUARDIAN_<TARGET_NAME_UPPER>_TOKEN` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `ai-guardian secret migrate` (it imports then renames the old `.env`).\n- The token is held only in memory and is never logged or echoed; exception text\n  is scrubbed of secret-shaped strings before being written to the audit log.\n\n## 5. Audit-annotation env vars (optional)\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement or the permission of the host/account you run it under. If you want the\naudit trail to record *who* ran a destructive op and *why*, set these; they are\nrecorded on the row, never required, and gate nothing:\n\n```bash\nexport AI_GUARDIAN_AUDIT_APPROVED_BY='you@example.com'\nexport AI_GUARDIAN_AUDIT_RATIONALE='decommissioning an unused model'\n```\n\n## Two separate SQLite databases\n\nState lives under `~/.ai-guardian/` (relocate the governance state with\n`AI_GUARDIAN_AIOPS_HOME`):\n\n- `audit.db` — the **governance audit log**: every ai-guardian *tool call*, with\n  risk tier and any approver/rationale.\n- `usage.db` — the **observed local-LLM usage log**: route-through prompts\n  (`guarded_generate` / `observe_chat`) with model, actor, prompt length, risk\n  band, redacted findings, and allowed/blocked. **The raw prompt is never stored.**\n- `undo.db` — inverse descriptors for reversible writes (e.g. `remove_model` →\n  re-pull, allowlist/denylist → prior list).\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops.\n\n## Verify\n\n```bash\nai-guardian doctor\n```\n\n`doctor` checks the config file, the model policy summary, the encrypted store and\nits permissions (if present), and (unless `--skip-auth`) Ollama reachability by\nhitting `/api/version`. It works with zero config, defaulting to the local Ollama.\n\nFile v0.11.3:skill-card.md\n\n## Description:\n\nai-guardian helps agents observe and govern local LLM endpoints by inventorying models, checking policy and provenance, scanning prompts for secrets, PII, code, and jailbreak signals, and routing allowed prompts through guarded generation.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use ai-guardian to inspect local LLM runtimes, detect shadow or drifted models, scan prompts before they reach a model, and audit observed local LLM usage. It is aimed at single-endpoint local runtimes such as Ollama, llama.cpp, LM Studio, and local vLLM, not multi-node inference clusters.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The release installs external code that the security evidence describes as unpinned.\n\nMitigation: Install only from a pinned and trusted package source and review the release before installation.\n\nRisk: Agent-exposed write tools can pull, unload, or delete local models without a built-in read-only or approval gate.\n\nMitigation: Prefer observe-only tool exposure or run against a runtime account that cannot administer the model store.\n\nRisk: Unauthenticated or remotely reachable model endpoints can broaden access to local model operations.\n\nMitigation: Keep model endpoints local or otherwise authenticated and avoid exposing unauthenticated endpoints remotely.\n\nRisk: Audit and observed-usage databases may contain sensitive operational records even when raw prompts are not stored.\n\nMitigation: Treat local ai-guardian state files as sensitive records and protect access to the user's home directory.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/ai-guardian)\n- [Project homepage](https://github.com/AIops-tools/AI-Guardian)\n- [capabilities.md](references/capabilities.md)\n- [cli-reference.md](references/cli-reference.md)\n- [setup-guide.md](references/setup-guide.md)\n- [agent-guardrails.md](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown or plain text with JSON tool results and shell command snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May invoke MCP tools and local CLI commands against configured local LLM endpoints.]\n\n## Skill Version(s):\n\n0.11.3 (source: evidence.release.version)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.2: 7 files, 18492 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4251b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2745b), SKILL.md (16167b), _meta.json (131b)\n\nFile v0.11.2:SKILL.md\n\n---\nname: ai-guardian\nslug: ai-guardian\ndisplayName: \"AI Guardian\"\nsummary: \"Governed local-LLM observability: model policy, prompt scanner, capture proxy, 21 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/AI-Guardian\ntags: [aiops, mcp, governance, ai-guardian]\ndescription: >\n  Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts).\n  Always use this skill for \"what local models are installed\", \"find shadow / unsanctioned AI models\", \"which model is loaded in VRAM\", \"scan this prompt for secrets/PII before sending\", \"stop secrets leaking into a local model\", \"block a prompt with an API key\", \"detect a jailbreak / prompt injection\", \"set a model allowlist / denylist\", \"detect a tampered / re-pulled model\", \"audit local LLM usage\", \"guard my llama.cpp / LM Studio / local vLLM endpoint\", or \"the complement to IGEL AI Armor\".\n  Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices.\n  Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.\ninstaller:\n  kind: uv\n  package: ai-guardian\nargument-hint: \"[model name, a prompt to scan, or describe your local-LLM task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"ai-guardian\",\"uvx\"]},\"optional\":{\"env\":[\"AI_GUARDIAN_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/AI-Guardian\",\"emoji\":\"🛡️\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed local-LLM (Ollama) observability + content governance. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Every tool call is audited to a local SQLite DB at ~/.ai-guardian/audit.db (relocatable via AI_GUARDIAN_AIOPS_HOME); the OBSERVED local-LLM usage log is a SEPARATE DB at ~/.ai-guardian/usage.db.\n  Zero-config: ai-guardian defaults to the local Ollama at http://localhost:11434 with no token. Ollama endpoints usually run open on a trusted host, so a bearer token is OPTIONAL; when one is supplied it is stored ENCRYPTED in ~/.ai-guardian/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. The store is unlocked by a master password from AI_GUARDIAN_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var AI_GUARDIAN_<TARGET_NAME_UPPER>_TOKEN is still honoured as a fallback with a deprecation warning (migrate with 'ai-guardian secret migrate').\n  The prompt scanner is deterministic and offline (no I/O, no network); route-through guards (guarded_generate/observe_chat) call Ollama only if the prompt's risk band is below block_threshold AND the model is allowed. The raw prompt is never stored — only its length + redacted findings.\n  State-changing operations: remove_model (high, dry-run + double confirm at the CLI, undo re-pull); pull/unload/allowlist/denylist/pin/guarded writes are medium. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label).\n  Webhooks: none — no outbound network calls beyond the configured Ollama REST API.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: the scanner/policy/risk-band are deterministic offline logic; the core Ollama route-through (real generation + policy deny + undo capture) was exercised against a live Ollama 0.24.0 on 2026-07-13, while the remaining runtime API paths and the OpenAI-compatible dialects are exercised against mocked responses (see docs/VERIFICATION.md). Content governance is opt-in route-through in v0.1, a transparent capture proxy is v0.2 roadmap, and IGEL AI Armor interop is doc-level positioning.\n---\n\n# AI Guardian\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Ollama, IGEL, or any AI-security vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian) under the MIT license.\n\nGoverned observability + governance for **on-endpoint local LLMs (Ollama)** —\n**21 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a\nlocal unified audit log under `~/.ai-guardian/`, token/runaway budget guard,\nundo-token recording, and descriptive risk tiers. It is the\n**complement to IGEL AI Armor**: AI Armor governs *whether* a local model may run;\nai-guardian records *what it did* and gates *what leaves in the prompt*.\n\nOllama keeps **no queryable prompt history** (context is client-supplied each\nrequest), so ai-guardian observes on two fronts: **passive inventory / state\nauditing** over `/api/tags`, `/api/ps`, `/api/show`, `/api/version`; and **opt-in\nroute-through content governance** — a caller sends a prompt *through*\n`guarded_generate` / `observe_chat`, which scans + policy-gates + records it and\nonly then calls Ollama.\n\n> **Standalone**: the governance harness is bundled in the package\n> (`ai_guardian.governance`) — no external skill-family dependency. A\n> transparent capture proxy for other clients' traffic is v0.2 roadmap, and\n> IGEL AI Armor interop is doc-level positioning.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Inventory / state** | `list_models`, `running_models`, `model_details`, `server_status`, `vram_usage` | 5 | read |\n| **Policy / provenance** | `policy_view`, `model_provenance` | 2 | read |\n| **Content governance (read)** | `scan_prompt`, `usage_events`, `anomaly_report` | 3 | read |\n| **Model lifecycle** | `pull_model` (medium), `remove_model` (high), `unload_model` (medium) | 3 | write |\n| **Policy writes** | `set_model_allowlist`, `set_model_denylist`, `pin_model_digest` (all medium) | 3 | write |\n| **Route-through guard** | `guarded_generate`, `observe_chat` (medium) | 2 | write |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n`scan_prompt` is pure (no Ollama call). `guarded_generate` / `observe_chat` block\nwhen the prompt's risk band `>= block_threshold` (default `high`) **or** the model\nis disallowed; blocked calls never reach Ollama and are recorded as blocked.\n\n## Quick Install\n\n```bash\nuv tool install ai-guardian-aiops\nai-guardian doctor          # works zero-config against a local Ollama\nai-guardian init            # optional: endpoint(s) + optional token + model allowlist\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/ai-guardian\nopenclaw skills info ai-guardian          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Inventory local models and **spot shadow AI** (`list_models` / `anomaly_report`): unsanctioned models show `allowed:false`\n- **Scan a prompt before sending it** (`scan_prompt`): secrets / PII / source-code / jailbreak → a weighted risk band, no model call\n- **Stop secrets or PII leaking into a local model** (`guarded_generate` / `observe_chat`): scan + policy-gate + record, then run only if allowed\n- **Detect a tampered / re-pulled model** (`model_provenance`): current digest vs its pin → drift\n- Enforce which models may run (`set_model_allowlist` / `set_model_denylist`) and pin trusted digests (`pin_model_digest`)\n- Inspect VRAM residency (`running_models` / `vram_usage`) and audit observed usage (`usage_events`)\n\n**Do NOT use when** the target is a GPU inference **cluster** (multi-node serving) — that is a different tool in the AIops-tools line. Also not for hypervisors, storage appliances, backup products, container clusters, or network devices.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| On-endpoint local LLM (Ollama): scan prompts, shadow-AI, provenance, policy | **ai-guardian** (this skill) |\n| GPU inference **cluster** serving/ops | another AIops-tools skill for cluster serving |\n| Hypervisor / storage / backup / container / network ops | the matching AIops-tools skill |\n\n## Common Workflows\n\n### 1. Find and shut down shadow (unsanctioned) local models\n\n1. `ai-guardian doctor` → confirm the Ollama endpoint is reachable before you\n   conclude a fleet has \"no models\" when it really has no connectivity\n2. `ai-guardian overview` → endpoint status, model count, and what is loaded\n   right now\n3. `ai-guardian model list` (MCP: `list_models`) → every installed model with its\n   allow/deny verdict; anything `allowed:false` is shadow AI\n4. `ai-guardian guard anomalies` (MCP: `anomaly_report`) → a one-shot rollup of\n   shadow models + digest drift + high-risk / blocked prompts, so you can tell a\n   single stray pull from a pattern\n5. `ai-guardian model running` / `vram_usage` → is the shadow model merely\n   installed, or actually loaded and consuming VRAM right now?\n6. Tighten policy so it cannot recur: `set_model_allowlist([\"llama3.*\", \"qwen*\"])`\n   → future unsanctioned models are refused at `pull_model`. Reversible: the\n   prior list is captured as the undo descriptor\n7. Remove the offender: `ai-guardian model remove <model> --dry-run`, then re-run\n   without `--dry-run` → **high** risk, double confirmation, needs\n   `AI_GUARDIAN_AUDIT_APPROVED_BY`; the undo descriptor records a re-pull\n8. **Failure branch**: if the new allowlist turns out to be too tight and blocks\n   a sanctioned model, `ai-guardian undo list` → `undo apply <id>` restores the\n   **prior** list exactly. If a removal was wrong, replaying the undo re-pulls\n   the model — but the weights come from the registry, so confirm the digest\n   afterwards with workflow 3 rather than assuming it is bit-identical.