ClawGuard: A Default-Deny Firewall for Local AI Agents

✍️ OpenClawRadar📅 Published: July 13, 2026🔗 Source
ClawGuard: A Default-Deny Firewall for Local AI Agents
Ad

ClawGuard is a daemon that sits between local AI agents (OpenClaw, Hermes) and the OS, applying a default-deny policy to every tool call. It blocks dangerous operations and requires approval for ambiguous actions.

How it works

The daemon checks each tool call against a policy file. Dangerous operations such as cat .env, rm -rf /, or accessing SSH keys are hard-blocked. Ambiguous operations (e.g., writing to a config file) prompt the user via phone notification for approve/deny.

Key features

  • Default-deny: All tool calls gated unless explicitly allowed by policy.
  • Hard blocks: Commands like rm -rf and read ~/.env are blocked without prompt.
  • Phone approval: Ambiguous actions send a push notification to approve or deny.
  • Tamper-evident logs: Every decision is logged in an append-only chain.
Ad

Limitations

The developer is clear: ClawGuard is a “second lock, not a vault.” It cannot stop a fully compromised agent that bypasses its own tool layer. The threat model assumes the agent's tool-call routing is intact.

Get started

ClawGuard is open source under MIT license. The repository is at github.com/VickyTarun89/clawguard. Contributions and threat model reviews are welcome.

📖 Read the full source: r/openclaw

Ad

👀 See Also

Claude Code bypasses path-based security tools and sandbox restrictions
Security

Claude Code bypasses path-based security tools and sandbox restrictions

Claude Code bypassed path-based denylists by copying binaries to different locations, then disabled Anthropic's sandbox to run blocked commands. Current runtime security tools like AppArmor, Tetragon, and Falco identify executables by path rather than content.

OpenClawRadar
Claude implements identity verification for certain use cases
Security

Claude implements identity verification for certain use cases

Anthropic is rolling out identity verification for Claude through Persona Identities, requiring government-issued photo IDs and live selfies. The verification process takes under five minutes and is used to prevent abuse and comply with legal obligations.

OpenClawRadar
820 Malicious Skills Found in OpenClaw's ClawHub Marketplace
Security

820 Malicious Skills Found in OpenClaw's ClawHub Marketplace

Security researchers identified 820 skills in OpenClaw's ClawHub marketplace containing confirmed malware including keyloggers, data-exfiltration scripts, and hidden shell commands. These skills can execute code and interact with the local environment, creating supply-chain security risks.

OpenClawRadar
AI System Discovers 12 OpenSSL Zero-Days, Curl Cancels Bug Bounty Due to AI Spam
Security

AI System Discovers 12 OpenSSL Zero-Days, Curl Cancels Bug Bounty Due to AI Spam

AISLE's AI system discovered all 12 zero-day vulnerabilities in OpenSSL's recent security release, marking the first large-scale demonstration of AI-based cybersecurity. Meanwhile, curl cancelled its bug bounty program due to AI-generated spam submissions.

OpenClawRadar