OpenClaw Traffic Guardian
This is a baseline specification skill. It intentionally does not ship a proxy or runtime implementation yet.
Vercel Skills Installation
Install with the Vercel Skills CLI for this harness:
npx skills add prompt-security/clawsec --skill openclaw-traffic-guardian -a openclaw -y
Release Artifact Verification
For standalone installs, verify the signed release manifest before trusting SKILL.md, skill.json, or the archive. The skill.json file is the package metadata/SBOM source, and the release pipeline signs checksums.json with the ClawSec release key.
set -euo pipefail
SKILL_NAME="openclaw-traffic-guardian"
VERSION="0.0.1-beta5"
REPO="prompt-security/clawsec"
TAG="${SKILL_NAME}-v${VERSION}"
BASE="https://github.com/${REPO}/releases/download/${TAG}"
ZIP_NAME="${SKILL_NAME}-v${VERSION}.zip"
TMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TMP_DIR"' EXIT
RELEASE_PUBKEY_SHA256="711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8"
curl -fsSL "$BASE/checksums.json" -o "$TMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TMP_DIR/checksums.sig"
curl -fsSL "$BASE/signing-public.pem" -o "$TMP_DIR/signing-public.pem"
curl -fsSL "$BASE/$ZIP_NAME" -o "$TMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/SKILL.md" -o "$TMP_DIR/SKILL.md"
curl -fsSL "$BASE/skill.json" -o "$TMP_DIR/skill.json"
ACTUAL_PUBKEY_SHA256="$(openssl pkey -pubin -in "$TMP_DIR/signing-public.pem" -outform DER | shasum -a 256 | awk '{print $1}')"
if [ "$ACTUAL_PUBKEY_SHA256" != "$RELEASE_PUBKEY_SHA256" ]; then
echo "ERROR: signing-public.pem fingerprint mismatch" >&2
exit 1
fi
openssl base64 -d -A -in "$TMP_DIR/checksums.sig" -out "$TMP_DIR/checksums.sig.bin"
openssl pkeyutl -verify -rawin -pubin \
-inkey "$TMP_DIR/signing-public.pem" \
-sigfile "$TMP_DIR/checksums.sig.bin" \
-in "$TMP_DIR/checksums.json" >/dev/null
hash_file() {
if command -v shasum >/dev/null 2>&1; then
shasum -a 256 "$1" | awk '{print $1}'
else
sha256sum "$1" | awk '{print $1}'
fi
}
verify_manifest_file() {
asset="$1"
path="$2"
expected="$(jq -r --arg asset "$asset" '.files[$asset].sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected" ]; then
echo "ERROR: checksums.json missing $asset" >&2
exit 1
fi
actual="$(hash_file "$path")"
if [ "$actual" != "$expected" ]; then
echo "ERROR: checksum mismatch for $asset" >&2
exit 1
fi
}
expected_archive="$(jq -r '.archive.sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected_archive" ]; then
echo "ERROR: checksums.json missing archive.sha256" >&2
exit 1
fi
actual_archive="$(hash_file "$TMP_DIR/$ZIP_NAME")"
if [ "$actual_archive" != "$expected_archive" ]; then
echo "ERROR: archive checksum mismatch" >&2
exit 1
fi
verify_manifest_file "SKILL.md" "$TMP_DIR/SKILL.md"
verify_manifest_file "skill.json" "$TMP_DIR/skill.json"
echo "Signed release manifest, archive, SKILL.md, and skill.json verified."
Only install or extract the archive after this verification succeeds.
Scope
Builders should use this skill as the OpenClaw landing zone for runtime traffic monitoring:
- operator-scoped HTTP proxy inspection
- optional HTTPS inspection with per-process CA trust
- outbound exfiltration detection
- inbound injection detection
- approval-sensitive social-account mutation review
- redacted local threat logs
- optional OpenClaw hook/status integration
Do not merge this capability into clawsec-scanner, openclaw-audit-watchdog, or soul-guardian. Those skills have different trust boundaries and safety contracts.
Safety Contract
- Opt-in only.
- Detect-and-log by default.
- No automatic system CA installation.
- No global
HTTP_PROXY or HTTPS_PROXY changes.
- No blocking in the first implementation.
- Redact secrets before logs or conversation alerts.
