Skip to content
Back to skills

Openclaw Shield

ASecurity

Enterprise security scanner for AI agents. Detects credential

  • 14 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 7, 2026
devopspythonrustbashnodegitsecuritydocumentation

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill openclaw-shield --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openclaw Shield?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Openclaw Shield
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-openclaw-shield/badge)](https://www.skillsdirectory.com/skills/modbender-openclaw-shield)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: OpenClaw Shield
description: Enterprise security scanner for AI agents. Detects credential
  theft, data exfiltration, and malicious code with static analysis + runtime
  guards + ClamAV integration. Audit logging and tamper-evide...
---

# OpenClaw Shield

Enterprise security scanner for AI agents. Detects credential theft, data exfiltration, and malicious code with static analysis + runtime guards + ClamAV integration. Audit logging and tamper-evident reports.

**When to use:** Security scanning, threat detection, code auditing, runtime protection for AI agents

**What to know:**

**Repository:** https://github.com/pfaria32/OpenClaw-Shield-Security

## Features

### Static Scanner
- Detects credential theft, data exfiltration, destructive operations
- Pattern-based analysis (no external dependencies)
- Python stdlib only (zero supply chain risk)
- Pre-execution scanning

### Runtime Guard  
- File/network/exec allowlists
- Output sanitization
- Policy enforcement
- Real-time protection

### Integration
- ClamAV integration (3.6M virus signatures)
- Telegram alerting on critical findings
- Hash-chained audit logging
- Tamper-evident security logs

## Installation

```bash
cd /home/node/.openclaw/workspace
git clone https://github.com/pfaria32/OpenClaw-Shield-Security.git projects/OpenClaw-Shield

# Test the scanner
python3 projects/OpenClaw-Shield/src/scanner.py /path/to/scan

# Deploy (see repository README for full setup)
```

## Usage

### Manual Scan
```bash
python3 projects/OpenClaw-Shield/src/scanner.py workspace --output shield-report.json
```

### Daily Automated Scans
Set up cron job (see repository deployment guide):
```bash
# Daily at 3 AM UTC
0 3 * * * /path/to/scan-script.sh
```

### Runtime Guard (Optional)
Configure allowlists and enable runtime protection (see deployment/openclaw-config.py in repo).

## Status

✅ **Deployed** on this instance (clawdbot-toronto)
- Daily scans: 3:00 AM UTC  
- ClamAV: Active (host-level)
- Runtime guard: Prepared (not enabled by default)

## Attribution

**Inspired by:** Resonant by Manolo Remiddi  
**Source:** https://github.com/ManoloRemiddi/resonantos-open-system-toolkit/blob/main/BUILD_YOUR_OWN_SHIELD.md

Built on the principle: "Don't trust, verify."

## Documentation

Full docs, threat model, and deployment guide in repository README.

Files in this skill

  • README.md643 B
  • SECURITY.md3.3 KB
  • SKILL.md2.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…