\n\n### 2. Stop secrets and PII leaking into a local model\n\n1. `ai-guardian guard scan \"…text…\"` (MCP: `scan_prompt`) → a **pure** call, no\n   model involved: deterministic findings (secrets / PII / code / jailbreak) plus\n   a weighted risk band. Use it to pre-check content offline before it ever\n   reaches a model\n2. `ai-guardian guard policy` (MCP: `policy_view`) → confirm which models are\n   permitted and what the current thresholds are\n3. Route real calls through the guard:\n   `guarded_generate(model, prompt, block_threshold=\"high\")` → the guard scans,\n   records to the usage log, and **blocks before Ollama** if the risk band is\n   `>= high` or the model is disallowed\n4. `ai-guardian guard usage` (MCP: `usage_events(allowed=False)`) → review what\n   was caught. The raw prompt is **never stored** — only its length and redacted\n   findings, so reviewing the log cannot itself leak the secret\n5. `ai-guardian guard anomalies` → confirm the rate of blocked prompts is falling\n   after you educate the user or fix the calling integration\n6. **Failure branch**: route-through is **opt-in** — anything that calls Ollama\n   directly bypasses the guard entirely. If `usage_events` is suspiciously empty\n   while `running_models` shows activity, you are looking at un-routed traffic,\n   not a clean fleet. A transparent capture proxy is a v0.2 roadmap item; until\n   then, treat guard coverage as coverage of what was routed, and say so.\n\n### 3. Detect tampered or silently re-pulled model weights\n\n1. `ai-guardian model list` / `model_details <model>` → read the current digest\n   for the models you sanction\n2. `pin_model_digest(model, digest)` → pin the trusted digest once, while you\n   still trust it. Pinning after a suspected compromise pins the compromise\n3. Later (or on a schedule): `ai-guardian guard provenance` (MCP:\n   `model_provenance`) → any model whose current digest differs from its pin\n   reports `status: DRIFT` — re-pulled or tampered weights\n4. `usage_events` around the drift timestamp → was the drifted model used, and\n   for what, before you noticed?\n5. **Failure branch**: `DRIFT` is a statement about the digest, not about intent\n   — a legitimate upgrade drifts identically to tampering. Investigate before\n   removing: check whether a `pull_model` appears in the audit trail at\n   `~/.ai-guardian/audit.db`. If it does not, treat it as untrusted and remove\n   under workflow 1. Re-pin only once you have re-established what the digest\n   *should* be.\n\n### 4. Fleet hygiene review before a rollout\n\n1. `ai-guardian overview` → the endpoint's current state at a glance\n2. `ai-guardian model list` → the full inventory with allow/deny verdicts\n3. `ai-guardian guard provenance` → every pinned model still matching its digest\n4. `vram_usage` + `running_models` → what is resident and whether the endpoint\n   has headroom for the model you are about to roll out\n5. `unload_model <model>` → free VRAM from an idle model without removing it\n   (reversible in practice — it reloads on next use)\n6. `ai-guardian model pull <model>` → the pull is checked against the allowlist,\n   so an unsanctioned rollout is refused rather than merely logged\n7. `ai-guardian guard anomalies` → a clean rollup is the exit criterion for the\n   review\n8. **Failure branch**: if `pull_model` is refused, the model is not on the\n   allowlist — widen the policy deliberately with `set_model_allowlist`\n   (audited, reversible) rather than working around the guard. If the pull fails\n   on VRAM, `unload_model` an idle model first; the audit trail records the\n   failed attempt with `status=error` and no undo token.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the host and account you run it under (point it at a runtime the account\ncannot administer, or hand the agent only the scan/observe tools). There is no\nread-only switch, deny-rules file, or approval gate — content governance (the\nmodel allow/deny policy and the `guarded_generate` block threshold) is a\nseparate, product-level control that stays.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.ai-guardian/audit.db` (relocatable via `AI_GUARDIAN_AIOPS_HOME`): params, result, status, duration, and the risk tier. Observed local-LLM usage lives in a **separate** `~/.ai-guardian/usage.db`.\n- `AI_GUARDIAN_AUDIT_APPROVED_BY` / `AI_GUARDIAN_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `AI_GUARDIAN_RUNAWAY_MAX=0`.\n- `remove_model` supports `--dry-run` + double confirmation at the CLI and records an undo (re-pull); allowlist/denylist writes record an undo → the prior list.\n- The scanner is deterministic and offline; findings are redacted so a secret is never re-emitted.\n\n## References\n\n- `references/capabilities.md` — full 21-tool + endpoint reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, optional token, and connectivity\n\nFile v0.11.2:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"ai-guardian\",\n  \"version\": \"0.11.2\",\n  \"publishedAt\": 1789221308442\n}\n\nFile v0.11.2:references/agent-guardrails.md\n\n# Agent guardrails — running ai-guardian with a smaller / local model\n\nThere is a pleasing recursion here: ai-guardian governs local LLMs, and this page\nis about driving ai-guardian *with* one. The same weaknesses this tool exists to\nobserve — a model that answers confidently without checking, that cannot tell\n\"unknown\" from \"none\", that reports a truncated view as complete — are the ones\nyou will hit while operating it.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The host and account you run under.** Point the tool at a runtime the account\n  cannot administer — an Ollama daemon whose model store the user can't modify —\n  so a `remove_model` or `pull_model` fails at the runtime, the only place the\n  permission actually lives. A revoked permission cannot be argued around by a\n  model; a skill-side flag can.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`), or hand\n  it only the scan/observe tools.\n\nContent governance is different, and it stays: `guarded_generate` still scans and\ngates each prompt against the allow/deny model policy and the block threshold\nbefore the model runs. That is a product control over *what a model is asked to\ndo*, not an authorization gate over *which tools an agent may call*.\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.ai-guardian/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. Observed local-LLM usage lives in a separate `~/.ai-guardian/usage.db`. |\n| \"Don't invent a digest / version / license\" | A field the runtime cannot report comes back as `null`, never as `\"\"`. This is load-bearing: Ollama and llama.cpp expose a pinnable identity, while LM Studio and vLLM expose only a model id. |\n| \"Don't call it tampering when you just can't tell\" | `model_provenance` reports a pinned model with no obtainable digest as `unverifiable`, never as `DRIFT`. Only a digest that is present **and** different is drift. |\n| \"Tell me if the output was cut off\" | `usage_events` returns `{\"events\": [...], \"count\": N, \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured (one extra row is fetched), not guessed. An under-reported usage log otherwise looks exactly like an absence of risky prompts. |\n| \"Never log the prompt text itself\" | The route-through path stores only the prompt's length, its risk band, and the redacted findings. The raw prompt is never written to the usage log. |\n| \"Redact secrets before showing me\" | The scanner's findings are already redacted; matched secrets and PII are reported by type and location, not by value. |\n| \"Confirm before anything destructive\" | `remove_model` is high-risk, requires a `--dry-run`-able preview + double confirmation at the CLI, and captures the model manifest for an undo (re-pull). |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate ai-guardian, which observes and governs local LLM runtimes (Ollama,\nllama.cpp, LM Studio, vLLM) on this machine.\n\nTOOL USE\n- Before answering any question about which models are installed, running,\n  sanctioned, or what has been observed, you MUST call a tool. Never answer from\n  memory — you are not a reliable witness to the machine you are running on.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreachable runtime\n  means unknown state, not \"no models installed\".\n\nREPORTING WHAT CAN AND CANNOT BE KNOWN\n- A null digest means the runtime cannot identify the weights. Report that as\n  \"unverifiable\" — never as clean, and never as drift.\n- A null version or license means the API does not expose it, not that the model\n  has none.\n- If usage_events returns truncated: true, say so. Never conclude \"no risky\n  prompts were observed\" from a truncated log.\n- A shadow model is a model present but not sanctioned by policy. That is a\n  policy finding, not evidence of malice. Report what the policy says, not what\n  you infer about intent.\n- scan_prompt results are heuristic. A \"none\" risk band means no pattern matched,\n  which is not the same as \"this prompt is safe\". Say which one you mean.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not recommend removing a model on the basis of it being unsanctioned alone —\n  surface it and let a human decide. remove_model deletes local weights.\n- Do not confuse the identifier kinds: a model name (llama3:8b) carries a tag, a\n  base name (llama3) does not, and a digest identifies the weights. A pinned\n  digest belongs to an exact model name.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — `remove_model` deletes local model\nweights, and re-pulling them is a large download rather than a quick undo:\n\n```bash\n# e.g. point ai-guardian at a runtime/account that can't administer the model\n# store, or hand the agent only the scan/observe tools. Then:\nai-guardian doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport AI_GUARDIAN_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport AI_GUARDIAN_AUDIT_RATIONALE=\"removing unsanctioned model per policy review\"\n```\n\nContent governance is independent of all this: `guarded_generate` / `observe_chat`\nscan each prompt, gate it against the allow/deny model policy and the block\nthreshold, record it to the usage log, and only then call the model. That is what\nkeeps secrets and jailbreaks out of a local model regardless of how read vs write\nis controlled.\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model reports \"no drift\" for an unverifiable runtime.** Ask it to quote\n  the `status` field per model rather than summarising; `unverifiable` and `ok`\n  are visually similar in a rollup but mean opposite things about confidence.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` or\n  `anomaly_report` — they fold inventory, policy verdicts, and usage stats into\n  one call.\n- **The model ignores later tool results in a long context.** Ask about one model\n  at a time with `model_details` rather than dumping the whole inventory.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.2:references/capabilities.md\n\n# ai-guardian capabilities\n\n> 21 MCP tools (11 read, 8 write, 2 undo) over Ollama's REST API\n> (default `http://localhost:11434`, usually no auth). The scanner / policy /\n> risk-band are pure deterministic offline logic; the Ollama paths need live\n> verification.\n\n## Read tools (10)\n\n| Tool | Ollama endpoint / pure | Returns |\n|------|------------------------|---------|\n| `list_models` | `GET /api/tags` | per-model: name, digest, sizeBytes, family, parameterSize, quantization, modifiedAt, **allowed** (allow/deny verdict — shadow → `false`) |\n| `running_models` | `GET /api/ps` | per-loaded-model: name, digest, sizeVramBytes, expiresAt, allowed |\n| `model_details` | `POST /api/show` | model, license, family, parameterSize, quantization, capabilities[] |\n| `server_status` | `GET /api/version` | reachable, version (or error) |\n| `vram_usage` | `GET /api/ps` | loadedModels, totalVramBytes, budgetBytes, overBudget, models[] |\n| `policy_view` | pure (reads config) | allowedModels, deniedModels, pinnedDigests, note |\n| `model_provenance` | `GET /api/tags` + config | driftCount, pinnedCount, models[]{model, currentDigest, pinnedDigest, status: ok/DRIFT/unpinned} |\n| `scan_prompt` | **pure** (no model call) | riskBand, findingCount, byCategory, findings[]{category, kind, severity, preview(redacted)} |\n| `usage_events` | reads `usage.db` | count, events[] (filter by model / risk_level / allowed / since / limit) |\n| `anomaly_report` | `GET /api/tags` + `usage.db` | shadowModels[], digestDrift[], highRiskPrompts, blockedPrompts, totalObserved |\n\n## Write tools (8)\n\n| Tool | Risk | Ollama endpoint / effect | Undo / safety |\n|------|------|--------------------------|---------------|\n| `pull_model` | medium | `POST /api/pull` | **refused if it violates the deny/allow policy** |\n| `remove_model` | **high** | `DELETE /api/delete` | captures the model manifest; records an undo (`pull_model` re-pull); CLI `--dry-run` + double confirm |\n| `unload_model` | medium | `POST /api/generate` `keep_alive:0` | evict from VRAM; no undo |\n| `set_model_allowlist` | medium | writes `config.yaml` | undo → prior allowlist (immutable replace, not append) |\n| `set_model_denylist` | medium | writes `config.yaml` | undo → prior denylist (deny patterns always win) |\n| `pin_model_digest` | medium | writes `config.yaml` | pin a model's expected provenance digest; undo → prior pin |\n| `guarded_generate` | medium | scan → policy-gate → record → `POST /api/generate` if allowed | blocks when risk band `>= block_threshold` (default `high`) OR model disallowed; blocked never reaches Ollama; raw prompt never stored |\n| `observe_chat` | medium | scan → policy-gate → record → `POST /api/chat` if allowed | same, for OpenAI-style `[{role,content}]` messages |\n\n## The deterministic scanner (behind `scan_prompt` / the route-through guards)\n\nPure, offline, no network. Categories and weighted risk band:\n\n- **secrets** — AWS access key (`AKIA…`, critical), private-key blocks (critical),\n  GitHub token (critical), OpenAI `sk-…` (critical), Slack token (high), JWT\n  (high), Google API key (high), assigned `api_key=…` / high-entropy fallback\n  (medium).