FireClaw
Open-source proxy defending AI agents from prompt injection
Details
- External ID
- 47414911
- Source
- HN
- Company
- —
- Product
- FireClaw
- Website domain
- github.com
- Launched
- March 17, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.1070110701107011
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hey HN,We built FireClaw because we kept watching AI agents get owned by prompt injection through web content. The agent fetches a page, the page says "ignore previous instructions," and suddenly your agent is leaking data or running commands it shouldn't.The existing solutions detect injection after the fact. We wanted to prevent it.FireClaw is a security proxy that sits between your AI agent and the web. Every fetch passes through a 4-stage pipeline:1. DNS blocklist check (URLhaus, PhishTank, community feed) 2. Structural sanitization (strip hidden CSS, zero-width Unicode, encoding tricks) 3. Isolated LLM summarization (hardened sub-process with no tools or memory) 4. Output scanning with canary tokens (detect if content bypassed summarization)The key insight: even if Stage 3's LLM gets injected, it has no tools, no memory, and no access to your data. It can only return text — which still gets scanned in Stage 4. The attacker hits a dead end.Other design decisions: - No bypass mode. The pipeline is fixed. If your agent gets compromised, it can't disable FireClaw. - Community threat feed — instances anonymously share detection metadata (domain, severity, detection count) to build a shared blocklist. No page content is ever sent. - Runs on a Raspberry Pi as a physical appliance with an OLED display that shows real-time stats and lights up with animated flames when it catches a threat.We searched the literature and open source extensively — no one else is doing proxy-based defense for agent prompt injection. Detection exists, sandboxing exists, but an inline proxy that sanitizes before content reaches the agent's context? We couldn't find it.200+ detection patterns, JSONL audit logging, domain trust tiers, rate limiting, and cost controls. AGPLv3 licensed.Website: https://fireclaw.appWould love feedback from anyone working on AI agent security. What are we missing? What attack vectors should we add to the pattern database?
Enrichment
- Theme
- browser automation and scraping for AI
- Vertical
- Security
- Function
- —
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- prompt injection defense for ai agents
- Manually corrected
- False
Could you build this?
Yes FireClaw is an HTTP proxy server that intercepts outbound agent web requests, strips hazardous content, and filters out prompt injection strings using pattern matching and LLM evaluators.
Discussion
7 comments analyzed.
Competitors mentioned: Rebuff, LLM Guard
Concerns raised: Doesn't catch injection via tool descriptions or memory artifacts, Treating symptoms rather than fixing underlying LLM/RDBMS layer, Detection-only approaches enter content into agent context before catching it
Feature requests: Replace emojis with Lucide SVG icons for cross-platform consistency
Competitors
Other products that read as similar to this one — 328 launches clear the similarity bar, closest 8 shown.
Attention rank: #303 of 329 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 134 days after the earliest competitor.
- Prompt-injection firewall for OpenClaw agents · hn · 2026-02-02 · 6 upvotes · similarity 0.64
- Agent-browser-shield · hn · 2026-06-03 · 7 upvotes · similarity 0.55
- ClawShell, Process-Level Isolation for OpenClaw Credentials · hn · 2026-02-19 · 10 upvotes · similarity 0.54
- My agents are building a secure fork of OpenClaw · hn · 2026-02-13 · 9 upvotes · similarity 0.53
- OpenClaw-superpowers · hn · 2026-03-15 · 8 upvotes · similarity 0.52
- AgentPort · hn · 2026-04-29 · 8 upvotes · similarity 0.52
- I built a firewall for agents because prompt engineering isn't security · hn · 2026-01-19 · 7 upvotes · similarity 0.51
- AgentArmor · hn · 2026-03-14 · 10 upvotes · similarity 0.51
Other launches for this product
- No other launches for this product.