{"_id":"@agentlair/defenseclaw","_rev":"3-a8bf37cfb60e52025a8ddb2f73308e56","name":"@agentlair/defenseclaw","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"@agentlair/defenseclaw","version":"0.1.0","keywords":["openclaw","openclaw-plugin","defenseclaw","agentlair","identity","trust","ai-safety","governance"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/defenseclaw@0.1.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev/docs/defenseclaw","bugs":{"url":"https://github.com/agentlair/agentlair/issues"},"dist":{"shasum":"d88e2e299abeff0a139995b8c8e5fd922de32652","tarball":"https://registry.npmjs.org/@agentlair/defenseclaw/-/defenseclaw-0.1.0.tgz","fileCount":5,"integrity":"sha512-TPn/xYz59V6gFIi89HhTxRyd0nmQV7VyxIcZfF1iT1OC+QvGR7XY1HoX5pFQgucuwaj4ScYiqV9aK0pppkF9RA==","signatures":[{"sig":"MEUCIQDKq3iG6i5dQd4k5tM8oAiJnpuU+hqXvqLPx/0AWloCEQIga69e9p7SXWmNJVu3bp/f5UI0gc1L/Y7SZxDReKwkP4U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15059},"main":"src/index.ts","type":"module","scripts":{"typecheck":"tsc --noEmit"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"openclaw":{"hooks":["./src/index.ts"],"extensions":["./src/index.ts"]},"repository":{"url":"git+https://github.com/agentlair/agentlair.git","type":"git","directory":"packages/defenseclaw"},"_npmVersion":"10.9.7","description":"AgentLair identity verification for DefenseClaw — trust-score gating for every OpenClaw tool call.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.11.0"},"peerDependencies":{"openclaw":">=2025.0.0"},"peerDependenciesMeta":{"openclaw":{"optional":false}},"_npmOperationalInternal":{"tmp":"tmp/defenseclaw_0.1.0_1776562856862_0.3272041955518685","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentlair/defenseclaw","version":"0.2.0","keywords":["agentlair","defenseclaw","openclaw","ai-security","agent-trust","governance","plugin"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/defenseclaw@0.2.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"661843adfb50f7247a972f6b6c1469bdd1bb4770","tarball":"https://registry.npmjs.org/@agentlair/defenseclaw/-/defenseclaw-0.2.0.tgz","fileCount":14,"integrity":"sha512-prDK8SB2BZ+x4pw9lC7INvPAdOYzZDJCXy+pxDNgJ+slR4SAD3Mbwdgx9NycRNbaAU5pi+J1VFsP8uRrapW4IA==","signatures":[{"sig":"MEQCIB59Vq/FGrdomr/4l4ooWhBRZyychCL1+yxn66CsumZjAiBR1hUEwkMNlVvWzmmtYCUmmTheiyF/5FEvZaijPe0e/g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28223},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"de0132bcc7bac7ac63fd9a558a924967c89e51eb","scripts":{"dev":"tsc --watch","test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"AgentLair behavioral trust verification for DefenseClaw — bridges cryptographic agent identity into DefenseClaw's governance pipeline","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"peerDependencies":{"@openclaw/plugin-sdk":">=1.0.0"},"peerDependenciesMeta":{"@openclaw/plugin-sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/defenseclaw_0.2.0_1776608138440_0.7991464070935441","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@agentlair/defenseclaw","version":"0.3.0","description":"AgentLair identity verification for DefenseClaw — AAT verification, trust-score gating, and behavioral telemetry for every OpenClaw tool call.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"openclaw":{"extensions":["./dist/index.js"],"hooks":["./dist/index.js"]},"scripts":{"build":"tsup src/index.ts --format esm --dts --out-dir dist","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"license":"MIT","author":{"name":"AgentLair"},"homepage":"https://agentlair.dev/docs/defenseclaw","repository":{"type":"git","url":"git+https://github.com/agentlair/agentlair.git","directory":"packages/defenseclaw"},"keywords":["openclaw","openclaw-plugin","defenseclaw","agentlair","identity","trust","jwt","jwks","eddsa","ai-safety","governance","behavioral-trust"],"peerDependencies":{"@openclaw/plugin-sdk":">=1.0.0"},"peerDependenciesMeta":{"@openclaw/plugin-sdk":{"optional":true}},"devDependencies":{"@types/node":"^20.11.0","tsup":"^8.5.1","typescript":"^5.4.0","vitest":"^3.2.4"},"engines":{"node":">=18.0.0"},"_id":"@agentlair/defenseclaw@0.3.0","bugs":{"url":"https://github.com/agentlair/agentlair/issues"},"_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-Gl28FB/J2Z/LmjWeK8Ekp0UFhnsuOIIwR56fKlE7DxL6PI3vg/ZUHIXEtmlTRNVvK937M3PDCLVgiE2AHlXzpw==","shasum":"f4bdfef287eed09e9cfffe811c15d9f01dfea08f","tarball":"https://registry.npmjs.org/@agentlair/defenseclaw/-/defenseclaw-0.3.0.tgz","fileCount":6,"unpackedSize":24139,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIF7WgZUmzkWAf9F6TyAw/RDLqpkot2j2npxAcy6HU8RNAiBh8ykieFNLCCSgle/jVRR5aMqhTYaSZlAmMhEO4/CMzg=="}]},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"directories":{},"maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/defenseclaw_0.3.0_1776622430627_0.13890873972836792"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-19T01:40:56.730Z","modified":"2026-04-19T18:13:50.905Z","0.1.0":"2026-04-19T01:40:57.036Z","0.2.0":"2026-04-19T14:15:38.603Z","0.3.0":"2026-04-19T18:13:50.778Z"},"bugs":{"url":"https://github.com/agentlair/agentlair/issues"},"author":{"name":"AgentLair"},"license":"MIT","homepage":"https://agentlair.dev/docs/defenseclaw","keywords":["openclaw","openclaw-plugin","defenseclaw","agentlair","identity","trust","jwt","jwks","eddsa","ai-safety","governance","behavioral-trust"],"repository":{"type":"git","url":"git+https://github.com/agentlair/agentlair.git","directory":"packages/defenseclaw"},"description":"AgentLair identity verification for DefenseClaw — AAT verification, trust-score gating, and behavioral telemetry for every OpenClaw tool call.","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"readme":"# @agentlair/defenseclaw\n\nOpenClaw plugin that adds **AgentLair identity verification** to [DefenseClaw](https://github.com/cisco-ai-defense/defenseclaw).\n\nDefenseClaw governs **what** agents can do (policy enforcement, threat detection). AgentLair governs **who** the agent is and **how** it behaves. This plugin wires them together — identity verification, trust-score gating, and behavioral telemetry — without touching your policy YAML.\n\nProposed in [cisco-ai-defense/defenseclaw#121](https://github.com/cisco-ai-defense/defenseclaw/discussions/121).\n\n## What it does\n\nOn every `before_tool_call` event:\n\n1. **(optional) Verify AAT JWT** — extracts the agent's [Agent Authentication Token](https://agentlair.dev) from `ctx.sessionKey`, verifies the EdDSA signature against AgentLair's JWKS endpoint, and rejects expired or tampered tokens.\n2. **Check trust score** — calls `GET /v1/trust/:agentId/check` to get the agent's behavioral trust score (0–100).\n3. **Gate execution** — if the score is below `trustThreshold`:\n   - **enforce** mode (default): block the tool call.\n   - **observe** mode: log a warning and allow execution.\n\nOn every `after_tool_call` event (fire-and-forget):\n\n4. **Report telemetry** — POSTs a structured event to `POST /v1/events` so AgentLair can update the agent's behavioral profile.