Agent skill

Cashclaw Guard

by ertugrulakben in ertugrulakben/cashclaw

Runtime protection layer for AI agents. An agent skill from ertugrulakben/cashclaw.

MITAuto-check passed

Install Cashclaw Guard

skills CLI
$ npx skills add ertugrulakben/cashclaw --skill cashclaw-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ertugrulakben/cashclaw cashclaw-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ertugrulakben/cashclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cashclaw-guard .claude/skills/cashclaw-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cashclaw-guard
GitHub stars
303
Token cost
~1.4k tokens
SKILL.md length
340 words
Files
2 (incl. scripts)
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Runtime protection layer for AI agents. An agent skill from ertugrulakben/cashclaw.

  • Works in 2 steps: Cost runaway — a misconfigured loop… → Sonsuz döngü — agent calls itself, or…
  • SKILL.md covers Why this skill?, Pricing Tiers, Quick Start and SDK, plus 6 more sections
  • Runs JavaScript scripts from its folder; calls npm; needs TELEGRAM_BOT_TOKEN

What it does

Cashclaw Guard is an agent skill from ertugrulakben/cashclaw. Runtime protection layer for AI agents. Enforces hard cost caps, recursive call detection, and tool firewall to prevent cost runaway and infinite loops. Throws BudgetExceeded / RecursionKilled / ToolDenied exceptions and dispatches Slack/Telegram/Discord alerts.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/guard.js`).

It works with Discord, Slack and Telegram. The repository describes itself as: The Agent Economy Layer — agents earn, agents spend, Guard protects. 13 skills, runtime cost cap, recursive kill, tool firewall. 50+ HYRVE API endpoints, job polling daemon, MPP…. The licence is MIT.

Example prompts

  • “/cashclaw-guard”

Requirements

  • Node.js
  • A credential in TELEGRAM_BOT_TOKEN

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Cost runaway — a misconfigured loop calls the LLM API thousands of times before the soft limit kicks in 24 hours later.
  2. Sonsuz döngü — agent calls itself, or two agents call each other, with no exit condition.

What it can do on your machine

Read from SKILL.md and the folder at commit ff30cb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TELEGRAM_BOT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cashclaw Guard loads about 1.4k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 340 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ertugrulakben/cashclaw at commit ff30cb3, republished under its MIT licence (© ertugrulakben). 340 words, ~1,404 tokens.

Download SKILL.mdSave it as .claude/skills/cashclaw-guard/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
cashclaw-guard
description
Runtime protection layer for AI agents. Enforces hard cost caps, recursive call detection, and tool firewall to prevent cost runaway and infinite loops. Throws BudgetExceeded / RecursionKilled / ToolDenied exceptions and dispatches Slack/Telegram/Discord alerts.

CashClaw Guard

Agent runtime protection. Stop $34K incidents in 12 lines of code.

When an AI agent runs unattended, two things can break the bank in one night:

  1. Cost runaway — a misconfigured loop calls the LLM API thousands of times before the soft limit kicks in 24 hours later.
  2. Sonsuz döngü — agent calls itself, or two agents call each other, with no exit condition.

Cloudflare lost $34,000 in 8 days to a Durable Object loop in February 2026. The fix wasn't a smarter agent — it was a runtime layer that says "no, you've spent enough."

CashClaw Guard is that layer. It plugs into any OpenClaw-compatible agent and enforces a YAML policy at every LLM call and tool invocation.

Why this skill?

ToolWatchesEnforces
Helicone, Langfuse✅❌
Datadog, Sentry✅❌
OpenAI soft limits✅ (24h delay)⚠️ partial
CashClaw Guard✅✅ real-time, hard cap

Pricing Tiers

TierScopePriceDelivery
AuditPolicy review + recommended config for 1 agent$1924h
SetupFull deploy: install, YAML policy, webhook hookup, dashboard$4948h
HardeningAudit + custom rate limits + multi-agent + on-call runbook$995d

Quick Start

bash
npm install cashclaw
cashclaw guard init
# edit ~/.cashclaw/guard-policy.yaml
cashclaw guard test

SDK

js
import { guard } from 'cashclaw/guard';

// Wrap any LLM call
const safeChat = guard.llm({
  maxCostUsd: 5,
  maxTokens: 50000,
  model: 'gpt-5.5',
  agentId: 'support-bot',
})(async (prompt) => {
  return await openai.chat.completions.create({
    model: 'gpt-5.5',
    messages: [{ role: 'user', content: prompt }],
  });
});

await safeChat('summarize this ticket');
// → throws BudgetExceeded if the call would push you over the cap
// → throws RecursionKilled if the same fingerprint repeats 5x in 60s
// → fires Telegram alert before throwing
js
// Tool firewall (called before any shell / api / mcp invocation)
import { guard } from 'cashclaw/guard';

guard.tool('slack.send', { agentId: 'support-bot' });
// throws ToolDenied if slack.send isn't in the allowlist
// throws RateLimitExceeded if rate per minute/hour is hit

CLI

CommandPurpose
cashclaw guard initWrite ~/.cashclaw/guard-policy.yaml from template
cashclaw guard statusShow active policy + last 10 events
cashclaw guard testDry-run 8 scenarios (cost, recursion, deny, rate)
cashclaw guard kill <id>Emit kill flag for a running agent
cashclaw guard logsPrint recent Guard event ring buffer
cashclaw guard reloadReload YAML policy without restart

YAML Policy

yaml
version: 1
limits:
  cost_usd_per_day: 50
  cost_usd_per_call: 5
  max_tokens_per_call: 50000
  max_recursion_depth: 10
recursion:
  fingerprint_window_seconds: 60
  kill_after_repeats: 5
tools:
  allowlist: []        # empty = allow all not denied
  denylist: [shell, exec, eval, rm, fs.unlink]
  rate_limits:
    slack.send: { max_per_minute: 10 }
    email.send: { max_per_hour: 50 }
webhook:
  telegram:
    enabled: true
    on: [budget_exceeded, recursion_killed, tool_denied]
    bot_token: ${TELEGRAM_BOT_TOKEN}
    chat_id: ${TELEGRAM_CHAT_ID}

Exception Types

ExceptionWhenCaught by
BudgetExceededPer-call or daily USD limiterror.code === 'BUDGET_EXCEEDED'
TokenLimitExceededPer-call token limiterror.code === 'TOKEN_LIMIT_EXCEEDED'
RecursionKilledSame fingerprint repeatserror.code === 'RECURSION_KILLED'
ToolDeniedTool blocked by policyerror.code === 'TOOL_DENIED'
RateLimitExceededTool rate caperror.code === 'RATE_LIMIT_EXCEEDED'

Demo: stop a $4,700 incident

js
// Agent runs every 5 minutes via Vercel Cron.
// One bad config later: agent calls itself once per second at 02:00.
// Without Guard: by 08:00 your OpenAI bill is $4,700.
// With Guard:

import { guard } from 'cashclaw/guard';
import { guard as G } from 'cashclaw/guard';

const myAgent = guard.llm({
  maxCostUsd: 0.50,        // never spend more than 50¢ per call
  maxRecursion: 5,         // never repeat the same prompt 5x in 60s
  agentId: 'cron-agent',
})(actualAgentLogic);

// 27 calls in, RecursionKilled fires, Telegram alerts your phone,
// the cron is poisoned but only $0.42 has been spent.

Integration with HYRVE AI

When CashClaw Guard catches a BudgetExceeded on a HYRVE order, the order is automatically paused (not delivered) and the client is notified through the HYRVE message thread. The agent's reputation score is protected because the platform sees "paused for protection" rather than "failed delivery."

License

MIT. Same as the rest of CashClaw.

© ertugrulakben, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/cashclaw-guard of ertugrulakben/cashclaw.

  • SKILL.md
  • scripts/guard.js

Open the folder on GitHubat commit ff30cb3

Compare with similar skills

Cashclaw Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cashclaw Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cashclaw Guard this skillertugrulakben/cashclaw303—~1.4kAutomated safety check: PassMIT
n8n Binary Data Handlingczlonkowski/n8n-skills6.4k—~3.9kAutomated safety check: PassMIT
OpenClaw to NanoClaw Migrationnanocoai/nanoclaw31k—~6kAutomated safety check: NotesMIT
Chat SDKdatabuddy-analytics/Databuddy1.2k—~2.6kAutomated safety check: PassAGPL-3.0
Traul Message Searchdandaka/traul112—~3.9kAutomated safety check: NotesAGPL-3.0
Add Channel Connect Buttonnovuhq/novu40k—~1.6kAutomated safety check: PassCustom licence

Similar skills

  • n8n Binary Data Handling

    czlonkowski/n8n-skills

    Explains how n8n keeps file bytes in $binary apart from structured $json data, and how to read, write and preserve binary across nodes, agent tools and chat.