\n- **pii** — email (low), US SSN (high), credit card **with a Luhn check** (high).\n- **code_leak** — source/config heuristics (fires on >= 2 signals, medium).\n- **jailbreak** — ignore-instructions / DAN / developer-mode / system-prompt-leak\n  signatures (medium).\n- **risk band** — weighted sum (low=1, medium=3, high=7, critical=15); bands\n  low 0-2, medium 3-6, high 7-14, critical >=15 — and **any single critical\n  dominates**. Findings are **redacted** (short masked preview only).\n\n## Out of scope (by design)\n\n- GPU inference-**cluster** serving/ops (multi-node) — a different AIops-tools tool\n- Model training / fine-tuning\n- Non-Ollama local-LLM runtimes\n- ~~A transparent capture proxy for other clients' traffic~~ — **shipped**:\n  `ai-guardian proxy serve` (CLI-only; it blocks while listening, so an MCP tool\n  that started it would hang the caller). `proxy_guidance` composes the command\n  and states the caveat: it is a **chokepoint, not an enforcement boundary**\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n\nFile v0.11.2:references/cli-reference.md\n\n# ai-guardian CLI reference\n\n> The CLI is a convenience subset; the full 21-tool surface\n> is via MCP (`ai-guardian mcp`). Works zero-config against a local Ollama\n> (`http://localhost:11434`).\n\n## Setup & diagnostics\n\n```bash\nai-guardian init                      # interactive wizard: Ollama endpoint(s) + optional token + model allowlist\nai-guardian doctor [--skip-auth]      # config + policy summary + Ollama reachability (/api/version)\nai-guardian mcp                       # start the MCP server (stdio transport)\n```\n\n## Overview\n\n```bash\nai-guardian overview [--target <t>]   # models installed/running, shadow count, observed-usage stats\n```\n\n## Models (inventory + guarded lifecycle)\n\n```bash\nai-guardian model list [--target <t>]         # installed models with allow/deny verdicts\nai-guardian model running [--target <t>]      # loaded models (VRAM + expiry)\nai-guardian model details <model>             # license / parameters / capabilities\nai-guardian model pull <model>                # pull a model (refused if it violates policy)\nai-guardian model remove <model> [--dry-run]  # (high) delete a local model; dry-run + double confirm; undo re-pull\nai-guardian model unload <model>              # (medium) evict from VRAM (keep_alive:0)\n```\n\n## Guard (policy, provenance, prompt scanning, usage, anomalies)\n\n```bash\nai-guardian guard policy                      # current model allow/deny policy + digest pins\nai-guardian guard provenance [--target <t>]   # installed digests vs their pins (drift detection)\nai-guardian guard scan \"<text>\"               # deterministic scan → findings + risk band (no model call)\nai-guardian guard usage [--limit 50]          # query the observed-usage log\nai-guardian guard anomalies [--target <t>]    # rollup: shadow models, digest drift, high-risk + blocked prompts\n```\n\n## Secrets (encrypted store ~/.ai-guardian/secrets.enc)\n\nA bearer token is optional (rare for local Ollama).\n\n```bash\nai-guardian secret set <target> [--value <token>]  # store a token (hidden prompt if no --value)\nai-guardian secret list                            # names only — values never shown\nai-guardian secret rm <target>\nai-guardian secret migrate                         # import legacy plaintext .env (AI_GUARDIAN_<T>_TOKEN)\nai-guardian secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Common options & notes\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target, i.e. the local Ollama)\n- `--dry-run` (on `model remove`) — print the API call that would be made, change nothing\n- `model remove` requires two confirmations; set `AI_GUARDIAN_AUDIT_APPROVED_BY` (+ `AI_GUARDIAN_AUDIT_RATIONALE`) to record who/why on the audit row (optional)\n- The route-through guards (`guarded_generate` / `observe_chat`) are MCP-only; use `guard scan` on the CLI to pre-check text without a model call\n\nFile v0.11.2:references/setup-guide.md\n\n# ai-guardian setup & security guide\n\n> The scanner / policy / risk-band are deterministic offline logic; the Ollama\n> API paths need live verification (see `docs/VERIFICATION.md`).\n\n## 1. Install\n\n```bash\nuv tool install ai-guardian-aiops\n```\n\n## 2. Zero-config default\n\nai-guardian works **out of the box** against the local Ollama at\n`http://localhost:11434` with **no token** — Ollama endpoints usually run open on\na trusted host. You can go straight to:\n\n```bash\nai-guardian doctor        # Ollama reachability + policy summary\nai-guardian overview\n```\n\nRun `init` only if you want to name multiple endpoints, add a token, or set a\nmodel allowlist.\n\n## 3. Onboard (optional)\n\n```bash\nai-guardian init\n```\n\nThe wizard records (non-secret) connection details and the optional model policy\ninto `~/.ai-guardian/config.yaml`. If the endpoint requires a bearer token (rare\nfor local Ollama), it is stored **encrypted** into `~/.ai-guardian/secrets.enc`.\nExample config:\n\n```yaml\ntargets:\n  - name: local\n    host: localhost\n    port: 11434\n    scheme: http\n    verify_ssl: false          # self-signed HTTPS lab certs only\nallowed_models:                # shell globs; empty = allow-all\n  - \"llama3.*\"\n  - \"qwen*\"\ndenied_models: []              # deny patterns always win\npinned_digests: {}             # model -> expected provenance digest (drift detection)\n```\n\nThe **policy** (`allowed_models` / `denied_models` / `pinned_digests`) is\n**non-secret** config — it lives in `config.yaml`, not the encrypted store.\n\n## 4. Optional bearer token\n\nMost local Ollama setups need no token. If yours does:\n\n```bash\nai-guardian secret set local        # hidden prompt for the token\n```\n\nFor non-interactive use (MCP server / CI / cron), export the master password so\nthe encrypted store can be unlocked without a prompt:\n\n```bash\nexport AI_GUARDIAN_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n### Token security\n\n- A token is **never** written to disk in plaintext. It lives only in\n  `~/.ai-guardian/secrets.enc`, encrypted with Fernet (AES-128-CBC + HMAC), the\n  key derived from your master password via scrypt. Only a per-store random salt\n  and the ciphertext are on disk (chmod 600); the master password is never stored.\n- A legacy plaintext env var `AI_GUARDIAN_<TARGET_NAME_UPPER>_TOKEN` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `ai-guardian secret migrate` (it imports then renames the old `.env`).\n- The token is held only in memory and is never logged or echoed; exception text\n  is scrubbed of secret-shaped strings before being written to the audit log.\n\n## 5. Audit-annotation env vars (optional)\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement or the permission of the host/account you run it under. If you want the\naudit trail to record *who* ran a destructive op and *why*, set these; they are\nrecorded on the row, never required, and gate nothing:\n\n```bash\nexport AI_GUARDIAN_AUDIT_APPROVED_BY='you@example.com'\nexport AI_GUARDIAN_AUDIT_RATIONALE='decommissioning an unused model'\n```\n\n## Two separate SQLite databases\n\nState lives under `~/.ai-guardian/` (relocate the governance state with\n`AI_GUARDIAN_AIOPS_HOME`):\n\n- `audit.db` — the **governance audit log**: every ai-guardian *tool call*, with\n  risk tier and any approver/rationale.\n- `usage.db` — the **observed local-LLM usage log**: route-through prompts\n  (`guarded_generate` / `observe_chat`) with model, actor, prompt length, risk\n  band, redacted findings, and allowed/blocked. **The raw prompt is never stored.**\n- `undo.db` — inverse descriptors for reversible writes (e.g. `remove_model` →\n  re-pull, allowlist/denylist → prior list).\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops.\n\n## Verify\n\n```bash\nai-guardian doctor\n```\n\n`doctor` checks the config file, the model policy summary, the encrypted store and\nits permissions (if present), and (unless `--skip-auth`) Ollama reachability by\nhitting `/api/version`. It works with zero config, defaulting to the local Ollama.\n\nFile v0.11.2:skill-card.md\n\n## Description:\n\nai-guardian helps agents audit and govern single-endpoint local LLM use with model inventory, policy checks, prompt scanning, route-through controls, usage logs, VRAM state, and provenance drift reporting.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and local AI operators use this skill to inspect local model inventory, identify unsanctioned or drifted models, scan prompts for sensitive data or jailbreak patterns, and route approved prompts through guard controls.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can exercise local model administration powers on the configured runtime.\n\nMitigation: Run it with an unprivileged or observe-only setup where possible, and expose write tools only when model lifecycle or policy changes are explicitly needed.\n\nRisk: Installation and package identity controls are unclear in the security evidence.\n\nMitigation: Verify the package name, version, and publisher before installation, and pin the release used by the agent environment.\n\nRisk: Proxy and non-Ollama support claims are unclear in the security evidence.\n\nMitigation: Treat non-Ollama and proxy workflows as requiring local validation until the publisher reconciles the documentation.\n\nRisk: Route-through prompt governance only covers traffic that is actually sent through the guard.\n\nMitigation: Interpret usage logs as coverage of routed traffic, and do not treat an empty usage log as proof that direct runtime traffic did not occur.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/zw008/skills/ai-guardian)\n- [AI Guardian Source Repository](https://github.com/AIops-tools/AI-Guardian)\n- [Capabilities Reference](references/capabilities.md)\n- [CLI Reference](references/cli-reference.md)\n- [Setup and Security Guide](references/setup-guide.md)\n- [Agent Guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with CLI commands, configuration snippets, and structured tool-result summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Outputs depend on the configured local LLM runtime and on which read or write tools the host exposes to the agent.]\n\n## Skill Version(s):\n\n0.11.2 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.1: 7 files, 18529 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4251b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2745b), SKILL.md (16173b), _meta.json (131b)\n\nFile v0.11.1:SKILL.md\n\n---\nname: ai-guardian\nslug: ai-guardian\ndisplayName: \"AI Guardian\"\nsummary: \"Governed local-LLM observability: model policy, prompt scanner, capture proxy, 21 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/AI-Guardian\ntags: [aiops, mcp, governance, ai-guardian]\ndescription: >\n  Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts).\n  Always use this skill for \"what local models are installed\", \"find shadow / unsanctioned AI models\", \"which model is loaded in VRAM\", \"scan this prompt for secrets/PII before sending\", \"stop secrets leaking into a local model\", \"block a prompt with an API key\", \"detect a jailbreak / prompt injection\", \"set a model allowlist / denylist\", \"detect a tampered / re-pulled model\", \"audit local LLM usage\", \"guard my llama.cpp / LM Studio / local vLLM endpoint\", or \"the complement to IGEL AI Armor\".\n  Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices.\n  Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.\ninstaller:\n  kind: uv\n  package: ai-guardian\nargument-hint: \"[model name, a prompt to scan, or describe your local-LLM task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"ai-guardian\",\"uvx\"]},\"optional\":{\"env\":[\"AI_GUARDIAN_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/AI-Guardian\",\"emoji\":\"🛡️\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed local-LLM (Ollama) observability + content governance. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Every tool call is audited to a local SQLite DB at ~/.ai-guardian/audit.db (relocatable via AI_GUARDIAN_AIOPS_HOME); the OBSERVED local-LLM usage log is a SEPARATE DB at ~/.ai-guardian/usage.db.\n  Zero-config: ai-guardian defaults to the local Ollama at http://localhost:11434 with no token. Ollama endpoints usually run open on a trusted host, so a bearer token is OPTIONAL; when one is supplied it is stored ENCRYPTED in ~/.ai-guardian/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. The store is unlocked by a master password from AI_GUARDIAN_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var AI_GUARDIAN_<TARGET_NAME_UPPER>_TOKEN is still honoured as a fallback with a deprecation warning (migrate with 'ai-guardian secret migrate').