\n\n## Installation\n\n```bash\nnpm install @agentlair/defenseclaw\n# or\nbun add @agentlair/defenseclaw\n```\n\n## Configuration\n\nAdd to your `openclaw.config.json`:\n\n```json\n{\n  \"plugins\": [\n    {\n      \"package\": \"@agentlair/defenseclaw\",\n      \"config\": {\n        \"agentlairApiKey\": \"al_live_...\",\n        \"agentId\": \"acc_abc123\",\n        \"trustThreshold\": 40,\n        \"mode\": \"enforce\",\n        \"verifyAat\": true,\n        \"reportTelemetry\": true\n      }\n    }\n  ]\n}\n```\n\n### Options\n\n| Key | Type | Default | Description |\n|-----|------|---------|-------------|\n| `agentlairUrl` | string | `https://agentlair.dev` | AgentLair base URL |\n| `agentlairApiKey` | string | — | API key (`al_live_...`). Or set `AGENTLAIR_API_KEY`. |\n| `agentId` | string | — | Fallback agent ID (`acc_...`). Used when `ctx.agentId` is not set. Or set `AGENTLAIR_AGENT_ID`. |\n| `jwksUrl` | string | `{agentlairUrl}/.well-known/jwks.json` | JWKS endpoint for AAT verification |\n| `trustThreshold` | number | `40` | Minimum trust score [0–100] required to execute tools |\n| `mode` | `observe\\|enforce` | `enforce` | `enforce` blocks; `observe` logs only |\n| `failOpen` | boolean | `false` | Allow tool calls when AgentLair is unreachable |\n| `verifyAat` | boolean | `true` | Verify AAT JWT signature before trust check |\n| `reportTelemetry` | boolean | `true` | Report post-call events to `/v1/events` |\n\n### Environment variables\n\n```bash\nAGENTLAIR_URL=https://agentlair.dev\nAGENTLAIR_API_KEY=al_live_...\nAGENTLAIR_AGENT_ID=acc_abc123\n```\n\n## Trust thresholds\n\nAgentLair trust scores map to ATF maturity levels:\n\n| Score | Level |\n|-------|-------|\n| 0–39 | intern |\n| 40–64 | junior |\n| 65–84 | senior |\n| 85–100 | principal |\n\nThe default threshold of **40** corresponds to the `junior` ATF level — agents must have demonstrated baseline behavioral consistency, restraint, and transparency before they can invoke tools.\n\n## Architecture\n\n```\nOpenClaw runtime\n  │\n  ├── before_tool_call\n  │     │\n  │     ├─① AgentLair JWKS  ←── verify AAT JWT (EdDSA/Ed25519)\n  │     │\n  │     ├─② AgentLair /v1/trust/:id/check  ←── get trust score\n  │     │\n  │     └─③ block (enforce) or warn (observe) if score < threshold\n  │\n  └── after_tool_call (fire-and-forget)\n        │\n        └─④ AgentLair /v1/events  ←── report outcome for behavioral profile\n```\n\n## How it relates to DefenseClaw's architecture\n\nDefenseClaw's sidecar inspects **what** a tool call contains (prompt injection, policy violations, data leakage). `@agentlair/defenseclaw` asks **who** is making the call and **whether that agent has earned the right** to execute. The two checks complement each other:\n\n| Layer | DefenseClaw | AgentLair |\n|-------|------------|-----------|\n| Identity | ❌ | ✅ AAT verification |\n| Content | ✅ threat scanning | ❌ |\n| Policy | ✅ block/allow lists | ✅ trust tiers |\n| Audit | ✅ local | ✅ behavioral profile |\n\n## Integration with the DefenseClaw plugin API\n\nThis package implements the [OpenClaw plugin API](https://github.com/cisco-ai-defense/defenseclaw/blob/main/extensions/defenseclaw/typings/%40openclaw/plugin-sdk.d.ts). The default export is a `PluginEntry` function that registers `before_tool_call` and `after_tool_call` hooks:\n\n```ts\nimport type { PluginApi } from '@openclaw/plugin-sdk';\nimport agentLairPlugin from '@agentlair/defenseclaw';\n\nexport default function(api: PluginApi) {\n  agentLairPlugin(api);\n}\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}