Connectors

OpenClaw

The reference proxy connector. DefenseClaw ships a TypeScript plugin that wires OpenClaw's fetch interceptor and before_tool_call hook directly into the gateway.

OpenClaw is the connector DefenseClaw was designed against. It ships a first-party TypeScript plugin (extensions/defenseclaw/) that routes recognized LLM provider requests and their responses through the guardrail proxy and sends OpenClaw's before_tool_call lifecycle events to the DefenseClaw gateway. Unknown request shapes that the interceptor cannot classify pass through; the connector emits egress telemetry for those passthroughs instead of claiming they were inspected.

Full OpenClaw end-to-end: prompt arrives → gateway inspects → policy decides → HITL approves → tool runs → audit row written.

Setup

defenseclaw setup openclaw --mode observe --restart
defenseclaw setup openclaw --mode action --human-approval --rule-pack default --restart

OpenClaw connector setup is supported on macOS and Linux. DefenseClaw is hook-only on native Windows and does not host the required guardrail proxy there, so Windows setup is unsupported.

setup openclaw is the dedicated OpenClaw alias. It delegates to the shared guardrail setup backend and exposes the proxy connector's common setup options; it is not a byte-for-byte copy of every setup guardrail flag. See the quick-alias reference for the alias and full guardrail setup for the complete wizard. The proxy is always in the data path: --mode observe records without policy blocking, while --mode action enforces.

What this command sets vs. leaves at defaults

The flags above explicitly set: connector, mode, optional HITL, and optional rule pack. Every other knob falls back to the values DefenseClaw ships with — schema-defined in internal/config/config.go and documented on the Defaults page.

KnobValue when omittedFlag to override
Scanner backendlocal (bundled regex packs, zero key)--scanner-mode local|remote|both
Rule packunset → built-in baseline (no overlay)--rule-pack default|strict|permissive
LLM judgeoff (regex-only triage)--judge-model <model> plus --judge-api-key-env
Detection strategyregex_judge if judge is on, else regex-only--detection-strategy regex_only|regex_judge|judge_first
HITLoff (no operator approval prompts)--human-approval plus --hilt-min-severity ...
HITL minimum severityHIGH (when --human-approval is on; stored uppercase in config)--hilt-min-severity low|medium|high|critical (case-insensitive)
Hook fail-modecurrent config; closed on a fresh install (open is retained for migrated legacy configs)defenseclaw guardrail fail-mode <open|closed> (no flag)
Proxy port4000--port <int>
Block messageempty (uses built-in copy)--block-message "<text>"
Redactionv8 bucket/profile policy (none for fresh v8)Edit observability.destinations[].routes[].selector.buckets and observability.redaction_profiles; then follow Redaction → Verify policy.
Verify after setupon--no-verify

See the full flag reference for the complete table or run defenseclaw setup guardrail --help.

Common variations — pick the recipe that fits your phase

defenseclaw setup openclaw \
  --mode observe \
  --rule-pack permissive \
  --restart

The proxy is in the data path but nothing blocks. Every collected prompt, response, and tool call lands in mandatory SQLite event history; optional v8 destinations receive their selected, redacted projections. Run this for at least a week before promoting — see Defaults → tuning by risk tolerance.

defenseclaw setup openclaw \
  --mode action \
  --human-approval \
  --hilt-min-severity high \
  --restart

HIGH findings can pause for operator approval; CRITICAL still blocks unconditionally. OpenClaw's bundled DefenseClaw plugin provides a native chat-origin approval surface, so approvals reach the agent UI directly. See the HITL page for the per-connector matrix.

export DEFENSECLAW_LLM_KEY='replace-with-your-key'

defenseclaw setup openclaw \
  --mode action \
  --human-approval \
  --hilt-min-severity high \
  --detection-strategy regex_judge \
  --judge-model anthropic/claude-sonnet-4-20250514 \
  --judge-api-key-env DEFENSECLAW_LLM_KEY \
  --restart

Adds the configured LLM judge as a second pass on regex-flagged prompts. Latency and provider cost depend on the selected judge model.

defenseclaw policy activate strict
defenseclaw setup openclaw \
  --mode action \
  --rule-pack strict \
  --restart

Block MEDIUM and above, alert on LOW, and do not offer approval for findings that have already crossed the block threshold. Pair it with the OpenShell sandbox profile and a reviewed first-party allow-list for additional containment.

Decision aids — should I turn this on?

Not sure what to pick? Run defenseclaw setup guardrail (no flags) — the interactive wizard walks you through every choice with safe defaults pre-selected and inline help. The Prompt → flag mapping table gives you the CI-shaped command for the same configuration.

Files DefenseClaw will modify

openclaw.json (plugin allow / load entries)

A hash-checked backup of openclaw.json is stored before edits; teardown restores or surgically removes only DefenseClaw-owned entries.

What the plugin does

  1. 01User OpenClaw

    prompt

  2. 02OpenClaw Plugin

    recognized LLM request

  3. 03Plugin Gateway

    proxy request + X-DC-Target-URL

  4. 04Gateway Plugin

    inspected upstream response

  5. 05Plugin OpenClaw

    response (or policy block)

  6. 06OpenClaw Plugin

    before_tool_call(name, args)

  7. 07Plugin Gateway

    POST /api/v1/inspect/tool

  8. 08Gateway Plugin

    verdict

  9. 09Plugin OpenClaw

    allow / block / pause

  10. 10OpenClaw User

    response

The bundled plugin redirects recognized LLM traffic through the guardrail proxy and calls the inspect API before tool execution. Gateway is defenseclaw-gateway.

Hook capabilities

The proxy can block inspected fetch requests, fetch responses, and tool calls. The bundled plugin provides native approval for before_tool_call, including chat-origin sessions.

Subprocess policy

sandbox — see Sandbox setup for the full openshell-sandbox workflow. The connector wires DefenseClaw into the sandbox's syscall and filesystem policy.

Disable

defenseclaw guardrail disable --yes

Restores ~/.openclaw/openclaw.json from the backup, removes the plugin entries, and stops the proxy.