Policy-based monitoring and command-line enforcement for high-risk agent operations. Intercepts sensitive commands and logs them for human auditing.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add dvcrn/openclaw-skills-marketplace --skill audit-log-firewall --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Audit Log Firewall?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/dvcrn-audit-log-firewall)More formats (shields.io, HTML) on the badges page.
---
name: audit-log-firewall
description: "Policy-based monitoring and command-line enforcement for high-risk agent operations. Intercepts sensitive commands and logs them for human auditing."
---
# Audit Log Firewall
Security is a non-negotiable protocol for autonomous agents. This skill acts as a dynamic guardrail.
## Operational Modes
### 1. Interception Mode
Every command is checked against a local allowlist (`config/allowlist.json`).
- **High Risk**: commands like `rm -rf`, `sudo`, or direct `curl` to unknown external IPs.
- **Protocol**: If a high-risk command is detected, the agent triggers a mandatory 'Pause and Ask' state.
### 2. Forensic Logging
All terminal activity is hashed and stored in `.logs/SECURITY.json`.
- **Fields**: Timestamp, Command, User, Working Directory, and Hash.
- **Utility**: Allows humans to reconstruct the agent's actions in case of a breach or error.
## Installation
```bash
clawhub install audit-log-firewall
```
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Playbook for creating and editing uCoz landing pages via MCP tools (`templates_tool`, `ftp_tool`, `modules_tool`). Use for tasks such as: "build a landing page", "update the homepage as a landing page", "create a promo page on the homepage", "add a lead form / menu / SEO to the homepage". Homepage: `page_list`, `page_get`; first publish — `page_update` with full `page_tmpl`; HTML edits after generation — `patch_template` (module_id=2, template_id=1), not `update_template`. Activate the mail f...