{"_id":"@authensor/safeclaw","_rev":"4-65c7c23d89ed364ee034a0be6a53e1e5","name":"@authensor/safeclaw","dist-tags":{"latest":"1.0.0-beta.2","beta":"1.0.0-beta.1"},"versions":{"1.0.0-beta":{"name":"@authensor/safeclaw","version":"1.0.0-beta","keywords":["ai","agent","safety","claude","openai","gpt","authensor","guardrails"],"license":"MIT","_id":"@authensor/safeclaw@1.0.0-beta","maintainers":[{"name":"jkearn","email":"john@authensor.com"}],"homepage":"https://github.com/JKEARN/SafeClaw","bugs":{"url":"https://github.com/JKEARN/SafeClaw/issues"},"bin":{"safeclaw":"src/cli.js"},"dist":{"shasum":"1d2e5aabbb283466a56602a80c3f77dab6b673f6","tarball":"https://registry.npmjs.org/@authensor/safeclaw/-/safeclaw-1.0.0-beta.tgz","fileCount":45,"integrity":"sha512-mrTuK2xNr+M/JtV2cjMhWKDVB1+jHZA0+Dpbg+dMfkD2S+ncOPkbdhU1fto36KztRNHx1FrerXbdAvNfvMYyuw==","signatures":[{"sig":"MEYCIQD8K90+DbRYBQYB+OAqh+lKxF26HD6XTe0BTB/w241pfAIhAMLBoxJcuQm5RouSP1jf4M+sQrCiCwHqZwFYUnuR1nAr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":371881},"type":"module","engines":{"node":">=20"},"gitHead":"37d2732f14e4095e07d7a2abf928cf837a189f09","scripts":{"test":"vitest run","start":"node src/cli.js","test:watch":"vitest"},"_npmUser":{"name":"jkearn","email":"john@authensor.com"},"repository":{"url":"git+https://github.com/JKEARN/SafeClaw.git","type":"git"},"_npmVersion":"11.6.1","description":"Safe-by-default AI agent. Gates every action through Authensor before it executes. Supports Claude and OpenAI.","directories":{},"_nodeVersion":"24.11.0","dependencies":{"@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/safeclaw_1.0.0-beta_1770945939269_0.8471874871584553","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.1":{"name":"@authensor/safeclaw","version":"1.0.0-beta.1","keywords":["ai","agent","safety","claude","openai","gpt","authensor","guardrails"],"license":"MIT","_id":"@authensor/safeclaw@1.0.0-beta.1","maintainers":[{"name":"jkearn","email":"john@authensor.com"}],"homepage":"https://github.com/AUTHENSOR/SafeClaw","bugs":{"url":"https://github.com/AUTHENSOR/SafeClaw/issues"},"bin":{"safeclaw":"src/cli.js"},"dist":{"shasum":"dd5dcfdfd8d46ef9afafdfc972e82bc66ecb8e3e","tarball":"https://registry.npmjs.org/@authensor/safeclaw/-/safeclaw-1.0.0-beta.1.tgz","fileCount":46,"integrity":"sha512-UYNuWcWc3HMM5O9p/ngW0U9f8JJxB5S3fnw1UjdXuPUGooC252p1fviml73x4UVgWsU+rgBVrnMgxJuA00vvVg==","signatures":[{"sig":"MEQCIDMAzBdRI0j7kMIVe5fPBHN1eoeihVWz07U4RdK4mgWlAiABUAikaEgz5Iz76BhTCXInLx38hN1IzUJmlgV71T80sQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":385388},"type":"module","engines":{"node":">=20"},"gitHead":"7300e8b52edb7d48c70b129ac903886d62ab2612","scripts":{"test":"vitest run","start":"node src/cli.js","test:watch":"vitest"},"_npmUser":{"name":"jkearn","email":"john@authensor.com"},"repository":{"url":"git+https://github.com/AUTHENSOR/SafeClaw.git","type":"git"},"_npmVersion":"11.6.1","description":"Safe-by-default AI agent. Gates every action through Authensor before it executes. Supports Claude and OpenAI.","directories":{},"_nodeVersion":"24.11.0","dependencies":{"@anthropic-ai/claude-agent-sdk":"^0.1.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vitest":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/safeclaw_1.0.0-beta.1_1770957258317_0.44740433832907955","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.2":{"name":"@authensor/safeclaw","version":"1.0.0-beta.2","type":"module","description":"Safe-by-default AI agent. Gates every action through Authensor before it executes. Supports Claude and OpenAI.","bin":{"safeclaw":"src/cli.js"},"scripts":{"start":"node src/cli.js","test":"vitest run","test:watch":"vitest"},"engines":{"node":">=20"},"keywords":["ai","agent","safety","claude","openai","gpt","authensor","guardrails"],"repository":{"type":"git","url":"git+https://github.com/AUTHENSOR/SafeClaw.git"},"homepage":"https://github.com/AUTHENSOR/SafeClaw","license":"MIT","dependencies":{"@anthropic-ai/claude-agent-sdk":"^0.1.0"},"devDependencies":{"vitest":"^4.0.18"},"_id":"@authensor/safeclaw@1.0.0-beta.2","gitHead":"7eb53e4b849e6ee8e0faa9f879059a3a1ee39991","bugs":{"url":"https://github.com/AUTHENSOR/SafeClaw/issues"},"_nodeVersion":"20.20.0","_npmVersion":"10.8.2","dist":{"integrity":"sha512-2+G+yOwnA7fkIFkivxiJclYVvrv0j45e66I64mM1ZDXAf2r6Llw4BlffQbQMFtrMRVkrh4iROIwlGtr93wdxjA==","shasum":"141e6f6d1cff1bdb0c081a87cb03f6c0c3b8b26f","tarball":"https://registry.npmjs.org/@authensor/safeclaw/-/safeclaw-1.0.0-beta.2.tgz","fileCount":46,"unpackedSize":397135,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDJzZ6+3sv0dqRH6FSVoPVTDH6YJAFlt9w6hEdTW+BheQIgUNVnvhH4fbIi1ieoYsyMfvWj75t4453FpLUkXvJfmHA="}]},"_npmUser":{"name":"jkearn","email":"john@authensor.com"},"directories":{},"maintainers":[{"name":"jkearn","email":"john@authensor.