Skip to content

Repository files navigation

ClawGuard

  ______ _                 _____                     _
 / ____| |               / ____|                   | |
| |    | | __ ___      _| |  __ _   _  __ _ _ __ __| |
| |    | |/ _` \ \ /\ / / | |_ | | | |/ _` | '__/ _` |
| |____| | (_| |\ V  V /| |__| | |_| | (_| | | | (_| |
 \_____|_|\__,_| \_/\_/  \_____|\__,_|\__,_|_|  \__,_|

Harden OpenClaw before the internet finds it.

ClawGuard, also known as 小龙虾卫士, is a CLI-first security scanner and one-click hardening tool for OpenClaw deployments.

Current release target: v0.1.2

Rust CLI Security Tool OpenClaw Security Audit Reports Locale support


Table of Contents

Why ClawGuard

OpenClaw deployments are being exposed with the same failure patterns again and again:

  • public control ports
  • weak or missing authentication
  • broken approval and permission chains
  • secrets left in .env files and logs
  • suspicious skills and untrusted install sources

ClawGuard exists to turn that into a practical operator workflow:

  1. inspect the deployment
  2. explain the risk
  3. harden what can be fixed safely
  4. export a report you can actually share

What It Does

Audit

  • Scan a single OpenClaw config file
  • Scan a deployment directory
  • Detect exposure, auth, permission, secrets, and supply-chain findings
  • Load custom rulesets

Harden

  • Back up configs before changes
  • Restrict risky bind addresses
  • Rotate weak tokens
  • Disable dangerous debug and status exposure
  • Remove suspicious skills from the active config path

Report

  • Export json, html, and text
  • Use English or Simplified Chinese output
  • Auto-detect system language when --locale is not provided
  • Generate operator-readable findings with evidence and remediation

Current Status

ClawGuard is currently a working Rust CLI MVP.

Implemented today:

  • operator-friendly check, fix, and remove commands
  • CLI scanning
  • CLI hardening
  • CLI uninstall command
  • deployment profile scanning
  • localized report output
  • system locale auto-detection
  • signed rules-pack generation, import, activation, and rollback
  • signed release manifest generation and install-time verification
  • ASCII startup banner
  • packaging script and installation guide
  • test coverage for core and CLI flows

Still in progress:

  • online rules-pack update checks
  • published install channels
  • npm wrapper distribution

Quick Start

Build the CLI:

cargo build --release -p clawguard

Run help:

cargo run -p clawguard -- help

Start the default interactive operator flow:

cargo run -p clawguard --

In a real terminal, ClawGuard now opens a richer TUI:

  • ASCII-only action labels and prompt markers
  • orange-accent terminal theme with stable alignment
  • arrow-key navigation
  • space-to-toggle quick actions
  • enter-to-run
  • automatic fallback to plain text prompts in non-interactive shells and test runs

Auto-discover a local OpenClaw profile and print a readable report:

cargo run -p clawguard -- check

check now prints the discovered profile_path and a local_probe result before the report body.

With no arguments, ClawGuard starts an interactive menu for check, fix, remove, and sample-config flows.

Start interactive mode in Simplified Chinese:

cargo run -p clawguard -- --locale zh-CN

Auto-discover a local config and harden it in place:

cargo run -p clawguard -- fix --yes

Auto-detect a local install and remove the binary:

cargo run -p clawguard -- remove --yes

Generate a sample config:

cargo run -p clawguard -- sample-config --output example.conf

Generate a signing keypair for rules-pack management:

cargo run -p clawguard -- generate-signing-keypair --output-dir .keys

Sign a rules pack from the default rules or a custom rules file:

cargo run -p clawguard -- sign-rules-pack --output rules-pack.json --version 0.1.2 --private-key .keys/clawguard-rules.private.key

Import and activate the signed rules pack:

cargo run -p clawguard -- import-rules-pack --pack rules-pack.json --public-key .keys/clawguard-rules.public.key --activate

Scan a config:

cargo run -p clawguard -- scan --config example.conf --format json

Scan with localized text output:

cargo run -p clawguard -- scan --config example.conf --format text --locale zh-CN

ClawGuard also localizes the help screen and interactive prompts when --locale zh-CN is supplied or when the environment resolves to Chinese.

