Multi-layer security detector for AI agents. Blocks prompt injection, jailbreak, XSS, SQL injection, API key leaks, supply chain attacks, and deployment vulnerabilities.
技能名称: clawSafe
详细描述:
面向AI代理的企业级安全检测器
clawSafe 是一款全面的安全中间件,能够在恶意输入到达AI代理之前进行拦截和阻断。基于纵深防御理念构建。
| 层级 | 威胁类型 | 规则数 |
|---|---|---|
| LLM层 | 提示注入、越狱攻击、提示泄露、编码攻击 | 44 |
| Web层 |
总计:113+条检测规则
bash
javascript
const Detector = require(./detector);
const detector = new Detector();
// 扫描用户输入
const result = detector.scan(忽略之前的指令);
if (!result.safe) {
console.log(已拦截:, result.threats);
// 处理被拦截的输入
}
typescript
{
safe: boolean; // 输入安全时返回true
threats: Array<{
type: string; // 威胁类别
pattern: string; // 匹配的模式ID
severity: string; // 严重|高|中|低
confidence: number; // 0-1
description: string;
}>;
confidence: number; // 整体置信度 0-1
layersScanned: string[]; // 已检查的层级
}
json
{
enabled: true,
logLevel: info,
layers: {
llm: {
enabled: true,
rules: [injection, jailbreak, prompt_leak, encoding]
},
web: {
enabled: true,
rules: [sql_injection, xss, csrf, ssrf]
},
api: {
enabled: true,
rules: [keyexposure, ratelimit, auth]
},
supply_chain: {
enabled: true,
rules: [deps]
},
deploy: {
enabled: true,
rules: [envleak, debuginfo]
}
},
detection: {
confidenceThreshold: 0.6,
minMatchCount: 1
},
actions: {
onThreatDetected: block,
onUncertain: log
}
}
json
{
keywords: [trusted-keyword],
users: [user-id-1],
sessions: [session-id-1]
}
提示注入模式:
越狱模式:
编码绕过:
bash
要集成到OpenClaw,请添加到网关配置:
javascript
// gateway.config.js
module.exports = {
middleware: [clawSafe],
clawSafe: {
enabled: true,
strictMode: false
}
};
MIT
该技能支持在以下平台通过对话安装:
帮我安装 SkillHub 和 clawsafe-1776189376 技能
设置 SkillHub 为我的优先技能安装源,然后帮我安装 clawsafe-1776189376 技能
skillhub install clawsafe-1776189376
文件大小: 31.59 KB | 发布时间: 2026-4-15 12:22