{"_id":"@capsulesecurity/clawguard","_rev":"6-fc64d1dd99a32e17b511225a67dcf54a","name":"@capsulesecurity/clawguard","dist-tags":{"latest":"0.1.5"},"versions":{"0.1.0":{"name":"@capsulesecurity/clawguard","version":"0.1.0","keywords":["openclaw","security","llm","agent","guardrails"],"author":{"name":"Capsule Security"},"license":"MIT","_id":"@capsulesecurity/clawguard@0.1.0","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/clawguard#readme","bugs":{"url":"https://github.com/capsulesecurity/clawguard/issues"},"dist":{"shasum":"08c746e444c2c3130297bd95216b625cc22137a5","tarball":"https://registry.npmjs.org/@capsulesecurity/clawguard/-/clawguard-0.1.0.tgz","fileCount":6,"integrity":"sha512-aqDoTEnwVc9U0BkwUBaNbIwfCcO3rG97XyfE9ry8eRWzcpglWfaVYnxb8SQMlhc1vP87jv3VYm0KGO4FBQJ94w==","signatures":[{"sig":"MEYCIQCFHZZL/Fhhy1duus01MWpq9TTN0eYOfaJvC2QKIniIWQIhAI7E+G8U91hb/crjeVj2u+RGoRP6pg/5x2sXBhUaeXHa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6548261},"main":"index.ts","type":"module","gitHead":"25362aed6e2609a195297e51f51a44f9535a58bd","_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"openclaw":{"extensions":["./index.ts"]},"repository":{"url":"git+https://github.com/capsulesecurity/clawguard.git","type":"git"},"_npmVersion":"10.9.2","description":"Security guard plugin for OpenClaw - uses LLM as a Judge to detect and block risky tool calls","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"devDependencies":{"openclaw":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/clawguard_0.1.0_1770036241027_0.07342355168054793","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@capsulesecurity/clawguard","version":"0.1.1","keywords":["openclaw","security","llm","agent","guardrails"],"author":{"name":"Capsule Security"},"license":"MIT","_id":"@capsulesecurity/clawguard@0.1.1","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/clawguard#readme","bugs":{"url":"https://github.com/capsulesecurity/clawguard/issues"},"dist":{"shasum":"ea7bb15ca5b48f8d1a10771b5f12a5ec16fa4124","tarball":"https://registry.npmjs.org/@capsulesecurity/clawguard/-/clawguard-0.1.1.tgz","fileCount":6,"integrity":"sha512-WD4gLUGwxz89VEgG644XAu7W5MYPSYSkaeRSagVA56pG87fd3/kvxyOftJANNaImUtYMb+X/Y61tYPdZO5rqoQ==","signatures":[{"sig":"MEUCIDELct2NPWSZA7FBn0eJ/xnTC18iFWqcC2OcGSejJjBJAiEAuvzTP7mJwXh2Us11U/YGOgJ/JYHhJGxi2GE4tGYtcIM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6548167},"main":"index.ts","type":"module","gitHead":"38cfe85262a8badaab5846cc6766e007ed32edac","_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"openclaw":{"extensions":["./index.ts"]},"repository":{"url":"git+https://github.com/capsulesecurity/clawguard.git","type":"git"},"_npmVersion":"10.9.2","description":"Security guard plugin for OpenClaw - uses LLM as a Judge to detect and block risky tool calls","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"devDependencies":{"openclaw":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/clawguard_0.1.1_1770044367823_0.0038640213491871744","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@capsulesecurity/clawguard","version":"0.1.2","keywords":["openclaw","security","llm","agent","guardrails"],"author":{"name":"Capsule