
ClawSecure
ClawSecure scans AI agent skills, MCP servers and CLI tools for malicious code and prompt injection before you install them, then watches your environment at runtime through Claw, its built-in AI CISO.
What is ClawSecure?
ClawSecure is a security platform for AI agents built around a simple split: check a component before it runs, then keep watching it afterwards. It describes itself as the integrity layer for agent skills, MCP servers and CLI tools, and it aims squarely at people who run agents without a security team, from individuals and prosumers to small development teams and SMBs.
The free entry point is a scanner. You paste a GitHub link, a ClawHub URL or a skill name, or upload a zip of up to 10 MB, and a 3-Layer Audit Protocol returns a public Security Audit Report in about thirty seconds. The first layer is a proprietary behavioural engine carrying more than fifty-five threat patterns, covering malicious code, command-and-control callbacks, data exfiltration, prompt injection, credential harvesting and ReDoS, with context-aware logic meant to separate real threats from ordinary agent capabilities. The second combines static pattern matching with behavioural dataflow analysis and taint tracking across tool-calling chains, targeting the convergence of data access, untrusted content and tool execution. The third walks the whole npm dependency tree against CVE databases and flags compromised or unpinned packages. Every report maps its findings onto the ten OWASP ASI categories, from agent goal hijacking to rogue agents.
Four more layers sit around that scanner. Claw, presented as the first AI CISO, configures installs and blocks prompt injection, social engineering and credential theft in real time, and answers from a dashboard, from Slack, Telegram, WhatsApp or WeChat, and from an MCP server wired into Claude Code, Cursor, Windsurf or Goose. A daemon installed with one npm command inventories the environment, maps MCP and CLI permissions and audits configurations. Watchtower compares SHA-256 hashes around the clock and re-scans a skill whose code changes after install. A Security Clearance API lets platforms verify integrity programmatically.
The vendor's own audits carry the pitch: 2,890 or more skills analysed, 9,515 threats detected, 41% of popular tools flagged with material risk and 22.9% rewriting themselves after installation. Two caveats matter. The runtime tiers are not live yet, sold instead as a waitlist with locked founding-member pricing, and the terms state that a scan is an informational assessment, never a certification.
What it does
- Scan an agent skill, an MCP server or a CLI tool before installing it
- Read a public Security Audit Report with a score, findings by severity and fix recommendations
- Map what every agent component can reach: Gmail, GitHub, Slack, the local filesystem
- Catch exposed API keys and misconfigured sandboxes across an agent environment
- Detect silent code changes after installation and trigger an automatic re-scan
- Watch agent behaviour at runtime and raise an alert on anomalous tool calls
- Verify an agent's current integrity status programmatically through the Clearance API
When to use ClawSecure / When not to
A quick filter to help you decide if ClawSecure is the right fit.
When to use ClawSecure
- Non-technical users and prosumers who install agent skills without any security team behind them
- Small development teams and SMBs running AI agents that hold full access to a working machine
- Developers who want a GitHub repository or a ClawHub skill checked before it touches their environment
- Platform and marketplace builders who need to verify an agent's integrity programmatically through an API
- Anyone worried about code drift, where a skill rewrites itself in the weeks after installation
When not to use ClawSecure
- Teams looking to harden a local OpenClaw gateway, file permissions or credential storage, which the vendor openly leaves to other tools
- Organisations needing a general-purpose antivirus or an enterprise endpoint detection suite
- Buyers who require a formal security certification, since the terms state that a scan is never one
- Anyone who needs runtime monitoring today, as the paid tiers are still a waitlist rather than a live service
- Regulated European organisations expecting a data processing agreement and a documented GDPR posture
How to use ClawSecure
A typical end-to-end flow, from setup to results.
- Open the scanner on the ClawSecure home page, in the section dedicated to scanning
- Paste a GitHub link, a ClawHub URL or a skill name, or drop a zip archive of 10 MB or less
- Start the scan without creating an account and without entering a card
- Wait about thirty seconds for the 3-Layer Audit Protocol to finish
- Enter an email address to unlock the full Security Audit Report and its findings by severity
- Check the OWASP ASI mapping and the fix recommendations before installing anything
- Browse the public registry to compare a component against the thousands already audited
- Install the daemon with a single global npm command when you want continuous coverage
- Sign in to the browser dashboard with GitHub or Google to read your environment risk score
- Query Claw from the terminal or from your messaging app whenever you need a second opinion
Pros & Cons
Pros
- The scanner is genuinely free, needs no account or card, and returns a verdict in about thirty seconds
- Every report is public and shareable, which makes the method open to third-party scrutiny
- Watchtower keeps checking after installation, where most scanners stop at a single point in time
- Coverage is claimed across all ten OWASP ASI categories, a published and peer-reviewed framework
- The entry price sits far below the enterprise tools the vendor quotes at 50,000 dollars a year and up
- Security hygiene is documented: published disclosure policy with safe harbour, security.txt, external testing
- API keys, credentials and source code are stated never to leave the user's machine
Cons
- The paid product is not shipped yet: Shield, Sentinel and Fortress are a waitlist, not a live service
- No GDPR mention at all, no data processing agreement, no named subprocessor list, United States governing law
- The compliance badges are self-attested, and the SOC 2 and ISO 27001 claims belong to the providers, not to ClawSecure
- Scan data is retained indefinitely and published for open-source components, with no documented removal path
- The company is very young, its domain registered in February 2026, with no about page and no team presented
- The full scan report is gated behind an email address, even though the scan itself is not
- The headline threat figures come from the vendor's own audits, with no independent verification
Pricing & Plans
ClawSecure offers a permanent free plan covering unlimited scanning, essential AI CISO protection and Watchtower monitoring, described by the vendor as free forever. The cheapest paid entry point is the Shield tier, listed at 29.00 USD per month at standard rate and offered at 9.99 USD per month under a Founding Member rate locked at signup. All paid tiers are billed monthly, without contract, and carry a thirty-day money-back guarantee. Prospective subscribers should note that the paid tiers are not yet commercially available: joining the waitlist reserves a rate rather than activating a service.
- 3-Layer Audit Protocol with 55+ threat patterns
- full OWASP ASI Top 10 coverage
- a public Security Audit Report for every scan
- essential AI CISO defence against prompt injection and credential theft
- and Watchtower community monitoring
- everything in Free
- one-command install
- AI-powered runtime monitoring
- advanced AI CISO with environment monitoring
- MCP and CLI permission mapping
- detection of exposed API keys and misconfigured sandboxes
- browser dashboard with GitHub or Google SSO
- weekly digest by email and Telegram
- everything in Shield
- advanced AI CISO with behavioural analysis
- visibility on which tools agents call and which data they touch
- anomaly detection
- real-time alerts
- full tool call history and behavioural trends
- community intelligence and a priority analysis queue
- everything in Sentinel
- advanced AI CISO with OS-level deep monitoring
- process monitoring and system-call interception
- network traffic analysis
- and full-stack visibility down to operating system events
Data, GDPR & hosting
A consolidated view of how ClawSecure handles your data.
GDPR overview
There is no GDPR mention anywhere on the site. The word does not appear on the privacy policy, the terms, the trust centre or any other published page, and no equivalent European wording replaces it. No data processing agreement is published or offered, no subprocessor list is named beyond a reference to Google Analytics, and no Article 27 representative is designated. Both the privacy policy and the terms state that they are governed by the laws of the United States of America. The rights section is limited to removing an email address on request, and the age threshold quoted is thirteen, which follows the American children's privacy standard rather than a European one. A user in the European Union should therefore treat the GDPR position as undocumented.
Who owns the data?
ClawSecure keeps ownership of its scanning technology, its reports and the "ClawSecure Verified" designation. Users keep what stays on their machine: the terms and the privacy policy both state that API keys, credentials and source code never leave the device, the daemon transmitting only component metadata, file hashes and configuration summaries. Scan results are a different matter. For publicly available open-source skills they are treated as public information, stored in the vendor's database and reachable through shareable report URLs that carry the agent name, its creator, the score and the findings. Email addresses are collected only when a visitor submits one. ClawSecure states that it does not sell, rent or trade user data.
Reuse rights
Reports are meant to circulate: the terms say scan results may be shared publicly through report URLs, so a user can pass on a report without asking permission, and third parties can read one from its link. What cannot be reused is the platform itself, its scanning technology and the "ClawSecure Verified" badge, which remain proprietary. On its own side, ClawSecure reuses scan data to publish public security reports, to maintain its Verified Agent Registry and to improve its scanning capabilities, and it reserves the right to publish aggregated, anonymised statistics in blog posts and marketing material. Once a public open-source skill has been scanned, its record stays in the public registry and the site does not offer a way to withdraw it.
Data retention & training
Hosting summary
ClawSecure does not name a hosting country or region anywhere on its site, so the jurisdiction where scan data physically sits is undocumented. The privacy policy describes its providers by category rather than by name: a cloud database and authentication provider, a cloud application hosting provider, and a transactional email delivery service, with Google Analytics named separately for site analytics. The trust centre adds that HTTPS is enforced on all endpoints through a managed CDN and DNS provider certified SOC 2 and ISO 27001, and that scan data is stored with a SOC 2 certified managed database provider using AES-256 encryption at rest, with row-level access controls. Those certifications belong to the suppliers, not to ClawSecure. At the time of collection the domain resolved to an anycast Cloudflare address, which indicates the edge network rather than the storage location. The counterweight to this opacity is the local boundary the vendor commits to: API keys, credentials and source code are stated never to leave the user's own machine.
Things to keep in mind
Risks and trade-offs to weigh before adopting ClawSecure.
- Paying today buys a reserved rate, not an active service: the three paid tiers have not launched
- Scan results for open-source components are published and kept indefinitely, with no documented removal route
- A clean score is not a guarantee: the terms state that scans are informational assessments, never certifications
- A green report can breed false confidence and discourage the manual review a risky component still deserves
- No GDPR position is published, no processing agreement is offered, and the governing law is that of the United States
- The daemon installs globally through npm and observes the whole agent environment, which deserves scrutiny before any professional rollout
- The threat figures driving the sales pitch come from the vendor's own audits and have not been independently verified
Setup & Integrations
Technical difficulty
Very low for the scanner: nothing to install, no account, a URL or a zip is enough and the report arrives in seconds. Moderate for continuous coverage, which needs one global npm command and therefore Node.js on the machine, plus a GitHub or Google sign-in for the dashboard. The vendor claims no Docker, no extra dependency and no configuration, with the AI CISO handling setup on the user's behalf. Wiring the MCP server into Claude Code, Cursor, Windsurf or Goose assumes some familiarity with those tools.
Deployment
Integrations
Behind ClawSecure
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement ClawSecure.
Frequently asked questions
Is the ClawSecure scanner really free?
What exactly does ClawSecure check?
How do I scan a component?
What does the ClawSecure daemon send to the cloud?
Is the AI CISO included in the free plan?
Can I use runtime monitoring today?
Is ClawSecure SOC 2 or ISO 27001 certified?
What happens to my scan results?
How do I report a vulnerability in ClawSecure itself?
Is there an age requirement?
Should you pick ClawSecure?
ClawSecure arrived with the problem it addresses. Agent skills, MCP servers and CLI tools now run on personal machines with wide access and almost no supervision, and the tooling built for enterprise security teams does not reach the people installing them. Pointing a free scanner at that gap, and returning a public report in half a minute, is a sound answer to a real blind spot.
What is genuinely usable today is the scanner and the public registry. They cost nothing, need no account and produce a shareable report mapped onto a recognised framework. The rest of the promise, the runtime daemon, the advanced AI CISO and the operating-system layer, is sold through a waitlist with a locked founding rate, so anyone signing up now is reserving a price rather than buying a service. Judging the product on its runtime claims would be premature.
The vendor's own security hygiene stands out for a company this young: a published disclosure policy with safe harbour, a valid security.txt, external application testing and an explicit statement that credentials and source code stay on the user's machine. The counterweight is the paperwork. There is no GDPR mention anywhere, no data processing agreement, no named subprocessor list, and the SOC 2 and ISO 27001 badges belong to suppliers rather than to ClawSecure, which the trust centre states plainly. Scan results for open-source components are kept indefinitely and published.
For an individual or a small team wanting a fast, free sanity check before installing an agent component, ClawSecure is worth using now. For a regulated organisation, or for anyone who needs runtime protection under contract, it is a company to revisit once the paid tiers ship and the data protection documentation catches up with the security discourse.
- Choosing a selection results in a full page refresh.
- Opens in a new window.