uncle-mattUncle Matt lets OpenClaw agents use approved API actions through a hardened local Broker without seeing secrets, calling arbitrary URLs, or becoming an open...
Install via ClawdBot CLI:
clawdbot install uncmatteth/uncle-mattGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://bobsturtletank.funAudited Apr 18, 2026 · audit v1.0
Generated Mar 22, 2026
A customer service AI agent needs to fetch order status and shipping information from internal APIs without exposing sensitive API keys. Uncle Matt ensures all external calls go through the Broker with mTLS authentication, preventing unauthorized access to customer databases while allowing safe data retrieval.
A financial advisory AI needs to pull real-time stock prices and market data from multiple paid APIs. Uncle Matt's action-based system allows controlled access to specific endpoints with rate limits, preventing accidental overspending on API calls while keeping subscription keys secure in the Broker.
A medical scheduling assistant requires access to patient scheduling systems and clinic calendars. Uncle Matt enforces strict allowlists for API endpoints, ensuring HIPAA compliance by preventing arbitrary data exfiltration and limiting access to only approved healthcare system interfaces.
An AI monitoring system needs to query smart home devices and industrial sensors through manufacturer APIs. Uncle Matt's Broker configuration restricts calls to specific device endpoints with request size limits, preventing denial-of-service attacks on vulnerable IoT devices while maintaining operational visibility.
A social media moderation AI needs to check user content against multiple third-party moderation services. Uncle Matt's action-based approach ensures each content check follows predefined paths with budget controls, preventing abuse of expensive moderation APIs while maintaining consistent safety checks.
Offer Uncle Matt as a managed security layer for AI agents, charging monthly per API call volume or number of protected endpoints. Provide configuration management and monitoring dashboards as premium features, with tiered pricing based on security audit requirements and compliance certifications.
Provide professional services to integrate Uncle Matt into existing AI workflows, including custom Broker action development, security audits, and compliance documentation. Offer ongoing support contracts for configuration updates and troubleshooting complex integration scenarios.
Create a marketplace where developers can share and sell pre-configured Broker actions for popular APIs (Stripe, Twilio, AWS services). Take a percentage of sales while providing validation and security certification for listed actions, reducing setup time for common integrations.
💬 Integration Tip
Start by identifying your most critical external API dependencies and create corresponding Broker actions before integrating Uncle Matt, ensuring you have fallback mechanisms for when actions need operator approval.
Scored Jul 20, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...