Govern agent skills, MCP servers, prompts, and tool calls with DefenseClaw
Use DefenseClaw as an operator-controlled admission, runtime guardrail, sandbox, and audit layer before untrusted agent capabilities run.
Prerequisites
DefenseClaw CLI, Go gateway sidecar, policy rules, optional OpenClaw plugin, optional OTLP/Splunk/webhook sinks
Installation
Use the upstream install or setup path that matches your environment:
- make build
- make test
- make lint
Requirements and caveats from upstream:
- DefenseClaw combines a Python operator CLI, a Go gateway sidecar, and an OpenClaw TypeScript plugin. Together they enforce a simple operating rule: untrusted agent capabilities are scanned, governed, logged, and block...
- | CLI Reference | Python CLI commands and operator workflows |
Basic usage or getting-started notes:
| Skills, MCP servers, plugins, and generated code before they run | Prompts, completions, tool calls, and sandbox activity at runtime | SQLite audit history, JSONL, OTLP, Splunk, webhooks, and TUI views |
Admission control - scan skills, MCP servers, plugins, and code before they run.
| Quick Start | First successful local setup and scan flow |
Source: https://github.com/cisco-ai-defense/defenseclaw
Extracted from upstream docs: https://raw.githubusercontent.com/cisco-ai-defense/defenseclaw/HEAD/README.md
Documentation
Source
1---2name: govern-agent-skills-mcp-servers-prompts-and-tool-calls-with-3description: Use DefenseClaw as an operator-controlled admission, runtime guardrail, sandbox, and audit layer before untrusted agent capabilities run.4---56# Govern agent skills, MCP servers, prompts, and tool calls with DefenseClaw78Use DefenseClaw as an operator-controlled admission, runtime guardrail, sandbox, and audit layer before untrusted agent capabilities run.910## Prerequisites1112DefenseClaw CLI, Go gateway sidecar, policy rules, optional OpenClaw plugin, optional OTLP/Splunk/webhook sinks1314## Installation1516Use the upstream install or setup path that matches your environment:17- make build18- make test19- make lint2021Requirements and caveats from upstream:22- <a href="https://www.python.org/downloads/"><img alt="Python 3.10+" src="https://img.shields.io/badge/python-3.10%2B-blue.svg" /></a>23- DefenseClaw combines a Python operator CLI, a Go gateway sidecar, and an OpenClaw TypeScript plugin. Together they enforce a simple operating rule: untrusted agent capabilities are scanned, governed, logged, and block...24- | [CLI Reference](docs/CLI.md) | Python CLI commands and operator workflows |2526Basic usage or getting-started notes:27- | Skills, MCP servers, plugins, and generated code before they run | Prompts, completions, tool calls, and sandbox activity at runtime | SQLite audit history, JSONL, OTLP, Splunk, webhooks, and TUI views |28- **Admission control** - scan skills, MCP servers, plugins, and code before they run.29- | [Quick Start](docs/QUICKSTART.md) | First successful local setup and scan flow |3031- Source: https://github.com/cisco-ai-defense/defenseclaw32- Extracted from upstream docs: https://raw.githubusercontent.com/cisco-ai-defense/defenseclaw/HEAD/README.md3334## Documentation3536- https://cisco-ai-defense.github.io/docs/defenseclaw3738## Source3940- [Agent Skill Exchange](https://agentskillexchange.com/skills/govern-agent-skills-mcp-servers-prompts-and-tool-calls-with-defenseclaw/)