\n  The prompt scanner is deterministic and offline (no I/O, no network); route-through guards (guarded_generate/observe_chat) call Ollama only if the prompt's risk band is below block_threshold AND the model is allowed. The raw prompt is never stored — only its length + redacted findings.\n  State-changing operations: remove_model (high, dry-run + double confirm at the CLI, undo re-pull); pull/unload/allowlist/denylist/pin/guarded writes are medium. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label).\n  Webhooks: none — no outbound network calls beyond the configured Ollama REST API.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: the scanner/policy/risk-band are deterministic offline logic; the core Ollama route-through (real generation + policy deny + undo capture) was exercised against a live Ollama 0.24.0 on 2026-07-13, while the remaining runtime API paths and the OpenAI-compatible dialects are exercised against mocked responses (see docs/VERIFICATION.md). Content governance is opt-in route-through in v0.1, a transparent capture proxy is v0.2 roadmap, and IGEL AI Armor interop is doc-level positioning.\n---\n\n# AI Guardian\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Ollama, IGEL, or any AI-security vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian) under the MIT license.\n\nGoverned observability + governance for **on-endpoint local LLMs (Ollama)** —\n**21 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a\nlocal unified audit log under `~/.ai-guardian/`, token/runaway budget guard,\nundo-token recording, and descriptive risk tiers. It is the\n**complement to IGEL AI Armor**: AI Armor governs *whether* a local model may run;\nai-guardian records *what it did* and gates *what leaves in the prompt*.\n\nOllama keeps **no queryable prompt history** (context is client-supplied each\nrequest), so ai-guardian observes on two fronts: **passive inventory / state\nauditing** over `/api/tags`, `/api/ps`, `/api/show`, `/api/version`; and **opt-in\nroute-through content governance** — a caller sends a prompt *through*\n`guarded_generate` / `observe_chat`, which scans + policy-gates + records it and\nonly then calls Ollama.\n\n> **Standalone**: the governance harness is bundled in the package\n> (`ai_guardian.governance`) — no external skill-family dependency. A\n> transparent capture proxy for other clients' traffic is v0.2 roadmap, and\n> IGEL AI Armor interop is doc-level positioning.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Inventory / state** | `list_models`, `running_models`, `model_details`, `server_status`, `vram_usage` | 5 | read |\n| **Policy / provenance** | `policy_view`, `model_provenance` | 2 | read |\n| **Content governance (read)** | `scan_prompt`, `usage_events`, `anomaly_report` | 3 | read |\n| **Model lifecycle** | `pull_model` (medium), `remove_model` (high), `unload_model` (medium) | 3 | write |\n| **Policy writes** | `set_model_allowlist`, `set_model_denylist`, `pin_model_digest` (all medium) | 3 | write |\n| **Route-through guard** | `guarded_generate`, `observe_chat` (medium) | 2 | write |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n`scan_prompt` is pure (no Ollama call). `guarded_generate` / `observe_chat` block\nwhen the prompt's risk band `>= block_threshold` (default `high`) **or** the model\nis disallowed; blocked calls never reach Ollama and are recorded as blocked.\n\n## Quick Install\n\n```bash\nuv tool install ai-guardian-aiops\nai-guardian doctor          # works zero-config against a local Ollama\nai-guardian init            # optional: endpoint(s) + optional token + model allowlist\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@aiops-tools/ai-guardian\nopenclaw skills info ai-guardian          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Inventory local models and **spot shadow AI** (`list_models` / `anomaly_report`): unsanctioned models show `allowed:false`\n- **Scan a prompt before sending it** (`scan_prompt`): secrets / PII / source-code / jailbreak → a weighted risk band, no model call\n- **Stop secrets or PII leaking into a local model** (`guarded_generate` / `observe_chat`): scan + policy-gate + record, then run only if allowed\n- **Detect a tampered / re-pulled model** (`model_provenance`): current digest vs its pin → drift\n- Enforce which models may run (`set_model_allowlist` / `set_model_denylist`) and pin trusted digests (`pin_model_digest`)\n- Inspect VRAM residency (`running_models` / `vram_usage`) and audit observed usage (`usage_events`)\n\n**Do NOT use when** the target is a GPU inference **cluster** (multi-node serving) — that is a different tool in the AIops-tools line. Also not for hypervisors, storage appliances, backup products, container clusters, or network devices.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| On-endpoint local LLM (Ollama): scan prompts, shadow-AI, provenance, policy | **ai-guardian** (this skill) |\n| GPU inference **cluster** serving/ops | another AIops-tools skill for cluster serving |\n| Hypervisor / storage / backup / container / network ops | the matching AIops-tools skill |\n\n## Common Workflows\n\n### 1. Find and shut down shadow (unsanctioned) local models\n\n1. `ai-guardian doctor` → confirm the Ollama endpoint is reachable before you\n   conclude a fleet has \"no models\" when it really has no connectivity\n2. `ai-guardian overview` → endpoint status, model count, and what is loaded\n   right now\n3. `ai-guardian model list` (MCP: `list_models`) → every installed model with its\n   allow/deny verdict; anything `allowed:false` is shadow AI\n4. `ai-guardian guard anomalies` (MCP: `anomaly_report`) → a one-shot rollup of\n   shadow models + digest drift + high-risk / blocked prompts, so you can tell a\n   single stray pull from a pattern\n5. `ai-guardian model running` / `vram_usage` → is the shadow model merely\n   installed, or actually loaded and consuming VRAM right now?\n6. Tighten policy so it cannot recur: `set_model_allowlist([\"llama3.*\", \"qwen*\"])`\n   → future unsanctioned models are refused at `pull_model`. Reversible: the\n   prior list is captured as the undo descriptor\n7. Remove the offender: `ai-guardian model remove <model> --dry-run`, then re-run\n   without `--dry-run` → **high** risk, double confirmation, needs\n   `AI_GUARDIAN_AUDIT_APPROVED_BY`; the undo descriptor records a re-pull\n8. **Failure branch**: if the new allowlist turns out to be too tight and blocks\n   a sanctioned model, `ai-guardian undo list` → `undo apply <id>` restores the\n   **prior** list exactly. If a removal was wrong, replaying the undo re-pulls\n   the model — but the weights come from the registry, so confirm the digest\n   afterwards with workflow 3 rather than assuming it is bit-identical.\n\n### 2. Stop secrets and PII leaking into a local model\n\n1. `ai-guardian guard scan \"…text…\"` (MCP: `scan_prompt`) → a **pure** call, no\n   model involved: deterministic findings (secrets / PII / code / jailbreak) plus\n   a weighted risk band. Use it to pre-check content offline before it ever\n   reaches a model\n2. `ai-guardian guard policy` (MCP: `policy_view`) → confirm which models are\n   permitted and what the current thresholds are\n3. Route real calls through the guard:\n   `guarded_generate(model, prompt, block_threshold=\"high\")` → the guard scans,\n   records to the usage log, and **blocks before Ollama** if the risk band is\n   `>= high` or the model is disallowed\n4. `ai-guardian guard usage` (MCP: `usage_events(allowed=False)`) → review what\n   was caught. The raw prompt is **never stored** — only its length and redacted\n   findings, so reviewing the log cannot itself leak the secret\n5. `ai-guardian guard anomalies` → confirm the rate of blocked prompts is falling\n   after you educate the user or fix the calling integration\n6. **Failure branch**: route-through is **opt-in** — anything that calls Ollama\n   directly bypasses the guard entirely. If `usage_events` is suspiciously empty\n   while `running_models` shows activity, you are looking at un-routed traffic,\n   not a clean fleet. A transparent capture proxy is a v0.2 roadmap item; until\n   then, treat guard coverage as coverage of what was routed, and say so.\n\n### 3. Detect tampered or silently re-pulled model weights\n\n1. `ai-guardian model list` / `model_details <model>` → read the current digest\n   for the models you sanction\n2. `pin_model_digest(model, digest)` → pin the trusted digest once, while you\n   still trust it. Pinning after a suspected compromise pins the compromise\n3. Later (or on a schedule): `ai-guardian guard provenance` (MCP:\n   `model_provenance`) → any model whose current digest differs from its pin\n   reports `status: DRIFT` — re-pulled or tampered weights\n4. `usage_events` around the drift timestamp → was the drifted model used, and\n   for what, before you noticed?\n5. **Failure branch**: `DRIFT` is a statement about the digest, not about intent\n   — a legitimate upgrade drifts identically to tampering. Investigate before\n   removing: check whether a `pull_model` appears in the audit trail at\n   `~/.ai-guardian/audit.db`. If it does not, treat it as untrusted and remove\n   under workflow 1. Re-pin only once you have re-established what the digest\n   *should* be.\n\n### 4. Fleet hygiene review before a rollout\n\n1. `ai-guardian overview` → the endpoint's current state at a glance\n2. `ai-guardian model list` → the full inventory with allow/deny verdicts\n3. `ai-guardian guard provenance` → every pinned model still matching its digest\n4. `vram_usage` + `running_models` → what is resident and whether the endpoint\n   has headroom for the model you are about to roll out\n5. `unload_model <model>` → free VRAM from an idle model without removing it\n   (reversible in practice — it reloads on next use)\n6. `ai-guardian model pull <model>` → the pull is checked against the allowlist,\n   so an unsanctioned rollout is refused rather than merely logged\n7. `ai-guardian guard anomalies` → a clean rollup is the exit criterion for the\n   review\n8. **Failure branch**: if `pull_model` is refused, the model is not on the\n   allowlist — widen the policy deliberately with `set_model_allowlist`\n   (audited, reversible) rather than working around the guard. If the pull fails\n   on VRAM, `unload_model` an idle model first; the audit trail records the\n   failed attempt with `status=error` and no undo token.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the host and account you run it under (point it at a runtime the account\ncannot administer, or hand the agent only the scan/observe tools). There is no\nread-only switch, deny-rules file, or approval gate — content governance (the\nmodel allow/deny policy and the `guarded_generate` block threshold) is a\nseparate, product-level control that stays.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.ai-guardian/audit.db` (relocatable via `AI_GUARDIAN_AIOPS_HOME`): params, result, status, duration, and the risk tier. Observed local-LLM usage lives in a **separate** `~/.ai-guardian/usage.db`.\n- `AI_GUARDIAN_AUDIT_APPROVED_BY` / `AI_GUARDIAN_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `AI_GUARDIAN_RUNAWAY_MAX=0`.\n- `remove_model` supports `--dry-run` + double confirmation at the CLI and records an undo (re-pull); allowlist/denylist writes record an undo → the prior list.\n- The scanner is deterministic and offline; findings are redacted so a secret is never re-emitted.\n\n## References\n\n- `references/capabilities.md` — full 21-tool + endpoint reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, optional token, and connectivity\n\nFile v0.11.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"ai-guardian\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1789206862390\n}\n\nFile v0.11.1:references/agent-guardrails.md\n\n# Agent guardrails — running ai-guardian with a smaller / local model\n\nThere is a pleasing recursion here: ai-guardian governs local LLMs, and this page\nis about driving ai-guardian *with* one. The same weaknesses this tool exists to\nobserve — a model that answers confidently without checking, that cannot tell\n\"unknown\" from \"none\", that reports a truncated view as complete — are the ones\nyou will hit while operating it.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The host and account you run under.** Point the tool at a runtime the account\n  cannot administer — an Ollama daemon whose model store the user can't modify —\n  so a `remove_model` or `pull_model` fails at the runtime, the only place the\n  permission actually lives. A revoked permission cannot be argued around by a\n  model; a skill-side flag can.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`), or hand\n  it only the scan/observe tools.\n\nContent governance is different, and it stays: `guarded_generate` still scans and\ngates each prompt against the allow/deny model policy and the block threshold\nbefore the model runs. That is a product control over *what a model is asked to\ndo*, not an authorization gate over *which tools an agent may call*.