← 返回 Skills 市场
thomas-security

MoltGuard - Security & Antivirus & Guardrails

作者 Thomas · GitHub ↗ · v6.8.16 · MIT-0
cross-platform ⚠ suspicious
25246
总下载
114
收藏
152
当前安装
56
版本数
在 OpenClaw 中安装
/install moltguard
功能描述
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
安全使用建议
Install only if you intentionally want a cloud-backed OpenClaw security plugin. Before enabling it, review the external plugin and provider terms, confirm what prompts, files, commands, secrets, and PII may be sent to Core, and treat any Agent ID or API key it shows or stores as a secret.
功能分析
Type: OpenClaw Skill Name: moltguard Version: 6.8.16 The moltguard skill bundle serves as an onboarding and management interface for a security guardrail service. The SKILL.md file provides instructions for installing the @openguardrails/moltguard plugin, performing a self-test, and managing account linking via an external 'Core' service (openguardrails.com). While the service involves sending agent activity to a remote endpoint for analysis, this behavior is transparently documented as its primary function (security monitoring), and no evidence of malicious intent, obfuscation, or unauthorized data theft was found.
能力评估
Purpose & Capability
The stated purpose is coherent: a guardrail service for prompt injection, data exfiltration, malicious commands, PII, and credential-theft risks. The concern is that the reviewed skill is instruction-only while directing installation of a separate plugin that changes OpenClaw behavior and sends security-relevant agent activity to an external Core service.
Instruction Scope
The install language applies when the user asks or when the agent wants to protect itself, and the onboarding flow advertises automatic zero-human-intervention activation. That is under-scoped for persistent security monitoring and credential setup.
Install Mechanism
Installation is transparent and uses an OpenClaw plugin install command for @openguardrails/moltguard, with update and uninstall commands documented. The actual plugin code is not present in this skill artifact, so the installed capability boundary is not fully reviewable here.
Credentials
Cloud analysis is purpose-aligned for this kind of security guard, but the artifact says Core evaluates prompts, behavior, commands, PII, and secret-leakage risks without defining what data is transmitted, retained, excluded, or user-controlled.
Persistence & Privilege
The skill documents persistent credentials under ~/.openclaw/credentials/moltguard/ and commands that show API keys. That is expected for account linking, but the artifact lacks clear warnings about protecting, masking, rotating, or removing those secrets outside the uninstall note.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install moltguard
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /moltguard 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v6.8.16
- Updated description and installation instructions to simplify setup; removed the restart step from installation. - Clarified terminology to refer to the user as "human" for more consistent documentation. - No code or functional changes—documentation update only.
v6.8.15
- Updated to version 6.8.15. - Clarified language for configuring an API key and onboarding steps. - Improved instructions for enterprise enrollment, specifying use of the local script. - Removed mention of API keys working across multiple agents from the Plans table. - Minor language and formatting improvements for clarity.
v6.8.14
- Enterprise onboarding instructions added, allowing managed device enrollment with private Core deployments. - New uninstall process: uses a script for complete cleanup, removing config, plugin files, and credentials. - Documentation refinements, including clearer separation for "human" and agent protection and expanded plan details. - Version updated from 6.7.23 to 6.8.14.
v6.7.23
- Updated homepage link in metadata to point to the MoltGuard GitHub repository. - No functional or documentation changes outside the metadata update.
v6.7.22
- Updated metadata homepage URL to https://www.moltguard.com - Clarified onboarding flow: plugin now gets API key from Core (removed “auto-registers with Core with agent name and description”) - No other content changes detected.
v6.7.21
- Documentation streamlined for clarity; redundant sections and technical transparency details removed. - "Description" updated for brevity and directness, with a clear source link. - Metadata simplified by removing detailed permission, network, and behavioral fields. - Privacy, network access, and local storage sections cut for conciseness. - Language around agent registration and onboarding flow simplified for easier understanding. - All core usage, installation, and command references retained; audience guidance unchanged.
v6.7.20
- Added new security notice: Users are advised to verify the source code and plugin registry before installing, as this skill instructs the installation of an external plugin. - Updated plugin description and metadata to highlight the use of external code and added a warning note. - Provided detailed verification steps for auditing the external plugin and network behavior. - Clarified commands that display sensitive data and advised caution in shared environments. - No changes to core installation, usage, or command structure.
v6.7.19
- Added a new "Privacy & Security Transparency" section detailing network access, local storage, and command behaviors. - Declared explicit permissions, including network domain (`api.openguardrails.com`) and local storage directory for credentials. - Clarified first-run behavior: MoltGuard auto-registers with the Core API, saves credentials locally, and begins protection. - Stated that content hashes, not raw content or user data, are sent for security checks. - Updated metadata to accurately reflect permissions, storage, network calls, and command key exposure.
