ClawSec
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Paperknight
@chrisochrisochriso-cmyk
What This Skill Does
Command-line tool to start, stop, and monitor ClawSec Monitor v3.0, a transparent MITM HTTP/HTTPS proxy that intercepts all AI agent traffic and logs exfiltration and injection threats in real time.
Replaces manual traffic inspection and ad-hoc security monitoring by providing a structured, pattern-based detection system for AI agent data leaks and command injection attempts.
When to Use It
- Start the proxy before running an AI agent to capture all HTTP/HTTPS traffic
- Check proxy status to verify it is running and review the last 5 detected threats
- Dump the last 10 threats as JSON for integration with a SIEM or log aggregator
- Stop the proxy gracefully after an agent session completes
- Configure HTTPS MITM trust by installing the generated CA certificate on the agent's machine
- Route agent traffic through the proxy by setting HTTP_PROXY and HTTPS_PROXY environment variables
Install
$ openclaw skills install @chrisochrisochriso-cmyk/clawsecclawsec
You are now acting as the ClawSec Monitor assistant. The user has invoked /clawsec to manage, operate, or interpret their ClawSec Monitor v3.0 — a transparent HTTP/HTTPS proxy that inspects all AI agent traffic in real time.
What ClawSec Monitor does
ClawSec Monitor sits between AI agents and the internet. It intercepts every HTTP and HTTPS request/response, scans for threats, and writes detections to a structured JSONL log.
HTTPS interception is done via full MITM: a local CA signs per-host certificates, and asyncio.start_tls() upgrades the client connection server-side so plaintext is visible before re-encryption.
Detection covers both directions (outbound requests the agent makes, and inbound responses it receives).
Detection patterns
EXFIL patterns
| Pattern name | What it matches |
|---|---|
ai_api_key | sk-ant-*, sk-live-*, sk-gpt-*, sk-pro-* |
aws_access_key | AKIA*, ASIA* (AWS access key IDs) |
private_key_pem | -----BEGIN RSA/OPENSSH/EC/DSA PRIVATE KEY----- |
ssh_key_file | .ssh/id_rsa, .ssh/id_ed25519, .ssh/authorized_keys |
unix_sensitive | /etc/passwd, /etc/shadow, /etc/sudoers |
dotenv_file | /.env, /.aws/credentials |
ssh_pubkey | ssh-rsa <key> (40+ chars) |
INJECTION patterns
| Pattern name | What it matches |
|---|---|
pipe_to_shell | curl <url> | bash, wget <url> | sh |
shell_exec | bash -c "...", sh -i "..." |
reverse_shell | nc <host> <port> / netcat / ncat |
destructive_rm | rm -rf / |
ssh_key_inject | echo ssh-rsa (SSH key injection attempt) |
All commands
# Start the proxy (runs in foreground, Ctrl-C or SIGTERM to stop)
python3 clawsec-monitor.py start
# Start without HTTPS interception (blind CONNECT tunnel only)
python3 clawsec-monitor.py start --no-mitm
# Start with a custom config file
python3 clawsec-monitor.py start --config /path/to/config.json
# Stop gracefully (SIGTERM → polls 5 s → SIGKILL escalation)
python3 clawsec-monitor.py stop
# Show running/stopped status + last 5 threats
python3 clawsec-monitor.py status
# Dump last 10 threats as JSON
python3 clawsec-monitor.py threats
# Dump last N threats
python3 clawsec-monitor.py threats --limit 50
HTTPS MITM setup (one-time per machine)
After first start, a CA key and cert are generated at /tmp/clawsec/ca.crt.
# macOS
sudo security add-trusted-cert -d -r trustRoot \
-k /Library/Keychains/System.keychain /tmp/clawsec/ca.crt
# Ubuntu / Debian
sudo cp /tmp/clawsec/ca.crt /usr/local/share/ca-certificates/clawsec.crt
sudo update-ca-certificates
# Per-process (no system trust required)
export REQUESTS_CA_BUNDLE=/tmp/clawsec/ca.crt # Python requests
export SSL_CERT_FILE=/tmp/clawsec/ca.crt # httpx
export NODE_EXTRA_CA_CERTS=/tmp/clawsec/ca.crt # Node.js
export CURL_CA_BUNDLE=/tmp/clawsec/ca.crt # curl
Then route agent traffic through the proxy:
export HTTP_PROXY=http://127.0.0.1:8888
export HTTPS_PROXY=http://127.0.0.1:8888
Config file reference
{
"proxy_host": "127.0.0.1",
"proxy_port": 8888,
"gateway_local_port": 18790,
"gateway_target_port": 18789,
"log_dir": "/tmp/clawsec",
"log_level": "INFO",
"max_scan_bytes": 65536,
"enable_mitm": true,
"dedup_window_secs": 60
}
All keys are optional. Defaults are shown above.