\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.ai-guardian/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. Observed local-LLM usage lives in a separate `~/.ai-guardian/usage.db`. |\n| \"Don't invent a digest / version / license\" | A field the runtime cannot report comes back as `null`, never as `\"\"`. This is load-bearing: Ollama and llama.cpp expose a pinnable identity, while LM Studio and vLLM expose only a model id. |\n| \"Don't call it tampering when you just can't tell\" | `model_provenance` reports a pinned model with no obtainable digest as `unverifiable`, never as `DRIFT`. Only a digest that is present **and** different is drift. |\n| \"Tell me if the output was cut off\" | `usage_events` returns `{\"events\": [...], \"count\": N, \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured (one extra row is fetched), not guessed. An under-reported usage log otherwise looks exactly like an absence of risky prompts. |\n| \"Never log the prompt text itself\" | The route-through path stores only the prompt's length, its risk band, and the redacted findings. The raw prompt is never written to the usage log. |\n| \"Redact secrets before showing me\" | The scanner's findings are already redacted; matched secrets and PII are reported by type and location, not by value. |\n| \"Confirm before anything destructive\" | `remove_model` is high-risk, requires a `--dry-run`-able preview + double confirmation at the CLI, and captures the model manifest for an undo (re-pull). |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate ai-guardian, which observes and governs local LLM runtimes (Ollama,\nllama.cpp, LM Studio, vLLM) on this machine.\n\nTOOL USE\n- Before answering any question about which models are installed, running,\n  sanctioned, or what has been observed, you MUST call a tool. Never answer from\n  memory — you are not a reliable witness to the machine you are running on.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreachable runtime\n  means unknown state, not \"no models installed\".\n\nREPORTING WHAT CAN AND CANNOT BE KNOWN\n- A null digest means the runtime cannot identify the weights. Report that as\n  \"unverifiable\" — never as clean, and never as drift.\n- A null version or license means the API does not expose it, not that the model\n  has none.\n- If usage_events returns truncated: true, say so. Never conclude \"no risky\n  prompts were observed\" from a truncated log.\n- A shadow model is a model present but not sanctioned by policy. That is a\n  policy finding, not evidence of malice. Report what the policy says, not what\n  you infer about intent.\n- scan_prompt results are heuristic. A \"none\" risk band means no pattern matched,\n  which is not the same as \"this prompt is safe\". Say which one you mean.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not recommend removing a model on the basis of it being unsanctioned alone —\n  surface it and let a human decide. remove_model deletes local weights.\n- Do not confuse the identifier kinds: a model name (llama3:8b) carries a tag, a\n  base name (llama3) does not, and a digest identifies the weights. A pinned\n  digest belongs to an exact model name.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — `remove_model` deletes local model\nweights, and re-pulling them is a large download rather than a quick undo:\n\n```bash\n# e.g. point ai-guardian at a runtime/account that can't administer the model\n# store, or hand the agent only the scan/observe tools. Then:\nai-guardian doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport AI_GUARDIAN_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport AI_GUARDIAN_AUDIT_RATIONALE=\"removing unsanctioned model per policy review\"\n```\n\nContent governance is independent of all this: `guarded_generate` / `observe_chat`\nscan each prompt, gate it against the allow/deny model policy and the block\nthreshold, record it to the usage log, and only then call the model. That is what\nkeeps secrets and jailbreaks out of a local model regardless of how read vs write\nis controlled.\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model reports \"no drift\" for an unverifiable runtime.** Ask it to quote\n  the `status` field per model rather than summarising; `unverifiable` and `ok`\n  are visually similar in a rollup but mean opposite things about confidence.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` or\n  `anomaly_report` — they fold inventory, policy verdicts, and usage stats into\n  one call.\n- **The model ignores later tool results in a long context.** Ask about one model\n  at a time with `model_details` rather than dumping the whole inventory.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.1:references/capabilities.md\n\n# ai-guardian capabilities\n\n> 21 MCP tools (11 read, 8 write, 2 undo) over Ollama's REST API\n> (default `http://localhost:11434`, usually no auth). The scanner / policy /\n> risk-band are pure deterministic offline logic; the Ollama paths need live\n> verification.\n\n## Read tools (10)\n\n| Tool | Ollama endpoint / pure | Returns |\n|------|------------------------|---------|\n| `list_models` | `GET /api/tags` | per-model: name, digest, sizeBytes, family, parameterSize, quantization, modifiedAt, **allowed** (allow/deny verdict — shadow → `false`) |\n| `running_models` | `GET /api/ps` | per-loaded-model: name, digest, sizeVramBytes, expiresAt, allowed |\n| `model_details` | `POST /api/show` | model, license, family, parameterSize, quantization, capabilities[] |\n| `server_status` | `GET /api/version` | reachable, version (or error) |\n| `vram_usage` | `GET /api/ps` | loadedModels, totalVramBytes, budgetBytes, overBudget, models[] |\n| `policy_view` | pure (reads config) | allowedModels, deniedModels, pinnedDigests, note |\n| `model_provenance` | `GET /api/tags` + config | driftCount, pinnedCount, models[]{model, currentDigest, pinnedDigest, status: ok/DRIFT/unpinned} |\n| `scan_prompt` | **pure** (no model call) | riskBand, findingCount, byCategory, findings[]{category, kind, severity, preview(redacted)} |\n| `usage_events` | reads `usage.db` | count, events[] (filter by model / risk_level / allowed / since / limit) |\n| `anomaly_report` | `GET /api/tags` + `usage.db` | shadowModels[], digestDrift[], highRiskPrompts, blockedPrompts, totalObserved |\n\n## Write tools (8)\n\n| Tool | Risk | Ollama endpoint / effect | Undo / safety |\n|------|------|--------------------------|---------------|\n| `pull_model` | medium | `POST /api/pull` | **refused if it violates the deny/allow policy** |\n| `remove_model` | **high** | `DELETE /api/delete` | captures the model manifest; records an undo (`pull_model` re-pull); CLI `--dry-run` + double confirm |\n| `unload_model` | medium | `POST /api/generate` `keep_alive:0` | evict from VRAM; no undo |\n| `set_model_allowlist` | medium | writes `config.yaml` | undo → prior allowlist (immutable replace, not append) |\n| `set_model_denylist` | medium | writes `config.yaml` | undo → prior denylist (deny patterns always win) |\n| `pin_model_digest` | medium | writes `config.yaml` | pin a model's expected provenance digest; undo → prior pin |\n| `guarded_generate` | medium | scan → policy-gate → record → `POST /api/generate` if allowed | blocks when risk band `>= block_threshold` (default `high`) OR model disallowed; blocked never reaches Ollama; raw prompt never stored |\n| `observe_chat` | medium | scan → policy-gate → record → `POST /api/chat` if allowed | same, for OpenAI-style `[{role,content}]` messages |\n\n## The deterministic scanner (behind `scan_prompt` / the route-through guards)\n\nPure, offline, no network. Categories and weighted risk band:\n\n- **secrets** — AWS access key (`AKIA…`, critical), private-key blocks (critical),\n  GitHub token (critical), OpenAI `sk-…` (critical), Slack token (high), JWT\n  (high), Google API key (high), assigned `api_key=…` / high-entropy fallback\n  (medium).\n- **pii** — email (low), US SSN (high), credit card **with a Luhn check** (high).\n- **code_leak** — source/config heuristics (fires on >= 2 signals, medium).\n- **jailbreak** — ignore-instructions / DAN / developer-mode / system-prompt-leak\n  signatures (medium).\n- **risk band** — weighted sum (low=1, medium=3, high=7, critical=15); bands\n  low 0-2, medium 3-6, high 7-14, critical >=15 — and **any single critical\n  dominates**. Findings are **redacted** (short masked preview only).\n\n## Out of scope (by design)\n\n- GPU inference-**cluster** serving/ops (multi-node) — a different AIops-tools tool\n- Model training / fine-tuning\n- Non-Ollama local-LLM runtimes\n- ~~A transparent capture proxy for other clients' traffic~~ — **shipped**:\n  `ai-guardian proxy serve` (CLI-only; it blocks while listening, so an MCP tool\n  that started it would hang the caller). `proxy_guidance` composes the command\n  and states the caveat: it is a **chokepoint, not an enforcement boundary**\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n\nFile v0.11.1:references/cli-reference.md\n\n# ai-guardian CLI reference\n\n> The CLI is a convenience subset; the full 21-tool surface\n> is via MCP (`ai-guardian mcp`). Works zero-config against a local Ollama\n> (`http://localhost:11434`).\n\n## Setup & diagnostics\n\n```bash\nai-guardian init                      # interactive wizard: Ollama endpoint(s) + optional token + model allowlist\nai-guardian doctor [--skip-auth]      # config + policy summary + Ollama reachability (/api/version)\nai-guardian mcp                       # start the MCP server (stdio transport)\n```\n\n## Overview\n\n```bash\nai-guardian overview [--target <t>]   # models installed/running, shadow count, observed-usage stats\n```\n\n## Models (inventory + guarded lifecycle)\n\n```bash\nai-guardian model list [--target <t>]         # installed models with allow/deny verdicts\nai-guardian model running [--target <t>]      # loaded models (VRAM + expiry)\nai-guardian model details <model>             # license / parameters / capabilities\nai-guardian model pull <model>                # pull a model (refused if it violates policy)\nai-guardian model remove <model> [--dry-run]  # (high) delete a local model; dry-run + double confirm; undo re-pull\nai-guardian model unload <model>              # (medium) evict from VRAM (keep_alive:0)\n```\n\n## Guard (policy, provenance, prompt scanning, usage, anomalies)\n\n```bash\nai-guardian guard policy                      # current model allow/deny policy + digest pins\nai-guardian guard provenance [--target <t>]   # installed digests vs their pins (drift detection)\nai-guardian guard scan \"<text>\"               # deterministic scan → findings + risk band (no model call)\nai-guardian guard usage [--limit 50]          # query the observed-usage log\nai-guardian guard anomalies [--target <t>]    # rollup: shadow models, digest drift, high-risk + blocked prompts\n```\n\n## Secrets (encrypted store ~/.ai-guardian/secrets.enc)\n\nA bearer token is optional (rare for local Ollama).\n\n```bash\nai-guardian secret set <target> [--value <token>]  # store a token (hidden prompt if no --value)\nai-guardian secret list                            # names only — values never shown\nai-guardian secret rm <target>\nai-guardian secret migrate                         # import legacy plaintext .env (AI_GUARDIAN_<T>_TOKEN)\nai-guardian secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Common options & notes\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target, i.e. the local Ollama)\n- `--dry-run` (on `model remove`) — print the API call that would be made, change nothing\n- `model remove` requires two confirmations; set `AI_GUARDIAN_AUDIT_APPROVED_BY` (+ `AI_GUARDIAN_AUDIT_RATIONALE`) to record who/why on the audit row (optional)\n- The route-through guards (`guarded_generate` / `observe_chat`) are MCP-only; use `guard scan` on the CLI to pre-check text without a model call\n\nFile v0.11.1:references/setup-guide.md\n\n# ai-guardian setup & security guide\n\n> The scanner / policy / risk-band are deterministic offline logic; the Ollama\n> API paths need live verification (see `docs/VERIFICATION.md`).\n\n## 1. Install\n\n```bash\nuv tool install ai-guardian-aiops\n```\n\n## 2. Zero-config default\n\nai-guardian works **out of the box** against the local Ollama at\n`http://localhost:11434` with **no token** — Ollama endpoints usually run open on\na trusted host. You can go straight to:\n\n```bash\nai-guardian doctor        # Ollama reachability + policy summary\nai-guardian overview\n```\n\nRun `init` only if you want to name multiple endpoints, add a token, or set a\nmodel allowlist.\n\n## 3. Onboard (optional)\n\n```bash\nai-guardian init\n```\n\nThe wizard records (non-secret) connection details and the optional model policy\ninto `~/.ai-guardian/config.yaml`. If the endpoint requires a bearer token (rare\nfor local Ollama), it is stored **encrypted** into `~/.ai-guardian/secrets.enc`.\nExample config:\n\n```yaml\ntargets:\n  - name: local\n    host: localhost\n    port: 11434\n    scheme: http\n    verify_ssl: false          # self-signed HTTPS lab certs only\nallowed_models:                # shell globs; empty = allow-all\n  - \"llama3.*\"\n  - \"qwen*\"\ndenied_models: []              # deny patterns always win\npinned_digests: {}             # model -> expected provenance digest (drift detection)\n```\n\nThe **policy** (`allowed_models` / `denied_models` / `pinned_digests`) is\n**non-secret** config — it lives in `config.yaml`, not the encrypted store.