Voice
Verificate Openclaw Guard
The trust layer for OpenClaw β a hook plugin that gates every answer and code-writing tool call through Verificate before you trust it. Fail-open, free to try.
Configuration Example
{
"plugins": {
"entries": {
"verificate-guard": {
"hooks": { "allowConversationAccess": true },
"config": {
"gateCode": true,
"guardToolWrites": false
}
}
}
}
}
README
# Verificate Guard β the trust layer for OpenClaw
ClawHub skills are powerful but untrusted β security audits keep finding prompt injection, malware and credential theft in community skills, and every AI answer sounds confident whether it's right or wrong. **Verificate Guard makes quality structural**: it hooks OpenClaw so every answer is verified before you see it, not something the agent may skip.
Two hooks:
- **`before_agent_finalize`** β before OpenClaw presents a final answer, if it contains code, Verificate runs it through 17 deterministic reality gates (mock/placeholder veto, invented-API checks, false-completion detection) + a frontier-model review. On a **reject**, the guard asks the harness for one more pass with the findings β the agent self-corrects before you ever see the bad answer.
- **`before_tool_call`** *(opt-in)* β validates code inside write/patch tool calls (`apply_patch`, `write_file`, β¦) *before they touch disk*, and requires your approval if the reality gates reject it.
Calls the hosted [Verificate MCP server](https://mcp.verificate.ai/mcp) directly β no separate `openclaw mcp add` needed. **Free tier: 25 validations per machine, no signup.**
## Install & enable
`before_agent_finalize` reads conversation content, so OpenClaw requires an explicit operator opt-in. In your config:
```json
{
"plugins": {
"entries": {
"verificate-guard": {
"hooks": { "allowConversationAccess": true },
"config": {
"gateCode": true,
"guardToolWrites": false
}
}
}
}
}
```
## Config
| key | default | what |
|---|---|---|
| `token` | β | Optional Verificate token. Omit for the free tier; add one to continue past 25 ([trial](https://verificate.ai/auth/signup)). |
| `gateCode` | `true` | Gate final answers containing code. |
| `gateProse` | `false` | Also gate prose answers (validated as documents). |
| `guardToolWrites` | `false` | Validate code in write/patch tool calls; require approval on reject. |
| `maxRevisions` | `2` | Extra passes to request on a reject. |
| `timeoutMs` | `20000` | Per-validation budget; on timeout the guard **fails open**. |
## Trust by design
- **Fail-open.** If Verificate is unreachable or times out, your answer is **never** blocked β a guard that breaks the agent on a network hiccup is worse than no guard.
- **One egress only** β `https://mcp.verificate.ai/mcp`. Nothing else. Read-only: your code is analyzed, never executed, never trained on. Open source, MIT.
- The reality gates are **deterministic** β they can't be sweet-talked by a prompt-injected answer, which is exactly the failure mode plaguing untrusted skills.
Privacy: https://verificate.ai/privacy Β· All Verificate clients: https://github.com/Verificate-Dev/verificate-mcp-quickstart
voice
Comments
Sign in to leave a comment