ClawShell
runta-dev/clawshell
Local proxy that swaps virtual API keys for real ones and scans traffic for PII, for OpenClaw and Hermes
ClawShell is a Rust security process that sits between OpenClaw or Hermes Agent and upstream LLM providers. The agent holds only virtual API keys, while ClawShell swaps in real keys and scans requests and responses for sensitive data.
What ClawShell does
ClawShell runs as a privileged process between the agent and providers such as OpenAI, Anthropic and OpenRouter. Real keys sit in /etc/clawshell/clawshell.toml, readable only by the clawshell system user, so the agent never sees them. It maps each virtual key to a provider and injects the right header format for that provider.
A data loss prevention layer scans request and response bodies with regex patterns you define in TOML, each set to block or redact; the README gives SSNs, credit card numbers and emails as examples. Streaming responses pass through without scanning. An email endpoint can expose a mailbox with sender allowlist or denylist rules per virtual key, with Gmail and Outlook presets and manual IMAP. OAuth sign-in for Codex and ChatGPT uses a device code flow with automatic token refresh. A loopback-only /admin/stats endpoint reports protected requests, token counts and emails hidden by the sender policy.
Key features
- Virtual-to-real API key mapping for OpenAI and Anthropic style providers
- PII scanning of requests and responses with custom block or redact regex patterns
- Sender-based email filtering per virtual key, with Gmail and Outlook presets
- OAuth device code login for Codex and ChatGPT with automatic token refresh
- Loopback-only /admin/stats counters persisted to disk
When to use it
- Keeping real API keys out of reach of an agent that runs tools and shell commands
- Blocking or redacting personal data before it reaches a model provider
- Letting an agent read only mail from approved senders
Who it is for: Operators who run Hermes Agent or OpenClaw on a server and want credential isolation and a data loss prevention layer.
How it fits with Hermes Agent
The README names OpenClaw and Hermes Agent together as the ecosystem it protects, and the repository carries hermes and hermes-agent topics.
Note: Streaming (SSE) responses are passed through without PII scanning.
FAQ
What is ClawShell?
ClawShell is a local security process that sits between OpenClaw or Hermes Agent and LLM providers. It maps virtual API keys to real ones and scans traffic for sensitive data.
Does ClawShell work with Hermes Agent?
Yes. The README describes it as a runtime control layer for OpenClaw and Hermes Agent, and the agent only holds virtual keys that ClawShell exchanges for real ones.
Is ClawShell free and open source?
Yes. The repository is licensed under Apache-2.0.
Similar security for Hermes Agent
All securitySelf-hosted control plane for governing OpenClaw, Hermes and SkillLite agents across a company
vivekchand ClawMetryLocal dashboard that reads agent session files to show timelines, tool calls and token costs
0xNyk LACPLocal policy, approval and recovery controls that wrap CLI coding agents such as Claude, Codex and Hermes
asimons81 Hermes VaultLocal-first credential broker, secret scanner and encrypted vault for Hermes agents
78 TenBoxLightweight virtual machine monitor for running OpenClaw, QwenPaw and Hermes Agent in isolation
nativ3ai Hermes Agent CaMeLHermes Agent fork with an opt-in CaMeL-style guard against indirect prompt injection
Related guides: How to run Hermes Agent securely