\n\n## 4. Optional bearer token\n\nMost local Ollama setups need no token. If yours does:\n\n```bash\nai-guardian secret set local        # hidden prompt for the token\n```\n\nFor non-interactive use (MCP server / CI / cron), export the master password so\nthe encrypted store can be unlocked without a prompt:\n\n```bash\nexport AI_GUARDIAN_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n### Token security\n\n- A token is **never** written to disk in plaintext. It lives only in\n  `~/.ai-guardian/secrets.enc`, encrypted with Fernet (AES-128-CBC + HMAC), the\n  key derived from your master password via scrypt. Only a per-store random salt\n  and the ciphertext are on disk (chmod 600); the master password is never stored.\n- A legacy plaintext env var `AI_GUARDIAN_<TARGET_NAME_UPPER>_TOKEN` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `ai-guardian secret migrate` (it imports then renames the old `.env`).\n- The token is held only in memory and is never logged or echoed; exception text\n  is scrubbed of secret-shaped strings before being written to the audit log.\n\n## 5. Audit-annotation env vars (optional)\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement or the permission of the host/account you run it under. If you want the\naudit trail to record *who* ran a destructive op and *why*, set these; they are\nrecorded on the row, never required, and gate nothing:\n\n```bash\nexport AI_GUARDIAN_AUDIT_APPROVED_BY='you@example.com'\nexport AI_GUARDIAN_AUDIT_RATIONALE='decommissioning an unused model'\n```\n\n## Two separate SQLite databases\n\nState lives under `~/.ai-guardian/` (relocate the governance state with\n`AI_GUARDIAN_AIOPS_HOME`):\n\n- `audit.db` — the **governance audit log**: every ai-guardian *tool call*, with\n  risk tier and any approver/rationale.\n- `usage.db` — the **observed local-LLM usage log**: route-through prompts\n  (`guarded_generate` / `observe_chat`) with model, actor, prompt length, risk\n  band, redacted findings, and allowed/blocked. **The raw prompt is never stored.**\n- `undo.db` — inverse descriptors for reversible writes (e.g. `remove_model` →\n  re-pull, allowlist/denylist → prior list).\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops.\n\n## Verify\n\n```bash\nai-guardian doctor\n```\n\n`doctor` checks the config file, the model policy summary, the encrypted store and\nits permissions (if present), and (unless `--skip-auth`) Ollama reachability by\nhitting `/api/version`. It works with zero config, defaulting to the local Ollama.\n\nFile v0.11.1:skill-card.md\n\n## Description:\n\nAI Guardian helps agents observe and govern single-endpoint local LLM runtimes by inventorying models, checking policy and provenance, scanning prompts for secrets, PII, source code, and jailbreak patterns, routing guarded generation when configured, and reporting usage anomalies.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to inspect local Ollama, llama.cpp, LM Studio, or single-node vLLM endpoints, detect unsanctioned or drifted models, scan prompts before model use, and audit guarded local LLM activity. It is intended for local endpoint governance rather than multi-node inference clusters or unrelated infrastructure operations.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can perform destructive or policy-changing local model operations.\n\nMitigation: Run it with least privilege and expose only scan/read tools unless model deletion, model pulls, or policy changes are explicitly required.\n\nRisk: Configured HTTP endpoints may expose local LLM control surfaces if reachable beyond the local host.\n\nMitigation: Keep endpoints loopback-only, or require HTTPS with verification before exposing them outside the trusted machine.\n\nRisk: Audit, usage, undo, and secret files under ~/.ai-guardian contain sensitive operational data.\n\nMitigation: Restrict filesystem access to the governance state directory and handle those files as sensitive local security records.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/ai-guardian)\n- [Project homepage](https://github.com/AIops-tools/AI-Guardian)\n- [Capabilities reference](references/capabilities.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, configuration examples, and tool-selection recommendations]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include local runtime observations, risk-band summaries, policy recommendations, and guarded workflow steps depending on available tools and endpoint state.]\n\n## Skill Version(s):\n\n0.11.1 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.0: 7 files, 18281 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4251b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2457b), SKILL.md (15863b), _meta.json (131b)\n\nFile v0.11.0:SKILL.md\n\n---\nname: ai-guardian\nslug: ai-guardian\ndisplayName: \"AI Guardian\"\nsummary: \"Governed local-LLM observability: model policy, prompt scanner, capture proxy, 21 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/AI-Guardian\ntags: [aiops, mcp, governance, ai-guardian]\ndescription: >\n  Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts).\n  Always use this skill for \"what local models are installed\", \"find shadow / unsanctioned AI models\", \"which model is loaded in VRAM\", \"scan this prompt for secrets/PII before sending\", \"stop secrets leaking into a local model\", \"block a prompt with an API key\", \"detect a jailbreak / prompt injection\", \"set a model allowlist / denylist\", \"detect a tampered / re-pulled model\", \"audit local LLM usage\", \"guard my llama.cpp / LM Studio / local vLLM endpoint\", or \"the complement to IGEL AI Armor\".\n  Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices.\n  Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.\ninstaller:\n  kind: uv\n  package: ai-guardian\nargument-hint: \"[model name, a prompt to scan, or describe your local-LLM task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"ai-guardian\",\"uvx\"]},\"optional\":{\"env\":[\"AI_GUARDIAN_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/AI-Guardian\",\"emoji\":\"🛡️\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed local-LLM (Ollama) observability + content governance. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Every tool call is audited to a local SQLite DB at ~/.ai-guardian/audit.db (relocatable via AI_GUARDIAN_AIOPS_HOME); the OBSERVED local-LLM usage log is a SEPARATE DB at ~/.ai-guardian/usage.db.\n  Zero-config: ai-guardian defaults to the local Ollama at http://localhost:11434 with no token. Ollama endpoints usually run open on a trusted host, so a bearer token is OPTIONAL; when one is supplied it is stored ENCRYPTED in ~/.ai-guardian/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. The store is unlocked by a master password from AI_GUARDIAN_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var AI_GUARDIAN_<TARGET_NAME_UPPER>_TOKEN is still honoured as a fallback with a deprecation warning (migrate with 'ai-guardian secret migrate').\n  The prompt scanner is deterministic and offline (no I/O, no network); route-through guards (guarded_generate/observe_chat) call Ollama only if the prompt's risk band is below block_threshold AND the model is allowed. The raw prompt is never stored — only its length + redacted findings.\n  State-changing operations: remove_model (high, dry-run + double confirm at the CLI, undo re-pull); pull/unload/allowlist/denylist/pin/guarded writes are medium. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label).\n  Webhooks: none — no outbound network calls beyond the configured Ollama REST API.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: the scanner/policy/risk-band are deterministic offline logic; the core Ollama route-through (real generation + policy deny + undo capture) was exercised against a live Ollama 0.24.0 on 2026-07-13, while the remaining runtime API paths and the OpenAI-compatible dialects are exercised against mocked responses (see docs/VERIFICATION.md). Content governance is opt-in route-through in v0.1, a transparent capture proxy is v0.2 roadmap, and IGEL AI Armor interop is doc-level positioning.\n---\n\n# AI Guardian\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Ollama, IGEL, or any AI-security vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian) under the MIT license.\n\nGoverned observability + governance for **on-endpoint local LLMs (Ollama)** —\n**21 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a\nlocal unified audit log under `~/.ai-guardian/`, token/runaway budget guard,\nundo-token recording, and descriptive risk tiers. It is the\n**complement to IGEL AI Armor**: AI Armor governs *whether* a local model may run;\nai-guardian records *what it did* and gates *what leaves in the prompt*.\n\nOllama keeps **no queryable prompt history** (context is client-supplied each\nrequest), so ai-guardian observes on two fronts: **passive inventory / state\nauditing** over `/api/tags`, `/api/ps`, `/api/show`, `/api/version`; and **opt-in\nroute-through content governance** — a caller sends a prompt *through*\n`guarded_generate` / `observe_chat`, which scans + policy-gates + records it and\nonly then calls Ollama.\n\n> **Standalone**: the governance harness is bundled in the package\n> (`ai_guardian.governance`) — no external skill-family dependency. A\n> transparent capture proxy for other clients' traffic is v0.2 roadmap, and\n> IGEL AI Armor interop is doc-level positioning.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Inventory / state** | `list_models`, `running_models`, `model_details`, `server_status`, `vram_usage` | 5 | read |\n| **Policy / provenance** | `policy_view`, `model_provenance` | 2 | read |\n| **Content governance (read)** | `scan_prompt`, `usage_events`, `anomaly_report` | 3 | read |\n| **Model lifecycle** | `pull_model` (medium), `remove_model` (high), `unload_model` (medium) | 3 | write |\n| **Policy writes** | `set_model_allowlist`, `set_model_denylist`, `pin_model_digest` (all medium) | 3 | write |\n| **Route-through guard** | `guarded_generate`, `observe_chat` (medium) | 2 | write |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n`scan_prompt` is pure (no Ollama call). `guarded_generate` / `observe_chat` block\nwhen the prompt's risk band `>= block_threshold` (default `high`) **or** the model\nis disallowed; blocked calls never reach Ollama and are recorded as blocked.\n\n## Quick Install\n\n```bash\nuv tool install ai-guardian-aiops\nai-guardian doctor          # works zero-config against a local Ollama\nai-guardian init            # optional: endpoint(s) + optional token + model allowlist\n```\n\n## When to Use This Skill\n\n- Inventory local models and **spot shadow AI** (`list_models` / `anomaly_report`): unsanctioned models show `allowed:false`\n- **Scan a prompt before sending it** (`scan_prompt`): secrets / PII / source-code / jailbreak → a weighted risk band, no model call\n- **Stop secrets or PII leaking into a local model** (`guarded_generate` / `observe_chat`): scan + policy-gate + record, then run only if allowed\n- **Detect a tampered / re-pulled model** (`model_provenance`): current digest vs its pin → drift\n- Enforce which models may run (`set_model_allowlist` / `set_model_denylist`) and pin trusted digests (`pin_model_digest`)\n- Inspect VRAM residency (`running_models` / `vram_usage`) and audit observed usage (`usage_events`)\n\n**Do NOT use when** the target is a GPU inference **cluster** (multi-node serving) — that is a different tool in the AIops-tools line. Also not for hypervisors, storage appliances, backup products, container clusters, or network devices.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| On-endpoint local LLM (Ollama): scan prompts, shadow-AI, provenance, policy | **ai-guardian** (this skill) |\n| GPU inference **cluster** serving/ops | another AIops-tools skill for cluster serving |\n| Hypervisor / storage / backup / container / network ops | the matching AIops-tools skill |\n\n## Common Workflows\n\n### 1. Find and shut down shadow (unsanctioned) local models\n\n1. `ai-guardian doctor` → confirm the Ollama endpoint is reachable before you\n   conclude a fleet has \"no models\" when it really has no connectivity\n2. `ai-guardian overview` → endpoint status, model count, and what is loaded\n   right now\n3. `ai-guardian model list` (MCP: `list_models`) → every installed model with its\n   allow/deny verdict; anything `allowed:false` is shadow AI\n4. `ai-guardian guard anomalies` (MCP: `anomaly_report`) → a one-shot rollup of\n   shadow models + digest drift + high-risk / blocked prompts, so you can tell a\n   single stray pull from a pattern\n5. `ai-guardian model running` / `vram_usage` → is the shadow model merely\n   installed, or actually loaded and consuming VRAM right now?\n6. Tighten policy so it cannot recur: `set_model_allowlist([\"llama3.*\", \"qwen*\"])`\n   → future unsanctioned models are refused at `pull_model`. Reversible: the\n   prior list is captured as the undo descriptor\n7. Remove the offender: `ai-guardian model remove <model> --dry-run`, then re-run\n   without `--dry-run` → **high** risk, double confirmation, needs\n   `AI_GUARDIAN_AUDIT_APPROVED_BY`; the undo descriptor records a re-pull\n8. **Failure branch**: if the new allowlist turns out to be too tight and blocks\n   a sanctioned model, `ai-guardian undo list` → `undo apply <id>` restores the\n   **prior** list exactly. If a removal was wrong, replaying the undo re-pulls\n   the model — but the weights come from the registry, so confirm the digest\n   afterwards with workflow 3 rather than assuming it is bit-identical.