
OpenClaw Traffic Guardian
FreeBaseline traffic monitoring for HTTP/HTTPS proxy inspection.
Free · Opens the source repo
What OpenClaw Traffic Guardian does
OpenClaw Traffic Guardian serves as a foundational skill designed for traffic monitoring within the OpenClaw ecosystem. It focuses on providing a baseline for HTTP and HTTPS proxy inspection, enabling developers to detect outbound exfiltration, inbound injection attempts, and review modifications to social accounts. This skill is particularly aimed at builders who need to establish a secure environment for monitoring network traffic without automatically altering system configurations or trust settings.
The skill operates by allowing optional inspection of HTTP requests and responses, with a strong emphasis on user consent and security. It does not implement automatic changes to the system's Certificate Authority (CA) store or global proxy settings, ensuring that users maintain control over their network configurations. Instead, it provides a structured environment to validate configurations and monitor traffic, logging findings in a secure manner. The data collected is redacted to protect sensitive information, which is crucial for maintaining privacy and security.
For developers and security engineers, OpenClaw Traffic Guardian offers a modular approach to traffic monitoring. It includes hooks for integration with OpenClaw, allowing for a customizable implementation tailored to specific needs. The skill's architecture supports the development of detection rules and logging mechanisms, making it suitable for various use cases, from compliance checks to proactive threat detection. Builders are encouraged to read the accompanying specification documents to fully understand the intended use and implementation guidelines.
In summary, OpenClaw Traffic Guardian is an essential tool for those looking to enhance their traffic monitoring capabilities within the OpenClaw framework, providing a secure and controlled environment for inspecting network activity while ensuring user privacy and consent.
When to use it
Use this skill when you need to monitor network traffic for security purposes while maintaining user control over configurations.
When not to use it
This skill is not suitable for scenarios requiring automatic traffic interception or system-wide proxy configurations.
What you can build with it
Monitoring Outbound Traffic
Use OpenClaw Traffic Guardian to monitor and log outbound HTTP/HTTPS requests for potential data exfiltration.
Detecting Inbound Attacks
Leverage the skill to identify and log inbound injection attempts targeting your applications.
Reviewing Social Account Changes
Implement the skill to review modifications to social accounts, ensuring compliance with security policies.
How to install OpenClaw Traffic Guardian
View source1. Install with the skills CLI
npx skills add prompt-security/clawsec/openclaw-traffic-guardian --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by prompt-securityOpenClaw Traffic Guardian
This is a baseline specification skill. It intentionally does not ship a proxy or runtime implementation yet.
Vercel Skills Installation
Install with the Vercel Skills CLI for this harness:
npx skills add prompt-security/clawsec --skill openclaw-traffic-guardian -a openclaw -y
Release Artifact Verification
For standalone installs, verify the signed release manifest before trusting SKILL.md, skill.json, or the archive. The skill.json file is the package metadata/SBOM source, and the release pipeline signs checksums.json with the ClawSec release key.
set -euo pipefail
SKILL_NAME="openclaw-traffic-guardian"
VERSION="0.0.1-beta5"
REPO="prompt-security/clawsec"
TAG="${SKILL_NAME}-v${VERSION}"
BASE="https://github.com/${REPO}/releases/download/${TAG}"
ZIP_NAME="${SKILL_NAME}-v${VERSION}.zip"
TMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TMP_DIR"' EXIT
RELEASE_PUBKEY_SHA256="711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8"
curl -fsSL "$BASE/checksums.json" -o "$TMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TMP_DIR/checksums.sig"
curl -fsSL "$BASE/signing-public.pem" -o "$TMP_DIR/signing-public.pem"
curl -fsSL "$BASE/$ZIP_NAME" -o "$TMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/SKILL.md" -o "$TMP_DIR/SKILL.md"
curl -fsSL "$BASE/skill.json" -o "$TMP_DIR/skill.json"
ACTUAL_PUBKEY_SHA256="$(openssl pkey -pubin -in "$TMP_DIR/signing-public.pem" -outform DER | shasum -a 256 | awk '{print $1}')"
if [ "$ACTUAL_PUBKEY_SHA256" != "$RELEASE_PUBKEY_SHA256" ]; then
