
from clawmoat36
Scans agent inputs and outputs for prompt injection, jailbreaks, credential leaks, PII, and unsafe tool calls; includes scripts for scanning and auditing.
ClawMoat provides real-time security scanning for AI agents. It detects prompt-injection patterns, jailbreak attempts, exposed secrets/credentials, PII, and dangerous tool call signatures. The skill ships with scripts to scan text or files, audit agent session logs, and run tests; findings are categorized by severity.
Run ClawMoat before processing untrusted inputs, prior to executing tool calls sourced from external content, when sending messages that may contain secrets, or periodically to audit agent session logs for security incidents.
scripts/scan.sh, scripts/audit.sh, scripts/test.shIntended for agents that can execute shell scripts and monitor logs (OpenClaw-compatible agents, CLI-enabled agents, security-focused automation agents).
This skill has not been reviewed by our automated audit pipeline yet.