ClawSecure logo
Privacy Security · Security Code Scanning

ClawSecure

ClawSecure scans AI agent skills, MCP servers and CLI tools for malicious code and prompt injection before you install them, then watches your environment at runtime through Claw, its built-in AI CISO.

Active Free plan Freemium API available 13+ Verified by Guidaio
Overview

What is ClawSecure?

ClawSecure is a security platform for AI agents built around a simple split: check a component before it runs, then keep watching it afterwards. It describes itself as the integrity layer for agent skills, MCP servers and CLI tools, and it aims squarely at people who run agents without a security team, from individuals and prosumers to small development teams and SMBs.

The free entry point is a scanner. You paste a GitHub link, a ClawHub URL or a skill name, or upload a zip of up to 10 MB, and a 3-Layer Audit Protocol returns a public Security Audit Report in about thirty seconds. The first layer is a proprietary behavioural engine carrying more than fifty-five threat patterns, covering malicious code, command-and-control callbacks, data exfiltration, prompt injection, credential harvesting and ReDoS, with context-aware logic meant to separate real threats from ordinary agent capabilities. The second combines static pattern matching with behavioural dataflow analysis and taint tracking across tool-calling chains, targeting the convergence of data access, untrusted content and tool execution. The third walks the whole npm dependency tree against CVE databases and flags compromised or unpinned packages. Every report maps its findings onto the ten OWASP ASI categories, from agent goal hijacking to rogue agents.

Four more layers sit around that scanner. Claw, presented as the first AI CISO, configures installs and blocks prompt injection, social engineering and credential theft in real time, and answers from a dashboard, from Slack, Telegram, WhatsApp or WeChat, and from an MCP server wired into Claude Code, Cursor, Windsurf or Goose. A daemon installed with one npm command inventories the environment, maps MCP and CLI permissions and audits configurations. Watchtower compares SHA-256 hashes around the clock and re-scans a skill whose code changes after install. A Security Clearance API lets platforms verify integrity programmatically.

The vendor's own audits carry the pitch: 2,890 or more skills analysed, 9,515 threats detected, 41% of popular tools flagged with material risk and 22.9% rewriting themselves after installation. Two caveats matter. The runtime tiers are not live yet, sold instead as a waitlist with locked founding-member pricing, and the terms state that a scan is an informational assessment, never a certification.

What it does

  • Scan an agent skill, an MCP server or a CLI tool before installing it
  • Read a public Security Audit Report with a score, findings by severity and fix recommendations
  • Map what every agent component can reach: Gmail, GitHub, Slack, the local filesystem
  • Catch exposed API keys and misconfigured sandboxes across an agent environment
  • Detect silent code changes after installation and trigger an automatic re-scan
  • Watch agent behaviour at runtime and raise an alert on anomalous tool calls
  • Verify an agent's current integrity status programmatically through the Clearance API
Audience

When to use ClawSecure / When not to

A quick filter to help you decide if ClawSecure is the right fit.

When to use ClawSecure

  • Non-technical users and prosumers who install agent skills without any security team behind them
  • Small development teams and SMBs running AI agents that hold full access to a working machine
  • Developers who want a GitHub repository or a ClawHub skill checked before it touches their environment
  • Platform and marketplace builders who need to verify an agent's integrity programmatically through an API
  • Anyone worried about code drift, where a skill rewrites itself in the weeks after installation

When not to use ClawSecure

  • Teams looking to harden a local OpenClaw gateway, file permissions or credential storage, which the vendor openly leaves to other tools
  • Organisations needing a general-purpose antivirus or an enterprise endpoint detection suite
  • Buyers who require a formal security certification, since the terms state that a scan is never one
  • Anyone who needs runtime monitoring today, as the paid tiers are still a waitlist rather than a live service
  • Regulated European organisations expecting a data processing agreement and a documented GDPR posture
Get started

How to use ClawSecure

A typical end-to-end flow, from setup to results.

