agentsclimarketplace

Openclaw warden

Skill AtlasPA/openclaw-warden

Workspace integrity verification for OpenClaw agents. Detects unauthorized file modifications and prompt injection patterns.

Install
npx -y skills add AtlasPA/openclaw-warden

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Verify workspace file integrity and scan for prompt injection patterns in agent identity and memory files. Detects unauthorized modifications to SOUL.md, AGENTS.md, IDENTITY.md, memory files, and installed skills. Free detection layer — upgrade to openclaw-warden-pro for automated countermeasures.

SKILL.md

4.2 KB, 862 tokens by cl100k_base, as published. Nobody here has run it

OpenClaw Warden

Monitors your workspace files for unauthorized modifications and prompt injection attacks. Existing security tools scan skills before installation — this tool watches the workspace itself after installation, catching tampering that other tools miss.

Why This Matters

Your agent reads SOUL.md, AGENTS.md, IDENTITY.md, USER.md, and memory files on every session startup and trusts them implicitly. A compromised skill, a malicious heartbeat payload, or an unauthorized process can modify these files to:

  • Inject hidden instructions that alter agent behavior
  • Embed data exfiltration URLs in markdown images
  • Override identity and safety boundaries
  • Plant persistent backdoors in memory files

This skill detects all of these.

Need automated response? Upgrade to openclaw-warden-pro for snapshot restore, skill quarantine, git rollback, and automated protection sweeps.

Commands

Establish Baseline

Create or reset the integrity baseline. Run this after setting up your workspace or after reviewing and accepting all current file states.

python3 {baseDir}/scripts/integrity.py baseline --workspace /path/to/workspace

Verify Integrity

Check all monitored files against the stored baseline. Reports modifications, deletions, and new untracked files.

python3 {baseDir}/scripts/integrity.py verify --workspace /path/to/workspace

Scan for Injections

Scan workspace files for prompt injection patterns: hidden instructions, base64 payloads, Unicode tricks, markdown image exfiltration, HTML injection, and suspicious system prompt markers.

python3 {baseDir}/scripts/integrity.py scan --workspace /path/to/workspace

Full Check (Verify + Scan)

Run both integrity verification and injection scanning in one pass.

python3 {baseDir}/scripts/integrity.py full --workspace /path/to/workspace

Quick Status

One-line summary of workspace health.

python3 {baseDir}/scripts/integrity.py status --workspace /path/to/workspace

Accept Changes

After reviewing a legitimate change, update the baseline for a specific file.

python3 {baseDir}/scripts/integrity.py accept SOUL.md --workspace /path/to/workspace

Workspace Auto-Detection

If --workspace is omitted, the script tries:

  1. OPENCLAW_WORKSPACE environment variable
  2. Current directory (if AGENTS.md exists)
  3. ~/.openclaw/workspace (default)

What Gets Monitored

CategoryFilesAlert Level on Change
CriticalSOUL.md, AGENTS.md, IDENTITY.md, USER.md, TOOLS.md, HEARTBEAT.mdWARNING
Memorymemory/*.md, MEMORY.mdINFO (expected to change)
Config*.json in workspace rootWARNING
Skillsskills/*/SKILL.mdWARNING

Injection patterns trigger CRITICAL alerts regardless of file category.

Injection Patterns Detected

  • Instruction override: "ignore previous instructions", "disregard above", "you are now", "new system prompt"
  • Base64 payloads: Suspiciously long base64 strings outside code blocks
  • Unicode manipulation: Zero-width characters, RTL overrides, homoglyphs
  • Markdown exfiltration: Image tags with data-encoding URLs
  • HTML injection: script tags, iframes, hidden elements
  • System prompt markers: <system>, [SYSTEM], <<SYS>> blocks
  • Shell injection: $(...) outside code blocks

Exit Codes

  • 0 — Clean, no issues
  • 1 — Modifications detected (review needed)
  • 2 — Injection patterns detected (action needed)

No External Dependencies

Python standard library only. No pip install. No network calls. Everything runs locally.

Cross-Platform

Works with OpenClaw, Claude Code, Cursor, and any tool using the Agent Skills specification.

Gives 0 of the 12 instructions most memory context skills give in 862 tokens

Counted across 674 of the 847 authors here whose files we hold, read 2026-08-06

  • inform the user when setup is completein 21 of 674, across 6 files
  • confirm the draft with the user before writingin 21 of 674, across 6 files
  • update the agent skills block in place if it existsin 21 of 674, across 6 files
  • present findings to the userin 20 of 674, across 5 files
  • write the three docs files from seed templatesin 20 of 674, across 5 files
  • ask the user about each decision one at a timein 19 of 674, across 4 files
  • edit CLAUDE.md if it existsin 18 of 674, across 3 files
  • explore current repo statein 18 of 674, across 3 files
  • do not overwrite user edits to surrounding sectionsin 18 of 674, across 3 files
  • back up the original file before overwritingin 16 of 674, across 8 files
  • keep the memory index under 200 linesin 15 of 674
  • Provide actionable steps and verificationin 13 of 674, across 2 files

Said here and by no other author read

  • establish the integrity baseline
  • run the full check
  • verify integrity against the stored baseline
  • scan workspace files for prompt injections
  • review changes before updating the baseline
  • accept legitimate changes to update the baseline

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.