{"_id":"@capsulesecurity/openclaw-capsule","_rev":"4-02cb9f6025266a2d2c75e4ef18c4ce31","name":"@capsulesecurity/openclaw-capsule","dist-tags":{"latest":"1.2.0"},"versions":{"0.0.1":{"name":"@capsulesecurity/openclaw-capsule","version":"0.0.1","keywords":["openclaw","openclaw-plugin","capsule","security","policy","agent-security"],"license":"Apache-2.0","_id":"@capsulesecurity/openclaw-capsule@0.0.1","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/capsule#readme","bugs":{"url":"https://github.com/capsulesecurity/capsule/issues"},"nx":{"name":"openclaw-plugin","targets":{"build":{"options":{"main":"libs/openclaw-plugin/src/index.ts","tsConfig":"libs/openclaw-plugin/tsconfig.lib.json","outputPath":"libs/openclaw-plugin/dist"},"outputs":["{options.outputPath}"],"executor":"@nx/js:tsc"}},"sourceRoot":"libs/openclaw-plugin/src","projectType":"library"},"dist":{"shasum":"356a86742f3b1b0b5052362d0cbb248659b476da","tarball":"https://registry.npmjs.org/@capsulesecurity/openclaw-capsule/-/openclaw-capsule-0.0.1.tgz","fileCount":2,"integrity":"sha512-ZHhowvMhLkoWaiuDJdtF/3u5DCi09lBBH9jW/HynnnddnejosQwfY4C/mDejoStUyqa7/z7mpocaUyi6imwZYA==","signatures":[{"sig":"MEUCIDLa3JjETLkr46HU8FKpuDfOEDcI5keon/Bq0rCM5NQ5AiEA/Ixi9xF/LRoruG6/PEIjmYeP36V/z1TAnZWXA8j/CXw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4546},"main":"./dist/src/index.js","type":"module","types":"./dist/src/index.d.ts","exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js","default":"./dist/src/index.js"},"./package.json":"./package.json"},"gitHead":"c013f72e121493f70a880dd09c6f15d891077a9e","_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"repository":{"url":"git+https://github.com/capsulesecurity/capsule.git","type":"git","directory":"libs/openclaw-plugin"},"_npmVersion":"10.9.2","description":"Capsule plugin for OpenClaw — forwards hook events to the Capsule agentsecurity service for centralized policy enforcement and audit.","directories":{},"_nodeVersion":"22.14.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/openclaw-capsule_0.0.1_1778011298904_0.2949152718448316","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@capsulesecurity/openclaw-capsule","version":"1.0.2","keywords":["openclaw","openclaw-plugin","capsule","security","policy","agent-security"],"license":"Apache-2.0","_id":"@capsulesecurity/openclaw-capsule@1.0.2","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/capsule#readme","bugs":{"url":"https://github.com/capsulesecurity/capsule/issues"},"nx":{"name":"openclaw-plugin","targets":{"build":{"options":{"main":"libs/openclaw-plugin/src/index.ts","tsConfig":"libs/openclaw-plugin/tsconfig.lib.json","outputPath":"libs/openclaw-plugin/dist"},"outputs":["{options.outputPath}"],"executor":"@nx/js:tsc"}},"sourceRoot":"libs/openclaw-plugin/src","projectType":"library"},"dist":{"shasum":"f38b646bcd3fdde92ab74fd895c4a9432c8f29b5","tarball":"https://registry.npmjs.org/@capsulesecurity/openclaw-capsule/-/openclaw-capsule-1.0.2.tgz","fileCount":16,"integrity":"sha512-8raE9gXTUcHpquC8DpTiD3D3tlW2WCqiiXkc7IfgO5D+3G71P4hzywssxaXuWmRe4HEf7u8/fMAg1XHdTRh2QQ==","signatures":[{"sig":"MEUCIQD1Xci0oDDaCNcWHnbbrLV2WbA3SdQe+n5wOUDpzIZWRQIgYN47xv0OJpn4AF467R5Lm6d+IQH+eJwy60AoIR3+3vo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25762},"main":"./dist/src/index.js","type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js","default":"./dist/src/index.js"},"./package.json":"./package.json"},"gitHead":"c013f72e121493f70a880dd09c6f15d891077a9e","_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"repository":{"url":"git+https://github.com/capsulesecurity/capsule.git","type":"git","directory":"libs/openclaw-plugin"},"_npmVersion":"10.9.2","description":"Capsule plugin for OpenClaw — forwards hook events to the Capsule agentsecurity service for centralized policy enforcement and audit.","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/openclaw-capsule_1.0.2_1778011751519_0.09590871874336715","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@capsulesecurity/openclaw-capsule","version":"1.1.0","keywords":["openclaw","openclaw-plugin","capsule","security","policy","agent-security"],"license":"Apache-2.0","_id":"@capsulesecurity/openclaw-capsule@1.1.0","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"homepage":"https://github.com/capsulesecurity/capsule#readme","bugs":{"url":"https://github.com/capsulesecurity/capsule/issues"},"dist":{"shasum":"ef12a34b75d704794d086c77a6b01ebcfc5534ea","tarball":"https://registry.npmjs.org/@capsulesecurity/openclaw-capsule/-/openclaw-capsule-1.1.0.tgz","fileCount":15,"integrity":"sha512-yos3hEjzRgo/6h2sf/TjssdwM2H8zKjHcKmo8bR9fhHI+7Mm/rzarP/bO4VbkwajcMk63cl1JrrxeGrexQ728Q==","signatures":[{"sig":"MEQCIF/fxPkfjOvlstTC1p9uLVrD0XzS74HIcoYGW9ABJfYaAiA1kbnMrMR/BjDFkgurorrppttrFqcFM8SzOxdCpDt4VA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":55045},"main":"./dist/src/index.js","type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js","default":"./dist/src/index.js"},"./package.json":"./package.json"},"gitHead":"47382fbdb33846944721cd1500b20b2d3ceabade","scripts":{"build":"tsc -p tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit"},"_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"repository":{"url":"git+https://github.com/capsulesecurity/capsule.git","type":"git","directory":"openclaw-plugin"},"_npmVersion":"10.9.2","description":"Capsule plugin for OpenClaw — forwards hook events to the Capsule agentsecurity service for centralized policy enforcement and audit.","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"5.8.2","@types/node":"22.13.10"},"_npmOperationalInternal":{"tmp":"tmp/openclaw-capsule_1.1.0_1778020393326_0.37657298021928187","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@capsulesecurity/openclaw-capsule","version":"1.2.0","packageManager":"yarn@4.7.0","description":"Capsule plugin for OpenClaw — forwards hook events to the Capsule agentsecurity service for centralized policy enforcement and audit.","main":"./dist/src/index.js","types":"./dist/src/index.d.ts","type":"module","scripts":{"build":"tsc -p tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit"},"exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js","default":"./dist/src/index.js"},"./package.json":"./package.json"},"engines":{"node":">=18"},"devDependencies":{"@types/node":"22.13.10","typescript":"5.8.2"},"publishConfig":{"access":"public"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/capsulesecurity/capsule.git","directory":"openclaw-plugin"},"keywords":["openclaw","openclaw-plugin","capsule","security","policy","agent-security"],"_id":"@capsulesecurity/openclaw-capsule@1.2.0","gitHead":"92b2ad94ef49595d6d43ca450126fb7019427721","bugs":{"url":"https://github.com/capsulesecurity/capsule/issues"},"homepage":"https://github.com/capsulesecurity/capsule#readme","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-e4lAq/6BeY26b5qx0l8lZNOOwiot5Z0qXeh4DrecpULbUDW8Mt1gSY/TkYXMdrkt4TQ0c4i28Eg9YCCCTJU6zw==","shasum":"616e7bec1a78c4d99d765c10face2e08b4861580","tarball":"https://registry.npmjs.org/@capsulesecurity/openclaw-capsule/-/openclaw-capsule-1.2.0.tgz","fileCount":15,"unpackedSize":56442,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHcLwNHfIlQQI9fV8opzQFvzWp2MY2V8ex18r1xhXEaUAiA53GVmQWqSF/lrTHwdPuiDL0LZAeVSJBtFmeHG6HNo6A=="}]},"_npmUser":{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"},"directories":{},"maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openclaw-capsule_1.2.0_1778049458606_0.16077482308723168"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-05T20:01:38.727Z","modified":"2026-05-06T06:37:38.870Z","0.0.1":"2026-05-05T20:01:39.024Z","1.0.2":"2026-05-05T20:09:11.661Z","1.1.0":"2026-05-05T22:33:13.475Z","1.2.0":"2026-05-06T06:37:38.740Z"},"bugs":{"url":"https://github.com/capsulesecurity/capsule/issues"},"license":"Apache-2.0","homepage":"https://github.com/capsulesecurity/capsule#readme","keywords":["openclaw","openclaw-plugin","capsule","security","policy","agent-security"],"repository":{"type":"git","url":"git+https://github.com/capsulesecurity/capsule.git","directory":"openclaw-plugin"},"description":"Capsule