frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Clawdstrike – a security toolbox for the OpenClaw ecosystem

https://github.com/backbay-labs/clawdstrike
3•backbay-machine•1h ago
Hi HN.

OpenClaw has been popping claw for weeks now…

We’ve seen the same question come up again and again: “This is fun but how do we no get fuk?”

My answer: Clawdstrike.

It’s an open-source toolbox for developers who want to ship EDR-style apps and security infrastructure to the OpenClaw ecosystem.

Disclaimer: this is an unpublished alpha (APIs will change). Beta is planned within ~7 days (aiming for Feb 10, 2026). Not audited—please treat as experimental.

Here’s my take: the first wave of “make autonomous agents safe where users are literally yoloing their entire system without even watching” is actually pretty simple.

Security needs to live at the boundary between an agent’s intent and action — the moment it tries to read/write files, patch code, call tools, or reach the network.

Not just “visibility.” Not just logs. But enforcement + proof.

What Clawdstrike gives you: - Fail-closed guards at the agent/tool boundary - Block sensitive paths, control network egress, detect secrets, validate patches, restrict tools, catch jailbreaks - A policy engine (YAML rulesets) so teams can start safe and tighten over time - Receipts + signatures (Ed25519) so wtf the agent actually did is verifiable — not a story in your log pipeline - An OpenClaw plugin so this drops into existing stacks with minimal friction

Everyone knows this turns into a forever cat-and-mouse game between model providers, agent frameworks, sandbox/runtime developers, and the adversaries. That’s the world we’re in. (boo. fuck you, bad guys.)

My hope is Clawdstrike becomes a useful foundation for people in the ecosystem: a place where developers and security people can encode + share proving strategies (guards, policies, verification patterns) instead of each team re-learning the same lessons in private.

Threat model (explicit, so nobody gets misled): Clawdstrike enforces policy at the agent/tool boundary. It is *NOT* an OS sandbox and does *NOT* intercept syscalls. If an agent can bypass the tool layer and touch the filesystem/network directly, gg, Clawdstrike can’t stop it. The intended setup is: pair this with OS/container sandboxing when you need syscall-level isolation (seccomp/gVisor/Firecracker/etc).

Why I’m posting: I want to do whatever I can to help build out the shared safety layer for the OpenClaw ecosystem. If this looks useful to you: clawdstrike is something you can adopt early and extend, help us help you build serious security/EDR-grade infrastructure on top of it.

Feedback I’d love: - Which single failure mode scares you most with OpenClaw today? - (exfiltration, destructive writes, supply-chain via patches, prompt/tool injection, credential leakage, lateral movement, etc.) - If this becomes a shared safety layer, what needs to be stable? - Unfortunately for you all I’ve never built a widely adopted open source security sdk, so really just looking for feedback on release cadence and stability from those who would plan on using something like this. Policy schema? guard API? receipt format? verification tooling? (Which thing must not break?) - What would make you trust it? - Formal threat model, fuzzing, reproducible builds, third-party audits, or just battle-testing? Do you want receipts to be human-legible or machine-verifiable first? (And if machine-first: what format would you want. JSON/JCS, CBOR, Merkle proofs, etc.) - How should policy be expressed? - Classic question…. So.. YAML? hybrid? - What other integrations would you like to see next?

Repo/docs: https://github.com/backbay-labs/clawdstrike

If you’re building with OpenClaw and security is on your mind, I’d love to collaborate and make this genuinely useful.

Does Intermittent Fasting Live Up to the Hype?

https://www.nytimes.com/2026/01/26/well/eat/intermittent-fasting.html
1•doener•2m ago•0 comments

2 days left to comment on DOT's plan to hike US fuel costs by $23B

https://electrek.co/2026/02/02/2-days-left-to-comment-on-dots-plan-to-hike-us-fuel-costs-by-23b/
1•Bender•4m ago•0 comments

Released: Ace-Step 1.5: Pushing the Boundaries of Open-Source Music Generation

https://ace-step.github.io/ace-step-v1.5.github.io/
1•4chandaily•4m ago•1 comments

Dual N-Back

https://gwern.net/dnb-faq
1•aggrrrh•5m ago•0 comments

FERC: Renewables made up 88% of new US power generating capacity to Nov 2025

https://electrek.co/2026/02/02/ferc-renewables-power-generating-capacity-to-nov-2025/
1•Bender•6m ago•0 comments

Four theories about the SpaceX – xAI merger

https://garymarcus.substack.com/p/four-theories-about-the-spacex-xai
2•headalgorithm•7m ago•0 comments

Bruce Schneier: AI and the scaling of betrayal

https://www.schneier.com/blog/archives/2023/12/ai-and-trust.html
4•insuranceguru•8m ago•1 comments

