ClawKeeper
SafeAI-Lab-X/ClawKeeper
Host-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results
ClawKeeper is a safety middleware that sits between an agent and its tools, blocking risky tool calls and redacting sensitive results. It ships a Python adapter for Hermes Agent that installs its guard chain without patching Hermes.
What ClawKeeper does
ClawKeeper checks what an agent is about to do and what its tools send back. The default guards cover dangerous shell execution, protected path access, unsafe URL and SSRF patterns, script bodies and dynamic paths, base64 and hex encoded payloads, credential discovery followed by network exfiltration, poisoned return content and credential redaction. The README calls the policies intentionally small and inspectable, with the code under clawkeeper_core/guards/.
For Hermes Agent, a Python adapter installs a pre-tool guard chain and post-tool result scanners through install_clawkeeper(Judge(), agent), and the README says no Hermes patching is required. Hosts that cannot import the package can call an HTTP Judge API started with clawkeeper-server. An optional Watcher daemon uses an OpenAI-compatible model to reason over intent and recent tool history, and its catches can become learned patterns stored under ~/.clawkeeper/ and hot-reloaded into the live guard layer.
Key features
- Pre-tool guards for shell, Python, browser, filesystem and network calls
- Detection of prompt injection, credential reads and exfiltration chains
- Redaction of credentials and poisoned tool output
- Hermes Agent adapter installed with one function call
- HTTP Judge API for hosts that cannot import the Python package
- Optional Watcher daemon with learned patterns that hot-reload
When to use it
- Putting a guardrail layer in front of a Hermes Agent that runs shell and browser tools
- Catching credential reads followed by outbound network calls
- Screening skills and logs through the scan endpoints
- Protecting a non-Python agent host through the HTTP API
Who it is for: Developers running tool-using agents such as Hermes Agent who want inspectable guardrails around shell, file and network access.
How it fits with Hermes Agent
ClawKeeper is host-agnostic and includes a Hermes adapter (clawkeeper_core.adapters.hermes) next to HTTP and OpenClaw-style integrations. Hermes Agent is one supported host, not the only one.
How to install ClawKeeper
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
git clone git@github.com:SafeAI-Lab-X/ClawKeeper.git
cd ClawKeeper
pip install -e ".[dev]"Requirements: A Python environment with pip; the optional Watcher needs an OpenAI-compatible API key and model
Note: The repository description frames it around OpenClaw agents, and GitHub shows no license file even though the README states Apache-2.0.
FAQ
What is ClawKeeper?
ClawKeeper is safety middleware for tool-using agents. It sits between an agent and its tools, blocks risky calls such as credential exfiltration chains, and redacts sensitive results.
Does ClawKeeper work with Hermes Agent?
Yes. The README documents a Hermes adapter: create a Judge, then call install_clawkeeper(Judge(), agent) to add the guard chain and result scanners. It says no Hermes patching is required.
How do I install ClawKeeper?
Clone the repository and run pip install -e ".[dev]" from its folder. The README suggests running pytest -q afterwards as a sanity check.
Similar security for Hermes Agent
All securityOpen-source static code security scanner with a built-in skill for AI agents including Hermes
Infisical Agent VaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
kenryu42 CC Safety NetGuard that blocks destructive Git and file commands and secret access before a coding agent runs them
prompt-security ClawSecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
Zyrexnn CybermesSecurity assistant framework for authorized bug bounty work, with an MCP server and Hermes Agent support
EXboys EvotownSelf-hosted control plane for governing OpenClaw, Hermes and SkillLite agents across a company
Related guides: How to run Hermes Agent securely