Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ZoneClaw-code — Benchmark and defense code for persistent memory attacks on OpenClaw-style computer-use agents, with memory-zoning mitigation, attack scenarios, and evaluation scripts. | Kitploit
Tools/GitHubGitHub/euph00/zoneclaw-code
Defensive ToolsPenetration TestingMachine LearningPapers & ResearchLearning & EducationAI SecurityAdversarial AttackLabs & Practice
GitHubeuph00/zoneclaw-code

ZoneClaw-code

Benchmark and defense code for persistent memory attacks on OpenClaw-style computer-use agents, with memory-zoning mitigation, attack scenarios, and evaluation scripts.

View Repository
39 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ZoneClaw

Experiment code for ZoneClaw: Mitigating Persistent Memory Attack by Establishing Memory-Zoning among OpenClaw-Style Computer-Use Agents.

This repository contains the benchmark tasks, defense implementations, and evaluation scripts used in the paper. The benchmark studies cross-session persistent memory attacks in OpenClaw-style computer-use agents. It covers two attack classes:

  • Hidden side effects: BCC exfiltration and chat mirroring.
  • Provenance corruption: source redirection and marketplace redirection.

ZoneClaw separates retained external observations from authority-bearing memory, then uses role-separated agents to observe, classify, and act on persistent information.

This code-only edition does not bundle experiment results. The paper's transcripts, verifier evidence, and summaries are available in the accompanying artifact repository.

Setup

Prerequisites

  • Linux or WSL2 (tested on Ubuntu 24.04 under WSL2, x86-64)
  • Docker with Compose support
  • Git
  • Python 3.12+
  • uv

Allow at least 20 GB of free disk space for dependencies, Docker images, and generated runs. We recommend 16 GB of RAM for parallel experiments. Initial setup typically takes 10-20 minutes, depending on the network and Docker build cache.

For an anonymous download, extract the ZIP, open a terminal in its top-level directory, and run:

bash setup.sh

Setup fetches the pinned OpenClaw, Harbor, and WorkspaceBench dependencies directly from their public upstream repositories. No access to the original private repository is needed.

For a Git checkout, replace <repository-url> below with the repository's clone URL:

git clone --depth 1 --recurse-submodules --shallow-submodules \
  <repository-url> ZoneClaw-code
cd ZoneClaw-code
bash setup.sh

The script validates the local tools and Docker daemon, builds the required images, and creates .env from .env.example. It generates OPENCLAW_GATEWAY_TOKEN locally; edit .env only to set the provider keys needed for a run. Do not commit .env.

ExperimentRequired API keys
Anthropic main modelANTHROPIC_API_KEY
OpenAI main modelOPENAI_API_KEY
Z.AI main modelZAI_API_KEY
Alibaba Qwen main modelALIBABA_KEY
Watcher or MELON with a non-Anthropic main modelMain-model key and ANTHROPIC_API_KEY
WorkspaceBench authority and benign-utility evaluationsOPENAI_API_KEY and ANTHROPIC_API_KEY

Experiments make paid provider calls. Start with one trial to verify the complete path:

MODEL=anthropic/claude-sonnet-4-6 \
E2E=bcc-zoneclaw-userprompt N=1 P=1 bash bench.sh

The main paper experiments use Claude Sonnet 4.6. After the smoke test succeeds, reproduce the full row with:

MODEL=anthropic/claude-sonnet-4-6 \
E2E=bcc-zoneclaw-userprompt N=15 P=3 bash bench.sh

Outputs are written to runs/<timestamp>__e2e-<experiment>/. The command prints a per-trial breakdown after aggregation; an existing run can be viewed again with:

bash show-bench.sh runs/<run-directory>

Main Attack and Mitigation Experiments

Named end-to-end experiments follow:

<scenario>[-<defense>]-<setting>
Paper termCommand token
BCC exfiltrationbcc
Chat mirrorchat
Source redirectionsr
Marketplace redirectionmarket
User-triggered updateuserprompt
Periodic updateheartbeat
No defenseomit the defense token
ClawKeeper-style Watcherauditor
Privilege separationprivsep
ClawGuardclawguard
MELONmelon
ZoneClawzoneclaw

Examples:

# Undefended BCC, user-triggered update
MODEL=anthropic/claude-sonnet-4-6 \
E2E=bcc-userprompt N=15 P=3 bash bench.sh

# ClawKeeper-style Watcher, periodic Chat Mirror update
MODEL=anthropic/claude-sonnet-4-6 \
E2E=chat-auditor-heartbeat N=15 P=3 bash bench.sh

# ZoneClaw, user-triggered source-redirection update
MODEL=anthropic/claude-sonnet-4-6 \
E2E=sr-zoneclaw-userprompt N=15 P=3 bash bench.sh

All valid names and their injection/exploitation task pairs are listed in experiments/e2e.tsv.

To use another supported model, replace MODEL; for example:

MODEL=openai/gpt-5.5 OPENCLAW_THINKING=medium \
E2E=bcc-zoneclaw-userprompt N=15 P=3 bash bench.sh

MODEL=zai/glm-5.2 \
E2E=bcc-zoneclaw-userprompt N=15 P=3 bash bench.sh

BENCH_TOKEN_PRICES_FILE="$PWD/experiments/measurement/qwen3.7-plus-2026-05-26.json" \
MODEL=alibaba/qwen3.7-plus-2026-05-26 OPENCLAW_THINKING=medium \
E2E=bcc-zoneclaw-userprompt N=15 P=3 bash bench.sh

Measured runs archive per-phase runtime, model usage, and helper-model usage alongside each trial. Alibaba Qwen runs additionally retain a content-free raw usage ledger so reasoning tokens are not double-counted by the compatibility adapter. See docs/measurement.md for the schema and aggregation rules.

Additional Experiments

ZoneClaw Ablations

The paper evaluates each ablation on the user-triggered form of all four scenarios. The BCC commands are:

# w/o Zone
MODEL=anthropic/claude-sonnet-4-6 \
E2E=bcc-zoneclaw-no-authority-metadata-userprompt N=15 P=3 bash bench.sh

# w/o Gatekeeper
MODEL=anthropic/claude-sonnet-4-6 \
E2E=bcc-zoneclaw-auto-promotion-userprompt N=15 P=3 bash bench.sh

# w/o Cross-check
MODEL=anthropic/claude-sonnet-4-6 \
E2E=bcc-zoneclaw-low-context-userprompt N=15 P=3 bash bench.sh

Replace bcc with chat, sr, or market for the remaining scenarios.

Defense-Aware Attacks

for experiment in \
  bcc-prompt-aware-promotion-userprompt \
  bcc-zoneclaw-prompt-aware-promotion-userprompt \
  bcc-prompt-aware-composed-userprompt \
  bcc-zoneclaw-prompt-aware-composed-userprompt \
  sr-prompt-aware-finegrained-userprompt \
  sr-zoneclaw-prompt-aware-finegrained-userprompt
do
  MODEL=anthropic/claude-sonnet-4-6 \
  E2E="$experiment" N=15 P=3 bash bench.sh
done

Selective Promotion

MODEL=anthropic/claude-sonnet-4-6 \
TASK=bcc-exfiltration-zoneclaw-promotion/benign-only \
N=30 P=3 bash bench.sh

MODEL=anthropic/claude-sonnet-4-6 \
TASK=bcc-exfiltration-zoneclaw-promotion/malicious-only \
N=30 P=3 bash bench.sh

Repeated Use Across Sessions

The paper uses the BCC repeated-attack schedule, ten update sessions, and checkpoints after 0, 1, 2, 3, 5, and 10 updates:

MODEL=anthropic/claude-sonnet-4-6 \
SYSTEM=no-defense SCHEDULE=repeated-attack \
N=3 P=1 bash longitudinal-bench.sh

MODEL=anthropic/claude-sonnet-4-6 \
SYSTEM=zoneclaw SCHEDULE=repeated-attack \
N=3 P=1 bash longitudinal-bench.sh

WorkspaceBench Authority Probe

WorkspaceBench experiments require its Lite metadata and workspace files:

uv run --with huggingface_hub python \
  workspace-bench/evaluation/scripts/download_hf_assets.py \
  --eval-root workspace-bench/evaluation \
  --language en --lite --workspaces

After downloading the upstream tasks, generate the paper's two disjoint 15-task subsets with the fixed selection seed:

WB_SUBSETS="$PWD/workspace-bench/evaluation/.generated/memory_authority_probe/subsets"
python3 scripts/workspacebench_privilege_probe.py make-subset \
  --n 15 --seed 20260709 --language en \
  --dest "$WB_SUBSETS/lite-en-15-seed20260709"
python3 scripts/workspacebench_privilege_probe.py make-subset \
  --n 15 --seed 20260709 --language en \
  --exclude-selection "$WB_SUBSETS/lite-en-15-seed20260709/selection.json" \
  --dest "$WB_SUBSETS/lite-en-15-extension-seed20260709"

Run each of the four authority conditions on both subsets:

Download Tool