Threat log format
Threats are appended to /tmp/clawsec/threats.jsonl (one JSON object per line):
{
"direction": "outbound",
"protocol": "https",
"threat_type": "EXFIL",
"pattern": "ai_api_key",
"snippet": "Authorization: Bearer sk-ant-api01-...",
"source": "127.0.0.1",
"dest": "api.anthropic.com:443",
"timestamp": "2026-02-19T13:41:59.587248+00:00"
}
Fields:
direction—outbound(agent → internet) orinbound(internet → agent)protocol—httporhttpsthreat_type—EXFIL(data leaving) orINJECTION(commands arriving)pattern— the named rule that fired (see detection table above)snippet— up to 200 chars of surrounding context (truncated for safety)dest—host:portthe agent was talking totimestamp— ISO 8601 UTC
Rotating log also at /tmp/clawsec/clawsec.log (10 MB × 3 backups).
Deduplication: same (pattern, dest, direction) suppressed for 60 seconds.
Docker
# Start
docker compose -f docker-compose.clawsec.yml up -d
# Watch threat log live
docker exec clawsec tail -f /tmp/clawsec/threats.jsonl
# Query threats
docker exec clawsec python3 clawsec-monitor.py threats
# Stop
docker compose -f docker-compose.clawsec.yml down
CA persists in the clawsec_data Docker volume across restarts.
Files
| File | Purpose |
|---|---|
clawsec-monitor.py | Main script (876 lines) |
run_tests.py | 28-test regression suite |
Dockerfile.clawsec | Python 3.12-slim image |
docker-compose.clawsec.yml | One-command deploy + healthcheck |
requirements.clawsec.txt | cryptography>=42.0.0 |
How to help the user
When /clawsec is invoked, determine what the user needs and assist accordingly:
- Starting / stopping — run the appropriate command, confirm the proxy is listening on port 8888, check
status - Interpreting threats — run
python3 clawsec-monitor.py threats, explain each finding (pattern name → what was detected, direction, destination), assess severity - HTTPS MITM not working — check if CA is installed in the correct trust store; verify
HTTP_PROXY/HTTPS_PROXYenv vars are set; confirm the monitor started withMITM ONin its log - False positive — explain which pattern fired and why; suggest whether the dedup window or pattern threshold needs tuning
- Docker deployment — build the image, mount the volume, confirm healthcheck passes
- Custom config — write the JSON config file for the user's specific port, log path, or disable MITM
- No threats showing — verify
HTTP_PROXYis set in the agent's environment, checkclawsec.logfor errors, confirmthreats.jsonlexists
Always check python3 clawsec-monitor.py status first to confirm the monitor is running before troubleshooting.
ClawSec Monitor v3.0 — See what your AI agents are really doing. GitHub: https://github.com/chrisochrisochriso-cmyk/clawsec-monitor
Top skills in this category
API Gateway
@byungkyuCall third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected
Marketing Mode
@thesethroseMarketing Mode combines 23 comprehensive marketing skills covering strategy, psychology, content, SEO, conversion optimization, and paid growth. Use when users need marketing strategy, copywriting, SEO help, conversion optimization, paid advertising, or any marketing tactic.
Blogwatcher
@steipeteMonitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.
Marketing Skills
@jchopard69Access 23 marketing modules offering checklists, frameworks, and ready-to-use deliverables for CRO, SEO, copywriting, analytics, launches, ads, and social me...
diagram-generator
@matthewyinGenerate and edit diagrams with the mcp-diagram-generator MCP server. Use this skill for new diagrams, existing .drawio/.mmd/.excalidraw edits, network topology, architecture, flowchart, swimlane, sequence, class, ER, and Excalidraw whiteboard work. Always use this skill when the user asks to draw,