Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
clawdguard — 🦞 Security hardening patch for Clawdbot/Moltbot. Detects and fixes exposed gateways automatically. | Kitploit
Tools/GitHubGitHub/fadidevv/clawdguard
Defensive ToolsVulnerability ScannersConfiguration AuditingNetwork SecurityAuthenticationMisconfiguration
GitHubfadidevv/clawdguard

clawdguard

🦞 Security hardening patch for Clawdbot/Moltbot. Detects and fixes exposed gateways automatically.

View Repository
21128 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🦞 ClawdGuard

Crates.io Downloads GitHub stars GitHub forks GitHub issues License: MIT

Security hardening for Clawdbot/Moltbot installations. Detects and fixes exposed gateways.

ClawdGuard fixing security issues

Detect and fix exposed Clawdbot/Moltbot gateways

Problem • Features • Quick Start • Docker • CLI • What Gets Fixed • Development


The Problem

900+ Clawdbot/Moltbot instances are currently exposed on the internet (visible on Shodan, port 18789) without any authentication. This allows anyone to:

RiskImpact
Access API keysSteal OpenAI, Anthropic, and other credentials
Execute commandsRun arbitrary shell commands on your machine
Control browserTake over your browsing session
Read emailsAccess Gmail, calendar, contacts
Read chatsSee all your conversation history
Hijack the botSend messages on your behalf

The issue isn't a bug—it's misconfiguration. Users who change gateway.bind to 0.0.0.0 or use Docker with -p 18789:18789 without proper auth are fully exposed.

ClawdGuard fixes this.


Features

  • Auto-Detect - Finds config, service, and running gateway automatically
  • Risk Analysis - Scores your configuration 0-10 with detailed breakdown
  • One-Click Fix - Patches config, generates secure token, restarts service
  • Verification - Confirms the fix worked (port closed, auth required)
  • Safe - Creates timestamped backup before any changes
  • Cross-Platform - macOS (launchd) and Linux (systemd)
  • Graceful Stop - Press Ctrl+C anytime to cancel safely
  • Verbose Mode - See detailed logs of every check being performed
  • Docker Ready - No Rust installation required

Quick Start

1. Choose Your Installation

Option A: Install from crates.io (Recommended)

cargo install clawdguard

# Run
clawdguard

Option B: Build from Source

# Clone repository
git clone https://github.com/fadidevv/clawdguard.git
cd clawdguard

# Build (first time takes ~2 min)
cargo build --release

# Run
./target/release/clawdguard

Option C: With Docker (No Rust Required)

# Clone repository
git clone https://github.com/fadidevv/clawdguard.git
cd clawdguard

# Build image (~3-5 min first time)
docker build --no-cache -t clawdguard .

# Run (mount your config directory)
docker run -v ~/.moltbot:/root/.moltbot clawdguard
# Or for legacy Clawdbot:
docker run -v ~/.clawdbot:/root/.clawdbot clawdguard

2. Run

clawdguard

That's it! ClawdGuard will:

  1. Detect your Clawdbot/Moltbot installation
  2. Analyze security risks in your configuration
  3. Ask for confirmation before making changes
  4. Patch the config with secure settings
  5. Verify the fixes were successful

3. Save Your Token

ClawdGuard generates a secure token. Save it!

╭────────────────────────────────────────────────────────────────────╮
│  ⚠️  IMPORTANT: Save your new gateway token!                       │
│                                                                    │
│    clwd_a8f2k9x3m1p7v4q2b6n8...                                    │
│                                                                    │
│  You'll need this to connect from the Control UI or CLI.          │
╰────────────────────────────────────────────────────────────────────╯

Docker Setup

Full Docker documentation for those without Rust installed.

Build & Run

# 1. Clone repository
git clone https://github.com/fadidevv/clawdguard.git
cd clawdguard

# 2. Build image (~3-5 min first time)
docker build --no-cache -t clawdguard .

# 3. Run scan (mount your config directory)
# For Moltbot (newer):
docker run -v ~/.moltbot:/root/.moltbot clawdguard

# For Clawdbot (legacy):
docker run -v ~/.clawdbot:/root/.clawdbot clawdguard

# With verbose mode
docker run -v ~/.moltbot:/root/.moltbot clawdguard --verbose

# Scan only (no fixes)
docker run -v ~/.moltbot:/root/.moltbot clawdguard --scan-only

# Auto mode (no prompts)
docker run -v ~/.moltbot:/root/.moltbot clawdguard --auto

# Show help
docker run clawdguard --help

Docker Compose

Simpler syntax using docker-compose:

# Run with docker-compose
docker-compose run clawdguard

# With verbose
docker-compose run clawdguard --verbose

# Scan only
docker-compose run clawdguard --scan-only

# Auto mode
docker-compose run clawdguard --auto

Docker Commands Reference

CommandDescription
docker build --no-cache -t clawdguard .Build image
docker run clawdguard --helpShow help
docker run -v ... clawdguardRun scan
docker run -v ... clawdguard --scan-onlyScan only
docker run -v ... clawdguard --autoAuto fix
docker run -v ... clawdguard --verboseVerbose mode
docker-compose run clawdguardRun with compose

Volume Mounts

MountPurpose
~/.moltbot:/root/.moltbotYour Moltbot config directory (newer)
~/.clawdbot:/root/.clawdbotYour Clawdbot config directory (legacy)
./results:/app/resultsSave results locally

Docker Tips

# Create alias for easier usage (use your config directory)
alias clawdguard='docker run -v ~/.moltbot:/root/.moltbot clawdguard'
# Or for legacy Clawdbot:
alias clawdguard='docker run -v ~/.clawdbot:/root/.clawdbot clawdguard'

# Then just run:
clawdguard
clawdguard --scan-only
clawdguard --verbose

CLI Reference

clawdguard [OPTIONS]

OPTIONS:
    --scan-only         Only scan for issues, don't apply fixes
    --auto              Apply all fixes without confirmation prompts
    --backup-dir <DIR>  Custom directory for backup files
    --skip-firewall     Skip adding firewall rules
    --skip-restart      Skip restarting the gateway service
    --token <TOKEN>     Use a specific token instead of generating one
    -v, --verbose       Show detailed output
    --json              Output results as JSON (for scripting)
    -h, --help          Print help
    -V, --version       Print version

Examples

# Basic usage - scan, fix, verify
clawdguard

# Scan only (don't fix anything)
clawdguard --scan-only

# Fix everything automatically (no prompts)
clawdguard --auto

# Use your own token
clawdguard --token "my-secure-token-here"

# Verbose output for troubleshooting
clawdguard --verbose

# JSON output for scripting
clawdguard --json

# Combine options
clawdguard --auto --skip-firewall --verbose

# Custom backup directory
clawdguard --backup-dir /tmp/backups

What Gets Fixed

Download Tool