openclaw-sec

Detect prompt injection, command injection, SSRF, path traversal, secret exposure, and content policy violations in AI agent interactions.

9|Updated Feb 1, 2026
One-click install
npx skills add https://github.com/PaoloRollo/openclaw-sec --skill openclaw-sec-paolorollo
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: openclaw-sec
Source: https://github.com/PaoloRollo/openclaw-sec/tree/main
Command: npx skills add https://github.com/PaoloRollo/openclaw-sec --skill openclaw-sec-paolorollo

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires better-sqlite3, commander, yaml, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides real-time, multi-layered security validation for AI agent systems, protecting against a wide range of threats.

Core Features & Use Cases

  • Comprehensive Threat Coverage: Detects prompt injection, command injection, SSRF, path traversal, secrets exposure, and obfuscation.
  • Real-time Validation: Operates with sub-50ms validation times, ensuring minimal impact on AI agent performance.
  • Use Case: Integrate this Skill into your AI agent pipeline to automatically scan user inputs and tool calls, blocking malicious attempts before they can compromise your system or data.

Quick Start

Use the openclaw-sec skill to validate the command 'ls -la'.

Frequently Asked Questions about openclaw-sec

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prevent prompt injection and command injection in AI agent systems?

AI agent security validation blocks prompt injection and command injection by scanning user inputs and tool calls in real-time. It employs six parallel detection modules to intercept malicious attempts before they compromise your system.

What's the best way to detect SSRF attacks and path traversal in AI pipelines?

Detecting SSRF attacks and path traversal in AI pipelines requires real-time security validation. This skill uses parallel detection modules to scan interactions, automatically blocking malicious requests with sub-50ms validation times.

How does real-time security validation work for AI agent interactions?

Real-time security validation for AI agent interactions works by running six parallel detection modules that scan inputs and tool calls. It provides intelligent severity scoring and automated action enforcement to block threats.

Can I scan for secrets exposure and content policy violations without slowing down my AI agent?

You can scan for secrets exposure and content policy violations without impacting AI agent performance. The validation operates with sub-50ms processing times, ensuring robust protection against threats with minimal latency.

Does AI agent security validation work with YAML and SQLite dependencies?

AI agent security validation relies on better-sqlite3 and YAML dependencies to function. It integrates into your existing AI agent pipeline using these components to execute its six parallel detection modules.

What are the limitations of automated action enforcement for AI agent security?

Automated action enforcement for AI agent security is limited to detecting prompt injection, command injection, SSRF, path traversal, secrets exposure, and obfuscation. It operates within sub-50ms validation times to enforce blocking actions.