What problem does it solve?
Picoclaw AI gateway operators lack visibility into security-relevant configuration changes, unverified advisory feeds, and untrusted release artifacts, leaving deployments exposed to silent drift and supply-chain tampering.
Core Features & Use Cases
- Advisory Awareness: Filters the signed ClawSec advisory feed (NVD CVEs, community advisories, GHSA records) for Picoclaw-relevant entries, failing closed when feed verification state is not verified.
- Configuration Drift Detection: Generates deterministic posture profiles of configs, Web UI exposure, tools, MCP, credentials, and release artifacts, then diffs them against an approved baseline with critical/high/medium/low/info findings.
- Supply-Chain Verification: Validates release artifacts against SHA-256 checksum manifests plus required Ed25519 detached signatures before trusting installs.
- Use Case: An operator baselines a hardened Picoclaw deployment, then runs drift checks on a schedule to catch critical changes like public Web UI enablement or disabled authentication before they become incidents.
Quick Start
Ask the agent to generate a Picoclaw security posture profile and compare it against your approved baseline to report any critical configuration drift.