# Skillshield

> Sandboxed command runner for AI agents — validates and isolates every shell action inside a Bubblewrap user namespace.

- Skill: `dvcrn/skillshield-2` (Agent Skill, multi-file: 8 files)
- Install (CLI): `npx skillmds@latest add dvcrn/skillshield-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/dvcrn/skillshield-2/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: dvcrn (https://skillmd.com/u/dvcrn)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/dvcrn/skillshield-2

---


# skillshield

**Sandboxed command runner for AI agents — validates and isolates every shell action inside a Bubblewrap user namespace.**

SkillShield sits between your AI agent and the operating system. Before any shell command runs, a lightweight Rust daemon checks it against a set of safety rules and decides whether to allow it, sandbox it, or ask for your confirmation. Every decision is logged so you always know what happened.

## What it does

1. **Validates commands** — checks each shell request against configurable rules before execution.
2. **Isolates execution** — runs approved commands inside a Bubblewrap sandbox with a minimal, read-only root filesystem.
3. **Limits repetition** — stops agents that get stuck in a loop and start consuming too many resources.
4. **Logs decisions** — every action (allowed, sandboxed, or paused for review) is recorded with structured metadata.

## How to use

```bash
# Install from ClawHub
npx clawhub@latest install skillshield-openclaw

# Run a command through the safety layer
./skillshield-exec.sh "echo hello world"
```

## Requirements

| Dependency | Purpose |
|---|---|
| Linux | User-namespace support |
| `bwrap` | Bubblewrap sandbox runtime |
| `cargo` | Builds the Rust daemon on first run |

## Links

- Homepage: https://coinwin.info
- Marketplace: https://clawhub.ai/star8592/skillshield-openclaw

