More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    🛡️ OpenClaw Guardrail Linter

    2

    Review selected OpenClaw configuration for risky declarations, with explicit reporting when inputs cannot be assessed.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    🛡️ OpenClaw Guardrail Linter

    🛡️ OpenClaw Guardrail Linter

    Example session with this skill installed

    Review only my selected stable OpenClaw configuration files. Report risky declarations and anything that could not be assessed. Do not execute OpenClaw or change configuration.

    • Read your context and instructions
    • Compiled the openclaw guardrail linter
    • Generated the document

    Illustrative v1.1.0 result guide, not a live-host audit

    Use the bundled clean and risky fixtures first. For your selected inputs, review the emitted findings and coverage status together; an incomplete assessment must not be treated as clean.

    ResultMeaningNext step
    Exit 0No findings in assessed inputsReview coverage and the tool limitations
    Exit 1Patterns need reviewInspect the cited rule and relevant declaration
    Exit 2Assessment incompleteResolve the input or coverage problem before drawing conclusions

    Reports identify inputs by ordinal and source hash rather than exposing raw values or absolute paths. Line 0 means source line mapping is unavailable, not that a precise line was verified.

    What this does not establish

    The linter does not resolve inherited policies, follow includes, or prove effective runtime permissions. Confirm actual host behavior separately. Review any proposed remediation and back up customizations before making changes.

    openclaw-guardrail-linter.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Flag literal credential-like values in selected configuration for review.Review sandbox-related declarations and Docker bind patterns.Check incomplete file-tool denials without assuming effective permissions.Review open inbound channel settings and broad tool declarations.

    About this skill

    Review declarations, not assumed protection

    OpenClaw Guardrail Linter reads selected local configuration and instruction files and flags patterns worth reviewing: broad tool declarations, open channel settings, literal credential-like values, incomplete file-tool denials and sandbox-related settings. It does not run OpenClaw, change configuration or calculate the running agent's effective permissions.

    Current package

    Package v1.1.0 is listed in Agensi revision v1.1. The changes and setup below apply to this version; inspect the version before updating an older installation.

    What changes in v1.1.0

    Parsed JSON5 replaces regex-only configuration interpretation. The update fixes missed file-mutation and neighboring-SecretRef findings and distinguishes incomplete input from a scan with no findings. Linked/reparse paths, missing or malformed inputs, unsupported includes and files above 64 KiB are not reported as clean. Credential/state paths are excluded without reading their contents. Reports withhold raw values and absolute paths, using input ordinals and source hashes. Source line mapping is unavailable (line 0).

    Setup and first use for v1.1.0

    Requires Python 3.10+ and json5==0.15.0. Extract the complete folder and install the pinned dependency in an approved environment with python -m pip install -r requirements.txt. Setup requires package-source access; scans are offline. No API key or live OpenClaw connection is required.

    Run python scripts/scan_openclaw_guardrails.py fixtures/clean-sample, then the risky fixture before selecting your own stable configuration. Exit 0 means no findings in assessed inputs, 1 means findings, and 2 means incomplete assessment. None is a security certification.

    Limits

    Not a complete host schema validator, vulnerability scanner or inherited-policy resolver. Includes are not followed. Other policy layers can constrain broad declarations; allowed shell execution can write files despite file-tool denials. Use native host policy/audit evidence for actual execution. No live-host enforcement or adversarial concurrent-replacement resistance is claimed. Back up customizations and check automation that previously expected only exit 0/1.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed3 months ago
    Updated11 days ago

    What's inside

    Frequently Asked Questions