GuardClaw - Local LLM-Powered Security Monitoring

Real-time security monitoring that risk-scores every tool call using a local LLM (qwen3-4b recommended). Features a 3-tier verdict system (SAFE/WARNING/BLOCK) with 100% accuracy on their 20-case benchmark. Runs in monitor-only mode by default, with optional OpenClaw plugin for pre-execution blocking. Includes chained tool analysis, sub-agent monitoring, and write/edit content scanning. Why we added it: Privacy-first approach — your agent audit trail never leaves your machine.

Details

Author / Org TobyGE

Related Resources