Token导航 LogoToken导航TokenDH.com
效率敏感数据clawhub未标认证来源可访问clear审计提醒

agentguardagentguard 效率

Agent Skill

agentguard 用于辅助安全审计、权限检查和凭据风险排查,适合在 OpenClaw 中需要复核安全边界、认证流程或敏感配置时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

115,260

周安装

4,851

GitHub Stars

3

下载量

40,360
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:agentguard(agentguard 效率)
来源仓库:https://github.com/manas-io-ai/agentguard
安装命令:
openclaw skills install agentguard
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install agentguard

简介

监控代理文件访问、API 调用和通信,以检测可疑行为、记录事件并生成可操作的安全报告。

SKILL.md

AgentGuard - Security Monitoring Skill

Version: 1.0.0 Author: Manas AI Category: Security & Monitoring

Overview

AgentGuard is a comprehensive security monitoring skill that watches over agent operations, detecting suspicious behavior, logging communications, and providing actionable security reports.


Capabilities

1. File Access Monitoring

Track all file read/write operations with pattern analysis.

Trigger: Continuous background monitoring Command: agentguard monitor files [--watch-dir <path>]

What it detects:

  • Unusual file access patterns (bulk reads, sensitive directories)
  • Access to credential files (.env, .secrets, keys)
  • Unexpected write operations to system directories
  • File exfiltration attempts (large reads followed by network calls)

2. API Call Detection

Monitor outbound API calls for suspicious activity.

Command: agentguard monitor api

What it detects:

  • Calls to unknown/untrusted endpoints
  • Unusual API call frequency (rate anomalies)
  • Sensitive data in request payloads
  • Authentication token exposure
  • Calls to known malicious domains

3. Communication Logging

Log all external communications for audit trails.

Command: agentguard log comms [--output <path>]

Logs include:

  • HTTP/HTTPS requests (sanitized)
  • WebSocket connections
  • Email sends
  • Message platform outputs (Telegram, Discord, etc.)
  • Timestamp, destination, payload hash

4. Anomaly Detection

ML-lite pattern analysis for behavioral anomalies.

Command: agentguard detect anomalies [--sensitivity <low|medium|high>]

Detection methods:

  • Baseline deviation (learns normal patterns)
  • Time-of-day anomalies
  • Sequence analysis (unusual operation chains)
  • Volume spikes
  • New destination detection

5. Security Reports

Generate comprehensive daily security reports.

Command: agentguard report [--period <daily|weekly|monthly>]

Report includes:

  • Activity summary
  • Alert breakdown by severity
  • Top accessed resources
  • Communication destinations
  • Anomaly timeline
  • Recommendations

Configuration

Config File: config/agentguard.yaml

monitoring:
  enabled: true
  file_watch_dirs:
    - ~/clawd
    - ~/.clawdbot
  exclude_patterns:
    - "*.log"
    - "node_modules/**"
    - ".git/**"

alerts:
  sensitivity: medium  # low, medium, high
  channels:
    - telegram
  alert_on:
    - credential_access
    - bulk_file_read
    - unknown_api_endpoint
    - data_exfiltration
  cooldown_minutes: 15

api_monitoring:
  trusted_domains:
    - api.anthropic.com
    - api.openai.com
    - api.telegram.org
    - api.elevenlabs.io
  block_on_suspicious: false  # true = prevent call, false = alert only

logging:
  retention_days: 30
  log_dir: ~/.agentguard/logs
  hash_sensitive_data: true

reporting:
  auto_daily_report: true
  report_time: "09:00"
  report_channel: telegram

Usage Examples

Start Full Monitoring

agentguard start

Enables all monitoring features with default config.

Check Current Security Status

agentguard status

Returns current threat level, active monitors, recent alerts.

Investigate Specific Activity

agentguard investigate --timerange "last 2 hours" --type file_access

Generate Immediate Report

agentguard report --now

Review Alert History

agentguard alerts --last 24h --severity high

Whitelist a Domain

agentguard trust add api.newservice.com --reason "Required for X integration"

Alert Severity Levels

LevelColorMeaningExample
INFO🔵Normal logged activityFile read in workspace
LOW🟢Minor deviationSlightly elevated API calls
MEDIUM🟡Notable anomalyAccess to .env file
HIGH🟠Potential threatBulk credential access
CRITICAL🔴Immediate action neededData exfiltration pattern

Integration Points

With Clawdbot

  • Receives file/API operation hooks
  • Sends alerts via configured channels
  • Integrates with heartbeat for periodic checks

With Other Skills

  • Shares threat data with other security skills
  • Can block operations (if configured)
  • Provides audit logs for compliance skills

Data Storage

~/.agentguard/
├── logs/
│   ├── file_access/
│   ├── api_calls/
│   └── communications/
├── baselines/
│   └── behavior_model.json
├── alerts/
│   └── YYYY-MM-DD.json
└── reports/
    └── YYYY-MM-DD_report.md

Privacy & Security

  • No external data transmission - All processing is local
  • Sensitive data hashing - Credentials are never logged in plain text
  • Configurable retention - Auto-delete old logs
  • Encrypted storage - Optional AES encryption for logs

Troubleshooting

High false positive rate

→ Increase baseline learning period or reduce sensitivity

Missing file events

→ Check file_watch_dirs config covers target directories

Reports not generating

→ Verify report_time format and timezone settings


Execution Scripts

ScriptPurpose
execution/monitor.pyCore monitoring daemon
execution/detector.pyAnomaly detection engine
execution/logger.pyStructured logging handler
execution/alerter.pyAlert dispatch system
execution/reporter.pyReport generation

Author Notes

AgentGuard is designed with defense-in-depth principles. It assumes agents can be compromised or manipulated, and provides visibility into their operations.

For maximum security, run AgentGuard in a separate process with limited write access to prevent a compromised agent from disabling monitoring.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

83.7%
按下载量换算33,781

安全审计

VirusTotal

通过

ClawScan

可疑

Static analysis

未展示

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills