# prompt-security/clawsec

A complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and variants). Protect your SOUL.md (etc') with drift detection, live security recommendations, automated audits, and skill integrity verification. All from one installable suite.

Repository: https://github.com/prompt-security/clawsec
Canonical: https://ross.abutalabs.com/products/clawsec
Homepage: https://prompt.security/clawsec
Language: JavaScript
License: AGPL-3.0
License Family: copyleft
Topics: clawdbot, clawdbot-skill, molt, moltbot-skill, moltbot-skills, openclaw, openclaw-extension, openclaw-plugin, openclaw-security, openclaw-skill, openclaw-skills, nanoclaw, hermes, hermes-agent, hermes-skill, hermes-skills, picoclaw, picoclaw-install
Last push: 2026-09-02T09:45:37+00:00

## Health v2 (maintenance only)
Score: 80/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 100, release rhythm 93, longevity 14
- inputs: {"age_days": 209, "days_push": 0, "days_rel": 50, "gap_med": 0, "n_releases_24m": 12}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1097, forks 113 (observed 2026-09-03T02:15:17.098367+00:00)

## What it is
ClawSec is an AGPL-licensed suite of security skills for AI agent runtimes such as OpenClaw, NanoClaw, Hermes, and Picoclaw. It verifies skill artifact integrity, detects configuration drift, audits agent environments, and gates risky installs using signed advisory intelligence.

## Use cases
- secure my OpenClaw agent against malicious skills
- detect configuration drift in my AI agent setup
- audit my agent environment for security issues
- verify integrity of installed agent skills
- get security advisories for AI agent runtimes
- approval-gate risky skill installs

## When to choose
- you run OpenClaw, NanoClaw, Hermes, or Picoclaw agents and want security monitoring
- you need skill integrity verification and drift detection for agent configurations
- you want automated security audits and advisory feeds for agent runtimes

## When to avoid
- you use agent frameworks outside the OpenClaw/Hermes/Picoclaw ecosystem
- you need general-purpose application security scanning rather than agent-runtime security
- you require a permissive license since the project is AGPL-3.0

## Facets
- artifact type: plugin
- maturity: active
- function: security, vulnerability-scanning, monitoring, alerting
- domain: security, developer-tools
- platform: cli, self-hosted
- tags: openclaw, ai-agent-security, skill-integrity, drift-detection, security-audit, advisory-feed, prompt-security, ai-agents, nodejs

## Member repositories
- prompt-security/clawsec (main) score 80

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:17.098367+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:49:09.922283+00:00, confidence not recorded.
  - readme: https://github.com/prompt-security/clawsec (fetched 2026-09-03T02:15:17.098367+00:00, sha 3c40ce7c40dd)
  - homepage: https://prompt.security/clawsec (fetched 2026-08-29T12:51:19.572372+00:00, sha 3770bbff7ce2)
- Data as of 2026-08-30T08:39:29.467469+00:00.