\n\n### 2. Stop secrets and PII leaking into a local model\n\n1. `ai-guardian guard scan \"…text…\"` (MCP: `scan_prompt`) → a **pure** call, no\n   model involved: deterministic findings (secrets / PII / code / jailbreak) plus\n   a weighted risk band. Use it to pre-check content offline before it ever\n   reaches a model\n2. `ai-guardian guard policy` (MCP: `policy_view`) → confirm which models are\n   permitted and what the current thresholds are\n3. Route real calls through the guard:\n   `guarded_generate(model, prompt, block_threshold=\"high\")` → the guard scans,\n   records to the usage log, and **blocks before Ollama** if the risk band is\n   `>= high` or the model is disallowed\n4. `ai-guardian guard usage` (MCP: `usage_events(allowed=False)`) → review what\n   was caught. The raw prompt is **never stored** — only its length and redacted\n   findings, so reviewing the log cannot itself leak the secret\n5. `ai-guardian guard anomalies` → confirm the rate of blocked prompts is falling\n   after you educate the user or fix the calling integration\n6. **Failure branch**: route-through is **opt-in** — anything that calls Ollama\n   directly bypasses the guard entirely. If `usage_events` is suspiciously empty\n   while `running_models` shows activity, you are looking at un-routed traffic,\n   not a clean fleet. A transparent capture proxy is a v0.2 roadmap item; until\n   then, treat guard coverage as coverage of what was routed, and say so.\n\n### 3. Detect tampered or silently re-pulled model weights\n\n1. `ai-guardian model list` / `model_details <model>` → read the current digest\n   for the models you sanction\n2. `pin_model_digest(model, digest)` → pin the trusted digest once, while you\n   still trust it. Pinning after a suspected compromise pins the compromise\n3. Later (or on a schedule): `ai-guardian guard provenance` (MCP:\n   `model_provenance`) → any model whose current digest differs from its pin\n   reports `status: DRIFT` — re-pulled or tampered weights\n4. `usage_events` around the drift timestamp → was the drifted model used, and\n   for what, before you noticed?\n5. **Failure branch**: `DRIFT` is a statement about the digest, not about intent\n   — a legitimate upgrade drifts identically to tampering. Investigate before\n   removing: check whether a `pull_model` appears in the audit trail at\n   `~/.ai-guardian/audit.db`. If it does not, treat it as untrusted and remove\n   under workflow 1. Re-pin only once you have re-established what the digest\n   *should* be.\n\n### 4. Fleet hygiene review before a rollout\n\n1. `ai-guardian overview` → the endpoint's current state at a glance\n2. `ai-guardian model list` → the full inventory with allow/deny verdicts\n3. `ai-guardian guard provenance` → every pinned model still matching its digest\n4. `vram_usage` + `running_models` → what is resident and whether the endpoint\n   has headroom for the model you are about to roll out\n5. `unload_model <model>` → free VRAM from an idle model without removing it\n   (reversible in practice — it reloads on next use)\n6. `ai-guardian model pull <model>` → the pull is checked against the allowlist,\n   so an unsanctioned rollout is refused rather than merely logged\n7. `ai-guardian guard anomalies` → a clean rollup is the exit criterion for the\n   review\n8. **Failure branch**: if `pull_model` is refused, the model is not on the\n   allowlist — widen the policy deliberately with `set_model_allowlist`\n   (audited, reversible) rather than working around the guard. If the pull fails\n   on VRAM, `unload_model` an idle model first; the audit trail records the\n   failed attempt with `status=error` and no undo token.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the host and account you run it under (point it at a runtime the account\ncannot administer, or hand the agent only the scan/observe tools). There is no\nread-only switch, deny-rules file, or approval gate — content governance (the\nmodel allow/deny policy and the `guarded_generate` block threshold) is a\nseparate, product-level control that stays.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.ai-guardian/audit.db` (relocatable via `AI_GUARDIAN_AIOPS_HOME`): params, result, status, duration, and the risk tier. Observed local-LLM usage lives in a **separate** `~/.ai-guardian/usage.db`.\n- `AI_GUARDIAN_AUDIT_APPROVED_BY` / `AI_GUARDIAN_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `AI_GUARDIAN_RUNAWAY_MAX=0`.\n- `remove_model` supports `--dry-run` + double confirmation at the CLI and records an undo (re-pull); allowlist/denylist writes record an undo → the prior list.\n- The scanner is deterministic and offline; findings are redacted so a secret is never re-emitted.\n\n## References\n\n- `references/capabilities.md` — full 21-tool + endpoint reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, optional token, and connectivity\n\nFile v0.11.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"ai-guardian\",\n  \"version\": \"0.11.0\",\n  \"publishedAt\": 1789173802085\n}\n\nFile v0.11.0:references/agent-guardrails.md\n\n# Agent guardrails — running ai-guardian with a smaller / local model\n\nThere is a pleasing recursion here: ai-guardian governs local LLMs, and this page\nis about driving ai-guardian *with* one. The same weaknesses this tool exists to\nobserve — a model that answers confidently without checking, that cannot tell\n\"unknown\" from \"none\", that reports a truncated view as complete — are the ones\nyou will hit while operating it.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The host and account you run under.** Point the tool at a runtime the account\n  cannot administer — an Ollama daemon whose model store the user can't modify —\n  so a `remove_model` or `pull_model` fails at the runtime, the only place the\n  permission actually lives. A revoked permission cannot be argued around by a\n  model; a skill-side flag can.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`), or hand\n  it only the scan/observe tools.\n\nContent governance is different, and it stays: `guarded_generate` still scans and\ngates each prompt against the allow/deny model policy and the block threshold\nbefore the model runs. That is a product control over *what a model is asked to\ndo*, not an authorization gate over *which tools an agent may call*.\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.ai-guardian/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. Observed local-LLM usage lives in a separate `~/.ai-guardian/usage.db`. |\n| \"Don't invent a digest / version / license\" | A field the runtime cannot report comes back as `null`, never as `\"\"`. This is load-bearing: Ollama and llama.cpp expose a pinnable identity, while LM Studio and vLLM expose only a model id. |\n| \"Don't call it tampering when you just can't tell\" | `model_provenance` reports a pinned model with no obtainable digest as `unverifiable`, never as `DRIFT`. Only a digest that is present **and** different is drift. |\n| \"Tell me if the output was cut off\" | `usage_events` returns `{\"events\": [...], \"count\": N, \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured (one extra row is fetched), not guessed. An under-reported usage log otherwise looks exactly like an absence of risky prompts. |\n| \"Never log the prompt text itself\" | The route-through path stores only the prompt's length, its risk band, and the redacted findings. The raw prompt is never written to the usage log. |\n| \"Redact secrets before showing me\" | The scanner's findings are already redacted; matched secrets and PII are reported by type and location, not by value. |\n| \"Confirm before anything destructive\" | `remove_model` is high-risk, requires a `--dry-run`-able preview + double confirmation at the CLI, and captures the model manifest for an undo (re-pull). |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate ai-guardian, which observes and governs local LLM runtimes (Ollama,\nllama.cpp, LM Studio, vLLM) on this machine.\n\nTOOL USE\n- Before answering any question about which models are installed, running,\n  sanctioned, or what has been observed, you MUST call a tool. Never answer from\n  memory — you are not a reliable witness to the machine you are running on.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreachable runtime\n  means unknown state, not \"no models installed\".\n\nREPORTING WHAT CAN AND CANNOT BE KNOWN\n- A null digest means the runtime cannot identify the weights. Report that as\n  \"unverifiable\" — never as clean, and never as drift.\n- A null version or license means the API does not expose it, not that the model\n  has none.\n- If usage_events returns truncated: true, say so. Never conclude \"no risky\n  prompts were observed\" from a truncated log.\n- A shadow model is a model present but not sanctioned by policy. That is a\n  policy finding, not evidence of malice. Report what the policy says, not what\n  you infer about intent.\n- scan_prompt results are heuristic. A \"none\" risk band means no pattern matched,\n  which is not the same as \"this prompt is safe\". Say which one you mean.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not recommend removing a model on the basis of it being unsanctioned alone —\n  surface it and let a human decide. remove_model deletes local weights.\n- Do not confuse the identifier kinds: a model name (llama3:8b) carries a tag, a\n  base name (llama3) does not, and a digest identifies the weights. A pinned\n  digest belongs to an exact model name.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — `remove_model` deletes local model\nweights, and re-pulling them is a large download rather than a quick undo:\n\n```bash\n# e.g. point ai-guardian at a runtime/account that can't administer the model\n# store, or hand the agent only the scan/observe tools. Then:\nai-guardian doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport AI_GUARDIAN_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport AI_GUARDIAN_AUDIT_RATIONALE=\"removing unsanctioned model per policy review\"\n```\n\nContent governance is independent of all this: `guarded_generate` / `observe_chat`\nscan each prompt, gate it against the allow/deny model policy and the block\nthreshold, record it to the usage log, and only then call the model. That is what\nkeeps secrets and jailbreaks out of a local model regardless of how read vs write\nis controlled.\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model reports \"no drift\" for an unverifiable runtime.** Ask it to quote\n  the `status` field per model rather than summarising; `unverifiable` and `ok`\n  are visually similar in a rollup but mean opposite things about confidence.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` or\n  `anomaly_report` — they fold inventory, policy verdicts, and usage stats into\n  one call.\n- **The model ignores later tool results in a long context.** Ask about one model\n  at a time with `model_details` rather than dumping the whole inventory.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/AI-Guardian](https://github.com/AIops-tools/AI-Guardian/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.0:references/capabilities.md\n\n# ai-guardian capabilities\n\n> 21 MCP tools (11 read, 8 write, 2 undo) over Ollama's REST API\n> (default `http://localhost:11434`, usually no auth). The scanner / policy /\n> risk-band are pure deterministic offline logic; the Ollama paths need live\n> verification.\n\n## Read tools (10)\n\n| Tool | Ollama endpoint / pure | Returns |\n|------|-----\n\nArchive v0.10.0: 7 files, 18244 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4251b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2431b), SKILL.md (15969b), _meta.json (131b)\n\nArchive v0.9.0: 7 files, 18224 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4017b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2650b), SKILL.md (15963b), _meta.json (130b)\n\nArchive v0.8.0: 7 files, 18222 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4017b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2818b), SKILL.md (15963b), _meta.json (130b)\n\nArchive v0.7.0: 7 files, 18186 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4017b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2729b), SKILL.md (15963b), _meta.json (130b)\n\nArchive v0.6.0: 7 files, 18173 bytes\n\nFiles: references/agent-guardrails.md (8393b), references/capabilities.md (4017b), references/cli-reference.md (2910b), references/setup-guide.md (4110b), skill-card.md (2672b), SKILL.md (15963b), _meta.json (130b)\n\nArchive v0.5.0: 7 files, 17232 bytes\n\nFiles: references/agent-guardrails.md (6982b), references/capabilities.md (4073b), references/cli-reference.md (2896b), references/setup-guide.md (3865b), skill-card.md (2697b), SKILL.md (15758b), _meta.json (130b)","readmeExcerpt":"Skill: ai-guardian Owner: zw008 Summary: Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"uv tool install ai-guardian-aiops\nai-guardian doctor          # works zero-config against a local Ollama\nai-guardian init            # optional: endpoint(s) + optional token + model allowlist"},{"language":"bash","snippet":"openclaw plugins install clawhub:@zw008/ai-guardian\nopenclaw skills info ai-guardian          # expect: Visible to model: yes"},{"language":"text","snippet":"You operate ai-guardian, which observes and governs local LLM runtimes (Ollama,\nllama.cpp, LM Studio, vLLM) on this machine.