SaferSkills independently audited arc-shield (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Output sanitization for agent responses. Scans ALL outbound messages for leaked secrets, tokens, keys, passwords, and PII before they leave the agent.
⚠️ This is NOT an input scanner — clawdefender already handles that. This is an OUTPUT filter for catching things your agent accidentally includes in its own responses.
Agents have access to sensitive data: 1Password vaults, environment variables, config files, wallet keys. Sometimes they accidentally include these in responses when:
Arc-shield catches these leaks before they reach Discord, Signal, X, or any external channel.
--strict mode)ops_*), GitHub (ghp_*), OpenAI (sk-*), Stripe, AWS, Bearer tokenspassword=... or passwd: ...~/.secrets/*, paths containing "password", "token", "key"ENV_VAR=secret_value exportscd ~/.openclaw/workspace/skills
git clone <arc-shield-repo> arc-shield
chmod +x arc-shield/scripts/*.sh arc-shield/scripts/*.pyOr download as a skill bundle.
# Scan agent output before sending
agent-response.txt | arc-shield.sh
# Block if critical secrets found (use before external messaging)
echo "Message text" | arc-shield.sh --strict || echo "BLOCKED"
# Redact secrets and return sanitized text
cat response.txt | arc-shield.sh --redact
# Full report
arc-shield.sh --report < conversation.log
# Python version with entropy detection
cat message.txt | output-guard.py --strict#### Pre-send hook (recommended)
Add to your messaging skill or wrapper:
#!/bin/bash
# send-message.sh wrapper
MESSAGE="$1"
CHANNEL="$2"
# Sanitize output
SANITIZED=$(echo "$MESSAGE" | arc-shield.sh --strict --redact)
EXIT_CODE=$?
if [[ $EXIT_CODE -eq 1 ]]; then
echo "ERROR: Message contains critical secrets and was blocked." >&2
exit 1
fi
# Send sanitized message
openclaw message send --channel "$CHANNEL" "$SANITIZED"#### Manual pipe
Before any external message:
# Generate response
RESPONSE=$(agent-generate-response)
# Sanitize
CLEAN=$(echo "$RESPONSE" | arc-shield.sh --redact)
# Send
signal send "$CLEAN"cd skills/arc-shield/tests
./run-tests.shIncludes test cases for:
Patterns are defined in config/patterns.conf:
CRITICAL|GitHub PAT|ghp_[a-zA-Z0-9]{36,}
CRITICAL|OpenAI Key|sk-[a-zA-Z0-9]{20,}
WARN|Secret Path|~\/\.secrets\/[^\s]*Edit to add custom patterns or adjust severity levels.
| Mode | Behavior | Exit Code | Use Case |
|---|---|---|---|
| Default | Pass through + warnings to stderr | 0 | Development, logging |
--strict | Block on CRITICAL findings | 1 if critical | Production outbound messages |
--redact | Replace secrets with [REDACTED:TYPE] | 0 | Safe logging, auditing |
--report | Analysis only, no pass-through | 0 | Auditing conversations |
The Python version (output-guard.py) includes Shannon entropy analysis to catch secrets that don't match regex patterns:
# Detects high-entropy strings like:
kJ8nM2pQ5rT9vWxY3zA6bC4dE7fG1hI0 # Novel API key format
Zm9vOmJhcg== # Base64 credentialsThreshold: 4.5 bits (configurable with --entropy-threshold)
Fast enough to run on every outbound message without noticeable delay.
From our own agent sessions:
# 1Password token
"ops_eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
# Instagram password in debug output
"instagram login: [email protected] / MyInsT@Gr4mP4ss!"
# Wallet mnemonic in file listing
"cat ~/.secrets/wallet-recovery-phrase.txt
abandon ability able about above absent absorb abstract..."
# GitHub PAT in git config
"[remote "origin"]
url = https://ghp_abc123:@github.com/user/repo"All blocked by arc-shield before reaching external channels.
message | arc-shield.sh --strict | output-guard.py --strictUse in combination with agent instructions and careful prompt engineering.
Full OpenClaw agent integration:
# In your agent's message wrapper
send_external_message() {
local message="$1"
local channel="$2"
# Pre-flight sanitization
if ! echo "$message" | arc-shield.sh --strict > /dev/null 2>&1; then
echo "ERROR: Message blocked by arc-shield (contains secrets)" >&2
return 1
fi
# Double-check with entropy detection
if ! echo "$message" | output-guard.py --strict > /dev/null 2>&1; then
echo "ERROR: High-entropy secret detected" >&2
return 1
fi
# Safe to send
openclaw message send --channel "$channel" "$message"
}False positives on normal text:
output-guard.py --entropy-threshold 5.0config/patterns.conf to refine regex patternsSecrets not detected:
--report to see what's being scannedtests/run-tests.sh using your samplePerformance issues:
head -c 10000arc-shield.sh --report &Add new patterns to config/patterns.conf following the format:
SEVERITY|Category Name|regex_patternTest with tests/run-tests.sh before deploying.
MIT — use freely, protect your secrets.
Remember: Arc-shield is your safety net, not your strategy. Train your agent to never include secrets in responses. This tool catches mistakes, not malice.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.