ClawSec Security Suite
A complete security skill suite for OpenClaw's and NanoClaw agents (and variants). Protect your SOUL.md with drift detection, live security recommendations, automated audits, and skill integrity verification.
Install on your platform
We auto-selected OpenClaw based on this skill’s supported platforms.
git clone https://github.com/prompt-security/clawsec && cd clawsec && ./install.sh
About This Skill
What it does
ClawSec is a complete security suite designed to protect AI agent platforms like OpenClaw and NanoClaw. It provides unified security monitoring, verifies the integrity of agent files, and incorporates threat intelligence to defend against prompt injection, drift, and malicious instructions. ClawSec includes features like automated updates, checksum verification, and self-check scripts for vulnerability detection.
When to use it
- Protecting OpenClaw agents: Use ClawSec when deploying or maintaining OpenClaw-based bots (like MoltBot or Clawdbot) to ensure their security and prevent unauthorized modifications.
- Securing NanoClaw WhatsApp bots: Implement ClawSec for NanoClaw deployments to monitor for threats specific to the WhatsApp environment, including MCP tool advisory monitoring.
- Regular Security Audits: Run ClawSec's self-check scripts periodically to proactively identify potential prompt injection vulnerabilities or other security weaknesses in your agent setup.
- Automated Integrity Verification: Leverage ClawSec’s automated updates and integrity verification to ensure the ongoing stability and trustworthiness of your AI agents.
Key capabilities
- Suite Installer (one-command installation)
- File Integrity Protection (drift detection & auto-restore)
- Live Security Advisories (NVD CVE polling)
- Security Audits (prompt injection detection)
- Checksum Verification (SHA256)
- Health Checks (automated updates and integrity verification)
Example prompts
- "Run a security audit on my OpenClaw agent."
- "Verify the integrity of my NanoClaw bot’s configuration files."
- “Check for any new threat advisories related to WhatsApp MCP tools.”
Tips & gotchas
ClawSec requires access to critical agent files like SOUL.md and IDENTITY.md for file integrity protection. Ensure the AI agent platform supports automated updates and has appropriate permissions granted to ClawSec for optimal functionality.
TrustedSkills Verification
Unlike other registries that point to live repositories, TrustedSkills pins every skill to a verified commit hash. This protects you from malicious updates — what you install today is exactly what was reviewed and verified.
Installing this skill downloads the exact code at commit 79c303fa, not the current state of the repository. This prevents supply-chain attacks from unauthorized updates.
Security Audits
| Gen Agent Trust Hub | Pass |
| Socket | Pass |
| Snyk | Pass |
Details
- Version
- vlatest
- License
- AGPL-3.0
- Author
- prompt-security
- Installs
- 0
- Updated
- Mar 4, 2026
- Published
- Mar 4, 2026
🌐 Community
Passed automated security scans.
Install command fetches the verified snapshot, not the live repository.