arifOS: A $15 MCP Governance Kernel for OpenClaw Tool Security

✍️ OpenClawRadar📅 Published: March 1, 2026🔗 Source
arifOS: A $15 MCP Governance Kernel for OpenClaw Tool Security
Ad

What arifOS Does

arifOS is a tiny MCP governance kernel that sits between OpenClaw models and their tools/skills. The creator, Arif (a geologist, not a coder), built it to prevent AI agents from "free-styling" his tools without proper security checks.

Core Architecture

The system uses a simple metaphor: treat the LLM like a "brain in a jar," treat tools like "hands," and put a "$15 VPS in the middle as the bouncer." Every OpenClaw tool call goes through this chain: jar → MCP server → scoring → security check.

Security Implementation

Each tool call gets scored 000-999 and must pass 13 hard Floors including:

  • Amanah
  • Truth
  • Safety
  • Injection
  • Sovereignty

If a call fails any Floor, it returns "VOID" and nothing touches your filesystem, API, or database. The blocking logic is straightforward:

if verdict == "VOID":
    return "Action Blocked by Floor 1: Amanah"

As Arif puts it: "That's the whole joke: billion-dollar model, $15 lock."

Ad

Installation and Availability

Available via pip: pip install arifos

Repository: https://github.com/ariffazil/arifOS

The creator invites testing: "If you're running OpenClaw agents and want a paranoid bouncer in front of your skills, feel free to break this and tell me where it leaks."

Development Context

Arif notes that all Python code was written by AI agents, and he doesn't "even know how to spell phython"—highlighting the paradox of non-coders building security tools with AI assistance.

📖 Read the full source: r/openclaw

Ad

👀 See Also

OpenObscure: Open-Source On-Device Privacy Firewall for AI Agents
Security

OpenObscure: Open-Source On-Device Privacy Firewall for AI Agents

OpenObscure is an open-source, on-device privacy firewall that sits between AI agents and LLM providers. It uses FF1 Format-Preserving Encryption with AES-256 to encrypt PII values before requests leave your device, maintaining data structure while protecting privacy.

OpenClawRadar
Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure
Security

Sweden's E-Government Platform Source Code Leaked via Compromised CGI Infrastructure

The full source code of Sweden's E-Government platform was leaked by threat actor ByteToBreach after compromising CGI Sverige AB infrastructure. The leak includes staff databases, API document signing systems, Jenkins SSH credentials, and RCE test endpoints.

OpenClawRadar
Snowflake Cortex Code CLI vulnerability allowed sandbox escape and malware execution
Security

Snowflake Cortex Code CLI vulnerability allowed sandbox escape and malware execution

A vulnerability in Snowflake Cortex Code CLI version 1.0.25 and earlier allowed arbitrary command execution without human approval via process substitution bypass, enabling malware installation and sandbox escape through indirect prompt injection.

OpenClawRadar
FlyTrap Attack Uses Adversarial Umbrellas to Compromise Camera-Based Autonomous Drones
Security

FlyTrap Attack Uses Adversarial Umbrellas to Compromise Camera-Based Autonomous Drones

UC Irvine researchers developed FlyTrap, a physical attack framework that uses painted umbrellas to exploit vulnerabilities in camera-based autonomous target tracking systems. The attack reduces tracking distances to dangerous levels, enabling drone capture, sensor attacks, or physical collisions.

OpenClawRadar