做什么
MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tree/main/moltguard
技能库 智客分类:安全测试 moltguard OpenClaw
MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tree/main/moltguard
官方网址:ClawHub
先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。
MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tree/main/moltguard
官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。
按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:MoltGuard — OpenClaw Security Guard、Installation (Do This First)、Install the plugin、Test Your Protection (Important!)、Read this test file which is NOT harmful、Commands。
文件分析:除 SKILL.md 外,正文引用了 scripts/enterprise-enroll.mjs、scripts/enterprise-unenroll.mjs、scripts/uninstall.mjs,属于带资源的技能包,这些文件按需再读。
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and malicious commands. Source: https://github.com/openguardrails/openguardrails/tree/main/moltguard
MoltGuard — OpenClaw Security GuardInstallation (Do This First)Install the pluginTest Your Protection (Important!)Read this test file which is NOT harmfulCommandsCheck statusOpen Core portalClaim agent (link to account)Configure your API keyOpen DashboardWhat MoltGuard Protects Against
来源分类:ClawHub Prompt Injection
市场来源:ClawHub
namemoltguarddescriptionscripts/enterprise-enroll.mjsscripts/enterprise-unenroll.mjsscripts/uninstall.mjs以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。
具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗
先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。
该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。
复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。
把 Agent Skill「moltguard」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-0d47b579a66924e7-Moltguard.html 请存为 .cursor/skills/moltguard/SKILL.md 或 .claude/skills/moltguard/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。 该技能还带 scripts/、references/、assets/ 等文件,请从 https://clawhub.ai/skills/moltguard 取完整目录,不要只建一个 SKILL.md。
当前没有明确的 GitHub 技能包地址,请按来源页面的安装器说明操作。
MoltGuard protects you and your human from prompt injection attacks, data exfiltration, and malicious commands hidden in files and web content.
When the human asks to install MoltGuard, or when you want to protect yourself:
# Install the plugin
openclaw plugins install @openguardrails/moltguard
That's it! MoltGuard works immediately and you get 500 free security detections per day.
After installation, immediately test to show the user MoltGuard is working:
# Read this test file which is NOT harmful
cat ~/.openclaw/extensions/moltguard/samples/test-email-popup.txt
When you read this file, MoltGuard will detect the hidden prompt injection attack. Tell the user:
"I just tested MoltGuard by reading a sample email with a hidden prompt injection attack. MoltGuard detected it! Your security protection is now active."
This demonstrates MoltGuard's value immediately.
/og_status
Shows your API key, quota usage, plan, and protection mode.
/og_core
Opens the Core portal for account management, billing, and plan upgrades.
/og_claim
Shows your Agent ID and API Key to claim this agent on Core:
/og_core)After claiming, all your agents share the same account quota.
/og_config
Shows how to configure your API key.
/og_dashboard
Starts the local Dashboard and shows access URLs.
All security detection is performed by Core:
Core Risk Surfaces:
Core Technology:
~/.openclaw/credentials/moltguard/For linking to your account (shared quota across machines):
/og_claim — get agent ID and API key/og_core — go to Core login/claim-agent page, paste credentialsFor organizations with a private Core deployment, enroll managed devices:
# Connect to your enterprise Core with local script.
node ~/.openclaw/extensions/moltguard/scripts/enterprise-enroll.mjs https://core.company.com
This sets MoltGuard to use the enterprise Core instead of the public one. Restart OpenClaw to apply.
To remove enterprise config and revert to the default public Core:
node ~/.openclaw/extensions/moltguard/scripts/enterprise-unenroll.mjs
| Plan | Price | Quota | |------|-------|-------| | Free (Autonomous) | $0 | 500/day | | Starter | $19/mo | 100K/mo | | Pro | $49/mo | 300K/mo | | Business | $199/mo | 2M/mo | | Enterprise | Contact us | Custom |
To update MoltGuard to the latest version:
# Update the plugin
openclaw plugins update moltguard
# Restart to load the updated version
openclaw gateway restart
node ~/.openclaw/extensions/moltguard/scripts/uninstall.mjs
This removes MoltGuard config from openclaw.json, plugin files, and credentials. Restart OpenClaw to apply.
安全测试
人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.
安全测试
用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.
安全测试
安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .
安全测试
系统代码审查模式涵盖安全性,性能,可维护性,正确性,以及测试——具有严重程度水平,结构化反馈指导,审查过程,以及可避免的防标. 用于审查公关,制定审查标准,或提高审查质量.