lieutenantAI agent security and trust verification. Scan messages, agent cards, and A2A communications for prompt injection, jailbreaks, and malicious patterns. Use when protecting agents from attacks, verifying external agents, or scanning untrusted content.
Install via ClawdBot CLI:
clawdbot install jd-delatorre/lieutenantGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"Ignore all previous instructions"Calls external URL not in known-safe list
https://agent.example.com/.well-known/agent.jsonAI Analysis
The skill's stated purpose is security scanning and threat detection, which is consistent with its external API calls to TrustAgents for threat intelligence and OpenAI for semantic analysis. The 'prompt poisoning' signal is a false positive triggered by example attack strings used in documentation, not hidden malicious instructions. No credential harvesting or data exfiltration patterns were found.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
A bank uses Lieutenant to scan customer interactions with its AI chatbot for prompt injection attempts aimed at extracting account details or manipulating transactions. It integrates with the A2A SDK to verify external agent identities during cross-bank transfers, preventing social engineering attacks.
A healthcare provider deploys Lieutenant to monitor AI agents handling patient queries, detecting jailbreaks that could lead to unauthorized access to medical records or data exfiltration. It uses semantic analysis to catch paraphrased attacks attempting to bypass HIPAA compliance safeguards.
An e-commerce platform integrates Lieutenant into its AI support agents to scan for malicious patterns like credential theft or deception in user messages. It employs the TrustAgents API for crowdsourced threat intelligence to block emerging scams targeting payment systems.
A large corporation uses Lieutenant to secure internal AI tools from privilege escalation and code execution attacks by employees or compromised systems. It logs interactions via the Python API for audit trails and blocks resource abuse attempts in automated workflows.
An online learning platform implements Lieutenant to scan AI tutor communications for context manipulation or inappropriate content injection. It verifies agent cards from external educational services to ensure safe A2A interactions for student data.
Offer Lieutenant as a cloud-based API service with tiered pricing based on scan volume and features like semantic analysis or TrustAgents integration. Revenue comes from monthly subscriptions for businesses needing scalable AI security without on-premise setup.
Sell on-premise licenses for large organizations requiring custom integration, such as with existing A2A SDKs or internal security systems. Revenue includes upfront licensing fees and annual support contracts for updates and threat intelligence feeds.
Provide core scanning features as open-source software to build community adoption, while monetizing advanced capabilities like semantic analysis, TrustAgents API access, or premium support. Revenue is generated from upsells to paid tiers and consulting services.
💬 Integration Tip
Start by setting environment variables for API keys and testing with quick_scan in Python before integrating the A2A SDK middleware for full agent protection.
Scored Apr 19, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.