echo "ERROR: signing-public.pem fingerprint mismatch" >&2
exit 1
fi
openssl base64 -d -A -in "$TMP_DIR/checksums.sig" -out "$TMP_DIR/checksums.sig.bin"
openssl pkeyutl -verify -rawin -pubin \
-inkey "$TMP_DIR/signing-public.pem" \
-sigfile "$TMP_DIR/checksums.sig.bin" \
-in "$TMP_DIR/checksums.json" >/dev/null
hash_file() {
if command -v shasum >/dev/null 2>&1; then
shasum -a 256 "$1" | awk '{print $1}'
else
sha256sum "$1" | awk '{print $1}'
fi
}
verify_manifest_file() {
asset="$1"
path="$2"
expected="$(jq -r --arg asset "$asset" '.files[$asset].sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected" ]; then
echo "ERROR: checksums.json missing $asset" >&2
exit 1
fi
actual="$(hash_file "$path")"
if [ "$actual" != "$expected" ]; then
echo "ERROR: checksum mismatch for $asset" >&2
exit 1
fi
}
expected_archive="$(jq -r '.archive.sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected_archive" ]; then
echo "ERROR: checksums.json missing archive.sha256" >&2
exit 1
fi
actual_archive="$(hash_file "$TMP_DIR/$ZIP_NAME")"
if [ "$actual_archive" != "$expected_archive" ]; then
echo "ERROR: archive checksum mismatch" >&2
exit 1
fi
verify_manifest_file "SKILL.md" "$TMP_DIR/SKILL.md"
verify_manifest_file "skill.json" "$TMP_DIR/skill.json"
echo "Signed release manifest, archive, SKILL.md, and skill.json verified."
Only install or extract the archive after this verification succeeds.
Scope
Builders should use this skill as the OpenClaw landing zone for runtime traffic monitoring:
- operator-scoped HTTP proxy inspection
- optional HTTPS inspection with per-process CA trust
- outbound exfiltration detection
- inbound injection detection
- approval-sensitive social-account mutation review
- redacted local threat logs
- optional OpenClaw hook/status integration
Do not merge this capability into clawsec-scanner, openclaw-audit-watchdog, or soul-guardian. Those skills have different trust boundaries and safety contracts.
Safety Contract
- Opt-in only.
- Detect-and-log by default.
- No automatic system CA installation.
- No global
HTTP_PROXYorHTTPS_PROXYchanges. - No blocking in the first implementation.
- Redact secrets before logs or conversation alerts.
- Keep all state under
OPENCLAW_TRAFFIC_GUARDIAN_HOMEor~/.openclaw/security/clawsec/traffic-guardian.
Builder Entry Points
Read SPEC.md before implementing. Use the placeholder folders as follows:
| Path | Intended use |
|---|---|
lib/ | Detector rules, redaction, event schema, report formatting |
scripts/ | Start, stop, status, config validation, log query helpers |
hooks/openclaw-traffic-guardian-hook/ | Optional OpenClaw hook/status integration |
test/ | Unit tests, proxy fixture tests, redaction tests, process-scope tests |
Required First Implementation Behavior
- Validate config without starting the proxy.
- Start monitor in foreground or explicit background mode.
- Scope proxy environment variables to the target OpenClaw process.
- Inspect HTTP request/response text up to a bounded byte limit.
- Support optional HTTPS MITM only when the operator supplies per-process trust configuration.
- Flag requests matching
SPEC.md's Outbound POLICY_REVIEW cases as operator-review findings, including TweetClaw or other X/Twitter automation writes and scheduler/background-runner repeats without a fresh operator-approval marker. - Detect repeat/background-runner context from bounded request metadata such as paths, headers, user-agent, client context, tool invocation metadata, or scheduler identifiers.
- Emit JSONL findings with redacted snippets plus source type, mutation category, approval-marker presence, and direct-operator versus background-runner context.
- Provide a
statuscommand that reports mode, listener, CA fingerprint if present, and last findings.
Out of Scope for v0.0.1 Implementation
- automatic system trust-store mutation
- transparent network interception
- default blocking
- sending traffic to external services
- collecting full request/response bodies
Frequently asked questions about OpenClaw Traffic Guardian
Similar skills
GitHub Actions Hardening
Enhance the security of your GitHub Actions workflows.
Sensitive Logging Audit
Audit and fix sensitive data exposure in Python logging.
Android App Static Analysis
Automate security assessments of Android apps with MobSF.
Integrating DAST with OWASP ZAP
Seamlessly integrate dynamic security testing into CI/CD pipelines.
Implementing Runtime Security with Tetragon
Enhance Kubernetes security with eBPF-based observability.
Implementing Mobile Application Management
Secure enterprise data on mobile devices with app-level controls.