Pornhub shuts off access to new UK users, citing age verification constraints

https://www.cnn.com/2026/02/02/uk/uk-pornography-restricted-access-intl
1•Bender•8m ago•0 comments

BYD's next-gen megawatt charger leaks: 1,500 kW vs. 1k kW first gen

https://carnewschina.com/2026/02/02/byds-next-gen-megawatt-charger-leaks-1500-kw-power-1500-a-cur...
1•jampa•8m ago•0 comments

In Under 500 Words, a Judge Weaponized Wit to Free the Child Detained by ICE

https://www.nytimes.com/interactive/2026/02/03/books/judge-ruling-liam-conejo-ramos-analysis.html
2•petethomas•9m ago•0 comments

Postgres managed by ClickHouse

https://clickhouse.com/cloud/postgres
2•tosh•9m ago•0 comments

Life without good internet is boring

https://blog.usmanity.com/posts/life-without-good-internet-is-boring
1•speckx•9m ago•0 comments

Where the Work Goes When Agents Arrive

https://dreamiurg.net/2026/02/02/where-the-work-goes-when-agents-arrive.html
1•dreamiurg•10m ago•1 comments

Mad Rust: The JVM Developer's Journey. Kotlin/Java Developer's Road to Valhalla

https://sobolev.substack.com/p/mad-rust-escape-from-the-jvm-citadel
1•alexsobolev•10m ago•0 comments

Show HN: Tenuo – Capability-Based Authorization (Macaroons for AI Agents)

2•niyikiza•11m ago•0 comments

Show HN: Real-world speedrun timer that auto-ticks via vision on smart glasses

https://github.com/RealComputer/GlassKit/tree/main/examples/rokid-rfdetr
2•tash_2s•12m ago•1 comments

My deep thoughts and considered opinions on AI

https://skryblans.com/my-very-deep-thoughts-and-considered-opinions-on-ai/
2•milkcircle•12m ago•0 comments

Why are Spain and Portugal growing twice as fast as the Eurozone?

https://www.euronews.com/business/2026/01/30/why-are-spain-and-portugal-growing-twice-as-fast-as-...
1•belter•13m ago•0 comments

Elon Musk is taking SpaceX's minority shareholders for a ride

https://www.theguardian.com/business/nils-pratley-on-finance/2026/feb/03/elon-musk-is-taking-spac...
2•6LLvveMx2koXfwn•13m ago•1 comments

PayPal Appoints Enrique Lores as Chief Executive Officer

https://investor.pypl.com/news-and-events/news-details/2026/PayPal-Appoints-Enrique-Lores-as-Chie...
1•zatkin•14m ago•0 comments

Elevated error rates for ChatGPT users – OpenAI Status

https://status.openai.com/incidents/01KGJK9Q6PDB3C3VX6MPCY6106
8•rossant•15m ago•1 comments

5M installs, $1M Open Source Grant program, and the story of how we got here

https://cline.bot/blog/5m-installs-1m-open-source-grant-program
2•raybb•15m ago•0 comments

Ruptures in China's Leadership Could Be Due to Paranoia and Power Plays

https://www.nytimes.com/2026/02/03/us/politics/china-xi-military-purge.html
2•JumpCrisscross•15m ago•0 comments

Nava Acquires Beam to Raise the Bar for Public Service IT

https://www.govtech.com/biz/nava-acquires-beam-to-raise-the-bar-for-public-service-it
1•stephenhuey•16m ago•1 comments

Epstein Backed Coinbase in Crypto Exchange's Early Years

https://www.bloomberg.com/news/articles/2026-02-03/epstein-backed-coinbase-in-crypto-exchange-s-e...
5•wslh•17m ago•1 comments

Rules_Claude: Hermetic Bazel toolchain and rules for Claude Code

https://github.com/buildbuddy-io/rules_claude
4•siggi•18m ago•1 comments

Future home might be framed with printed plastic

https://news.mit.edu/2026/your-future-home-might-be-framed-with-printed-plastic-0203
1•gnabgib•20m ago•0 comments

Fintech CEO and Forbes 30 Under 30 alum has been charged for alleged fraud

https://techcrunch.com/2026/02/02/fintech-ceo-and-forbes-30-under-30-alum-has-been-charged-for-al...
1•wslh•21m ago•1 comments

Net Neutrality for AI

https://vanderbiltpolicyaccelerator.substack.com/p/net-neutrality-for-ai
1•geox•24m ago•0 comments

When Vibe Coded Consumer Agents Go Rogue

https://nearfuturelaboratory.com/editorial/when-vibe-coded-consumer-agents-go-rogue/
2•cyanbane•25m ago•0 comments