kefal-guardInfrastructure security monitor — detects exposed services, privilege escalation paths, and novel threats using compositional reasoning. Read-only host telem...
Install via ClawdBot CLI:
clawdbot install davidangularme/kefal-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdAccesses system directories or attempts privilege escalation
/proc/Calls external URL not in known-safe list
https://kefal.devAI Analysis
The skill references a legitimate external service (kefal.dev) for its dashboard and documentation, and explicitly states it does not auto-execute or download remote code. The mention of /etc/passwd and /proc/ is consistent with local system monitoring for security invariants, not credential harvesting. However, the external URL is not in a known-safe list, and the skill could potentially expose system state to a third-party dashboard, warranting a low-level caution.
Generated Oct 2, 2026
A solo developer spins up a fresh Ubuntu VPS to self-host their OpenClaw gateway and installs Kefal Guard the same day. As third-party skills accumulate from ClawHub, the 60-second scans flag newly exposed databases, unexpected listeners, and rogue SSH keys before they become breaches.
A seed-stage fintech startup needs evidence of continuous host monitoring for SOC 2 readiness without hiring a dedicated security engineer. Kefal's incident severity levels and plain-English remediation commands give the founding team an auditable trail of infrastructure checks on every production node.
A DevOps agency manages dozens of client servers running OpenClaw autonomously and struggles to catch configuration drift across them. The Kefal dashboard's live infrastructure graph lets one operator triage privilege-escalation paths and exposed services across all tenants from a single pane.
A small healthtech team runs OpenClaw on internal servers handling sensitive workflows and needs read-only telemetry that never touches application data. Kefal inspects only process, port, and key metadata, keeping the agent compliant with strict data-handling policies while surfacing novel outbound connections to unknown IPs.
An e-commerce operator adds Kefal after a scare involving a service accidentally bound to a public interface during a flash sale. When a new admin account or unexpected outbound connection appears, the agent raises an incident within a minute and hands over copy-paste remediation commands.
A 7-day free trial lets operators install the agent and see real incidents before paying, then tiered monthly plans priced by number of monitored agents drive conversion. Upsells center on additional hosts, longer incident retention, and team seats.
MSPs and agencies bundle Kefal Guard into their existing server-management retainers as a value-added security layer. They resell dashboard access per client environment while centralizing alerting in their own tooling.
Companies pursuing SOC 2, ISO 27001, or HIPAA readiness license Kefal for its continuous scan history, severity-graded incidents, and remediation records. The audit trail substitutes for manual evidence collection during certification.
💬 Integration Tip
Install the kefal-agent binary manually via the documented install guide, verify with --version and --status, then wire the /kefal commands to exec calls kefal-agent --status and --scan so the agent surfaces incidents proactively whenever security or new-skill topics arise.
Scored Oct 2, 2026
Audited Apr 26, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...