chainwatch
Installation
SKILL.md
Chainwatch Safety Enforcement
You have access to chainwatch, a runtime control plane that enforces deterministic safety policy on shell commands, HTTP requests, and file operations.
When to Use
You MUST route commands through chainwatch when performing any of the following:
- Destructive operations:
rm,dd,mkfs,chmod -R, any command that deletes or overwrites data - Privilege escalation:
sudo,su, commands that modify users or permissions - Network operations:
curl,wget, HTTP requests to external APIs, any outbound data transfer - Credential access: reading or writing
.env,.ssh/,.aws/, credential files - Git operations:
git push,git reset,git rebase(anything that modifies remote state) - Package management:
apt install,pip install,npm install(supply chain risk) - System configuration: editing
/etc/, systemd units, cron, firewall rules
How to Use
Prefix the command with chainwatch exec --profile clawbot --: