Made by Mohammad Ibrahim Saleem · He/Him
AI Security Engineer @ AT&T · Researcher @ University of Houston
Houston, Texas, United States
Quickstart • What’s Included • Architecture • Installation • Deployment • Configuration • Testing • Paper
Install Guide • Policy Language • Audit Log Format • WSL2 Notes • Test Summary • Paper PDF
Security proxy and defense-in-depth stack for AI agents. ClawProtect sits in front of your AI gateway (for example OpenClaw) and inspects every request and response for prompt injection, PII leaks, secrets, vulnerabilities, and malware—before they reach the model or leave your network.
ClawProtect ships with:
- HTTP security proxy with streaming inspection and a YAML policy engine
- eBPF kernel monitor for syscall-level anomaly detection
- Network egress firewall for tight outbound control
- RAG-backed helper agents and a web dashboard
Everything can be run via Docker or built from source.
Prerequisites: Docker and an Anthropic API key.
# 1. Clone this repository
git clone https://github.com/ibrahimsaleem/clawprotect.git
cd clawprotect
# 2. Configure environment
cp standalone/.env.template standalone/.env
# Edit standalone/.env and set your ANTHROPIC_API_KEY (and any other variables)
# 3. Start the stack
cd standalone
docker compose up -dThen open http://localhost:18801 in your browser to access the ClawProtect dashboard and built‑in agents.
ClawProtect uses Claude (via Anthropic's API) as the default language model.
- Go to
https://console.anthropic.comand sign up or log in. - Navigate to API Keys.
- Click Create Key.
- Copy the key (it starts with
sk-ant-). - Paste it into
standalone/.env:
ANTHROPIC_API_KEY=sk-ant-your-key-hereYou can also configure other OpenAI‑compatible providers by editing standalone/config/openclaw.json.
The docker-compose.yml files in the root and standalone/ directories provide ready‑to‑run stacks for:
- ClawProtect proxy
- OpenClaw gateway
- Supporting services (dashboard, storage, etc.)
See the comments in those compose files for the latest environment variables and ports.
If you package ClawProtect as binaries, the primary components are:
clawprotect-proxy– HTTP security proxyclawprotect-setup– interactive configuration helperclawprotect-fw– network firewall controllerclawprotect-ebpf– kernel monitor
The exact download location and filenames depend on where you publish your builds (for example, GitHub Releases or your internal artifact registry).
Requires Go 1.24+ and (optionally) Python for the eBPF monitor.
git clone https://github.com/ibrahimsaleem/ClawProtect.git
cd clawprotect
# Build the proxy
cd proxy/cmd/clawprotect-proxy
go build -o clawprotect-proxy
# Build the setup helper
cd ../../clawprotect-setup
go build -o clawprotect-setupSee the individual cmd/ directories for additional flags and usage examples.
ClawProtect exposes a Prometheus‑compatible /metrics endpoint for real‑time monitoring:
curl http://localhost:18789/metricsExample metrics (names may vary depending on your build/config):
clawprotect_requests_total– total requests evaluatedclawprotect_decisions_allowed_total/_denied_total/_redacted_totalclawprotect_scanner_detections_total{scanner,action}clawprotect_evaluation_duration_secondsclawprotect_active_connections
The ClawProtect proxy is an HTTP reverse proxy that intermediates all traffic between users and your AI gateway.
Capabilities:
- Prompt injection detection – jailbreaks, role manipulation, instruction override
- PII detection and redaction – emails, phone numbers, SSNs, credit cards
- Secrets detection – API keys, tokens, passwords before they leave your environment
- Vulnerability scanning – SQLi, SSRF, XSS, path traversal, command injection patterns
- Malware analysis – detection of suspicious binaries, scripts, and archive bombs
Policies are defined in YAML and are deny‑by‑default. See policy/examples/ for sample policies.
The eBPF component (clawprotect-ebpf) attaches to kernel syscalls and emits high‑fidelity security events, for example:
- Suspicious process execution (reverse shells, fork bombs)
- Sensitive file access (
/etc/shadow,sudoers, SSH keys) - Suspicious outbound connections and port scans
- Privilege escalation attempts
See ebpf/README.md and ebpf/config/ for configuration.
The firewall component (clawprotect-fw) configures iptables‑based egress rules to restrict which domains and IPs your agents can reach.
Example:
cd firewall/cmd/clawprotect-fw
go build -o clawprotect-fw
sudo ./clawprotect-fw apply --config firewall/examples/firewall.yamlClawProtect is designed as a defense‑in‑depth stack with three layers:
- Application layer – ClawProtect proxy (content and policy enforcement)
- Network layer – ClawProtect firewall (egress control)
- Kernel layer – ClawProtect eBPF monitor (behavioral detection)
Layers can be deployed independently, but work best together.
Some deployments wire these layers together with a Unix socket‑based event bus so that high‑severity events at one layer can trigger automatic reactions at another (for example, a port scan detected by eBPF can tighten firewall rules temporarily).
See docs/ and policy/examples/adaptive_crosslayer.yaml for more detail.
For TLS‑terminated production deployments, see docs/install-guide.md and the manifests in deploy/:
cloud-init.yaml– VM hardening and base setupdocker-compose.yml– full stack with reverse proxynginx/conf.d/– example nginx configurationdeploy.sh,smoke-test.sh– automation and verification helpers
Adapt these to your environment, security requirements, and infrastructure.
Common environment variables (exact names may vary depending on your configuration):
| Variable | Required | Description |
|---|---|---|
ANTHROPIC_API_KEY |
Yes | Anthropic API key (sk-ant-...) |
GATEWAY_AUTH_TOKEN |
No | Shared auth token for the AI gateway |
CLAWPROTECT_PORT |
No | Host port for the proxy UI / API |
CLAWPROTECT_STUDIO_URL |
No | Optional deep‑link base URL for dashboards |
| File | Purpose |
|---|---|
standalone/config/openclaw.json |
OpenClaw gateway configuration |
standalone/config/policy.yaml |
ClawProtect security policy |
standalone/agents/*/ |
Agent configs and knowledge bases |
# Unit tests
go test ./proxy/...
go test ./firewall/...
# Integration tests (if present)
go test ./integration/...Issues, feature requests, and pull requests are welcome. Open them against this repository in your own hosting environment (for example, GitHub, GitLab, or an internal forge).
MIT (see LICENSE for details).