  1. Open the scanner on the ClawSecure home page, in the section dedicated to scanning
  2. Paste a GitHub link, a ClawHub URL or a skill name, or drop a zip archive of 10 MB or less
  3. Start the scan without creating an account and without entering a card
  4. Wait about thirty seconds for the 3-Layer Audit Protocol to finish
  5. Enter an email address to unlock the full Security Audit Report and its findings by severity
  6. Check the OWASP ASI mapping and the fix recommendations before installing anything
  7. Browse the public registry to compare a component against the thousands already audited
  8. Install the daemon with a single global npm command when you want continuous coverage
  9. Sign in to the browser dashboard with GitHub or Google to read your environment risk score
  10. Query Claw from the terminal or from your messaging app whenever you need a second opinion
Quick read

Pros & Cons

Pros

  • The scanner is genuinely free, needs no account or card, and returns a verdict in about thirty seconds
  • Every report is public and shareable, which makes the method open to third-party scrutiny
  • Watchtower keeps checking after installation, where most scanners stop at a single point in time
  • Coverage is claimed across all ten OWASP ASI categories, a published and peer-reviewed framework
  • The entry price sits far below the enterprise tools the vendor quotes at 50,000 dollars a year and up
  • Security hygiene is documented: published disclosure policy with safe harbour, security.txt, external testing
  • API keys, credentials and source code are stated never to leave the user's machine

Cons

  • The paid product is not shipped yet: Shield, Sentinel and Fortress are a waitlist, not a live service
  • No GDPR mention at all, no data processing agreement, no named subprocessor list, United States governing law
  • The compliance badges are self-attested, and the SOC 2 and ISO 27001 claims belong to the providers, not to ClawSecure
  • Scan data is retained indefinitely and published for open-source components, with no documented removal path
  • The company is very young, its domain registered in February 2026, with no about page and no team presented
  • The full scan report is gated behind an email address, even though the scan itself is not
  • The headline threat figures come from the vendor's own audits, with no independent verification
Pricing

Pricing & Plans

ClawSecure offers a permanent free plan covering unlimited scanning, essential AI CISO protection and Watchtower monitoring, described by the vendor as free forever. The cheapest paid entry point is the Shield tier, listed at 29.00 USD per month at standard rate and offered at 9.99 USD per month under a Founding Member rate locked at signup. All paid tiers are billed monthly, without contract, and carry a thirty-day money-back guarantee. Prospective subscribers should note that the paid tiers are not yet commercially available: joining the waitlist reserves a rate rather than activating a service.

Free — 0 USD, described as free forever
  • 3-Layer Audit Protocol with 55+ threat patterns
  • full OWASP ASI Top 10 coverage
  • a public Security Audit Report for every scan
  • essential AI CISO defence against prompt injection and credential theft
  • and Watchtower community monitoring
Sentinel — 79.00 USD per month, or 24.99 USD per month as Founding Member
  • everything in Shield
  • advanced AI CISO with behavioural analysis
  • visibility on which tools agents call and which data they touch
  • anomaly detection
  • real-time alerts
  • full tool call history and behavioural trends
  • community intelligence and a priority analysis queue
Fortress — 199.00 USD per month, or 79.99 USD per month as Founding Member, marked Advanced
  • everything in Sentinel
  • advanced AI CISO with OS-level deep monitoring
  • process monitoring and system-call interception
  • network traffic analysis
  • and full-stack visibility down to operating system events
Special offers — Founding Member pricing locked for life when joining the waitlist: Shield at 9.99 USD instead of 29.00, Sentinel at 24.99 USD instead of 79.00, Fortress at 79.99 USD instead of 199.00 · Limited window: once the Founding Member period closes, new subscribers pay the standard rates · Thirty-day money-back guarantee on every paid plan, refundable on request without justification · Free scanner and essential AI CISO protection kept for life, whether or not a subscription is taken
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how ClawSecure handles your data.

GDPR overview

There is no GDPR mention anywhere on the site. The word does not appear on the privacy policy, the terms, the trust centre or any other published page, and no equivalent European wording replaces it. No data processing agreement is published or offered, no subprocessor list is named beyond a reference to Google Analytics, and no Article 27 representative is designated. Both the privacy policy and the terms state that they are governed by the laws of the United States of America. The rights section is limited to removing an email address on request, and the age threshold quoted is thirteen, which follows the American children's privacy standard rather than a European one. A user in the European Union should therefore treat the GDPR position as undocumented.