- Keep all state under
OPENCLAW_TRAFFIC_GUARDIAN_HOME or ~/.openclaw/security/clawsec/traffic-guardian.
Builder Entry Points
Read SPEC.md before implementing. Use the placeholder folders as follows:
| Path |
Intended use |
lib/ |
Detector rules, redaction, event schema, report formatting |
scripts/ |
Start, stop, status, config validation, log query helpers |
hooks/openclaw-traffic-guardian-hook/ |
Optional OpenClaw hook/status integration |
test/ |
Unit tests, proxy fixture tests, redaction tests, process-scope tests |
Required First Implementation Behavior
- Validate config without starting the proxy.
- Start monitor in foreground or explicit background mode.
- Scope proxy environment variables to the target OpenClaw process.
- Inspect HTTP request/response text up to a bounded byte limit.
- Support optional HTTPS MITM only when the operator supplies per-process trust configuration.
- Flag requests matching
SPEC.md's Outbound POLICY_REVIEW cases as operator-review findings, including TweetClaw or other X/Twitter automation writes and scheduler/background-runner repeats without a fresh operator-approval marker.
- Detect repeat/background-runner context from bounded request metadata such as paths, headers, user-agent, client context, tool invocation metadata, or scheduler identifiers.
- Emit JSONL findings with redacted snippets plus source type, mutation category, approval-marker presence, and direct-operator versus background-runner context.
- Provide a
status command that reports mode, listener, CA fingerprint if present, and last findings.
Out of Scope for v0.0.1 Implementation
- automatic system trust-store mutation
- transparent network interception
- default blocking
- sending traffic to external services
- collecting full request/response bodies
1---2name: openclaw-traffic-guardian3description: OpenClaw runtime traffic monitoring baseline for opt-in HTTP/HTTPS proxy inspection, egress detection, inbound injection detection, and social-account policy review.4license: AGPL-3.0-or-later5---6
7# OpenClaw Traffic Guardian
8
9This is a baseline specification skill. It intentionally does not ship a proxy or runtime implementation yet.
10
11## Vercel Skills Installation
12
13Install with the Vercel Skills CLI for this harness:
14
15```bash
16npx skills add prompt-security/clawsec --skill openclaw-traffic-guardian -a openclaw -y
17```
18
19## Release Artifact Verification
20
21For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.
22
23```bash
24set -euo pipefail
25
26SKILL_NAME="openclaw-traffic-guardian"
27VERSION="0.0.1-beta5"
28REPO="prompt-security/clawsec"
29TAG="${SKILL_NAME}-v${VERSION}"
30BASE="https://github.com/${REPO}/releases/download/${TAG}"
31ZIP_NAME="${SKILL_NAME}-v${VERSION}.zip"
32TMP_DIR="$(mktemp -d)"
33trap 'rm -rf "$TMP_DIR"' EXIT
34
35RELEASE_PUBKEY_SHA256="711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8"
36
37curl -fsSL "$BASE/checksums.json" -o "$TMP_DIR/checksums.json"
38curl -fsSL "$BASE/checksums.sig" -o "$TMP_DIR/checksums.sig"
39curl -fsSL "$BASE/signing-public.pem" -o "$TMP_DIR/signing-public.pem"
40curl -fsSL "$BASE/$ZIP_NAME" -o "$TMP_DIR/$ZIP_NAME"
41curl -fsSL "$BASE/SKILL.md" -o "$TMP_DIR/SKILL.md"
42curl -fsSL "$BASE/skill.json" -o "$TMP_DIR/skill.json"
43
44ACTUAL_PUBKEY_SHA256="$(openssl pkey -pubin -in "$TMP_DIR/signing-public.pem" -outform DER | shasum -a 256 | awk '{print $1}')"
45if [ "$ACTUAL_PUBKEY_SHA256" != "$RELEASE_PUBKEY_SHA256" ]; then
46 echo "ERROR: signing-public.pem fingerprint mismatch" >&2
47 exit 1
48fi
49
50openssl base64 -d -A -in "$TMP_DIR/checksums.sig" -out "$TMP_DIR/checksums.sig.bin"
51openssl pkeyutl -verify -rawin -pubin \
52 -inkey "$TMP_DIR/signing-public.pem" \
53 -sigfile "$TMP_DIR/checksums.sig.bin" \
54 -in "$TMP_DIR/checksums.json" >/dev/null
55
56hash_file() {
57 if command -v shasum >/dev/null 2>&1; then
58 shasum -a 256 "$1" | awk '{print $1}'
59 else
60 sha256sum "$1" | awk '{print $1}'
61 fi
62}
63
64verify_manifest_file() {
65 asset="$1"
66 path="$2"
67 expected="$(jq -r --arg asset "$asset" '.files[$asset].sha256 // empty' "$TMP_DIR/checksums.json")"
68 if [ -z "$expected" ]; then
69 echo "ERROR: checksums.json missing $asset" >&2
70 exit 1
71 fi
72 actual="$(hash_file "$path")"
73 if [ "$actual" != "$expected" ]; then
74 echo "ERROR: checksum mismatch for $asset" >&2
75 exit 1
76 fi
77}
78
79expected_archive="$(jq -r '.archive.sha256 // empty' "$TMP_DIR/checksums.json")"
80if [ -z "$expected_archive" ]; then
81 echo "ERROR: checksums.json missing archive.sha256" >&2
82 exit 1
83fi
84actual_archive="$(hash_file "$TMP_DIR/$ZIP_NAME")"
85if [ "$actual_archive" != "$expected_archive" ]; then
86 echo "ERROR: archive checksum mismatch" >&2
87 exit 1
88fi
89
90verify_manifest_file "SKILL.md" "$TMP_DIR/SKILL.md"
91verify_manifest_file "skill.json" "$TMP_DIR/skill.json"
92
93echo "Signed release manifest, archive, SKILL.md, and skill.json verified."
94```
95
96Only install or extract the archive after this verification succeeds.
97
98## Scope
99
100Builders should use this skill as the OpenClaw landing zone for runtime traffic monitoring:
101
102- operator-scoped HTTP proxy inspection
103- optional HTTPS inspection with per-process CA trust
104- outbound exfiltration detection
105- inbound injection detection
106- approval-sensitive social-account mutation review
107- redacted local threat logs
108- optional OpenClaw hook/status integration
109
110Do not merge this capability into `clawsec-scanner`, `openclaw-audit-watchdog`, or `soul-guardian`. Those skills have different trust boundaries and safety contracts.
111
112## Safety Contract
113
114- Opt-in only.
115- Detect-and-log by default.
116- No automatic system CA installation.
117- No global `HTTP_PROXY` or `HTTPS_PROXY` changes.
118- No blocking in the first implementation.
119- Redact secrets before logs or conversation alerts.
120- Keep all state under `OPENCLAW_TRAFFIC_GUARDIAN_HOME` or `~/.openclaw/security/clawsec/traffic-guardian`.
121
122## Builder Entry Points
123
124Read `SPEC.md` before implementing. Use the placeholder folders as follows:
125
126| Path | Intended use |
127|---|---|
128| `lib/` | Detector rules, redaction, event schema, report formatting |
129| `scripts/` | Start, stop, status, config validation, log query helpers |
130| `hooks/openclaw-traffic-guardian-hook/` | Optional OpenClaw hook/status integration |
131| `test/` | Unit tests, proxy fixture tests, redaction tests, process-scope tests |
132
133## Required First Implementation Behavior
134
1351. Validate config without starting the proxy.
1362. Start monitor in foreground or explicit background mode.
1373. Scope proxy environment variables to the target OpenClaw process.
1384. Inspect HTTP request/response text up to a bounded byte limit.
1395. Support optional HTTPS MITM only when the operator supplies per-process trust configuration.
1406. Flag requests matching `SPEC.md`'s Outbound POLICY_REVIEW cases as operator-review findings, including TweetClaw or other X/Twitter automation writes and scheduler/background-runner repeats without a fresh operator-approval marker.
1417. Detect repeat/background-runner context from bounded request metadata such as paths, headers, user-agent, client context, tool invocation metadata, or scheduler identifiers.
1428. Emit JSONL findings with redacted snippets plus source type, mutation category, approval-marker presence, and direct-operator versus background-runner context.
1439. Provide a `status` command that reports mode, listener, CA fingerprint if present, and last findings.
144
145## Out of Scope for v0.0.1 Implementation
146
147- automatic system trust-store mutation
148- transparent network interception
149- default blocking
150- sending traffic to external services
151- collecting full request/response bodies