
🦞 Security hardening patch for Clawdbot/Moltbot. Detects and fixes exposed gateways automatically.
Security hardening for Clawdbot/Moltbot installations. Detects and fixes exposed gateways.
Detect and fix exposed Clawdbot/Moltbot gateways
Problem • Features • Quick Start • Docker • CLI • What Gets Fixed • Development
900+ Clawdbot/Moltbot instances are currently exposed on the internet (visible on Shodan, port 18789) without any authentication. This allows anyone to:
| Risk | Impact |
|---|---|
| Access API keys | Steal OpenAI, Anthropic, and other credentials |
| Execute commands | Run arbitrary shell commands on your machine |
| Control browser | Take over your browsing session |
| Read emails | Access Gmail, calendar, contacts |
| Read chats | See all your conversation history |
| Hijack the bot | Send messages on your behalf |
The issue isn't a bug—it's misconfiguration. Users who change gateway.bind to 0.0.0.0 or use Docker with -p 18789:18789 without proper auth are fully exposed.
ClawdGuard fixes this.
cargo install clawdguard
# Run
clawdguard
# Clone repository
git clone https://github.com/fadidevv/clawdguard.git
cd clawdguard
# Build (first time takes ~2 min)
cargo build --release
# Run
./target/release/clawdguard
# Clone repository
git clone https://github.com/fadidevv/clawdguard.git
cd clawdguard
# Build image (~3-5 min first time)
docker build --no-cache -t clawdguard .
# Run (mount your config directory)
docker run -v ~/.moltbot:/root/.moltbot clawdguard
# Or for legacy Clawdbot:
docker run -v ~/.clawdbot:/root/.clawdbot clawdguard
clawdguard
That's it! ClawdGuard will:
ClawdGuard generates a secure token. Save it!
╭────────────────────────────────────────────────────────────────────╮
│ ⚠️ IMPORTANT: Save your new gateway token! │
│ │
│ clwd_a8f2k9x3m1p7v4q2b6n8... │
│ │
│ You'll need this to connect from the Control UI or CLI. │
╰────────────────────────────────────────────────────────────────────╯
Full Docker documentation for those without Rust installed.
# 1. Clone repository
git clone https://github.com/fadidevv/clawdguard.git
cd clawdguard
# 2. Build image (~3-5 min first time)
docker build --no-cache -t clawdguard .
# 3. Run scan (mount your config directory)
# For Moltbot (newer):
docker run -v ~/.moltbot:/root/.moltbot clawdguard
# For Clawdbot (legacy):
docker run -v ~/.clawdbot:/root/.clawdbot clawdguard
# With verbose mode
docker run -v ~/.moltbot:/root/.moltbot clawdguard --verbose
# Scan only (no fixes)
docker run -v ~/.moltbot:/root/.moltbot clawdguard --scan-only
# Auto mode (no prompts)
docker run -v ~/.moltbot:/root/.moltbot clawdguard --auto
# Show help
docker run clawdguard --help
Simpler syntax using docker-compose:
# Run with docker-compose
docker-compose run clawdguard
# With verbose
docker-compose run clawdguard --verbose
# Scan only
docker-compose run clawdguard --scan-only
# Auto mode
docker-compose run clawdguard --auto
| Command | Description |
|---|---|
docker build --no-cache -t clawdguard . | Build image |
docker run clawdguard --help | Show help |
docker run -v ... clawdguard | Run scan |
docker run -v ... clawdguard --scan-only | Scan only |
docker run -v ... clawdguard --auto | Auto fix |
docker run -v ... clawdguard --verbose | Verbose mode |
docker-compose run clawdguard | Run with compose |
| Mount | Purpose |
|---|---|
~/.moltbot:/root/.moltbot | Your Moltbot config directory (newer) |
~/.clawdbot:/root/.clawdbot | Your Clawdbot config directory (legacy) |
./results:/app/results | Save results locally |
# Create alias for easier usage (use your config directory)
alias clawdguard='docker run -v ~/.moltbot:/root/.moltbot clawdguard'
# Or for legacy Clawdbot:
alias clawdguard='docker run -v ~/.clawdbot:/root/.clawdbot clawdguard'
# Then just run:
clawdguard
clawdguard --scan-only
clawdguard --verbose
clawdguard [OPTIONS]
OPTIONS:
--scan-only Only scan for issues, don't apply fixes
--auto Apply all fixes without confirmation prompts
--backup-dir <DIR> Custom directory for backup files
--skip-firewall Skip adding firewall rules
--skip-restart Skip restarting the gateway service
--token <TOKEN> Use a specific token instead of generating one
-v, --verbose Show detailed output
--json Output results as JSON (for scripting)
-h, --help Print help
-V, --version Print version
# Basic usage - scan, fix, verify
clawdguard
# Scan only (don't fix anything)
clawdguard --scan-only
# Fix everything automatically (no prompts)
clawdguard --auto
# Use your own token
clawdguard --token "my-secure-token-here"
# Verbose output for troubleshooting
clawdguard --verbose
# JSON output for scripting
clawdguard --json
# Combine options
clawdguard --auto --skip-firewall --verbose
# Custom backup directory
clawdguard --backup-dir /tmp/backups