Who owns the data?

ClawSecure keeps ownership of its scanning technology, its reports and the "ClawSecure Verified" designation. Users keep what stays on their machine: the terms and the privacy policy both state that API keys, credentials and source code never leave the device, the daemon transmitting only component metadata, file hashes and configuration summaries. Scan results are a different matter. For publicly available open-source skills they are treated as public information, stored in the vendor's database and reachable through shareable report URLs that carry the agent name, its creator, the score and the findings. Email addresses are collected only when a visitor submits one. ClawSecure states that it does not sell, rent or trade user data.

Reuse rights

Reports are meant to circulate: the terms say scan results may be shared publicly through report URLs, so a user can pass on a report without asking permission, and third parties can read one from its link. What cannot be reused is the platform itself, its scanning technology and the "ClawSecure Verified" badge, which remain proprietary. On its own side, ClawSecure reuses scan data to publish public security reports, to maintain its Verified Agent Registry and to improve its scanning capabilities, and it reserves the right to publish aggregated, anonymised statistics in blog posts and marketing material. Once a public open-source skill has been scanned, its record stays in the public registry and the site does not offer a way to withdraw it.

Data retention & training

Retention summary
Retention depends on the type of data. Scan data is kept indefinitely, because it forms part of the public registry, and results for publicly available open-source components stay in that public record even if a removal is requested. Email addresses are kept until the user asks for them to be deleted, which is done by writing to the contact address in the privacy policy. Standard web server logs, including IP addresses, timestamps and user agents, are kept for thirty days. No anonymisation timetable is published, although the vendor reserves the right to publish aggregated and anonymised statistics. The privacy policy carrying these rules is dated July 2026.
Trains on customer data
Unclear
GDPR contact

Hosting summary

ClawSecure does not name a hosting country or region anywhere on its site, so the jurisdiction where scan data physically sits is undocumented. The privacy policy describes its providers by category rather than by name: a cloud database and authentication provider, a cloud application hosting provider, and a transactional email delivery service, with Google Analytics named separately for site analytics. The trust centre adds that HTTPS is enforced on all endpoints through a managed CDN and DNS provider certified SOC 2 and ISO 27001, and that scan data is stored with a SOC 2 certified managed database provider using AES-256 encryption at rest, with row-level access controls. Those certifications belong to the suppliers, not to ClawSecure. At the time of collection the domain resolved to an anycast Cloudflare address, which indicates the edge network rather than the storage location. The counterweight to this opacity is the local boundary the vendor commits to: API keys, credentials and source code are stated never to leave the user's own machine.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting ClawSecure.

  • Paying today buys a reserved rate, not an active service: the three paid tiers have not launched
  • Scan results for open-source components are published and kept indefinitely, with no documented removal route
  • A clean score is not a guarantee: the terms state that scans are informational assessments, never certifications
  • A green report can breed false confidence and discourage the manual review a risky component still deserves
  • No GDPR position is published, no processing agreement is offered, and the governing law is that of the United States
  • The daemon installs globally through npm and observes the whole agent environment, which deserves scrutiny before any professional rollout
  • The threat figures driving the sales pitch come from the vendor's own audits and have not been independently verified
Setup

Setup & Integrations

Technical difficulty

Very low for the scanner: nothing to install, no account, a URL or a zip is enough and the report arrives in seconds. Moderate for continuous coverage, which needs one global npm command and therefore Node.js on the machine, plus a GitHub or Google sign-in for the dashboard. The vendor claims no Docker, no extra dependency and no configuration, with the AI CISO handling setup on the user's behalf. Wiring the MCP server into Claude Code, Cursor, Windsurf or Goose assumes some familiarity with those tools.

Deployment

Web appAPIDesktop app

Integrations

Claude Code Cursor Windsurf Goose OpenAI Google Gemini OpenClaw ClawHub GitHub Google Slack Telegram WhatsApp WeChat Npm
Company

Behind ClawSecure

Company name
ClawSecure
Founded
12/02/2026
Country of origin
🇺🇸 United States
Headquarters
1209 Orange Street, Wilmington, DE 19801, United States of America
UBO
J.D. Salbego
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement ClawSecure.

S SecureClawC ClawdexC Cisco DefenseClawS SkillRiskS SnykA AikidoZ ZenityA AstrixO OasisC CrowdStrikeS SentinelOne
FAQ

Frequently asked questions

Is the ClawSecure scanner really free?
Yes. Scanning a skill, an MCP server or a CLI tool requires no account, no sign-up and no credit card, and the vendor describes the free tier as free forever. Reading the complete Security Audit Report does require an email address.
What exactly does ClawSecure check?
Its 3-Layer Audit Protocol looks for malicious code, command-and-control callbacks, data exfiltration, prompt injection, credential harvesting and ReDoS, traces dataflow across tool-calling chains, and scans the full npm dependency tree against CVE databases. More than fifty-five threat patterns are involved and every finding is mapped onto the OWASP ASI Top 10.
How do I scan a component?
Paste a GitHub link, a ClawHub URL or a skill name into the scanner on the home page, or upload a zip archive of 10 MB or less. A report with a security score, findings by severity and fix recommendations comes back in roughly thirty seconds.
What does the ClawSecure daemon send to the cloud?
Component metadata, file hashes and configuration summaries, according to the privacy policy and the trust centre. API keys, credentials and source code are stated never to leave the machine, and the daemon is described as not touching personal files or browsing history.
Is the AI CISO included in the free plan?
Yes, in an essential form covering real-time defence against prompt injection, social engineering and credential theft. The advanced AI CISO comes with the paid tiers, alongside environment monitoring, behavioural analysis or OS-level monitoring depending on the plan.
Can I use runtime monitoring today?
No. Shield, Sentinel and Fortress are announced through a waitlist. Joining locks a Founding Member rate that applies when the tiers launch, but nothing beyond the free scanner and the AI CISO essentials is active in the meantime.
Is ClawSecure SOC 2 or ISO 27001 certified?
No. The trust centre attributes those certifications to its providers: a managed CDN and DNS provider certified SOC 2 and ISO 27001, and a managed database provider certified SOC 2. The OWASP, NIST and CSA alignments are described by the site itself as self-attested and not independently verified.
What happens to my scan results?
Scan results for publicly available open-source components are treated as public information, kept indefinitely in the public registry and reachable through shareable report URLs carrying the component name, its creator, the score and the findings.
How do I report a vulnerability in ClawSecure itself?
Through security@clawsecure.ai, under a published disclosure policy with safe harbour for good-faith research. The vendor commits to acknowledging a report within three business days and asks for coordinated disclosure within ninety days.
Is there an age requirement?
The privacy policy states that the service is not directed at children under thirteen and that data is not knowingly collected from them.
Conclusion

Should you pick ClawSecure?

ClawSecure arrived with the problem it addresses. Agent skills, MCP servers and CLI tools now run on personal machines with wide access and almost no supervision, and the tooling built for enterprise security teams does not reach the people installing them. Pointing a free scanner at that gap, and returning a public report in half a minute, is a sound answer to a real blind spot.

What is genuinely usable today is the scanner and the public registry. They cost nothing, need no account and produce a shareable report mapped onto a recognised framework. The rest of the promise, the runtime daemon, the advanced AI CISO and the operating-system layer, is sold through a waitlist with a locked founding rate, so anyone signing up now is reserving a price rather than buying a service. Judging the product on its runtime claims would be premature.

The vendor's own security hygiene stands out for a company this young: a published disclosure policy with safe harbour, a valid security.txt, external application testing and an explicit statement that credentials and source code stay on the user's machine. The counterweight is the paperwork. There is no GDPR mention anywhere, no data processing agreement, no named subprocessor list, and the SOC 2 and ISO 27001 badges belong to suppliers rather than to ClawSecure, which the trust centre states plainly. Scan results for open-source components are kept indefinitely and published.

For an individual or a small team wanting a fast, free sanity check before installing an agent component, ClawSecure is worth using now. For a regulated organisation, or for anyone who needs runtime protection under contract, it is a company to revisit once the paid tiers ship and the data protection documentation catches up with the security discourse.