ClawKeeper: Comprehensive Safety Protection for OpenClaw Agents Through Skills, Plugins, and Watchers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Songyang, Li, Chaozhuo, Wang, Chenxu, Hou, Jinyu, Chen, Zejian, Zhang, Litian, Liu, Zheng, Ye, Qiwei, Hei, Yiming, Zhang, Xi, Wang, Zhongyuan
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910072512184320
author Liu, Songyang
Li, Chaozhuo
Wang, Chenxu
Hou, Jinyu
Chen, Zejian
Zhang, Litian
Liu, Zheng
Ye, Qiwei
Hei, Yiming
Zhang, Xi
Wang, Zhongyuan
author_facet Liu, Songyang
Li, Chaozhuo
Wang, Chenxu
Hou, Jinyu
Chen, Zejian
Zhang, Litian
Liu, Zheng
Ye, Qiwei
Hei, Yiming
Zhang, Xi
Wang, Zhongyuan
contents OpenClaw has rapidly established itself as a leading open-source autonomous agent runtime, offering powerful capabilities including tool integration, local file access, and shell command execution. However, these broad operational privileges introduce critical security vulnerabilities, transforming model errors into tangible system-level threats such as sensitive data leakage, privilege escalation, and malicious third-party skill execution. Existing security measures for the OpenClaw ecosystem remain highly fragmented, addressing only isolated stages of the agent lifecycle rather than providing holistic protection. To bridge this gap, we present ClawKeeper, a real-time security framework that integrates multi-dimensional protection mechanisms across three complementary architectural layers. (1) \textbf{Skill-based protection} operates at the instruction level, injecting structured security policies directly into the agent context to enforce environment-specific constraints and cross-platform boundaries. (2) \textbf{Plugin-based protection} serves as an internal runtime enforcer, providing configuration hardening, proactive threat detection, and continuous behavioral monitoring throughout the execution pipeline. (3) \textbf{Watcher-based protection} introduces a novel, decoupled system-level security middleware that continuously verifies agent state evolution. It enables real-time execution intervention without coupling to the agent's internal logic, supporting operations such as halting high-risk actions or enforcing human confirmation. We argue that this Watcher paradigm holds strong potential to serve as a foundational building block for securing next-generation autonomous agent systems. Extensive qualitative and quantitative evaluations demonstrate the effectiveness and robustness of ClawKeeper across diverse threat scenarios. We release our code.
format Preprint
id arxiv_https___arxiv_org_abs_2603_24414
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle ClawKeeper: Comprehensive Safety Protection for OpenClaw Agents Through Skills, Plugins, and Watchers
Liu, Songyang
Li, Chaozhuo
Wang, Chenxu
Hou, Jinyu
Chen, Zejian
Zhang, Litian
Liu, Zheng
Ye, Qiwei
Hei, Yiming
Zhang, Xi
Wang, Zhongyuan
Cryptography and Security
Artificial Intelligence
OpenClaw has rapidly established itself as a leading open-source autonomous agent runtime, offering powerful capabilities including tool integration, local file access, and shell command execution. However, these broad operational privileges introduce critical security vulnerabilities, transforming model errors into tangible system-level threats such as sensitive data leakage, privilege escalation, and malicious third-party skill execution. Existing security measures for the OpenClaw ecosystem remain highly fragmented, addressing only isolated stages of the agent lifecycle rather than providing holistic protection. To bridge this gap, we present ClawKeeper, a real-time security framework that integrates multi-dimensional protection mechanisms across three complementary architectural layers. (1) \textbf{Skill-based protection} operates at the instruction level, injecting structured security policies directly into the agent context to enforce environment-specific constraints and cross-platform boundaries. (2) \textbf{Plugin-based protection} serves as an internal runtime enforcer, providing configuration hardening, proactive threat detection, and continuous behavioral monitoring throughout the execution pipeline. (3) \textbf{Watcher-based protection} introduces a novel, decoupled system-level security middleware that continuously verifies agent state evolution. It enables real-time execution intervention without coupling to the agent's internal logic, supporting operations such as halting high-risk actions or enforcing human confirmation. We argue that this Watcher paradigm holds strong potential to serve as a foundational building block for securing next-generation autonomous agent systems. Extensive qualitative and quantitative evaluations demonstrate the effectiveness and robustness of ClawKeeper across diverse threat scenarios. We release our code.
title ClawKeeper: Comprehensive Safety Protection for OpenClaw Agents Through Skills, Plugins, and Watchers
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2603.24414