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/safeclaw_1.0.0-beta.2_1781246805386_0.9374736926181484"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-13T01:25:39.146Z","modified":"2026-06-12T06:46:45.678Z","1.0.0-beta":"2026-02-13T01:25:39.457Z","1.0.0-beta.1":"2026-02-13T04:34:18.525Z","1.0.0-beta.2":"2026-06-12T06:46:45.565Z"},"bugs":{"url":"https://github.com/AUTHENSOR/SafeClaw/issues"},"license":"MIT","homepage":"https://github.com/AUTHENSOR/SafeClaw","keywords":["ai","agent","safety","claude","openai","gpt","authensor","guardrails"],"repository":{"type":"git","url":"git+https://github.com/AUTHENSOR/SafeClaw.git"},"description":"Safe-by-default AI agent. Gates every action through Authensor before it executes. Supports Claude and OpenAI.","maintainers":[{"name":"jkearn","email":"john@authensor.com"}],"readme":"# SafeClaw\n\n[![node](https://img.shields.io/node/v/@authensor/safeclaw)](https://nodejs.org/)\n[![license: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n\n**AI agents that ask before they act.**\n\nSafeClaw intercepts every action your AI agent tries to take (file writes, shell commands, network requests) and checks it against a safety policy before it executes. If something looks risky, you get asked first. Nothing runs without your say-so.\n\nWorks with **Claude** and **OpenAI**. Open-source client. Free tier included.\n\n## Part of the Authensor Safety Stack\n\nSafeClaw is part of [Authensor](https://github.com/AUTHENSOR/AUTHENSOR) -- the open-source safety stack for AI agents. SafeClaw defaults to a self-hosted control plane at `http://localhost:3000`. Start one by cloning [AUTHENSOR/AUTHENSOR](https://github.com/AUTHENSOR/AUTHENSOR) and running `docker compose up -d` (it serves `http://localhost:3000`), then run SafeClaw -- no external services required.\n\n- **[Authensor](https://github.com/AUTHENSOR/AUTHENSOR)** - Policy engine & control plane for agent action authorization\n- **[SafeClaw](https://github.com/AUTHENSOR/SafeClaw)** - Local agent gating with approval workflows *(you are here)*\n\n![SafeClaw dashboard](docs/dashboard.png)\n\n## Install\n\n```bash\nnpx @authensor/safeclaw\n```\n\nYour browser opens. A wizard walks you through everything: pick your AI provider, paste your API key, and you're running.\n\n> **Need Node.js?** Download it at [nodejs.org](https://nodejs.org/) (v20+). That's the only prerequisite.\n\n### First run (no control plane yet)\n\nYou can try SafeClaw before standing up a control plane. Once the wizard (or `safeclaw init`) has saved your provider API key, this works standalone and exits 0:\n\n```bash\nsafeclaw run --dry-run \"Summarize README.md\"\n```\n\nIt prints your provider, profile, and a policy simulation -- no agent is started and nothing leaves your machine. Read-only tasks (`Read`, `Glob`, `Grep`, ...) also run locally without a control plane.\n\nWhat to expect until a control plane is up, all **by design**:\n\n- **Write / exec / network actions fail closed.** SafeClaw denies anything that isn't a local read until it can check it against a policy. That's the point -- nothing risky runs unchecked.\n- **`safeclaw doctor` shows a `[WARN]` on \"Authensor connectivity\"** (\"Control plane unreachable\"). Every other check still passes once your API key is set. This warning is expected, not an error.\n- **`safeclaw health` reports \"Control plane unreachable\" and exits non-zero.** `health` is a pure connectivity probe -- a non-zero exit here just means no control plane is running yet.\n\nTo progress past read-only and dry-run actions, start a control plane (see [Part of the Authensor Safety Stack](#part-of-the-authensor-safety-stack) above) and re-run.\n\n### Other install options\n\n**GUI (no terminal):** [Download the release](https://github.com/AUTHENSOR/SafeClaw/releases), extract, double-click the launcher.\n\n**Clone and run:**\n```bash\ngit clone https://github.com/AUTHENSOR/SafeClaw.git && cd SafeClaw\nnpm install && npm start\n```\n\n## How it works\n\nEvery tool call your AI agent makes goes through SafeClaw's gateway before it executes:\n\n```\nYou give the agent a task\n  → Agent decides to take an action (write a file, run a command, etc.)\n  → SafeClaw intercepts it\n  → Checks it against your policy: allow / deny / require approval\n  → If approval needed: you get notified, agent waits for your decision\n  → Action only runs after you approve\n```\n\n**What leaves your machine:** Action metadata only (e.g., `\"filesystem.write /tmp/output.txt\"`)\n**What stays local:** Your API keys, your files, your data. Always.\n\n## Features\n\n- **Multi-provider:** Claude (Anthropic SDK) and OpenAI (GPT-4o, custom loop)\n- **Browser dashboard:** setup wizard, task runner, approval center, analytics, policy editor, settings\n- **Policy engine:** deny-by-default rules, visual editor, versioning, rollback, dry-run simulation, time-based rules\n- **Audit ledger:** append-only JSONL with SHA-256 hash chain, tamper detection via `audit verify`\n- **Analytics:** cost tracking, approval metrics, tool usage, MCP server breakdown, CSV/JSON export\n- **Budget controls:** spending caps (daily/weekly/monthly) with warn/require_approval/block actions\n- **Scheduler:** cron-based recurring tasks with quiet hours\n- **Container mode:** Docker/Podman sandboxed execution with filesystem isolation\n- **Mobile PWA:** installable, responsive, swipe-to-approve\n- **SMS notifications:** Twilio integration for approval alerts\n- **Webhooks:** Slack, Discord, and generic HTTP notifications\n- **Offline cache:** cached allow decisions for Authensor downtime (fail-safe: denies never cached)\n- **Workspace scoping:** project boundary detection, path restriction enforcement\n- **Risk signals:** advisory badges on approvals for obfuscated execution, credential access, pipe-to-external, destructive commands, and persistence mechanisms\n\n## Security model\n\n- **Deny by default:** unknown actions are blocked\n- **CSRF protection:** all write endpoints require `X-Requested-With: SafeClaw` header\n- **ReDoS protection:** user-supplied regex patterns in policy rules validated for nested quantifiers before execution\n- **Secrets redaction:** API keys stripped from SSE output before reaching the browser\n- **File permissions:** all sensitive files written with mode 0o600\n- **Rate limiting:** sliding window limits on all write API endpoints\n- **Fail closed:** if Authensor is unreachable and no cached allow exists, actions are denied\n- **Local pre-filter:** `safe.read.*` tools (Read, Glob, Grep, TodoWrite, AskUserQuestion, Skill, TaskOutput) are allowed locally without a control plane call. All other tools always go through Authensor\n- **Security headers:** CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, X-XSS-Protection\n- **Audit integrity:** SHA-256 hash chain on every audit entry, verifiable via `safeclaw audit verify`\n\n## Default policy\n\n| Action type | Effect | Examples |\n|------------|--------|----------|\n| `safe.read.*` | Allow (local pre-filter) | Read, Glob, Grep, TodoWrite, AskUserQuestion, Skill |\n| `filesystem.*` | Require approval | Write/edit files |\n| `code.*` | Require approval | Bash commands |\n| `network.*` | Require approval | HTTP requests, web search |\n| `secrets.*` | Require approval | Access secrets |\n| `mcp.*` | Require approval | MCP tool calls |\n| Everything else | Deny | - |\n\n## Commands\n\n```bash\nsafeclaw                          # Open the browser dashboard\nsafeclaw init                     # Set up a profile (default: Claude)\nsafeclaw init --provider openai   # Set up with OpenAI/GPT-4o\nsafeclaw init --workspace         # Initialize workspace scoping\nsafeclaw run \"task\"               # Run a task locally\nsafeclaw run --container \"task\"   # Run inside Docker/Podman\nsafeclaw run --dry-run \"task\"     # Preview config + policy simulation (no agent started)\nsafeclaw approvals                # List pending approvals\nsafeclaw approvals approve <id>   # Approve\nsafeclaw approvals reject <id>    # Reject\nsafeclaw receipts                 # View audit trail\nsafeclaw audit                    # View recent audit log\nsafeclaw audit verify             # Verify audit hash chain integrity\nsafeclaw history                  # View task history\nsafeclaw policy show|apply|help   # Manage policy\nsafeclaw profile list|use <name>  # Manage profiles\nsafeclaw health                   # Check Authensor connectivity\nsafeclaw doctor                   # Run 10 diagnostic checks\nsafeclaw config show              # Show current config\nsafeclaw --version                # Show version\n```\n\n### Flags\n\n| Flag | Description |\n|------|-------------|\n| `--verbose, -v` | Show detailed output |\n| `--provider <name>` | AI provider: `claude` (default) or `openai` |\n| `--model <model>` | Model override (e.g. `gpt-4o`, `gpt-4o-mini`) |\n| `--container` | Run inside Docker/Podman |\n| `--workspace <path>` | Workspace directory for container mode |\n| `--rebuild` | Rebuild container image before running |\n| `--dry-run` | Show task config + policy simulation without running |\n| `--no-open` | Start dashboard without opening browser |\n\n## Architecture\n\n```\nsrc/\n  cli.js          CLI entry point\n  server.js       Localhost dashboard server (Node http, zero deps)\n  agent.js        Agent runner with provider dispatch + secrets redaction\n  openai-agent.js Custom agent loop for OpenAI/GPT (raw fetch, zero deps)\n  gateway.js      PreToolUse hook → Authensor policy check + SMS + audit\n  classifier.js   Tool name → action type mapping\n  authensor.js    Authensor control plane API client\n  container.js    Docker/Podman container runner\n  notify.js       Twilio SMS notifications\n  config.js       Profile, config, and .env management\n  policy.js       Policy file management, versioning, simulation, ReDoS protection\n  templates.js    Default policy template\n  audit.js        Append-only JSONL audit ledger with SHA-256 hash chain\n  session.js      Per-task session history\n  workspace.js    Workspace detection and path scoping\n  settings.js     Settings management with validation\n  analytics.js    Cost summary, approval metrics, tool usage, MCP analytics\n  cache.js        Offline decision cache (memory + disk, TTL-based)\n  rate-limit.js   Sliding window rate limiter\n  webhook.js      Slack/Discord/generic webhook notifications\n  budget.js       Budget enforcement and cost estimation\n  doctor.js       10 diagnostic checks for setup health\n  scheduler.js    Cron-based recurring task scheduler with quiet hours\n  validate.js     Input validation, ReDoS protection, secrets redaction\n  logger.js       Structured JSON logging to stderr\nui/dashboard/     Browser dashboard (PWA, mobile-responsive, swipe approvals)\nui/               Standalone approvals UI (auto-refreshes every 5s)\npolicies/         Policy templates and schema\ntests/            446 tests across 24 files\nDockerfile        Container image for sandboxed execution\n```\n\n## Configuration\n\nAll config is stored in `~/.safeclaw/`:\n\n| File | Purpose |\n|------|---------|\n| `config.json` | Profiles, provider, control plane URL |\n| `.env` | API keys (chmod 600, never sent anywhere) |\n| `settings.json` | Timeouts, retention, cache, budget, webhooks |\n| `policy.json` | Active policy rules |\n| `audit.jsonl` | Append-only audit ledger with hash chain |\n| `sessions/` | Per-task session history |\n| `schedules.json` | Cron-based scheduled tasks |\n| `decision-cache.json` | Offline allow cache |\n\n## What stays private\n\nSafeClaw's client is fully open source: the agent, classifier, policy engine, dashboard, and all 446 tests are right here on GitHub. The Authensor control plane runs locally by default (`http://localhost:3000`) and evaluates action metadata against your policy. It only sees what the agent wants to do (e.g., \"write a file to /tmp\"), never your API keys, file contents, or data. Start the control plane by cloning [AUTHENSOR/AUTHENSOR](https://github.com/AUTHENSOR/AUTHENSOR) and running `docker compose up -d`.\n\nIf the control plane is unreachable, SafeClaw fails closed. Every action is denied. Nothing slips through.\n\n## License\n\nMIT\n\nPowered by [Authensor](https://github.com/AUTHENSOR/AUTHENSOR)\n","readmeFilename":"README.md"}