Claw Patrol, a security firewall for agents
Details
- External ID
- 48462928
- Source
- HN
- Company
- —
- Product
- Claw Patrol, a security firewall for agents
- Website domain
- github.com
- Launched
- June 9, 2026
- Cohort
- —
- Upvotes
- 112
- Upvotes percentile
- 0.9241803278688525
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
At Deno we've been using OpenClaw and other agents increasingly for addressing production problems in Deno Deploy - when a PagerDuty alert fires, the agent starts researching the cause and making fixes.In order to do this, the agent needs access to real production systems - postgres, kubernetes, gcp, clickhouse, github, etc. But this is dangerous to say the least - we want destructive actions to be reviewed by other LLMs, approved by humans, and logged appropriately.Claw Patrol terminates TCP connections over WireGuard or Tailscale, then parses application protocols (eg http, postgres, ssh) to apply rules that allow you to deny/allow requests.There are a few projects that sit as a proxy in front of agents to do secret injection or apply various guardrails, but none met our needs (LLM gateways, MCP proxies, sandboxes), particularly the need to handle low-level protocols, or handle complex real world situations like tunneling postgres through k8s.Written in Go, configured in HCL, MIT licensed. Happy to answer any questions.https://clawpatrol.dev/
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Security
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Commercial product
- Normalized one-liner
- security firewall for agents
- Manually corrected
- False
Could you build this?
Yes Claw Patrol is an authorization and proxy firewall intercepting API/database/cloud requests made by autonomous agents, which can be implemented using standard proxy middleware and declarative permission rules.
Discussion
20 comments analyzed.
Competitors mentioned: Agent Vault, Tesla API Firewall, MCP (Model Context Protocol), Deno
Concerns raised: Agents can circumvent restrictions (DROP table -> remove all rows), Single point of failure for security policy across services, Approval timeout handling when operators unavailable, Reinventing permissions instead of using native service accounts, Credential storage and leakage risks
Feature requests: Support for discovery endpoint to show agents available credentials, Handle approval timeouts with agent retry logic, Redaction capabilities in addition to blocking requests, LLM caching problem solutions
Competitors
Other products that read as similar to this one — 160 launches clear the similarity bar, closest 8 shown.
Attention rank: #16 of 161 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 205 days after the earliest competitor.
- ClawShell, Process-Level Isolation for OpenClaw Credentials · hn · 2026-02-19 · 10 upvotes · similarity 0.58
- Prompt-injection firewall for OpenClaw agents · hn · 2026-02-02 · 6 upvotes · similarity 0.51
- ClawSecure · ph · 2026-03-15 · 316 upvotes · similarity 0.51
- ClawSecure · ph · 2026-05-11 · 247 upvotes · similarity 0.51
- FireClaw · hn · 2026-03-17 · 5 upvotes · similarity 0.51
- ClawDeploy · hn · 2026-02-12 · 6 upvotes · similarity 0.50
- Clawbernetes · hn · 2026-02-20 · 5 upvotes · similarity 0.50
- NanoClaw · hn · 2026-02-01 · 533 upvotes · similarity 0.47
Other launches for this product
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.