ClawSec
prompt-security/clawsec
Security skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
ClawSec is a collection of security skills and signed advisory intelligence for AI agent runtimes, including Hermes. For Hermes users, the hermes-attestation-guardian skill covers signed advisory checks, guarded verification, deterministic attestations and baseline drift detection.
What ClawSec does
ClawSec helps operators verify skill artifacts, detect configuration drift, audit agent environments and approval-gate risky installs across OpenClaw, NanoClaw, Hermes and Picoclaw. Its protection layers are signed intelligence, guarded installs that require a second explicit confirmation on advisory matches, integrity and drift baselines, and audit and reporting packages. ClawSec recommends and gates actions, while destructive removal and install overrides remain approval-controlled.
Each platform has its own entry point. The Hermes one is skills/hermes-attestation-guardian, while OpenClaw users start with clawsec-suite. The README's step-by-step install commands target OpenClaw, where optional protections ship as separate packages that the suite discovers from a published catalog. A soul-guardian demo shows a protected agent file being changed, the mismatch detected and the response walked through. The repository description says it can protect SOUL.md files with drift detection, and it is released under AGPL-3.0.
Key features
- hermes-attestation-guardian skill for signed advisory checks and guarded verification
- Deterministic attestations and baseline drift detection for Hermes
- Signed advisory feed and checksum manifest verification
- Guarded installs that require a second confirmation on advisory matches
- soul-guardian demo for detecting changes to protected agent files
- Separate entry points for OpenClaw, NanoClaw, Hermes and Picoclaw
When to use it
- Checking that a Hermes installation's critical files have not drifted from a baseline
- Blocking a risky skill install until you confirm it a second time
- Auditing agent environments in a setup that mixes OpenClaw and Hermes agents
Who it is for: Operators who run Hermes Agent or related runtimes and want signed advisories, integrity checks and install gating.
How it fits with Hermes Agent
Supports Hermes among four agent runtimes through the hermes-attestation-guardian skill. The suite is not Hermes-only, and its worked install example targets OpenClaw.
FAQ
What is ClawSec?
ClawSec is an AGPL collection of security skills and signed advisory intelligence for AI agent runtimes. It verifies skill artifacts, detects configuration drift, audits environments and gates risky installs.
Does ClawSec work with Hermes Agent?
Yes, Hermes is one of four supported platforms. The Hermes entry point is the hermes-attestation-guardian skill under skills/, which handles signed advisory checks, guarded verification, attestations and baseline drift detection.
Is ClawSec free and open source?
Yes, the repository is released under the AGPL-3.0 license, which is an open source license.
Similar security for Hermes Agent
All securityOpen-source static code security scanner with a built-in skill for AI agents including Hermes
Infisical Agent VaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
kenryu42 CC Safety NetGuard that blocks destructive Git and file commands and secret access before a coding agent runs them
SafeAI-Lab-X ClawKeeperHost-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results
Zyrexnn CybermesSecurity assistant framework for authorized bug bounty work, with an MCP server and Hermes Agent support
EXboys EvotownSelf-hosted control plane for governing OpenClaw, Hermes and SkillLite agents across a company
Related guides: How to run Hermes Agent securely