claw-release
Release automation for Claw skills and website. Guides through version bumping, tagging, and release verification.
Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.
$ npx -y skills add prompt-security/clawsec --skill hermes-attestation-guardian --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/hermes-attestation-guardianContext preview
The summary Claude sees to decide when to auto-load this skill.
Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.
name: hermes-attestation-guardian
version: 0.1.7
description: Hermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.
homepage: https://clawsec.prompt.security
hermes:
emoji: "🛡️"
requires:
bins: [node]IMPORTANT SCOPE:
Install with the Vercel Skills CLI for this harness:
npx skills add prompt-security/clawsec --skill hermes-attestation-guardian -a hermes-agent -y
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBOM source, and the release pipeline signs `checksums.json` with the ClawSec release key.
set -euo pipefail
SKILL_NAME="hermes-attestation-guardian"
VERSION="0.1.7"
REPO="prompt-security/clawsec"
TAG="${SKILL_NAME}-v${VERSION}"
BASE="https://github.com/${REPO}/releases/download/${TAG}"
ZIP_NAME="${SKILL_NAME}-v${VERSION}.zip"
TMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TMP_DIR"' EXIT
RELEASE_PUBKEY_SHA256="711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8"
curl -fsSL "$BASE/checksums.json" -o "$TMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TMP_DIR/checksums.sig"
curl -fsSL "$BASE/signing-public.pem" -o "$TMP_DIR/signing-public.pem"
curl -fsSL "$BASE/$ZIP_NAME" -o "$TMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/SKILL.md" -o "$TMP_DIR/SKILL.md"
curl -fsSL "$BASE/skill.json" -o "$TMP_DIR/skill.json"
ACTUAL_PUBKEY_SHA256="$(openssl pkey -pubin -in "$TMP_DIR/signing-public.pem" -outform DER | shasum -a 256 | awk '{print $1}')"
if [ "$ACTUAL_PUBKEY_SHA256" != "$RELEASE_PUBKEY_SHA256" ]; then
echo "ERROR: signing-public.pem fingerprint mismatch" >&2
exit 1
fi
openssl base64 -d -A -in "$TMP_DIR/checksums.sig" -out "$TMP_DIR/checksums.sig.bin"
openssl pkeyutl -verify -rawin -pubin \
-inkey "$TMP_DIR/signing-public.pem" \
-sigfile "$TMP_DIR/checksums.sig.bin" \
-in "$TMP_DIR/checksums.json" >/dev/null
hash_file() {
if command -v shasum >/dev/null 2>&1; then
shasum -a 256 "$1" | awk '{print $1}'
else
sha256sum "$1" | awk '{print $1}'
fi
}
verify_manifest_file() {
asset="$1"
path="$2"
expected="$(jq -r --arg asset "$asset" '.files[$asset].sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected" ]; then
echo "ERROR: checksums.json missing $asset" >&2
exit 1
fi
actual="$(hash_file "$path")"
if [ "$actual" != "$expected" ]; then
echo "ERROR: checksum mismatch for $asset" >&2
exit 1
fi
}
expected_archive="$(jq -r '.archive.sha256 // empty' "$TMP_DIR/checksums.json")"
if [ -z "$expected_archive" ]; then
echo "ERROR: checksums.json missing archive.sha256" >&2
exit 1
fi
actual_archive="$(hash_file "$TMP_DIR/$ZIP_NAME")"
if [ "$actual_archive" != "$expected_archive" ]; then
echo "ERROR: archive checksum mismatch" >&2
exit 1
fi
verify_manifest_file "SKILL.md" "$TMP_DIR/SKILL.md"
verify_manifest_file "skill.json" "$TMP_DIR/skill.json"
echo "Signed release manifest, archive, SKILL.md, and skill.json verified."Only install or extract the archive after this verification succeeds.
Generate deterministic Hermes posture attestations, verify them with fail-closed integrity checks, and compare baseline drift using stable severity mapping.
When installing from community sources, configure Hermes guard to use signature-aware trust (trusted signer fingerprint allowlist) rather than source-name-only trust. Unknown signer fingerprints should stay on community policy, and invalid signatures must remain blocked.
# Generate attestation (default output: ~/.hermes/security/attestations/current.json) node scripts/generate_attestation.mjs # Generate with explicit policy + deterministic timestamp node scripts/generate_attestation.mjs \ --policy ~/.hermes/security/attestation-policy.json \ --generated-at 2026-04-15T18:00:00.000Z \ --write-sha256 # Verify schema + canonical digest node scripts/verify_attestation.mjs --input ~/.hermes/security/attestations/current.json # Verify with baseline diff (baseline must be authenticated) node scripts/verify_attestation.mjs \ --input ~/.hermes/security/attestations/current.json \ --baseline ~/.hermes/security/attestations/baseline.json \ --baseline-expected-sha256 <trusted-baseline-sha256> \ --fail-on-severity high # Optional detached signature verification node scripts/verify_attestation.mjs \ --input ~/.hermes/security/attestations/current.json \ --signature ~/.hermes/security/attestations/current.json.sig \ --public-key ~/.hermes/security/keys/attestation-public.pem # Refresh advisory feed verification state (fail-closed by default) node scripts/refresh_advisory_feed.mjs # Check advisory feed verification + feed summary node scripts/check_advisories.mjs # Guarded advisory-aware skill verification gate (returns 42 on advisory match without explicit confirm) node scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3 # Explicit operator acknowledgement path for advisory matches node scripts/guarded_skill_verify.mjs --skill some-skill --version 1.2.3 --confirm-advisory # Optional temporary unsigned bypass (dangerous; emergency-only) HERMES_ADVISORY_ALLOW_UNSIGNED_FEED=1 node scripts/refresh_advisory_feed.mjs --allow-unsigned # Preview scheduler config without mutating user schedule state node scripts/setup_attestation_cron.mjs --every 6h --print-only # Apply managed scheduler block node scripts/setup_attestation_cron.mjs --every 6h --apply # Preview advisory check scheduler config (guarded flow, print-only default) node scripts/setup_advisory_check_cron.mjs --every 6h --skill some-skill --print-only # Apply advisory check sch
A complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and variants). Protect your SOUL.md (etc') with drift detection, live security recommendations, automated audits, and skill integrity verification. All from one installable suite.
Repo: prompt-security/clawsec
Release automation for Claw skills and website. Guides through version bumping, tagging, and release verification.
ClawHub reputation checker for clawsec-suite. Adds a standalone reputation gate before guarded skill installation.
Security advisory feed package for OpenClaw-related threats and vulnerabilities. The upstream feed is updated daily; local automation is handled by…
Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub…
ClawSec suite manager with embedded advisory-feed monitoring, cryptographic signature verification, approval-gated malicious-skill response, and guided setup…