{"_id":"@andrewlabs/openclaw-messageguard","name":"@andrewlabs/openclaw-messageguard","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@andrewlabs/openclaw-messageguard","version":"1.0.0","description":"OpenClaw plugin: filters outgoing messages for API keys, credentials, PII, and other sensitive data using MessageGuard.","type":"module","main":"./index.js","types":"./index.d.ts","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"keywords":["openclaw","openclaw-plugin","messageguard","secret-detection","security","message-filter"],"author":{"name":"AndrewAndersen"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/AndrewAndrewsen/MessageGuard.git"},"homepage":"https://github.com/AndrewAndrewsen/MessageGuard#readme","bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard/issues"},"openclaw":{"extensions":["./index.js"]},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.4.5"},"peerDependencies":{"openclaw":">=2026.0.0"},"peerDependenciesMeta":{"openclaw":{"optional":true}},"_id":"@andrewlabs/openclaw-messageguard@1.0.0","_nodeVersion":"24.13.1","_npmVersion":"11.8.0","dist":{"integrity":"sha512-jLmtSDH5JdL6lA6ltTsJFOwQygcGMznIjLUugQ4WhTpSNFkj2LAsu3ZKnmxxrIbMPNHRrZVpHaFvtkzoFldohg==","shasum":"a2f31dc69d33954b384b6e1a36e83b895a4cf019","tarball":"https://registry.npmjs.org/@andrewlabs/openclaw-messageguard/-/openclaw-messageguard-1.0.0.tgz","fileCount":9,"unpackedSize":11030,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIG6EYtc0YY/INA5Lfs80FGP9xeZ06S1amgJgvHI7uqKZAiEAqtXSp7qgj5WfhmAN9dB3I4QKDJ9rZAqqyhx11tsM1NE="}]},"_npmUser":{"name":"andrewandrewsen","email":"mail@andersandersson.net"},"directories":{},"maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openclaw-messageguard_1.0.0_1771948561284_0.7922424377670221"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-24T15:56:01.189Z","1.0.0":"2026-02-24T15:56:01.415Z","modified":"2026-02-24T15:56:01.630Z"},"maintainers":[{"name":"andrewandrewsen","email":"mail@andersandersson.net"}],"description":"OpenClaw plugin: filters outgoing messages for API keys, credentials, PII, and other sensitive data using MessageGuard.","homepage":"https://github.com/AndrewAndrewsen/MessageGuard#readme","keywords":["openclaw","openclaw-plugin","messageguard","secret-detection","security","message-filter"],"repository":{"type":"git","url":"git+https://github.com/AndrewAndrewsen/MessageGuard.git"},"author":{"name":"AndrewAndersen"},"bugs":{"url":"https://github.com/AndrewAndrewsen/MessageGuard/issues"},"license":"MIT","readme":"# @andrewandersen/openclaw-messageguard\n\nAn [OpenClaw](https://openclaw.ai) plugin that automatically filters outgoing messages for secrets and sensitive data before they are delivered to any channel.\n\n## What it does\n\nMessageGuard intercepts every outgoing message via the `message_sending` hook and runs it through a Python-based pattern scanner. It can:\n\n- **Block** messages containing hard secrets (AWS keys, private key PEM blocks, JWTs)\n- **Mask** sensitive values (generic API keys, tokens, etc.) with redacted output\n- **Warn** (log only, message still sent) for lower-confidence matches\n\nFiltering is infrastructure-level — it applies regardless of which skill, tool, or agent sends the message.\n\n## Requirements\n\n- [OpenClaw](https://openclaw.ai) gateway running\n- Python 3 available as `python3`\n- [MessageGuard](https://github.com/AndrewAndrewsen/MessageGuard) filter script installed\n\n## Installation\n\n```bash\n# 1. Install the plugin\nopenclaw plugins install @andrewandersen/openclaw-messageguard\n\n# 2. Clone MessageGuard (if not already present)\ngit clone https://github.com/AndrewAndrewsen/MessageGuard.git \\\n  ~/.openclaw/workspace/skills/MessageGuard\n\n# 3. Restart the gateway\nopenclaw gateway restart\n```\n\n## Configuration\n\nIn your OpenClaw config (`~/.openclaw/config.yaml`), under `plugins`:\n\n```yaml\nplugins:\n  entries:\n    messageguard:\n      enabled: true\n      config:\n        enabled: true           # optional — defaults to true\n        scriptPath: ~/.openclaw/workspace/skills/MessageGuard/scripts/filter_message.py\n        configPath: ~/.openclaw/messageguard.yaml   # optional custom patterns\n```\n\n### Config options\n\n| Key | Type | Default | Description |\n|-----|------|---------|-------------|\n| `enabled` | boolean | `true` | Disable to skip all filtering |\n| `scriptPath` | string | `~/.openclaw/workspace/skills/MessageGuard/scripts/filter_message.py` | Path to the Python filter script |\n| `configPath` | string | — | Optional path to a MessageGuard YAML/JSON config (custom patterns, mode, etc.) |\n\n## Behaviour\n\n| Outcome | Action |\n|---------|--------|\n| Script not found at startup | Logs a warning; messages pass through |\n| Filter script error | Logs an error; message passes through (fail-open) |\n| Message **blocked** | Delivery cancelled; warning logged |\n| Message **masked** | Sanitised content delivered instead of original |\n| **Warn**-only match | Warning logged; original content delivered |\n| Clean message | Delivered unchanged |\n\n## Customising patterns\n\nSee the [MessageGuard README](https://github.com/AndrewAndrewsen/MessageGuard#readme) for pattern configuration. Custom patterns and mode (`mask`/`block`/`warn`) are controlled by the MessageGuard config file, not the plugin config.\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-606e3655cbeb2c06e980c80b5fecbd8f"}