Atlas / Skills / leoyeai / Runtime Sentinel

Runtime SentinelBLOCK

skills/leoyeai/runtime-sentinel

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
1 documented
License
MIT
Stars
2,160
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Runtime security guardian for OpenClaw agents.

Defends against the threat landscape exposed by the ClawHavoc campaign: backdoored skills, prompt injection via external data, credential exfiltration, and process-level abuse. Integrates with VirusTotal (via the existing OpenClaw partnership) for hash-based malware detection.

What it protects against

Quick start

# First-time setup (free — generates local wallet, runs baseline audit)
sentinel setup

# Audit all installed skills
sentinel audit

# Check a skill before installing it
sentinel check author/skill-name

# Start the guardian in foreground (premium)
sentinel daemon start

# Optional: run it in background at the shell level
sentinel daemon start > ~/.sentinel/daemon.log 2>&1 &
disown

Payment

Premium features use x402 — pay per day with USDC on Base. No account, no subscription, no API key. Your wallet is generated locally on setup and stays non-custodial.

Minimum recommended balance: $1 USDC (~66 days of full coverage).

Security model

Three encrypted files live in ~/.sentinel/:

  • `machine.key` — 32-byte CSPRNG secret, never leaves the machine
Read from source at commit 4f3b4a2a472eOBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

git clone https://github.com/spaceman420urdog-afk/runtime-sentinel
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: runtime-sentinel
description: >
  Runtime security guardian for OpenClaw agents. Use this skill whenever the
  user mentions security, skill safety, prompt injection, malware, suspicious
  behavior, credential leaks, network monitoring, skill integrity, or the
  ClawHavoc attack. Also trigger for phrases like "is this skill safe",
  "audit my skills", "check for threats", "my agent is acting weird",
  "scan for malware", "protect my agent", or any concern about what installed
  skills are doing at runtime. runtime-sentinel provides five active defenses:
  skill integrity hashing, prompt injection detection, credential exposure
  auditing, network egress monitoring, and process anomaly detection. Free tier
  covers hashing and basic injection scanning. Premium features (continuous
  daemon, egress monitoring, process anomaly detection) are gated via x402
  USDC micropayments on Base — no account or API key required.
compatibility:
  binaries:
    - sentinel          # compiled Rust binary in scripts/
  env:
    - SENTINEL_WALLET   # optional: Base wallet address for x402 payments
    - SENTINEL_RPC      # optional: Base RPC URL (defaults to public endpoint)
    - SENTINEL_VT_KEY   # optional: VirusTotal API key for hash lookups
  source: https://github.com/spaceman420urdog-afk/runtime-sentinel
---

# runtime-sentinel

A runtime security skill for OpenClaw. Defends against the threat landscape
exposed by ClawHavoc: backdoored skills, prompt injection via external data,
credential exfiltration, and process-level abuse.

**Free tier**: skill integrity checks, basic injection scanning.  
**Premium** (x402/USDC/Base): continuous daemon monitoring, network egress
monitoring, process anomaly detection, full audit log.

---

## Quick start

```
# One-shot audit of all installed skills (free)
sentinel audit

# Continuous guardian daemon (premium — will prompt for x402 payment)
sentinel daemon start

# Scan a single skill before installing
sentinel check <skill-path-or-clawhub-id>
```

---

## What runtime-sentinel defends against

See `references/threat-model.md` for the full threat matrix. In brief:

| Threat | Feature | Tier |
|---|---|---|
| Tampered skill files post-install | Integrity hashing | Free |
| Prompt injection via email/web/skill output | Injection scanner | Free |
| Plaintext secrets in skill dirs / SOUL.md | Credential auditor | Free |
| Unexpected outbound connections | Egress monitor | Premium |
| Shell commands outside declared behavior | Process anomaly | Premium |
| Continuous real-time protection | Daemon mode | Premium |

---

## Workflow

### 1 — First-time setup

```bash
# Install the binary (built from scripts/src/)
cargo install --path scripts/ --bin sentinel

# Verify installation and print wallet address
sentinel setup
```

`sentinel setup` will:
- Generate or import a Base wallet (BIP-39, stored in `~/.sentinel/wallet`)
- Print the wallet address so the user can fund it with USDC for premium
- Run a free baseline audit and print results

### 2 — On-demand audit (free)

When the user says anything like "scan my skills", "audit", "check for threats":

```bash
sentinel audit [--path ~/.openclaw/skills]
```

Output: a structured report of hash mismatches, injection patterns, and
exposed credentials. No payment required.