Security"},"license":"MIT","_id":"@capsulesecurity/clawguard@0.1.2","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/clawguard#readme","bugs":{"url":"https://github.com/capsulesecurity/clawguard/issues"},"dist":{"shasum":"05dd7bcbb1678351ab52c998dae26b4d3de77de3","tarball":"https://registry.npmjs.org/@capsulesecurity/clawguard/-/clawguard-0.1.2.tgz","fileCount":6,"integrity":"sha512-X18WsQtfZhHRhNHFf0ofrKO9KOCo1CQRI9ULpkgCXvZXXVZ35i4AnsXL3k86y8tc4caTSTZO2acue+xM4QjOoQ==","signatures":[{"sig":"MEYCIQDAEVRUMBB6zr8EXo6/UwPQW9Nd1yjhfX4w40vSSu3VqQIhAO7DPbY3TuXfLjmHw8+D9DhNppS1rtyid5UDySITmkeD","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6551512},"main":"index.ts","type":"module","gitHead":"5371facdf82097d7495f1b074726f4e52c5b6ca0","_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"openclaw":{"extensions":["./index.ts"]},"repository":{"url":"git+https://github.com/capsulesecurity/clawguard.git","type":"git"},"_npmVersion":"10.9.2","description":"Security guard plugin for OpenClaw - uses LLM as a Judge to detect and block risky tool calls","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"devDependencies":{"openclaw":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/clawguard_0.1.2_1770048924822_0.04663676918912252","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@capsulesecurity/clawguard","version":"0.1.3","keywords":["openclaw","security","llm","agent","guardrails"],"author":{"name":"Capsule Security"},"license":"MIT","_id":"@capsulesecurity/clawguard@0.1.3","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/clawguard#readme","bugs":{"url":"https://github.com/capsulesecurity/clawguard/issues"},"dist":{"shasum":"6b535c5368c4c3b66dacc394cc2fc4642a2b3d75","tarball":"https://registry.npmjs.org/@capsulesecurity/clawguard/-/clawguard-0.1.3.tgz","fileCount":6,"integrity":"sha512-nm8qnrGzghfGUfoGIA+1V1wj3wuLwn81DLD8/3CmOYIzraHQNs5NMELuLHnV+RmrHT9INnbUFsfQeQUKr0Qgww==","signatures":[{"sig":"MEUCIQDZWknmWDAM7NQl5cOf+t58AXko8VcfIFApqy5KnAdsHQIgecfIiSKETRZ7uxBJXBgTgbH6M8H54iEVNGvvML8qiiA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6551215},"main":"index.ts","type":"module","gitHead":"c8bb686dcf04df24e8b802481cc572812a794980","_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"openclaw":{"extensions":["./index.ts"]},"repository":{"url":"git+https://github.com/capsulesecurity/clawguard.git","type":"git"},"_npmVersion":"10.9.2","description":"Security guard plugin for OpenClaw - uses LLM as a Judge to detect and block risky tool calls","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"devDependencies":{"openclaw":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/clawguard_0.1.3_1770050741463_0.9551617094083054","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@capsulesecurity/clawguard","version":"0.1.4","keywords":["openclaw","security","llm","agent","guardrails"],"author":{"name":"Capsule Security"},"license":"MIT","_id":"@capsulesecurity/clawguard@0.1.4","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/clawguard#readme","bugs":{"url":"https://github.com/capsulesecurity/clawguard/issues"},"dist":{"shasum":"ea678da6e45b09cee640cf5f6d7e6980b79509f7","tarball":"https://registry.npmjs.org/@capsulesecurity/clawguard/-/clawguard-0.1.4.tgz","fileCount":6,"integrity":"sha512-uJdduPJuskRWXSBgEmwgSgU23TopgtjQ0wt+i7XC0ZOFV+xALLQc9R3nK6acZRIigBb3jPkL9mISKNu1LcOPxw==","signatures":[{"sig":"MEUCIQDc4Lq/zgCiDmfFDS+Jl6BVIqlxfqtsYP7rtGnw54tE2wIgTNlXYu4aAG/1u8l1aQxOEi/FDIIXNvJmw7DmLVufj6I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6551618},"main":"index.ts","type":"module","gitHead":"63b7efcf654cec0c8487e89b86d4764d01468a81","_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"openclaw":{"extensions":["./index.ts"]},"repository":{"url":"git+https://github.com/capsulesecurity/clawguard.git","type":"git"},"_npmVersion":"10.9.2","description":"Security guard plugin for OpenClaw - uses LLM as a Judge to detect and block risky tool calls","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"devDependencies":{"openclaw":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/clawguard_0.1.4_1770065856740_0.14470699809858356","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@capsulesecurity/clawguard","version":"0.1.5","description":"Security guard plugin for OpenClaw - uses LLM as a Judge to detect and block risky tool calls","type":"module","main":"index.ts","keywords":["openclaw","security","llm","agent","guardrails"],"author":{"name":"Capsule Security"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/capsulesecurity/clawguard.git"},"homepage":"https://github.com/capsulesecurity/clawguard#readme","bugs":{"url":"https://github.com/capsulesecurity/clawguard/issues"},"devDependencies":{"openclaw":"workspace:*"},"openclaw":{"extensions":["./index.ts"]},"_id":"@capsulesecurity/clawguard@0.1.5","gitHead":"9f7850474fb934258df7d27a6f47b5540fd523bf","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-XyEf0ZKPh06eFBsK5Dmw/oVdjmh8tAeTGvvL13cl8F99xCgko4AI1HjtrwENDaVTS0z7uylqtazThOk69t1LWg==","shasum":"7e0a52b106f8014fc2fd18b66e5320e4eee90fe6","tarball":"https://registry.npmjs.org/@capsulesecurity/clawguard/-/clawguard-0.1.5.tgz","fileCount":9,"unpackedSize":6554708,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD1PR7X4/pkERmri8Z+NIpIAG9gCaxglrc3jwTlDkTR5QIgGPcRx4sDkBTKuR/zbsSDe2pqOWr/DByOC6jRMDR17dU="}]},"_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"directories":{},"maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/clawguard_0.1.5_1770112193667_0.5082682266239893"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-02T12:44:00.945Z","modified":"2026-02-03T09:49:54.206Z","0.1.0":"2026-02-02T12:44:01.373Z","0.1.1":"2026-02-02T14:59:28.160Z","0.1.2":"2026-02-02T16:15:25.201Z","0.1.3":"2026-02-02T16:45:41.794Z","0.1.4":"2026-02-02T20:57:37.183Z","0.1.5":"2026-02-03T09:49:54.074Z"},"bugs":{"url":"https://github.com/capsulesecurity/clawguard/issues"},"author":{"name":"Capsule Security"},"license":"MIT","homepage":"https://github.com/capsulesecurity/clawguard#readme","keywords":["openclaw","security","llm","agent","guardrails"],"repository":{"type":"git","url":"git+https://github.com/capsulesecurity/clawguard.git"},"description":"Security guard plugin for OpenClaw - uses LLM as a Judge to detect and block risky tool calls","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"readme":"# ClawGuard by Capsule\n\n![ClawGuard](clawguard.png)\n\nA security guard plugin for OpenClaw that monitors and validates tool calls before execution using an **LLM as a Judge** approach for risk detection.\n\n## Features\n\n- **Tool Call Logging** - Logs full JSON of every tool call before execution\n- **LLM as a Judge** - Uses a secondary LLM to judge and evaluate tool calls for security risks\n- **Configurable Blocking** - Automatically blocks high/critical risk operations based on the judge's verdict\n- **Custom Judge Prompts** - Override the default judging prompt for security evaluation\n\n## Installation\n\n```bash\nopenclaw plugins install @capsulesecurity/clawguard\n```\n\n## Configuration\n\n| Option | Type | Default | Description |\n|--------|------|---------|-------------|\n| `enabled` | boolean | `true` | Enable or disable the plugin |\n| `logToolCalls` | boolean | `true` | Log full tool call JSON to logger |\n| `securityCheckEnabled` | boolean | `true` | Enable LLM as a Judge for security evaluation |\n| `securityPrompt` | string | (built-in) | Custom prompt for the judge LLM |\n| `blockOnRisk` | boolean | `true` | Block tool calls judged as high/critical risk |\n| `timeoutMs` | number | `15000` | Timeout for judge evaluation in milliseconds |\n| `maxContextWords` | number | `2000` | Maximum words of session context to include |\n| `gatewayHost` | string | `127.0.0.1` | Gateway host for LLM calls |\n| `gatewayPort` | number | `18789` | Gateway port for LLM calls |\n\n### Example Configuration\n\n```json\n{\n  \"plugins\": {\n    \"capsule-claw-guard\": {\n      \"enabled\": true,\n      \"logToolCalls\": true,\n      \"securityCheckEnabled\": true,\n      \"blockOnRisk\": true,\n      \"timeoutMs\": 20000\n    }\n  }\n}\n```\n\n## Security Risks Evaluated\n\nThe judge LLM evaluates tool calls for:\n\n- Command injection (shell commands with untrusted input)\n- Path traversal attacks (accessing files outside allowed directories)\n- Sensitive data exposure (reading credentials, secrets, private keys)\n- Destructive operations (deleting important files, dropping databases)\n- Network attacks (unauthorized external requests, data exfiltration)\n- Privilege escalation attempts\n- Malicious file operations (writing to system directories)\n- SQL injection patterns\n- Code execution with untrusted input\n- Rogue agent behavior (attempts to bypass safety controls, deceptive actions, unauthorized autonomous operations)\n\n## Custom Judge Prompt\n\nYou can provide a custom prompt for the judge LLM using the `securityPrompt` configuration option. Use `{TOOL_CALL_JSON}` as a placeholder for the tool call data:\n\n```json\n{\n  \"plugins\": {\n    \"capsule-claw-guard\": {\n      \"securityPrompt\": \"You are a security judge. Evaluate this tool call:\\n{TOOL_CALL_JSON}\\n\\nReturn your verdict as JSON: {\\\"isRisk\\\": boolean, \\\"riskLevel\\\": \\\"none\\\"|\\\"low\\\"|\\\"medium\\\"|\\\"high\\\"|\\\"critical\\\", \\\"riskType\\\": string, \\\"reason\\\": string}\"\n    }\n  }\n}\n```\n\n## Requirements\n\nThe plugin makes HTTP calls to the OpenClaw Gateway's `/v1/chat/completions` endpoint for LLM evaluation. This requires:\n\n1. **Gateway running**: The OpenClaw gateway must be running and accessible\n2. **Enable chat completions endpoint**: Set `gateway.http.endpoints.chatCompletions.enabled` to `true` in your config:\n   ```bash\n   openclaw config set gateway.http.endpoints.chatCompletions.enabled true\n   ```\n3. **Authentication** (optional): If your gateway requires authentication, set one of:\n   - `OPENCLAW_GATEWAY_TOKEN` environment variable\n   - `OPENCLAW_GATEWAY_PASSWORD` environment variable\n\n## How It Works\n\n1. The plugin hooks into `before_tool_call` events\n2. Logs the full tool call JSON (if logging enabled)\n3. Loads the session context from session files (limited by `maxContextWords`)\n4. Sends both the tool call and session context to the judge LLM for security evaluation\n5. The judge returns a verdict with risk level and reasoning\n6. If judged as high/critical risk and blocking is enabled, the tool call is blocked\n7. All verdicts are logged for audit purposes\n\n## Session Context\n\nThe plugin loads conversation history from the session files to provide context for the judge LLM. This allows the judge to make more informed decisions by understanding the conversation flow that led to the tool call.\n\n- Session files are located at `~/.openclaw/agents/{agentId}/sessions/*.jsonl`\n- The context is limited by word count (default: 2000 words) to manage token usage\n- Most recent messages are prioritized when truncating\n- Only user and assistant messages are included (system messages are filtered out)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}