input-guardScan untrusted external text (web pages, tweets, search results, API responses) for prompt injection attacks. Returns severity levels and alerts on dangerous content. Use BEFORE processing any text from untrusted sources.
Install via ClawdBot CLI:
clawdbot install dgriffin831/input-guardGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://example.com/pageUses known external API (expected, informational)
api.anthropic.comGenerated Mar 1, 2026
AI agents fetching search results from external APIs can use Input Guard to scan each result before processing, preventing malicious actors from embedding prompt injections in search snippets or page content. This ensures safe information retrieval for tasks like market research or data aggregation.
Companies monitoring X/Twitter or other social platforms for brand mentions or trends can deploy Input Guard to scan posts and comments before analysis, blocking attempts to manipulate AI responses through embedded instructions. This protects automated sentiment analysis and alert systems.
Businesses integrating data from external APIs, such as weather services or financial feeds, can use Input Guard to validate responses for hidden prompt injections before feeding them into AI workflows. This secures automated reporting and decision-making processes.
AI-powered customer support systems that pull information from knowledge bases or external websites can scan fetched content with Input Guard to prevent injection attacks that might alter response behavior. This maintains trust and accuracy in automated support interactions.
Edtech platforms using AI to summarize or explain web-based educational materials can employ Input Guard to ensure content is free from malicious injections that could mislead students or alter learning outcomes. This supports safe, reliable educational tools.
Offer Input Guard as a cloud-based API or SaaS tool, charging monthly fees based on scan volume or enterprise tiers. This model targets developers and companies needing scalable, managed security for AI applications without infrastructure overhead.
Provide professional services to integrate Input Guard into existing AI systems, offering customization, training, and ongoing support. This model appeals to large organizations with complex workflows requiring tailored security solutions.
Distribute Input Guard as open-source software to build community trust, while monetizing advanced features like LLM-powered scanning, real-time threat intelligence updates, or priority support. This attracts users who start free and upgrade for enhanced capabilities.
💬 Integration Tip
Start by integrating the scan.sh script into data ingestion pipelines as a pre-processing step, using default sensitivity and JSON output for easy automation.
Scored Apr 22, 2026
AI Analysis
The skill is a defensive scanner designed to detect prompt injection in external content, not to exfiltrate user data. While it mentions optional reporting to 'MoltThreats', this is opt-in and for threat intelligence, not covert data harvesting. The primary risk is the potential for false positives causing operational disruption, not malicious intent.
Audited Apr 17, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.