plugin for OpenClaw — forwards hook events to the Capsule agentsecurity service for centralized policy enforcement and audit.","maintainers":[{"name":"lidanhazoutcapsule","email":"lidan@capsule.security"}],"readme":"# @capsulesecurity/openclaw-capsule\n\nCapsule plugin for [OpenClaw](https://docs.openclaw.ai/). Forwards every OpenClaw hook event to your Capsule\nagentsecurity tenant and applies async hook verdicts (block, params rewrite, approval prompt) returned by Capsule policy.\n\n## Install\n\n```bash\nnpm i @capsulesecurity/openclaw-capsule\n```\n\n## Configure\n\nAdd the plugin to your OpenClaw plugin config:\n\n```jsonc\n{\n  \"plugins\": [\n    {\n      \"package\": \"@capsulesecurity/openclaw-capsule\",\n      \"config\": {\n        \"endpoint\": \"https://agents.capsule.security\",\n        \"token\": \"<jwt-signed-with-tenant-OPENCLAW_SECRET>\",\n        \"blockOnRisk\": true,\n        \"failOpen\": true,\n        \"timeoutMs\": 5000,\n        \"allowConversationAccess\": false,\n      },\n    },\n  ],\n}\n```\n\n| Option                    | Default                           | Description                                                                  |\n| ------------------------- | --------------------------------- | ---------------------------------------------------------------------------- |\n| `endpoint`                | —                                 | Capsule agentsecurity base URL.                                              |\n| `token`                   | —                                 | JWT with `tid` (tenant) and `eid` (env external ID) claims.                  |\n| `blockOnRisk`             | `true`                            | Apply server `block` verdicts. Set to `false` for shadow mode.               |\n| `failOpen`                | `true`                            | Allow the agent to proceed when Capsule is unreachable.                      |\n| `timeoutMs`               | `5000`                            | Per-request timeout in ms.                                                   |\n| `allowConversationAccess` | `false`                           | When true, parse `~/.openclaw/agents/{id}/sessions/{sid}.jsonl` and forward. |\n| `pluginVersion`           | package version                   | Tag every event with a custom plugin identifier.                             |\n| `user`                    | `process.env.USER` or `\"unknown\"` | User identifier sent on every event.                                         |\n\n## Hooks\n\n- **Blocking** (priority `100`): `before_tool_call`, `before_agent_reply`, `before_install`\n- **Synchronous audit** (priority `100`, fire-and-forget): `before_message_write`\n- **Observation** (priority `10`, fire-and-forget): `after_tool_call`, `agent_end`, `session_start`, `session_end`,\n  `before_compaction`, `after_compaction`, `model_call_started`, `model_call_ended`\n\n## Server contract\n\nThe plugin POSTs to `POST {endpoint}/v1/openclaw/hooks/events` with:\n\n```json\n{\n  \"hook\": {\n    \"hook_event_name\": \"before_tool_call\",\n    \"context\": { \"agent_id\": \"...\" },\n    \"tool_name\": \"...\",\n    \"params\": {}\n  },\n  \"user\": \"user@example.com\",\n  \"transcript_lines\": [],\n  \"plugin_version\": \"1.2.0\"\n}\n```\n\nThe server response is mapped directly back to the OpenClaw plugin SDK return shape — `{ block, blockReason }`,\n`{ params }` rewrite, or `{ requireApproval: { ... } }` for `before_tool_call`; `{ cancel, syntheticReply, reason }`\nfor `before_agent_reply`; `{ block, blockReason }` for `before_install`.\n\n`before_message_write` is synchronous in OpenClaw. The plugin forwards it to Capsule for audit, but it cannot apply an\nasync server verdict inline for that hook.\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}