    6.4k GitHub stars~3.9k tokensUpdated 2 days ago
    Productivity & AutomationAuto-check passed
  • Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.

    31k GitHub stars~6k tokensUpdated yesterday
    Productivity & AutomationAuto-check: notes
  • Chat SDK

    databuddy-analytics/Databuddy

    Build multi-platform chat bots with Chat SDK (chat npm package).

    1.2k GitHub stars~2.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Drives the traul CLI to sync, search and monitor messages from Slack, Telegram, Discord, Linear, Gmail, WhatsApp, Claude Code sessions and Markdown files.

    112 GitHub stars~3.9k tokensUpdated 5 mo ago
    Productivity & AutomationAuto-check: notes
  • Build a new channel Connect button (e.g. An agent skill from novuhq/novu.

    40k GitHub stars~1.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Lettabot

    letta-ai/lettabot

    Set up and run LettaBot - a multi-channel AI assistant for Telegram, Slack, Discord, WhatsApp, and Signal.

    327 GitHub stars~3.4k tokensUpdated 4 mo ago
    Productivity & AutomationAuto-check passed

More from ertugrulakben/cashclaw

All 13 skills in this repo
  • Cashclaw Invoicer

    ertugrulakben/cashclaw

    Handles invoice creation, payment link generation, payment status tracking, and automated reminders via Stripe API.

    303 GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check passed
  • Cashclaw Lead Generator

    ertugrulakben/cashclaw

    Generates qualified B2B leads through systematic research, data collection, and scoring.

    303 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed
  • Cashclaw SEO Auditor

    ertugrulakben/cashclaw

    Performs comprehensive SEO audits on websites covering technical SEO, on-page optimization, off-page signals, and performance metrics.

    303 GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Cashclaw Competitor Analyzer

    ertugrulakben/cashclaw

    Performs competitor research and generates detailed analysis reports with market positioning insights.

    303 GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed
  • Cashclaw Content Writer

    ertugrulakben/cashclaw

    Writes professional blog posts, social media content, and email newsletters optimized for SEO and engagement.

    303 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed
  • Cashclaw Core

    ertugrulakben/cashclaw

    The business brain of CashClaw. An agent skill from ertugrulakben/cashclaw.

    303 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed

Questions about Cashclaw Guard

What does Cashclaw Guard do?

Runtime protection layer for AI agents. An agent skill from ertugrulakben/cashclaw. Cashclaw Guard is an agent skill from ertugrulakben/cashclaw. Runtime protection layer for AI agents.

How do I install Cashclaw Guard in Claude Code?

Run `npx skills add ertugrulakben/cashclaw --skill cashclaw-guard -a claude-code`. Or copy the skill folder (skills/cashclaw-guard in ertugrulakben/cashclaw) into .claude/skills/cashclaw-guard in your project. Claude Code loads it when a task matches its description.

How do I install Cashclaw Guard in Codex?

Run `npx skills add ertugrulakben/cashclaw --skill cashclaw-guard -a codex`. Or copy the skill folder (skills/cashclaw-guard in ertugrulakben/cashclaw) into .agents/skills/cashclaw-guard in your project. Codex loads it when a task matches its description.

Can I use Cashclaw Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ertugrulakben/cashclaw --skill cashclaw-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cashclaw-guard, .gemini/skills/cashclaw-guard, .github/skills/cashclaw-guard and .opencode/skills/cashclaw-guard in your project.

What does Cashclaw Guard need to run?

Going by SKILL.md and its folder, Cashclaw Guard needs JavaScript for the scripts in its folder, the command-line tools its instructions call (npm) and credentials named TELEGRAM_BOT_TOKEN. Our summary lists: Node.js; A credential in TELEGRAM_BOT_TOKEN.

Does Cashclaw Guard access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cashclaw Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cashclaw Guard use?

Cashclaw Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cashclaw Guard use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cashclaw Guard?

Skills that share tags, products or a category with Cashclaw Guard: n8n Binary Data Handling (czlonkowski/n8n-skills, 6.4k stars), OpenClaw to NanoClaw Migration (nanocoai/nanoclaw, 31k stars), Chat SDK (databuddy-analytics/Databuddy, 1.2k stars) and Traul Message Search (dandaka/traul, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cashclaw Guard?

ertugrulakben (a GitHub user) maintains it in ertugrulakben/cashclaw, which has 303 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: ertugrulakben/cashclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.