
Full-stack security OS for AI agents with five-layer defense-in-depth architecture covering foundation scan, input sanitization, cognition protection, decision alignment, and execution control.
AgentWard (玄甲) is a full-stack security operating system purpose-built for trustworthy, scalable AI agent deployment, with native code adaptation to OpenClaw. AgentWard unifies agent onboarding, secure reasoning, and trusted execution in one cohesive security architecture, with upcoming native support for other leading mainstream agent frameworks. Its heterogeneous defense-in-depth design rearchitects the agent workflow into five coordinated security layers across startup, perception, memory, decision-making, and execution, with dynamic cross-stage protections that verify foundation integrity, block adversarial deception, stop memory tampering, and validate every autonomous decision and high-risk command — a complete, end-to-end closed security loop that delivers on the promise of "trustworthy at inception, controllable throughout the process, and reliable in outcomes". If you find this repo useful, please cite our paper on the design of AgentWard architecture:
@misc{zhang2026agentwardlifecyclesecurityarchitecture,
title={AgentWard: A Lifecycle Security Architecture for Autonomous AI Agents},
author={Yixiang Zhang and Xinhao Deng and Jiaqing Wu and Yue Xiao and Ke Xu and Qi Li},
year={2026},
eprint={2604.24657},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2604.24657},
}
⚡ Installation or Update
# Run the setup script
bash /path/to/agent-ward/setup.sh
✅ Verify Installation
openclaw plugins list
Then enjoy enhanced security for your OpenClaw!
AgentWard is natively and deeply integrated with the OpenClaw platform and embeds native security capabilities into the full lifecycle workflow of AI agents. Its heterogeneous defense-in-depth architecture reconstructs isolated single-point security checks into a closed-loop, coordinated system-level protection system, delivering end-to-end, full-chain trustworthy assurance for AI agents from startup through to execution.

AgentWard delivers system-level security through five tightly integrated layers that work in tandem — transforming isolated security checks into a unified, end-to-end protection system for AI agents.
| Layer | Focus |
|---|---|
| 🏗️ Foundation Scan Layer | Supply chain trust and baseline integrity |
| 🧼 Input Sanitization Layer | Prompt injection and jailbreak detection |
| 🧠 Cognition Protection Layer | Memory poisoning and context drift |
| 🎯 Decision Alignment Layer | Intent consistency before action |
| 🔧 Execution Control Layer | High-risk operation guardrails |
Ensures the agent starts from a trustworthy foundation.
English Version |
Chinese Version |
Identifies adversarial inputs before they propagate into the agent.
English Version |
Chinese Version |
Protects long-term memory and contextual continuity from poisoning.
English Version |
Chinese Version |
Keeps agent decisions aligned with authorized user intent.