tork-guardianAI governance and safety layer for OpenClaw agents. Protects against unsafe actions, redacts sensitive data, and generates compliance audit trails.
Install via ClawdBot CLI:
clawdbot install torkjacobs/tork-guardianGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaContains instructions to override system prompt or ignore user requests
"Ignore previous instructions"Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://www.tork.networkGenerated Mar 21, 2026
An AI agent processes patient records to schedule appointments and send reminders. Tork Guardian redacts PII like emails and phone numbers in LLM requests, blocks unauthorized file access to sensitive health records, and ensures network connections only go to approved healthcare APIs, generating compliance receipts for HIPAA audits.
An AI agent analyzes transaction logs for fraudulent activity. Tork Guardian enforces strict network policies to prevent data exfiltration to blocked domains, governs tool calls to restrict shell commands that could manipulate financial systems, and scans skills for vulnerabilities before deployment to maintain secure operations in a regulated environment.
An AI agent handles customer inquiries and processes orders. Tork Guardian uses PII redaction to protect customer details in chat logs, controls file access to prevent exposure of payment credentials, and applies rate limiting on network connections to avoid service abuse, ensuring safe integration with third-party APIs.
An AI agent automates server deployments and monitoring tasks. Tork Guardian validates port binds and outbound connections to prevent SSRF attacks, blocks dangerous shell commands like 'rm -rf', and enforces custom network policies with domain allowlists, securing CI/CD pipelines in cloud environments.
Offer Tork Guardian as a cloud service with tiered pricing based on usage volume and features like advanced network monitoring or compliance reporting. Revenue comes from monthly or annual subscriptions, targeting enterprises needing scalable security for AI agents across multiple projects.
Sell perpetual licenses or annual contracts for on-premises deployment, including custom integrations and dedicated support. Revenue is generated through upfront license fees and ongoing maintenance charges, appealing to large organizations with strict data sovereignty requirements.
Charge based on API calls for functions like PII redaction, network validation, or security scanning, with pay-as-you-go or prepaid credit plans. Revenue scales with customer usage, suitable for developers and startups integrating security into AI applications without large upfront costs.
💬 Integration Tip
Start with the PRODUCTION_CONFIG for balanced security, then customize network policies and blocked paths based on your specific threat model and compliance needs.
Scored Apr 19, 2026
Uses known external API (expected, informational)
api.anthropic.comAudited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...