Scan a deployment directory:

cargo run -p clawguard -- scan-profile --path /path/to/openclaw-profile --format html --output report.html

Apply hardening:

cargo run -p clawguard -- harden --config example.conf --output hardened.conf

Uninstall from a target install directory:

cargo run -p clawguard -- uninstall --install-dir "$HOME/.local/bin"

Installation

Install from the local source tree:

cargo install --path crates/cli

Remove the Cargo-installed binary:

cargo uninstall clawguard

Install with curl after release archives are published:

curl -fsSL https://raw.githubusercontent.com/legeling/ClawGuard/main/scripts/install-clawguard.sh | bash

The installer verifies a signed release manifest against the committed release public key before extracting the archive.

Uninstall the curl install:

curl -fsSL https://raw.githubusercontent.com/legeling/ClawGuard/main/scripts/uninstall-clawguard.sh | bash

Install with npm or run with npx after the npm wrapper is published:

npx clawguard --help
npm install -g clawguard
clawguard --help

Detailed installation and packaging notes:

Example Use Cases

  • Audit a publicly reachable OpenClaw host before putting it behind a reverse proxy
  • Check whether a home-lab or VPS deployment leaked secrets into .env or logs
  • Validate installed skills against suspicious pattern rules
  • Produce an HTML report for review, documentation, or incident follow-up

Project Layout

crates/core-engine   Shared scanning, reporting, and remediation logic
crates/cli           Command-line entry point
rules/               Ruleset content
reports/             Report-related assets and conventions
docs/                Product, design, security, and operations docs
scripts/             Packaging and project automation

Documentation

Roadmap

  • Improve artifact signing and verification
  • Add online rules-pack update checks
  • Expand detector coverage for more real-world OpenClaw deployment patterns
  • Add published installation channels
  • Add npm wrapper distribution if a Node-based install path is still needed

Development

Build:

cargo build --workspace

Test:

cargo test --workspace

Lint:

cargo clippy --workspace --all-targets -- -D warnings

Package a release archive:

bash scripts/package-release.sh

Can Users Install It With npm Today?

Not yet.

ClawGuard is currently distributed as a Rust CLI, not an npm package.

What exists now:

  • Rust workspace
  • CLI binary
  • local packaging script
  • curl installer script
  • npm wrapper package scaffold

What does not exist yet:

  • published npm package
  • npx clawguard install path
  • published GitHub release archives for the download installers

FAQ

Does ClawGuard auto-detect the user locale?

Yes.

If --locale is not provided, ClawGuard checks LC_ALL, LC_MESSAGES, and LANG. If the environment looks Chinese, it switches to zh-CN. Otherwise it defaults to English.

The same locale selection applies to:

  • the help screen
  • the interactive menu
  • interactive prompts and confirmations
  • terminal report output

If colors do not appear in your terminal, check whether NO_COLOR=1 is set in your shell environment.

Does ClawGuard have an uninstall flow?

Yes, for the current CLI installation model.

  • CLI command: clawguard uninstall --install-dir <path>
  • Shell script: scripts/uninstall-clawguard.sh

Does ClawGuard show an ASCII banner on startup?

Yes.

The help screen now includes an ASCII banner and a localized tagline for ClawGuard / 小龙虾卫士.

Visual Direction

ClawGuard should look like a precise, sharp, modern security product, not a generic hacker terminal brand.

Contributing

Contributions are welcome, but the repository follows a few strict rules:

  • repository-facing content stays in English
  • code comments stay in English
  • security-impacting changes should update the tracker and related docs
  • new behavior should land with tests and verification

Repository

  • GitHub: git@github.com:legeling/ClawGuard.git

License

License file not added yet.

About

CLI-first OpenClaw security audit, hardening, and signed-release verification tool./小龙虾卫士

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages