
Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF kernel monitor. YAML policy engine, audit logging, 5 AI agents with RAG knowledge bases.
Security proxy for AI agents. Sits in front of OpenClaw and scans every message for prompt injection, PII leaks, and secrets — before they reach the model or leave the network.
Ships with 5 specialized AI agents, a built-in dashboard, and a YAML policy engine. One command to start.
┌──────────────┐ ┌──────────────────┐ ┌──────────────┐
│ Browser │────▶│ ClawShield │────▶│ OpenClaw │
│ (you) │◀────│ Security Proxy │◀────│ Gateway │
└──────────────┘ └──────────────────┘ └──────────────┘
▪ Prompt injection ▪ Claude, GPT,
detection LM Studio
▪ PII/secrets redaction ▪ Multi-agent
▪ Policy enforcement routing
▪ Audit logging ▪ RAG knowledge
Prerequisites: Docker and an Anthropic API key.
# 1. Clone the repo
git clone https://github.com/SleuthCo/clawshield-public.git
cd clawshield-public
# 2. Set your API key
cp standalone/.env.template standalone/.env
# Edit standalone/.env and paste your Anthropic API key
# 3. Start
cd standalone
docker compose up -d
Open http://localhost:18801 in your browser. You'll see the ClawShield dashboard with 5 AI agents ready to chat.
That's it. ClawShield is scanning all traffic between you and the agents.
ClawShield uses Claude (via Anthropic's API) as the default language model. Here's how to get your key:
sk-ant-standalone/.env file:
ANTHROPIC_API_KEY=sk-ant-your-key-here
Cost: Anthropic charges per token. A typical chat session costs a few cents. New accounts get $5 in free credits. See anthropic.com/pricing for details.
Using a different model? ClawShield works with any OpenAI-compatible API (GPT, LM Studio, Ollama, etc.). Edit standalone/config/openclaw.json to point at your preferred provider.
Everything runs in a single container — ClawShield proxy + OpenClaw gateway + 5 agents.
See Quickstart above.
Download the latest release from GitHub Releases:
| Platform | File |
|---|---|
| Windows | clawshield-proxy-windows-amd64.exe |
| Linux x64 | clawshield-proxy-linux-amd64 |
| Linux ARM64 | clawshield-proxy-linux-arm64 |
| macOS Apple Silicon | clawshield-proxy-darwin-arm64 |
| macOS Intel | clawshield-proxy-darwin-amd64 |
Then run the interactive setup wizard:
# Download the setup wizard too
chmod +x clawshield-setup-*
# Run the wizard — it walks you through everything
./clawshield-setup-linux-amd64
The wizard will:
Requires Go 1.24+.
git clone https://github.com/SleuthCo/clawshield-public.git
cd clawshield-public
# Build the proxy
cd proxy/cmd/clawshield-proxy
go build -o clawshield-proxy
# Build the setup wizard
cd ../../clawshield-setup
go build -o clawshield-setup
# Run setup
./clawshield-setup
ClawShield exposes a Prometheus-compatible /metrics endpoint for real-time monitoring:
curl http://localhost:18789/metrics
Key metrics:
clawshield_requests_total — Total requests evaluatedclawshield_decisions_allowed_total / _denied_total / _redacted_total — Decision outcomesclawshield_scanner_detections_total{scanner,action} — Detections by scanner typeclawshield_evaluation_duration_seconds — Evaluation latency histogramclawshield_active_connections — Current WebSocket connectionsclawshield_crosslayer_events_* — Cross-layer event bus activityThe core of ClawShield. An HTTP reverse proxy that intercepts all traffic between users and the AI gateway.
Scanners (each produces structured forensic audit records with rule IDs and redacted match excerpts):
Production Hardening (Layer 3):
/proc polling when eBPF is unavailable (no CAP_BPF, old kernel, containers)Policy Hot-Reload:
policy.yaml and changes take effect within 5 seconds, no restart neededStreaming Response Scanning:
Policy engine — YAML-based, deny-by-default:
default_action: deny
scanners:
prompt_injection:
enabled: true
action: block
pii:
enabled: true
action: redact
secrets:
enabled: true
action: block
domain_allowlist:
- "api.anthropic.com"
- "api.openai.com"
See policy/examples/ for more examples.
Each agent has a specialized role and its own RAG knowledge base:
| Agent | Role | Knowledge |
|---|---|---|
| Anvil | Software Development | Languages, architecture, DevOps, testing, secure coding |
| Shield | Security Engineering | NIST, MITRE ATT&CK, OWASP, zero trust, threat modeling |
| Harbor | Cloud Engineering | AWS, Azure, GCP, Kubernetes, IaC, networking |
| Beacon | Communications | Crisis comms, content strategy, executive briefings |
| Lens | Research & Analysis | OSINT, structured analysis, cognitive biases, intelligence |