v6.7.18
- Updated the homepage URL in metadata to https://moltguard.com. - Removed the GitHub Issues and Documentation links from the Contact & Support section; now only the support email remains.
v6.7.17
- Clarified installation instructions for immediate activation after install. - Updated onboarding flow details to specify auto-registration with agent name and description. - Simplified API key configuration steps in command documentation. - Minor text tweaks for accuracy and readability.
v6.7.16
- Documentation streamlined by removing sections on daily risk announcements, local data sanitization, and quota instructions. - Kept onboarding, commands, feature overview, and support sections clear and concise. - No functional or technical changes—documentation only.
v6.7.15
- Added a new "Local Data Sanitization" section to document support for local sanitization and restoration of sensitive data during LLM calls. - Clarified that sensitive data stays on your machine and is never transmitted externally. - No other content or functional changes noted.
v6.7.14
- Removed the file references/details.md. - No other changes to documentation or functionality in this release.
v6.7.13
- Removed detailed instructions and messaging for what to do when quota is exceeded. - Now only refers users to configure a new API key via `/og_config` after upgrading their plan. - No functional or code changes; documentation update only.
v6.7.12
- Changed the sample test file in the installation/test instructions from a hidden phishing attack file to a non-harmful test file: `test-email-popup.txt`. - Removed explicit instructions to notify the user when `<openguardrails-quota-exceeded>` tags appear, though quota information is still relayed. - No other content or functional changes detected.
v6.7.11
- Major documentation rewrite: clear step-by-step install, test, and usage instructions. - Added specific sample test workflow to show immediate protection in action. - New guidance: how to announce risks and quota issues to users. - Expanded command reference section with explanations for each command. - Detailed onboarding flow, claim process, and plan comparison tables. - Added explicit update and uninstall instructions.
v6.7.10
- Clarified architecture: this version documents that the ClawHub skill is for guidance only and **does not include any code or security functionality**. - Added a prominent section describing the distinction between this skill (documentation) and the actual npm package (`@openguardrails/moltguard`), which must be installed separately to get security protection. - Included a verification checklist to help users safely review and install the actual npm package. - Made security trust boundaries more explicit: reading/using this skill is low risk, installing the npm package requires a full security audit. - Installation instructions now direct users to install the npm package for real protection and explain how to verify its provenance and runtime behavior.
v6.7.9
**Summary: v6.7.9 introduces a new "Trust Model & Threat Assumptions" section, clarifying what is and is not protected, and updates security best practices.** - Added an in-depth "Trust Model & Threat Assumptions" section, detailing security boundaries, trust requirements, and the threat model for MoltGuard users. - Provided explicit lists of what users must and do not need to trust, and clear tables on what is protected or not in different architectural boundaries. - Enhanced security guidance with updated recommendations for sandbox testing, production installation, and defense-in-depth practices. - Added new warnings and safety instructions to improve user understanding of MoltGuard's architecture and recommended deployment practices.
v6.7.8
**Version 6.7.8 Changelog** - Updated documentation to clarify MoltGuard's hybrid architecture: now emphasizes local data sanitization before cloud-based security detection. - Added prominent warnings and a new "Quick Architecture Summary" table describing what data stays local and what leaves the machine. - Included a new "Read This Before Installing" section, with a checklist for transparency and trust decisions. - Enhanced guidance on package provenance, review steps, and verification for security-conscious users. - No changes to plugin code or runtime functionality; documentation only.
v6.7.7
Version 6.7.7 - Added documentation for the AI Security Gateway: a local proxy for data sanitization of secrets and PII before LLM requests. - Clarified that the data sanitization gateway runs locally (localhost:38790), never sends data to OpenGuardrails, and only communicates with your LLM provider. - Included instructions for network verification to demonstrate that no sensitive data leaves your device via the gateway. - Provided detailed architecture and data flow diagrams illustrating how the AI Security Gateway sanitizes and restores sensitive data. - Emphasized that all gateway code is open source and fully auditable.
元数据
Slug moltguard
版本 6.8.16
许可证 MIT-0
累计安装 865
当前安装数 152
历史版本数 56
常见问题

MoltGuard - Security & Antivirus & Guardrails 是什么?

MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 25246 次。

如何安装 MoltGuard - Security & Antivirus & Guardrails?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install moltguard」即可一键安装,无需额外配置。

MoltGuard - Security & Antivirus & Guardrails 是免费的吗?

是的,MoltGuard - Security & Antivirus & Guardrails 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

MoltGuard - Security & Antivirus & Guardrails 支持哪些平台?

MoltGuard - Security & Antivirus & Guardrails 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 MoltGuard - Security & Antivirus & Guardrails?

由 Thomas(@thomas-security)开发并维护,当前版本 v6.8.16。

💬 留言讨论