Cl

ClawCare – Security scanner and runtime guard for AI agent skills

Hacker News

ClawCare – Security scanner and runtime guard for AI agent skills

Lately I've been more or less a human wrapper around my AI agents — Claude Code, OpenClaw, etc. They're incredibly productive, but they scare me regularly. The wake up moment: I had an agent run tasks involved checking my environment variables. I totally had an AWS secret sitting right in there. By the time I realized, my key had already entered the session context — meaning it was sent to the LLM provider and whatever router layers sit in between. I had to rotate that secret immediately. That was a wake-up call. These agents can run commands, read files, and access secrets without visibility to human. Third-party skills and plugins make it worse — Cisco recently found an OpenClaw skill silently exfiltrating data via curl. CrowdStrike, NCC Group published similar findings. The attack surface is real and it's everywhere. I spent my past week's nights building ClawCare. It does two things: 1. Static scanning — scans plugin/skill files for dangerous patterns (pipe-to-shell, credential access, reverse shells, data exfiltration, prompt injection) before they ever run. Works in CI. 2. Runtime guard — hooks into the agent's tool execution pipeline and blocks dangerous commands in real time. That env dump that leaked my AWS key? ClawCare blocks it before it reaches the LLM. pip install clawcare clawcare guard activate --platform {claude|openclaw} Currently supports Claude Code (PreToolUse hooks) and OpenClaw (before_tool_call plugin) for runtime guarding, plus static scanning on Claude/Codex/OpenClaw/Cursor skill and plugin formats. Include 30+ detection rules, custom rules and integration supported, support skill manifests on permission boundaries, full audit trail. Apache 2.0. Python 3.10+. GitHub: https://github.com/natechensan/ClawCare Demo: https://github.com/natechansan/ClawCare-demo

Share card

Actual performance

1points
4comments
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: agents, agent, cursor · Missing: mac, macos, model
88%88% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Strong signals: supports · Missing: reddit linkedin, podcasting, created
79%79% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
TrustMRRFits verified-revenue profile · Strong signals: scanner · Missing: mobile apps, ios, personal
50%50% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: plus, platform · Missing: intuitive, reviews, host
32%32% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
25%25% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
Hacker NewsMay not resonate with HN audience · Strong signals: ide, pipe, io · Missing: https docs, excited, just released
18%18% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
BetaListMay not resonate with beta-testers · Strong signals: real time · Missing: web3, chat, crypto
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

SClawHub
SClawHub67%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Security scanner for OpenClaw AI agent skills

Product Hunt+96Developer Tools
Glitchlog
Glitchlog19%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Security scanner

Product Hunt+1
Novingly
Novingly17%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Security scoring for AI agent skills. Score any public GitHu

Indie Hackers1ai
SafeSAI
SafeSAI66%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Website security scanner

Indie Hackerscommitment-full-time
Protego
Protego23%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Website security scanner

Product Hunt+12
Sk
SkillPreflight – score AI agent skills before installing them33%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

SkillPreflight – score AI agent skills before installing them

Hacker News1
Ai1 site security scanner
Ai1 site security scanner24%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Ai1 site security scanner

Product Hunt+8
Sk
SkillFortify, a formal verification for AI agent skills12%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

SkillFortify, a formal verification for AI agent skills

Hacker News2
YS
YScan – WordPress Security Scanner34%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

YScan – WordPress Security Scanner

Hacker News1
VulnTitan
VulnTitan63%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

WordPress security scanner.

Indie Hackerscommitment-full-time