Skip to content

Repository files navigation

ClawProtect

Defense-in-Depth AI Security Stack for Agent Gateways

Version Go Python License OWASP Modules

Made by Mohammad Ibrahim Saleem · He/Him
AI Security Engineer @ AT&T · Researcher @ University of Houston
Houston, Texas, United States

Quickstart • What’s Included • Architecture • Installation • Deployment • Configuration • Testing • Paper

Install Guide • Policy Language • Audit Log Format • WSL2 Notes • Test Summary • Paper PDF


Security proxy and defense-in-depth stack for AI agents. ClawProtect sits in front of your AI gateway (for example OpenClaw) and inspects every request and response for prompt injection, PII leaks, secrets, vulnerabilities, and malware—before they reach the model or leave your network.

ClawProtect ships with:

  • HTTP security proxy with streaming inspection and a YAML policy engine
  • eBPF kernel monitor for syscall-level anomaly detection
  • Network egress firewall for tight outbound control
  • RAG-backed helper agents and a web dashboard

Everything can be run via Docker or built from source.


Quickstart (Docker)

Prerequisites: Docker and an Anthropic API key.

# 1. Clone this repository
git clone https://github.com/ibrahimsaleem/clawprotect.git
cd clawprotect

# 2. Configure environment
cp standalone/.env.template standalone/.env
# Edit standalone/.env and set your ANTHROPIC_API_KEY (and any other variables)

# 3. Start the stack
cd standalone
docker compose up -d

Then open http://localhost:18801 in your browser to access the ClawProtect dashboard and built‑in agents.


Getting an Anthropic API Key

ClawProtect uses Claude (via Anthropic's API) as the default language model.

  1. Go to https://console.anthropic.com and sign up or log in.
  2. Navigate to API Keys.
  3. Click Create Key.
  4. Copy the key (it starts with sk-ant-).
  5. Paste it into standalone/.env:
ANTHROPIC_API_KEY=sk-ant-your-key-here

You can also configure other OpenAI‑compatible providers by editing standalone/config/openclaw.json.


Installation Options

Option 1: Docker (recommended)

The docker-compose.yml files in the root and standalone/ directories provide ready‑to‑run stacks for:

  • ClawProtect proxy
  • OpenClaw gateway
  • Supporting services (dashboard, storage, etc.)

See the comments in those compose files for the latest environment variables and ports.

Option 2: Pre‑built binaries

If you package ClawProtect as binaries, the primary components are:

  • clawprotect-proxy – HTTP security proxy
  • clawprotect-setup – interactive configuration helper
  • clawprotect-fw – network firewall controller
  • clawprotect-ebpf – kernel monitor

The exact download location and filenames depend on where you publish your builds (for example, GitHub Releases or your internal artifact registry).

Option 3: Build from source

Requires Go 1.24+ and (optionally) Python for the eBPF monitor.

git clone https://github.com/ibrahimsaleem/ClawProtect.git
cd clawprotect

# Build the proxy
cd proxy/cmd/clawprotect-proxy
go build -o clawprotect-proxy

# Build the setup helper
cd ../../clawprotect-setup
go build -o clawprotect-setup

See the individual cmd/ directories for additional flags and usage examples.


What’s Included

Observability

ClawProtect exposes a Prometheus‑compatible /metrics endpoint for real‑time monitoring:

curl http://localhost:18789/metrics

Example metrics (names may vary depending on your build/config):

  • clawprotect_requests_total – total requests evaluated
  • clawprotect_decisions_allowed_total / _denied_total / _redacted_total
  • clawprotect_scanner_detections_total{scanner,action}
  • clawprotect_evaluation_duration_seconds
  • clawprotect_active_connections

Security Proxy

The ClawProtect proxy is an HTTP reverse proxy that intermediates all traffic between users and your AI gateway.

Capabilities:

  • Prompt injection detection – jailbreaks, role manipulation, instruction override
  • PII detection and redaction – emails, phone numbers, SSNs, credit cards
  • Secrets detection – API keys, tokens, passwords before they leave your environment
  • Vulnerability scanning – SQLi, SSRF, XSS, path traversal, command injection patterns
  • Malware analysis – detection of suspicious binaries, scripts, and archive bombs

Policies are defined in YAML and are deny‑by‑default. See policy/examples/ for sample policies.

eBPF Monitor (optional)

The eBPF component (clawprotect-ebpf) attaches to kernel syscalls and emits high‑fidelity security events, for example:

  • Suspicious process execution (reverse shells, fork bombs)
  • Sensitive file access (/etc/shadow, sudoers, SSH keys)
  • Suspicious outbound connections and port scans
  • Privilege escalation attempts

See ebpf/README.md and ebpf/config/ for configuration.

Network Firewall (optional)

The firewall component (clawprotect-fw) configures iptables‑based egress rules to restrict which domains and IPs your agents can reach.

Example:

cd firewall/cmd/clawprotect-fw
go build -o clawprotect-fw
sudo ./clawprotect-fw apply --config firewall/examples/firewall.yaml

Architecture

ClawProtect AI Security Stack Architecture

ClawProtect is designed as a defense‑in‑depth stack with three layers:

  1. Application layer – ClawProtect proxy (content and policy enforcement)
  2. Network layer – ClawProtect firewall (egress control)
  3. Kernel layer – ClawProtect eBPF monitor (behavioral detection)

Layers can be deployed independently, but work best together.

Defense-in-depth layered architecture

Some deployments wire these layers together with a Unix socket‑based event bus so that high‑severity events at one layer can trigger automatic reactions at another (for example, a port scan detected by eBPF can tighten firewall rules temporarily).

See docs/ and policy/examples/adaptive_crosslayer.yaml for more detail.


Production Deployment

For TLS‑terminated production deployments, see docs/install-guide.md and the manifests in deploy/:

  • cloud-init.yaml – VM hardening and base setup
  • docker-compose.yml – full stack with reverse proxy
  • nginx/conf.d/ – example nginx configuration
  • deploy.sh, smoke-test.sh – automation and verification helpers

Adapt these to your environment, security requirements, and infrastructure.


Configuration

Environment variables

Common environment variables (exact names may vary depending on your configuration):

Variable Required Description
ANTHROPIC_API_KEY Yes Anthropic API key (sk-ant-...)
GATEWAY_AUTH_TOKEN No Shared auth token for the AI gateway
CLAWPROTECT_PORT No Host port for the proxy UI / API
CLAWPROTECT_STUDIO_URL No Optional deep‑link base URL for dashboards

Key files

File Purpose
standalone/config/openclaw.json OpenClaw gateway configuration
standalone/config/policy.yaml ClawProtect security policy
standalone/agents/*/ Agent configs and knowledge bases

Testing

# Unit tests
go test ./proxy/...
go test ./firewall/...

# Integration tests (if present)
go test ./integration/...

Contributing

Issues, feature requests, and pull requests are welcome. Open them against this repository in your own hosting environment (for example, GitHub, GitLab, or an internal forge).


License

MIT (see LICENSE for details).

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages