面向 AI 代理的安全代理。 置于 OpenClaw 之前,在消息到达模型或离开网络之前,对每条消息进行提示注入、PII 泄露和机密扫描。
附带 5 个专用 AI 代理、内置仪表板和一个 YAML 策略引擎。一条命令即可启动。
┌──────────────┐ ┌──────────────────┐ ┌──────────────┐
│ Browser │────▶│ ClawShield │────▶│ OpenClaw │
│ (you) │◀────│ Security Proxy │◀────│ Gateway │
└──────────────┘ └──────────────────┘ └──────────────┘
▪ Prompt injection ▪ Claude, GPT,
detection LM Studio
▪ PII/secrets redaction ▪ Multi-agent
▪ Policy enforcement routing
▪ Audit logging ▪ RAG knowledge
前置要求: Docker 和一个 Anthropic API 密钥。
# 1. Clone the repo
git clone https://github.com/SleuthCo/clawshield-public.git
cd clawshield-public
# 2. Set your API key
cp standalone/.env.template standalone/.env
# Edit standalone/.env and paste your Anthropic API key
# 3. Start
cd standalone
docker compose up -d
在浏览器中打开 **http://localhost:18801**。你会看到 ClawShield 仪表板,其中有 5 个 AI 代理已就绪,可直接聊天。
就这样。ClawShield 正在扫描你和代理之间的所有流量。
ClawShield 使用 Claude(通过 Anthropic 的 API)作为默认语言模型。以下是获取密钥的方法:
sk-ant- 开头standalone/.env 文件中:
ANTHROPIC_API_KEY=sk-ant-your-key-here
费用: Anthropic 按 token 计费。一次典型的聊天会话只需几美分。新账户可获得 $5 的免费额度。详情请参阅 anthropic.com/pricing。
使用不同的模型? ClawShield 可与任何兼容 OpenAI 的 API(GPT、LM Studio、Ollama 等)配合使用。编辑 standalone/config/openclaw.json 以指向你偏好的提供商。
一切都在单个容器中运行——ClawShield 代理 + OpenClaw 网关 + 5 个代理。
请参阅上面的 快速开始。
从 GitHub Releases 下载最新版本:
| 平台 | 文件 |
|---|---|
| Windows | clawshield-proxy-windows-amd64.exe |
| Linux x64 | clawshield-proxy-linux-amd64 |
| Linux ARM64 | clawshield-proxy-linux-arm64 |
| macOS Apple Silicon | clawshield-proxy-darwin-arm64 |
| macOS Intel | clawshield-proxy-darwin-amd64 |
然后运行交互式设置向导:
# Download the setup wizard too
chmod +x clawshield-setup-*
# Run the wizard — it walks you through everything
./clawshield-setup-linux-amd64
向导将:
需要 Go 1.24+。
git clone https://github.com/SleuthCo/clawshield-public.git
cd clawshield-public
# Build the proxy
cd proxy/cmd/clawshield-proxy
go build -o clawshield-proxy
# Build the setup wizard
cd ../../clawshield-setup
go build -o clawshield-setup
# Run setup
./clawshield-setup
ClawShield 暴露了一个兼容 Prometheus 的 /metrics 端点,用于实时监控:
curl http://localhost:18789/metrics
关键指标:
clawshield_requests_total——已评估的请求总数clawshield_decisions_allowed_total / _denied_total / _redacted_total——决策结果clawshield_scanner_detections_total{scanner,action}——按扫描器类型统计的检测数clawshield_evaluation_duration_seconds——评估延迟直方图clawshield_active_connections——当前 WebSocket 连接数clawshield_crosslayer_events_*——跨层事件总线活动ClawShield 的核心。一个 HTTP 反向代理,拦截用户与 AI 网关之间的所有流量。
扫描器(每个都会生成结构化的取证审计记录,包含规则 ID 和已脱敏的匹配片段):
生产级加固(第 3 层):
CAP_BPF、内核过旧、容器环境),自动回退到 /proc 轮询策略热重载:
policy.yaml 后 5 秒内生效,无需重启流式响应扫描:
策略引擎——基于 YAML,默认拒绝:
default_action: deny
scanners:
prompt_injection:
enabled: true
action: block
pii:
enabled: true
action: redact
secrets:
enabled: true
action: block
domain_allowlist:
- "api.anthropic.com"
- "api.openai.com"
更多示例请参阅 policy/examples/。
每个代理都有专门的职责领域和各自独立的 RAG 知识库:
| 代理 | 职责 | 知识库 |
|---|---|---|
| Anvil | 软件开发 | 编程语言、架构、DevOps、测试、安全编码 |
| Shield | 安全工程 | NIST、MITRE ATT&CK、OWASP、零信任、威胁建模 |
| Harbor | 云工程 | AWS、Azure、GCP、Kubernetes、IaC、网络 |
| Beacon | 通信 | 危机沟通、内容策略、高管简报 |
| Lens | 研究与分析 | OSINT、结构化分析、认知偏差、情报 |
每个请求和响应都会记录到本地 SQLite 数据库中,包含:
clawshield-audit --db /var/lib/clawshield/audit.db --last 50
clawshield-audit --db /var/lib/clawshield/audit.db --blocked-only
clawshield-audit --db /var/lib/clawshield/audit.db --scanner injection
clawshield-audit --db /var/lib/clawshield/audit.db --rule-id sqli
完整的模式请参阅 docs/audit-log-format.md,取证查询详情请参阅 决策可解释性。
SIEM 集成:
基于 iptables 的出站防火墙,限制代理可以访问的域名/IP:
cd firewall/cmd/clawshield-fw && go build -o clawshield-fw
sudo ./clawshield-fw apply --config firewall/examples/firewall.yaml
用于检测可疑代理行为的内核级系统调用监控:
sudo python3 ebpf/cmd/clawshield-ebpf/main.py --config ebpf/config/default.yaml
检测项:fork 炸弹、敏感文件访问、权限提升、异常网络连接。
ClawShield 采用纵深防御——由跨层事件总线连接的三个安全层:
Layer 1: Application (ClawShield Proxy)
▪ Scans message content
▪ Enforces YAML policies
▪ Logs all decisions
Layer 2: Network (ClawShield Firewall)
▪ iptables egress rules
▪ Domain/IP allowlist
▪ Blocks unapproved connections
▪ Dynamic temporary rules from cross-layer events
Layer 3: Kernel (ClawShield eBPF)
▪ Syscall monitoring
▪ Behavioral anomaly detection
▪ Real-time alerts
每一层都独立工作。如果某一层被绕过,其他层仍能提供保护。
三个层通过基于 Unix socket 的事件总线进行通信,实现跨层的自适应安全响应:
┌──────────────┐ ┌──────────────┐
│ eBPF │──── Unix Socket ────────▶│ Proxy │
│ (Layer 3) │ /tmp/clawshield- │ (Layer 1) │
│ Produces: │ events.sock │ Produces: │
│ • privesc │ │ • injection │
│ • port_scan │◀── Adaptive Controller ──│ • malware │
│ • file_access│ │ • vuln_scan │
└──────────────┘ └──────────────┘
│
▼
┌──────────────┐
│ Firewall │
│ (Layer 2) │
│ Consumes: │
│ • temp block│
│ rules │
└──────────────┘
自适应响应示例: