runtime-sentinelRuntime security guardian for OpenClaw agents. Use this skill whenever the user mentions security, skill safety, prompt injection, malware, suspicious behavi...
Install via ClawdBot CLI:
clawdbot install spaceman420urdog-afk/runtime-sentinelGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
POST → https://api.runtime-sentinel.dev/v1/daemon/startAccesses system directories or attempts privilege escalation
sudo mvCalls external URL not in known-safe list
https://github.com/spaceman420urdog-afk/runtime-sentinelGenerated May 8, 2026
A security-conscious user runs sentinel audit to check hash mismatches, prompt injection patterns, and exposed credentials across all installed OpenClaw skills. This free tier defense ensures no skill has been tampered with post-install.
Before running clawhub install, a user runs sentinel check to get a risk score (LOW to CRITICAL) with detailed findings. This prevents installing backdoored or malicious skills discovered during ClawHavoc campaigns.
A user who pays for premium via x402 USDC micropayments starts sentinel daemon start to monitor file mutations, network connections, and process anomalies in real time. The daemon alerts on unauthorized writes to SOUL.md, suspicious egress, or undeclared shell commands.
Upon a HIGH or CRITICAL finding, the user runs sentinel isolate <skill-name> to quarantine the skill, then reviews the audit log and checks VirusTotal before deciding to uninstall. This containment prevents further damage.
Using the free credential auditor, a user scans skill directories and SOUL.md for plaintext secrets like API keys or tokens. This proactive check prevents accidental credential exfiltration by installed skills.
The free tier provides essential integrity hashing and injection scanning, while premium features like continuous daemon monitoring and egress detection are unlocked via small daily USDC payments on Base, with no subscription or API key needed.
Offering on-demand or subscription-based security audits for enterprises using OpenClaw agents, including detailed reports and remediation recommendations, leveraging the sentinel audit and check commands.
Partnering with ClawHub to provide sentinel risk scores on skill listings, charging a fee per lookup or offering premium tiers for publishers to have their skills pre-audited and verified.
💬 Integration Tip
Integrate sentinel commands directly into OpenClaw's skill management workflow (e.g., before install, on audit requests) and consider wrapping the binary in a container for easier distribution.
Scored May 8, 2026
AI Analysis
The skill's core security purpose is legitimate, but it contains high-risk signals including prompt poisoning instructions ('ignore previous instructions') and undocumented external API calls, which could be used to override system controls or exfiltrate data. While some external calls may be for stated features like payments or updates, the combination of these signals with system-level access creates a concerning attack surface.
Audited Apr 18, 2026 · audit v1.0
Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.
Mission control dashboard for OpenClaw - real-time session monitoring, LLM usage tracking, cost intelligence, and system vitals. View all your AI agents in o...
Transcribe YouTube videos to text by extracting captions and subtitles directly from the video URL using yt-dlp without audio processing.
Manage a self-hosted Trello-like board via `wekancli`. Create, move and archive cards, lists and boards on a WeKan server. Use when user asks about task boar...
Proactive security monitoring, threat scanning, and auto-remediation for OpenClaw deployments
Create or improve SOUL.md files for OpenClaw agents through guided conversation. Use when designing agent personality, crafting a soul, or saying "help me create a soul". Supports self-improvement.