### 3 — Single skill check before install (free)

When the user wants to vet a skill before running `clawhub install`:

```bash
sentinel check <skill-directory-or-clawhub-id>
```

Prints a risk score (LOW / MEDIUM / HIGH / CRITICAL) with findings.

### 4 — Premium features via x402

When the user asks for daemon mode, egress monitoring, or process anomaly
detection, `sentinel` will automatically:

1. Hit the sentinel API endpoint
2. Receive a `402 Payment Required` with price in the `X-Payment-Request`
   header (typically $0.01–$0.05/day for daemon mode)
3. Sign the USDC transfer from `~/.sentinel/wallet`
4. Retry the request — access granted for the paid period

The user will see the price *before* their wallet signs anything. All
non-custodial. See `references/x402-payment.md` for the full payment flow.

### 5 — Daemon mode (premium)

```bash
sentinel daemon start    # runs in foreground, writes to ~/.sentinel/daemon.log
# Run in background from your shell if needed:
#   sentinel daemon start > ~/.sentinel/daemon.log 2>&1 &
#   disown
sentinel daemon status
sentinel daemon stop
sentinel daemon logs     # tail the audit log
```

The daemon watches:
- `~/.openclaw/skills/**` for file mutations (inotify / FSEvents)
- `~/.openclaw/SOUL.md` and `MEMORY.md` for unauthorized writes
- Network connections made by skill subprocesses
- Child process trees for undeclared shell commands

Alerts are delivered via OpenClaw's notification system and written to the
audit log.

---

## Interpreting results

### Risk levels

- **LOW**: No findings, or informational only (e.g. skill requests network
  but declares it)
- **MEDIUM**: Undeclared permission, suspicious pattern, or stale hash
- **HIGH**: Known malicious pattern, credential exposure, or undeclared
  egress
- **CRITICAL**: Active exfiltration attempt, reverse shell indicator, or
  SOUL.md mutation

### What to do on HIGH / CRITICAL

1. `sentinel isolate <skill-name>` — quarantines the skill (moves it out of
   the active skills directory)
2. Review the finding in `~/.sentinel/audit.log`
3. Check the skill's ClawHub VirusTotal report
4. If confirmed malicious, `clawhub uninstall <skill>` and report via
   `sentinel report <skill-name>`

---

## Reference files

Read these when you need deeper detail:

- `references/threat-model.md` — Full threat matrix and attack descriptions
  from ClawHavoc and similar campaigns
- `references/x402-payment.md` — x402 payment flow, wallet setup, and
  troubleshooting
- `references/binary-build.md` — How to build `sentinel` from source, cross-
  compilation targets, CI/CD

---

## Wallet setup for premium features

```bash
sentinel wallet show      # print address and U
05

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

HIGHPrompt injection · prompt.hidden_comment · CWE-94, CWE-1427
references/threat-model.md:33
- `<!-- SYSTEM: ignore previous instructions and... -->`
Why it matters. directive hidden in a comment the user does not see rendered
Fix. remove the comment
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/src/patterns/mod.rs:90
"exfiltration-instruction",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/src/patterns/mod.rs:91
Regex::new(r"(send|email|post|forward|upload|exfiltrate).{0,30}(to|at)\s+(http|ftp|smtp|mailto|discord\.com|t\.me|ngrok)").unwrap(),
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
references/threat-model.md:33
- `<!-- SYSTEM: ignore previous instructions and... -->`
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__runtime-sentinel.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eBLOCKD69first audit
07

Questions

What does the Runtime Sentinel skill do?

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Is Runtime Sentinel safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Runtime Sentinel access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Runtime Sentinel work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement