Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Manage DefenseClaw enterprise security - scan components, manage tool permissions, view alerts, configure guardrails
.claude/skills/automateyournetwork-defenseclaw-ops/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 121% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 35% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 658% | 0% |
| case-04 | ✗→✓ | ▲ Improved | -19% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -4% | 0% |
This skill manages DefenseClaw enterprise security for NetClaw deployments.
DefenseClaw from Cisco AI Defense provides enterprise-grade security:
defenseclaw CLI in PATHCheck status:
bashdefenseclaw --version
bash# View DefenseClaw version defenseclaw --version # Check gateway status pgrep defenseclaw-gateway # View current configuration cat ~/.openclaw/config/openclaw.json | grep -A2 security
Before deploying new skills, MCPs, or plugins, scan them:
bash# Scan a skill defenseclaw skill scan pyats-health-check # Scan an MCP server defenseclaw mcp scan meraki-mcp # Scan a plugin defenseclaw plugin scan custom-tool
Expected output for clean component:
Scanning skill: pyats-health-check
✓ No HIGH/CRITICAL findings
Status: ALLOWEDExpected output for blocked component:
Scanning skill: bad-skill
✗ HIGH: Hardcoded credential detected
Location: config.py:15
Status: BLOCKEDBlock or allow specific tools:
bash# Block a destructive tool defenseclaw tool block delete_file --reason "destructive operation" # Block all write operations defenseclaw tool block "*_write" --reason "read-only policy" # Allow a previously blocked tool defenseclaw tool allow delete_file # List all tool rules defenseclaw tool list
bash# View recent alerts defenseclaw alerts # View last 50 alerts defenseclaw alerts --limit 50 # Filter by severity defenseclaw alerts --severity HIGH # Filter by date defenseclaw alerts --after 2026-04-01
For compliance reporting:
bash# Export to JSON defenseclaw alerts --export json > audit-$(date +%Y%m%d).json # Export to CSV defenseclaw alerts --export csv > audit-$(date +%Y%m%d).csv
bash# Check current mode defenseclaw config get guardrail.mode # Enable observe mode (logging only - default) defenseclaw setup guardrail --mode observe # Enable action mode (blocking) defenseclaw setup guardrail --mode action --restart # Restart gateway after mode change defenseclaw setup guardrail --restart
| Mode | Behavior | Use Case | |------|----------|----------| | observe | Log violations, allow execution | Development, onboarding | | action | Log violations AND block | Production, compliance |
Guardrails check for these categories:
| Category | Description | |----------|-------------| | secret | Credential exfiltration | | command | Shell command execution | | sensitive-path | File system access | | c2 | Command & control communication | | cognitive-file | AI memory manipulation | | trust-exploit | Prompt injection |
Configure external SIEM:
bash# Splunk HEC defenseclaw config siem --type splunk \ --endpoint https://splunk.example.com:8088 \ --token $SPLUNK_HEC_TOKEN # OTLP defenseclaw config siem --type otlp \ --endpoint https://otel-collector.example.com:4318 # Test connectivity defenseclaw config siem --test
bash# Slack defenseclaw config webhook --slack $SLACK_WEBHOOK_URL # PagerDuty defenseclaw config webhook --pagerduty $PD_ROUTING_KEY # Webex defenseclaw config webhook --webex $WEBEX_WEBHOOK_URL
bashexport PATH="$HOME/.local/bin:$PATH"
bash# Check status pgrep defenseclaw-gateway # Start manually defenseclaw-gateway start # Check logs tail -f ~/.defenseclaw/logs/gateway.log
bash# View detailed findings defenseclaw skill scan <name> --verbose # Add exception if false positive defenseclaw exception add <component> --finding <id> --reason "reviewed"
Other measured skills in the registry, with their headline benchmark lift.