Hermes Atlas
Security & sandboxing · works with Hermes Agent

ClawKeeper

SafeAI-Lab-X/ClawKeeper

Host-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results

In short

ClawKeeper is a safety middleware that sits between an agent and its tools, blocking risky tool calls and redacting sensitive results. It ships a Python adapter for Hermes Agent that installs its guard chain without patching Hermes.

What ClawKeeper does

ClawKeeper checks what an agent is about to do and what its tools send back. The default guards cover dangerous shell execution, protected path access, unsafe URL and SSRF patterns, script bodies and dynamic paths, base64 and hex encoded payloads, credential discovery followed by network exfiltration, poisoned return content and credential redaction. The README calls the policies intentionally small and inspectable, with the code under clawkeeper_core/guards/.

For Hermes Agent, a Python adapter installs a pre-tool guard chain and post-tool result scanners through install_clawkeeper(Judge(), agent), and the README says no Hermes patching is required. Hosts that cannot import the package can call an HTTP Judge API started with clawkeeper-server. An optional Watcher daemon uses an OpenAI-compatible model to reason over intent and recent tool history, and its catches can become learned patterns stored under ~/.clawkeeper/ and hot-reloaded into the live guard layer.

Key features

  • Pre-tool guards for shell, Python, browser, filesystem and network calls
  • Detection of prompt injection, credential reads and exfiltration chains
  • Redaction of credentials and poisoned tool output
  • Hermes Agent adapter installed with one function call
  • HTTP Judge API for hosts that cannot import the Python package
  • Optional Watcher daemon with learned patterns that hot-reload

When to use it

  • Putting a guardrail layer in front of a Hermes Agent that runs shell and browser tools
  • Catching credential reads followed by outbound network calls
  • Screening skills and logs through the scan endpoints
  • Protecting a non-Python agent host through the HTTP API

Who it is for: Developers running tool-using agents such as Hermes Agent who want inspectable guardrails around shell, file and network access.

How it fits with Hermes Agent

ClawKeeper is host-agnostic and includes a Hermes adapter (clawkeeper_core.adapters.hermes) next to HTTP and OpenClaw-style integrations. Hermes Agent is one supported host, not the only one.

How to install ClawKeeper

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

git clone git@github.com:SafeAI-Lab-X/ClawKeeper.git
cd ClawKeeper
pip install -e ".[dev]"

Requirements: A Python environment with pip; the optional Watcher needs an OpenAI-compatible API key and model

Note: The repository description frames it around OpenClaw agents, and GitHub shows no license file even though the README states Apache-2.0.

FAQ

What is ClawKeeper?

ClawKeeper is safety middleware for tool-using agents. It sits between an agent and its tools, blocks risky calls such as credential exfiltration chains, and redacts sensitive results.

Does ClawKeeper work with Hermes Agent?

Yes. The README documents a Hermes adapter: create a Judge, then call install_clawkeeper(Judge(), agent) to add the guard chain and result scanners. It says no Hermes patching is required.

How do I install ClawKeeper?

Clone the repository and run pip install -e ".[dev]" from its folder. The README suggests running pytest -q afterwards as a sanity check.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely