Prompt-injection firewall for OpenClaw agents
Details
- External ID
- 46854807
- Source
- HN
- Company
- —
- Product
- Prompt-injection firewall for OpenClaw agents
- Website domain
- github.com
- Launched
- Feb. 2, 2026
- Cohort
- —
- Upvotes
- 6
- Upvotes percentile
- 0.28099730458221023
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
People seem to be blindly hooking up their OpenClaw’s to their personal data. So, I built runtime controls to prevent at the least, very simple prompt injection attacks.Once installed, it hooks to Node.js child_process module in the gateway process and listens to tool calls and their response streams. And a fetch hook to monitor user prompts (both could’ve been through fetch, happy to discuss why this whole layer couldn’t just be a proxy).There are two layers of protection:First: Whenever there is a read-only tool call whose response an attacker can modify, we extract that part of the json response and send it to a small haiku model to check if it has instruction asking the LLM to do something differentSecond: For when the prompt injection detection fails, we maintain a list of function calls which can write to places that an external actor can access. We prompt the user for explicit permission to go forward through the UI.I would love a discussion on how this second layer could be made better and less frequent by relying on some decision process. My current idea: Based on a collected set of “trusted” context (user prompts, responses from tool calls attackers cannot manipulate), can we detect if this tool call was necessary. There are scenarios where you’d need detection at the parameter-level.Two notes:1) This cannot just be a proxy because you need application level integration to have humans in the loop when needed and push UI controls.2) How i improved accuracy of detecting prompt injection is by selecting only that content from the entire response json that can be manipulated by an external actor. This had to be done for each tool separately. The current implementation is for 2 skills I randomly chose (Notion & Github).P.S.: I maintain one for claude code myself while working: https://github.com/ContextFort-AI/Runtime-Controls, I created this over the weekend OpenClaw
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Hobby / open-source project
- Normalized one-liner
- prompt injection firewall for ai agents
- Manually corrected
- False
Could you build this?
Yes It is a lightweight Node.js monkey-patching script that intercepts `child_process` calls and inspects tool-call streams for obvious prompt injection strings.
Discussion
3 comments analyzed.
Concerns raised: AI assumes context from earlier prompts without explicit confirmation, Attackers can control tool responses before red teaming occurs, Second validation layer depends on human judgment, creating decision fatigue
Feature requests: Use consistent italics for clarity in AI responses, Create red teaming dataset for edge cases
Competitors
Other products that read as similar to this one — 122 launches clear the similarity bar, closest 8 shown.
Attention rank: #99 of 123 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 73 days after the earliest competitor.
- FireClaw · hn · 2026-03-17 · 5 upvotes · similarity 0.64
- ClawShell, Process-Level Isolation for OpenClaw Credentials · hn · 2026-02-19 · 10 upvotes · similarity 0.55
- Claw Patrol, a security firewall for agents · hn · 2026-06-09 · 112 upvotes · similarity 0.51
- OpenClaw-superpowers · hn · 2026-03-15 · 8 upvotes · similarity 0.48
- Klaus · hn · 2026-03-11 · 160 upvotes · similarity 0.48
- Make sure your OpenClaw isn't doing things it's not supposed to · hn · 2026-04-15 · 18 upvotes · similarity 0.47
- BrokenClaw Part 5: GPT-5.4 Edition (Prompt Injection) · hn · 2026-04-09 · 10 upvotes · similarity 0.45
- AgentPort · hn · 2026-04-29 · 8 upvotes · similarity 0.44
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.