OpenClaw Guardian
The missing safety layer for AI agents.
What It Does
Guardian sits between the AI's decision and actual execution, automatically assessing risk and routing dangerous operations through independent Guardian Agents for voting-based approval.
95% of operations pass instantly (zero latency, zero cost). Only the ~5% that are potentially dangerous trigger Guardian review.
Architecture
Tool Call → Risk Assessor (keyword rules, 0ms)
↓
Score 0-30 → Fast Lane (just execute)
Score 31-70 → Light Review (1 Guardian, ~1-2s)
Score 71-100 → Full Vote (3 Guardians, ~2-4s, majority rules)
Guardian Perspectives (Full Vote)
| Guardian | Focus |
|---|---|
| Safety | Destructive potential, system recovery |
| Privacy | Credentials, API keys, personal data |
| Permission | Scope of user authorization |
| Reversibility | Undo capability, blast radius |
| Comprehensive | All angles (used in Light Review) |
Installation
- Clone into your OpenClaw workspace:
cd ~/.openclaw/workspace
git clone https://github.com/fatcatMaoFei/openclaw-guardian.git
- Register the plugin in
openclaw.json:
{
"plugins": {
"load": {
"openclaw-guardian": {
"path": "workspace://openclaw-guardian",
"enabled": true
}
}
}
}
- Restart OpenClaw gateway.
Configuration
Edit default-policies.json to enable/disable:
{ "enabled": true }
File Structure
index.ts— Entry point; registersbefore_tool_callhooksrc/blacklist.ts— Keyword rule engine for risk scoringsrc/llm-voter.ts— Tiered LLM voting with parallel executionsrc/audit-log.ts— SHA-256 hash-chain audit loggeropenclaw.plugin.json— Plugin manifestdefault-policies.json— Default risk policies (user-customizable)
Token Cost
| Tier | % of Ops | Extra Cost |
|---|---|---|
| Fast Lane | 85-95% | 0 (rule-based only) |
| Light Review | 5-10% | ~500 tokens per review |
| Full Vote | 1-3% | ~1500 tokens per review |
Average overhead: ~15-35% of total token usage.
License
MIT