sentinel-shield

Runtime security for OpenClaw agents. Monitors tool calls, enforces rate limits, scans for prompt injection, and alerts on suspicious behavior. Protect your gateway token and agent session from infostealers and session hijacking.

Safety Notice

This listing is from the official public ClawHub registry. Review SKILL.md and referenced scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "sentinel-shield" with this command: npx skills add shadowfax-mitch/sentinel-shield

Sentinel Shield — Runtime Security for OpenClaw Agents

Everyone else secures the model. We secure the agent.

Sentinel Shield is a lightweight security layer for OpenClaw agents. It monitors what your agent does — not just what it says — and alerts you before damage is done.

What It Protects Against

  • Stolen gateway tokens — Rate limiting + anomaly detection catches unauthorized sessions
  • Prompt injection — Scans inbound content for 16+ injection pattern signatures
  • Session hijacking — Behavioral fingerprinting flags sessions that don't match your patterns
  • Runaway agents — 50-call/60s sliding window kills runaway loops automatically
  • Silent exfiltration — File integrity monitoring on critical OpenClaw files

Quick Commands

Status Check

node {baseDir}/scripts/sentinel.js status

Returns current health, active session stats, and recent alert summary.

Security Audit

node {baseDir}/scripts/sentinel.js audit

Full audit: file integrity, rate limit state, injection scanner status, anomaly log.

Recent Alerts

node {baseDir}/scripts/sentinel.js alerts [--hours 24]

Shows alerts from the last N hours (default: 24).

Rate Limit Status

node {baseDir}/scripts/sentinel.js ratelimit

Shows current call counts per window for all monitored tools.

Kill Switch

node {baseDir}/scripts/sentinel.js kill

Emergency stop. Terminates active rate counters, logs kill event, sends Telegram alert.

Run Injection Scan

node {baseDir}/scripts/sentinel.js scan --text "some content to check"

Manually scan text for injection signatures.

Initialize / Reset Baselines

node {baseDir}/scripts/sentinel.js init

Establishes file integrity baselines for critical OpenClaw files.

Configuration

Edit {baseDir}/config/shield.json to customize:

{
  "rateLimit": {
    "maxCalls": 50,
    "windowSeconds": 60,
    "alertThreshold": 40
  },
  "telegram": {
    "enabled": true,
    "botToken": "YOUR_BOT_TOKEN",
    "chatId": "YOUR_CHAT_ID"
  },
  "monitoredFiles": [
    "~/.openclaw/openclaw.json",
    "~/.openclaw/credentials",
    "~/.ssh/authorized_keys",
    "/etc/passwd"
  ],
  "injectionScanning": true,
  "alertLevel": "medium"
}

Setup (Telegram Alerts)

  1. Create a Telegram bot via @BotFather → copy the token
  2. Message your bot to get your chat ID: https://api.telegram.org/bot<TOKEN>/getUpdates
  3. Add both to {baseDir}/config/shield.json

How to Use in Agent Sessions

When you see a suspicious message or want to verify your session is clean:

User: "Run a security check" Action: Run node {baseDir}/scripts/sentinel.js status

User: "Show me recent security alerts"
Action: Run node {baseDir}/scripts/sentinel.js alerts

User: "Scan this text for injection: [text]" Action: Run node {baseDir}/scripts/sentinel.js scan --text "[text]"

User: "Emergency stop sentinel" Action: Run node {baseDir}/scripts/sentinel.js kill

Alert Levels

LevelTriggerAction
INFONormal activity loggedWrite to log only
MEDIUMRate limit >80%Log + Telegram
HIGHRate limit hit, injection detectedLog + Telegram + kill option
CRITICALFile integrity violationLog + Telegram + alert all channels

Files Monitored (Default)

  • ~/.openclaw/openclaw.json — Gateway auth token (THE critical file)
  • ~/.openclaw/credentials — Stored credentials
  • ~/.ssh/authorized_keys — SSH access control
  • /etc/passwd — System user accounts
  • /etc/sudoers — Privilege escalation paths

Version History

  • v0.2.0 — Rate limiting (50/60s sliding window), Telegram alerts, clawhub distribution
  • v0.1.0 — File integrity monitoring, process scanning, injection detection (16 patterns)

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

Active Defense Sentinal

Defensive triage skill for OpenClaw, Hermes Agent, host integrity, and OpenClaw skill-supply-chain scanning. Detects prompt injection, session drift, context...

Registry SourceRecently Updated
1970Profile unavailable
Security

Aegis Protocol

Self-healing stability monitor for AI agents - 5 core checks + 15 extended checks, auto-recovery, health scoring

Registry SourceRecently Updated
1930Profile unavailable
Security

✅ AgentVerif — Scan. Sign. Verify. Control your distribution.

SCAN → SIGN → VERIFY. Certify your skill, detect tampering, revoke instantly. Full control over how your skill is distributed and run. Requires AGENTVERIF_AP...

Registry SourceRecently Updated
3010Profile unavailable
Security

IdentityMonitoringAgent

An OSINT sentinel that monitors the public web for email exposure, username footprint, and identity leaks without API keys.

Registry SourceRecently Updated
2120Profile unavailable