openguardrails
OpenGuardrails
What this skill is: This is the installation and usage guide for the OpenGuardrails security plugin. The plugin code itself lives in the open-source repository at github.com/openguardrails/openguardrails (subdirectory
openclaw-security/). This skill does not execute code on its own — it documents how to install, configure, and verify the plugin.ClawHub ↔ GitHub identity: This skill is published on ClawHub as
ThomasLWang/openguardrails. The upstream source is atgithub.com/openguardrails/openguardrails, maintained by the same author (Thomas Wang). The npm package is@openguardrails/openclaw-security. All three point to the same codebase.
Runtime security guard for OpenClaw agents. Protects against the most critical AI agent threats:
- Data exfiltration defense — detects and blocks when an agent reads sensitive files then attempts to send them to external servers
- Sensitive data leakage prevention — sanitizes PII, credentials, and secrets before they reach LLM providers
- Prompt injection protection — identifies crafted inputs designed to hijack agent behavior
- Command injection blocking — catches shell escapes, backtick substitution, and command chaining in tool parameters
- Content safety — filters NSFW content and enforces minor protection policies
Security & Trust
Open source and auditable. All code is Apache 2.0 licensed at github.com/openguardrails/openguardrails. You can audit every line before installing — especially the tool-event hooks, sanitization logic, and network calls. Key files to review: