{"data":{"slug":"knostic-openclaw-shield","name":"openclaw-shield","tagline":"Security plugin for OpenClaw agents","github_url":"https://github.com/knostic/openclaw-shield","owner":"knostic","repo":"openclaw-shield","owner_avatar_url":"https://avatars.githubusercontent.com/u/145111474?v=4","primary_language":"TypeScript","stars":91,"forks":12,"topics":["clawdbot-plugin","guardrails","openclaw","openclaw-plugin","openclaw-security"],"archived":false,"github_pushed_at":"2026-05-12T11:30:45+00:00","maintenance_label":"Slowing","stars_delta_30d":2,"url":"https://www.graphcanon.com/tools/knostic-openclaw-shield","markdown_url":"https://www.graphcanon.com/tools/knostic-openclaw-shield.md","api_url":"https://www.graphcanon.com/api/graphcanon/tools/knostic-openclaw-shield","graph_url":"https://www.graphcanon.com/api/graphcanon/graph?tool=knostic-openclaw-shield","description":"Security plugin for OpenClaw agents - prevents secret leaks, PII exposure, and destructive command execution","homepage_url":"https://www.knostic.ai","license":"Apache-2.0","open_issues":8,"watchers":1,"ai_summary":"Provides functionality to prevent secret leaks, PII exposure, and destructive command execution in OpenClaw AI environment.","readme_excerpt":"## Installation\n\n```bash\nopenclaw plugins install @knostic/openclaw-shield\n```\n\nThat's it. The plugin activates on the next gateway restart with all layers enabled in `enforce` mode.\n\n---\n\n# Install locally for testing\nopenclaw plugins install ./\n```\n\nNo build step required — OpenClaw transpiles TypeScript at load time via jiti.\n\n---\n\n## License\n\nApache 2.0 — see LICENSE for details.","github_created_at":"2026-02-04T16:12:24+00:00","created_at":"2026-07-15T10:43:39.071463+00:00","updated_at":"2026-09-20T04:26:09.194913+00:00","categories":[{"slug":"ai-agents","name":"AI Agents","url":"https://www.graphcanon.com/categories/ai-agents","markdown_url":"https://www.graphcanon.com/categories/ai-agents.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/ai-agents"}],"tags":[{"slug":"clawdbot-plugin","name":"clawdbot-plugin"},{"slug":"guardrails","name":"guardrails"},{"slug":"openclaw-plugin","name":"openclaw-plugin"},{"slug":"openclaw-security","name":"openclaw-security"}],"trust":{"provenance":{"is_fork":false,"github_id":1149873873,"owner_type":"Organization","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-09-12T06:00:40.712Z","maintenance":{"label":"Slowing","score":36,"methodology":"github_public_v1","releases_90d":0,"days_since_push":122,"last_release_at":null,"stars_delta_30d":2,"open_issues_delta_30d":0},"security_summary":{"status":"no_lockfile","scanner":null,"low_count":0,"high_count":0,"last_scan_at":"2026-07-15T10:43:40.475Z","medium_count":0,"scan_profile":"none","critical_count":0}},"capability_facts":{"mcp":{"source":"repo_scan","observed_at":"2026-09-12T06:00:41.176Z","server_manifest":false},"scan":{"source":"repo_scan","observed_at":"2026-09-12T06:00:41.176Z"},"languages":{"value":["typescript","javascript"],"source":"github.language+package.json","observed_at":"2026-09-12T06:00:41.176Z"},"license_spdx":{"value":"Apache-2.0","source":"github.license","observed_at":"2026-09-12T06:00:41.176Z"}},"decision_facts":{"hosting":{"model":"self_hosted","summary":"Supports self-hosting for environments that require local deployment or custom configurations."},"pricing":null,"requirements":null,"constraints":{"hosting_model":"self_hosted"},"when_to_use":["Use openclaw-shield if you are specifically working within an OpenClaw environment and require protection against secret leaks, PII exposure, or potentially destructive command execution.","Integrate this plugin when your development workflow demands immediate activation upon the next gateway restart without manual configuration."],"when_not_to_use":["Avoid openclaw-shield if you are not using OpenClaw agents as it will not integrate with other agent frameworks.","Do not use if your project necessitates a different license type than Apache-2.0; the plugin may not align with proprietary or restrictively licensed projects."],"source":"enrich:decision_facts","observed_at":"2026-07-16T16:08:17.537Z"},"constraint_facets":{"hosting_model":"self_hosted"},"decision_summary":[{"label":"Hosting","value":"self hosted - Supports self-hosting for environments that require local deployment or custom configurations."},{"label":"Adopt for","value":"openclaw-shield is a security plugin for OpenClaw agents written in TypeScript under the Apache-2.0 license."},{"label":"License detail","value":"Licensed under the Apache-2.0 License, permitting users to freely use, modify, and distribute the software."}]}}