Sep 13, 2026
Gate Risky Installs and Detect Drift with ClawSec for Agent Runtimes
ClawSec adds signed advisory intelligence, guarded installs, and drift detection to OpenClaw, NanoClaw, Hermes, and Picoclaw agent runtimes.
Agents install skills from strangers, and most runtimes let them. ClawSec, maintained by Prompt Security (from SentinelOne), is an AGPL-licensed collection of security skills and signed advisory intelligence that verifies skill artifacts, detects configuration drift, audits agent environments, and approval-gates risky installs. The repo sits at 1,101 stars on the SkillMap leaderboard and covers four runtimes: OpenClaw, NanoClaw, Hermes, and Picoclaw.
Why This Skill Matters
A skill you install can change your agent's behavior in ways a README will not tell you. ClawSec's answer is defense in depth: a signed advisory feed it verifies before matching published risk against your installed skills, guarded installs that stop on advisory matches and require a second explicit confirmation, platform-specific baselines for critical files and configuration, and focused audit and reporting packages. The project publishes the feed, its detached signature, and a pinned Ed25519 public key so consumers can verify what they read.
Installation
The OpenClaw entry point is the clawsec-suite package. Adding the suite and enabling its persistent hook are separate, reviewable steps — by design:
npx skills add prompt-security/clawsec --skill clawsec-suite -a openclaw --global -y
Then review and enable the advisory hook:
SUITE_DIR="${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-suite"
node "$SUITE_DIR/scripts/setup_advisory_hook.mjs"
The setup script prints its preflight before changing persistent OpenClaw configuration. After it succeeds, restart the OpenClaw gateway and run /new once to trigger the first advisory scan. To list the current optional protections:
node "$SUITE_DIR/scripts/discover_skill_catalog.mjs"
Real Workflow: Audit Your Installed Skills
- Install the suite and enable the advisory hook as above.
- Restart the gateway and start a fresh session with
/new. The first advisory scan matches your installed skills against the signed feed; on a match, a risky install stops and waits for a second, explicit confirmation. - Watch for drift. The README's demo (
soul-guardian) shows the flow end to end: a protected agent file changes, the mismatch is detected, and the suite walks through the response. - Before approving any install for someone else, the README's guidance is to show them the hook preflight and wait for approval before enabling the hook or any optional cron job.
The other runtimes have their own entry points: clawsec-nanoclaw for NanoClaw, hermes-attestation-guardian for Hermes, and picoclaw-security-guardian for Picoclaw, with picoclaw-self-pen-testing as a separate opt-in package.
You can also query the advisory channel directly — the consolidated feed can contain NVD CVEs, approved community reports, and provisional GitHub advisories without CVE identifiers yet:
curl -fsSL https://clawsec.prompt.security/advisories/feed.json \
| jq '.advisories[] | select(.severity == "critical" or .severity == "high")'
Tips
- Do not single-quote paths containing
$HOME; in PowerShell, build the path withJoin-Pathinstead. POSIX.shworkflows need WSL or Git Bash on Windows. - ClawSec recommends and gates actions — destructive removal and install overrides stay approval-controlled.
- The
*-traffic-guardiandirectories in the repo are specification baselines for platform builders, not shipped runtime proxies today. - The project's wiki is the source of truth for documentation; GitHub Wiki pages and LLM-ready exports are generated from it.
When Not to Use This
ClawSec's platform entry points cover OpenClaw, NanoClaw, Hermes, and Picoclaw — for another runtime, the README documents no entry point, and the platform-specific baselines will not apply. The signed advisory feed can still be queried with the curl command above, since it is published independently. The source is AGPL-3.0-or-later, which matters if you plan to embed it in a product.
See the leaderboard for more skills.