\n\nTOOL USE\n- Before answering any question about which models are installed, running,\n  sanctioned, or what has been observed, you MUST call a tool. Never answer from\n  memory — you are not a reliable witness to the machine you are running on.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreachable runtime\n  means unknown state, not \"no models installed\".\n\nREPORTING WHAT CAN AND CANNOT BE KNOWN\n- A null digest means the runtime cannot identify the weights. Report that as\n  \"unverifiable\" — never as clean, and never as drift.\n- A null version or license means the API does not expose it, not that the model\n  has none.\n- If usage_events returns truncated: true, say so. Never conclude \"no risky\n  prompts were observed\" from a truncated log.\n- A shadow model is a model present but not sanctioned by policy. That is a\n  policy finding, not evidence of malice. Report what the policy says, not what\n  you infer about intent.\n- scan_prompt results are heuristic. A \"none\" risk band means no pattern matched,\n  which is not the same as \"this prompt is safe\". Say which one you mean.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not recommend removing a model on the basis of it being unsanctioned alone —\n  surface it and let a human decide. remove_model deletes local weights.\n- Do not confuse the identifier kinds: a model name (llama3:8b) carries a tag, a\n  base name (llama3) does not, and a digest identifies the weights. A pinned\n  digest belongs to an exact model name."},{"language":"bash","snippet":"# e.g. point ai-guardian at a runtime/account that can't administer the model\n# store, or hand the agent only the scan/observe tools. Then:\nai-guardian doctor"},{"language":"bash","snippet":"export AI_GUARDIAN_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport AI_GUARDIAN_AUDIT_RATIONALE=\"removing unsanctioned model per policy review\""},{"language":"bash","snippet":"ai-guardian init                      # interactive wizard: Ollama endpoint(s) + optional token + model allowlist\nai-guardian doctor [--skip-auth]      # config + policy summary + Ollama reachability (/api/version)\nai-guardian mcp                       # start the MCP server (stdio transport)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: ai-guardian\nslug: ai-guardian\ndisplayName: \"AI Guardian\"\nsummary: \"Governed local-LLM observability: model policy, prompt scanner, capture proxy, 21 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/AI-Guardian\ntags: [aiops, mcp, governance, ai-guardian]\ndescription: >\n  Use this skill whenever the user needs to observe or govern on-endpoint local LLMs running on Ollama, llama.cpp (llama-server), LM Studio, or a local single-node vLLM — inventory installed/running models with an allow/deny verdict (shadow-AI detection), inspect VRAM residency, model license/params/capabilities and server version, view the model policy, detect model provenance/digest drift (re-pulled or tampered weights; strong for Ollama/llama.cpp, id-only and honestly weaker for LM Studio/vLLM), scan a prompt for secrets / PII / source-code / jailbreak with a weighted risk band, route a prompt THROUGH a guard that scans + policy-gates + records + runs-if-allowed (guarded_generate / observe_chat), query the observed-usage log, and roll up anomalies (shadow models, digest drift, high-risk + blocked prompts).\n  Always use this skill for \"what local models are installed\", \"find shadow / unsanctioned AI models\", \"which model is loaded in VRAM\", \"scan this prompt for secrets/PII before sending\", \"stop secrets leaking into a local model\", \"block a prompt with an API key\", \"detect a jailbreak / prompt injection\", \"set a model allowlist / denylist\", \"detect a tampered / re-pulled model\", \"audit local LLM usage\", \"guard my llama.cpp / LM Studio / local vLLM endpoint\", or \"the complement to IGEL AI Armor\".\n  Do NOT use for GPU inference CLUSTERS (multi-node / fleet-scale vLLM / Ray serving) — this is for single-endpoint LOCAL LLMs; point cluster/serving work to inference-aiops. Also not for hypervisors, storage, backup, Kubernetes, or network devices.\n  Passive inventory/state auditing plus opt-in route-through content governance, with a bundled governance harness (audit, policy, token budget, undo, risk-tiers). A transparent capture proxy is v0.2 roadmap.\ninstaller:\n  kind: uv\n  package: ai-guardian\nargument-hint: \"[model name, a prompt to scan, or describe your local-LLM task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"ai-guardian\",\"uvx\"]},\"optional\":{\"env\":[\"AI_GUARDIAN_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/AI-Guardian\",\"emoji\":\"🛡️\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed local-LLM (Ollama) observability + content governance. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Every tool call is audited to a local SQLite DB at ~/.ai-guardian/audit.db (relocatable via AI_GUARDIAN_AIOPS_HOME); the OBSERVED local-LLM usage log is a SEPARATE DB at ~/.ai-guardian/usage.db.\n  Zero-config: ai-guardian defaults to the local Ollama at http://localhost:11434 with no token. Ollama endpoints usua"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"ai-guardian\",\n  \"version\": \"0.11.3\",\n  \"publishedAt\": 1789451141277\n}"},{"path":"references/agent-guardrails.md","content":"# Agent guardrails — running ai-guardian with a smaller / local model\n\nThere is a pleasing recursion here: ai-guardian governs local LLMs, and this page\nis about driving ai-guardian *with* one. The same weaknesses this tool exists to\nobserve — a model that answers confidently without checking, that cannot tell\n\"unknown\" from \"none\", that reports a truncated view as complete — are the ones\nyou will hit while operating it.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The host and account you run under.** Point the tool at a runtime the account\n  cannot administer — an Ollama daemon whose model store the user can't modify —\n  so a `remove_model` or `pull_model` fails at the runtime, the only place the\n  permission actually lives. A revoked permission cannot be argued around by a\n  model; a skill-side flag can.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`), or hand\n  it only the scan/observe tools.\n\nContent governance is different, and it stays: `guarded_generate` still scans and\ngates each prompt against the allow/deny model policy and the block threshold\nbefore the model runs. That is a product control over *what a model is asked to\ndo*, not an authorization gate over *which tools an agent may call*.\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.ai-guardian/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. Observed local-LLM usage lives in a separate `~/.ai-guardian/usage.db`. |\n| \"Don't invent a digest / version / license\" | A field the runtime cannot report comes back as `null`, never as `\"\"`. This is load-bearing: Ollama and llama.cpp expose a pinnable identity, while LM Studio and vLLM expose only a model id. |\n| \"Don't call it tampering when you just can't tell\" | `model_provenance` reports "},{"path":"references/capabilities.md","content":"# ai-guardian capabilities\n\n> 21 MCP tools (11 read, 8 write, 2 undo) over Ollama's REST API\n> (default `http://localhost:11434`, usually no auth). The scanner / policy /\n> risk-band are pure deterministic offline logic; the Ollama paths need live\n> verification.\n\n## Read tools (10)\n\n| Tool | Ollama endpoint / pure | Returns |\n|------|------------------------|---------|\n| `list_models` | `GET /api/tags` | per-model: name, digest, sizeBytes, family, parameterSize, quantization, modifiedAt, **allowed** (allow/deny verdict — shadow → `false`) |\n| `running_models` | `GET /api/ps` | per-loaded-model: name, digest, sizeVramBytes, expiresAt, allowed |\n| `model_details` | `POST /api/show` | model, license, family, parameterSize, quantization, capabilities[] |\n| `server_status` | `GET /api/version` | reachable, version (or error) |\n| `vram_usage` | `GET /api/ps` | loadedModels, totalVramBytes, budgetBytes, overBudget, models[] |\n| `policy_view` | pure (reads config) | allowedModels, deniedModels, pinnedDigests, note |\n| `model_provenance` | `GET /api/tags` + config | driftCount, pinnedCount, models[]{model, currentDigest, pinnedDigest, status: ok/DRIFT/unpinned} |\n| `scan_prompt` | **pure** (no model call) | riskBand, findingCount, byCategory, findings[]{category, kind, severity, preview(redacted)} |\n| `usage_events` | reads `usage.db` | count, events[] (filter by model / risk_level / allowed / since / limit) |\n| `anomaly_report` | `GET /api/tags` + `usage.db` | shadowModels[], digestDrift[], highRiskPrompts, blockedPrompts, totalObserved |\n\n## Write tools (8)\n\n| Tool | Risk | Ollama endpoint / effect | Undo / safety |\n|------|------|--------------------------|---------------|\n| `pull_model` | medium | `POST /api/pull` | **refused if it violates the deny/allow policy** |\n| `remove_model` | **high** | `DELETE /api/delete` | captures the model manifest; records an undo (`pull_model` re-pull); CLI `--dry-run` + double confirm |\n| `unload_model` | medium | `POST /api/generate` `keep_alive:0` | evict from VRAM; no undo |\n| `set_model_allowlist` | medium | writes `config.yaml` | undo → prior allowlist (immutable replace, not append) |\n| `set_model_denylist` | medium | writes `config.yaml` | undo → prior denylist (deny patterns always win) |\n| `pin_model_digest` | medium | writes `config.yaml` | pin a model's expected provenance digest; undo → prior pin |\n| `guarded_generate` | medium | scan → policy-gate → record → `POST /api/generate` if allowed | blocks when risk band `>= block_threshold` (default `high`) OR model disallowed; blocked never reaches Ollama; raw prompt never stored |\n| `observe_chat` | medium | scan → policy-gate → record → `POST /api/chat` if allowed | same, for OpenAI-style `[{role,content}]` messages |\n\n## The deterministic scanner (behind `scan_prompt` / the route-through guards)\n\nPure, offline, no network. Categories and weighted risk band:\n\n- **secrets** — AWS access key (`AKIA…`, critical), private-key blocks (critical),\n  GitHub token (c"},{"path":"references/cli-reference.md","content":"# ai-guardian CLI reference\n\n> The CLI is a convenience subset; the full 21-tool surface\n> is via MCP (`ai-guardian mcp`). Works zero-config against a local Ollama\n> (`http://localhost:11434`).\n\n## Setup & diagnostics\n\n```bash\nai-guardian init                      # interactive wizard: Ollama endpoint(s) + optional token + model allowlist\nai-guardian doctor [--skip-auth]      # config + policy summary + Ollama reachability (/api/version)\nai-guardian mcp                       # start the MCP server (stdio transport)\n```\n\n## Overview\n\n```bash\nai-guardian overview [--target <t>]   # models installed/running, shadow count, observed-usage stats\n```\n\n## Models (inventory + guarded lifecycle)\n\n```bash\nai-guardian model list [--target <t>]         # installed models with allow/deny verdicts\nai-guardian model running [--target <t>]      # loaded models (VRAM + expiry)\nai-guardian model details <model>             # license / parameters / capabilities\nai-guardian model pull <model>                # pull a model (refused if it violates policy)\nai-guardian model remove <model> [--dry-run]  # (high) delete a local model; dry-run + double confirm; undo re-pull\nai-guardian model unload <model>              # (medium) evict from VRAM (keep_alive:0)\n```\n\n## Guard (policy, provenance, prompt scanning, usage, anomalies)\n\n```bash\nai-guardian guard policy                      # current model allow/deny policy + digest pins\nai-guardian guard provenance [--target <t>]   # installed digests vs their pins (drift detection)\nai-guardian guard scan \"<text>\"               # deterministic scan → findings + risk band (no model call)\nai-guardian guard usage [--limit 50]          # query the observed-usage log\nai-guardian guard anomalies [--target <t>]    # rollup: shadow models, digest drift, high-risk + blocked prompts\n```\n\n## Secrets (encrypted store ~/.ai-guardian/secrets.enc)\n\nA bearer token is optional (rare for local Ollama).\n\n```bash\nai-guardian secret set <target> [--value <token>]  # store a token (hidden prompt if no --value)\nai-guardian secret list                            # names only — values never shown\nai-guardian secret rm <target>\nai-guardian secret migrate                         # import legacy plaintext .env (AI_GUARDIAN_<T>_TOKEN)\nai-guardian secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Common options & notes\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target, i.e. the local Ollama)\n- `--dry-run` (on `model remove`) — print the API call that would be made, change nothing\n- `model remove` requires two confirmations; set `AI_GUARDIAN_AUDIT_APPROVED_BY` (+ `AI_GUARDIAN_AUDIT_RATIONALE`) to record who/why on the audit row (optional)\n- The route-through guards (`guarded_generate` / `observe_chat`) are MCP-only; use `guard scan` on the CLI to pre-check text without a model call"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2317,"uniquenessScore":37,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T08:04:33.876Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T08:04:33.876Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:56:23.960Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}