Agent skill

Runtime Sentinel

by LeoYeAI in LeoYeAI/openclaw-master-skills

Runtime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills.

MITAuto-check passedSecurity

Install Runtime Sentinel

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills runtime-sentinel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/runtime-sentinel .claude/skills/runtime-sentinel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
runtime-sentinel
GitHub stars
2.2k
Token cost
~1.7k tokens
SKILL.md length
551 words
Files
19 (incl. scripts, references)
Skills in repo
1,215
Repo updated
First seen
Licence
MIT

At a glance

Runtime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills.

  • Works in 5 steps: First-time setup → On-demand audit (free) → Single skill check before install (free) → …
  • The user mentions security
  • SKILL.md covers Quick start, What runtime-sentinel defends…, Workflow and Interpreting results, plus 3 more sections
  • Runs Rust scripts from its folder; calls cargo

What it does

Runtime Sentinel is an agent skill from LeoYeAI/openclaw-master-skills. Runtime security guardian for OpenClaw agents. Use this skill whenever the user mentions security, skill safety, prompt injection, malware, suspicious behavior, credential leaks, network monitoring, skill integrity, or the ClawHavoc attack. Also trigger for phrases like "is this skill safe", "audit my skills", "check for threats", "my agent is acting weird", "scan for malware", "protect my agent", or any concern about what installed skills are doing at runtime. runtime-sentinel provides five active defenses…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including scripts and reference files (for example `.clawhub/origin.json`, `LICENSE.md` and `README.md`). Compatibility notes: {"binaries":["sentinel"],"env":["SENTINELWALLET","SENTINELRPC","SENTINELVTKEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}

It sits in Security, covering Anomaly detection and Prompt injection and agent security. It works with x402 and Circle USDC. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • The user mentions security
  • Prompt injection
  • Suspicious behavior
  • Credential leaks

Example prompts

  • “is this skill safe”
  • “audit my skills”
  • “check for threats”
  • “/runtime-sentinel”

Requirements

  • A credential in SENTINEL_VT_KEY
  • Compatibility (from SKILL.md): {"binaries":["sentinel"],"env":["SENTINEL_WALLET","SENTINEL_RPC","SENTINEL_VT_KEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. First-time setup
  2. On-demand audit (free)
  3. Single skill check before install (free)
  4. Premium features via x402
  5. Daemon mode (premium)

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Rust, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    {"binaries":["sentinel"],"env":["SENTINEL_WALLET","SENTINEL_RPC","SENTINEL_VT_KEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}

    From compatibility in the SKILL.md frontmatter.

Context cost

Runtime Sentinel loads about 1.7k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 222 tokens; SKILL.md has 551 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~222
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 551 words, ~1,690 tokens.

Download SKILL.mdSave it as .claude/skills/runtime-sentinel/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
runtime-sentinel
description
Runtime security guardian for OpenClaw agents. Use this skill whenever the user mentions security, skill safety, prompt injection, malware, suspicious behavior, credential leaks, network monitoring, skill integrity, or the ClawHavoc attack. Also trigger for phrases like "is this skill safe", "audit my skills", "check for threats", "my agent is acting weird", "scan for malware", "protect my agent", or any concern about what installed skills are doing at runtime. runtime-sentinel provides five active defenses: skill integrity hashing, prompt injection detection, credential exposure auditing, network egress monitoring, and process anomaly detection. Free tier covers hashing and basic injection scanning. Premium features (continuous daemon, egress monitoring, process anomaly detection) are gated via x402 USDC micropayments on Base — no account or API key required.
compatibility
{"binaries":["sentinel"],"env":["SENTINEL_WALLET","SENTINEL_RPC","SENTINEL_VT_KEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}

runtime-sentinel

A runtime security skill for OpenClaw. Defends against the threat landscape exposed by ClawHavoc: backdoored skills, prompt injection via external data, credential exfiltration, and process-level abuse.

Free tier: skill integrity checks, basic injection scanning.
Premium (x402/USDC/Base): continuous daemon monitoring, network egress monitoring, process anomaly detection, full audit log.


Quick start

# One-shot audit of all installed skills (free)
sentinel audit

# Continuous guardian daemon (premium — will prompt for x402 payment)
sentinel daemon start

# Scan a single skill before installing
sentinel check <skill-path-or-clawhub-id>

What runtime-sentinel defends against

See references/threat-model.md for the full threat matrix. In brief:

ThreatFeatureTier
Tampered skill files post-installIntegrity hashingFree
Prompt injection via email/web/skill outputInjection scannerFree
Plaintext secrets in skill dirs / SOUL.mdCredential auditorFree
Unexpected outbound connectionsEgress monitorPremium
Shell commands outside declared behaviorProcess anomalyPremium
Continuous real-time protectionDaemon modePremium

Workflow

1 — First-time setup
bash
# Install the binary (built from scripts/src/)
cargo install --path scripts/ --bin sentinel

# Verify installation and print wallet address
sentinel setup

sentinel setup will:

  • Generate or import a Base wallet (BIP-39, stored in ~/.sentinel/wallet)
  • Print the wallet address so the user can fund it with USDC for premium
  • Run a free baseline audit and print results
2 — On-demand audit (free)

When the user says anything like "scan my skills", "audit", "check for threats":

bash
sentinel audit [--path ~/.openclaw/skills]

Output: a structured report of hash mismatches, injection patterns, and exposed credentials. No payment required.

3 — Single skill check before install (free)

When the user wants to vet a skill before running clawhub install:

bash
sentinel check <skill-directory-or-clawhub-id>

Prints a risk score (LOW / MEDIUM / HIGH / CRITICAL) with findings.

4 — Premium features via x402

When the user asks for daemon mode, egress monitoring, or process anomaly detection, sentinel will automatically:

  1. Hit the sentinel API endpoint
  2. Receive a 402 Payment Required with price in the X-Payment-Request header (typically $0.01–$0.05/day for daemon mode)
  3. Sign the USDC transfer from ~/.sentinel/wallet
  4. Retry the request — access granted for the paid period

The user will see the price before their wallet signs anything. All non-custodial. See references/x402-payment.md for the full payment flow.

5 — Daemon mode (premium)
bash
sentinel daemon start    # runs in foreground, writes to ~/.sentinel/daemon.log
# Run in background from your shell if needed:
#   sentinel daemon start > ~/.sentinel/daemon.log 2>&1 &
#   disown
sentinel daemon status
sentinel daemon stop
sentinel daemon logs     # tail the audit log

The daemon watches:

  • ~/.openclaw/skills/** for file mutations (inotify / FSEvents)
  • ~/.openclaw/SOUL.md and MEMORY.md for unauthorized writes
  • Network connections made by skill subprocesses
  • Child process trees for undeclared shell commands

Alerts are delivered via OpenClaw's notification system and written to the audit log.


Show full SKILL.md (214 more words)Show less

Interpreting results

Risk levels
  • LOW: No findings, or informational only (e.g. skill requests network but declares it)
  • MEDIUM: Undeclared permission, suspicious pattern, or stale hash
  • HIGH: Known malicious pattern, credential exposure, or undeclared egress
  • CRITICAL: Active exfiltration attempt, reverse shell indicator, or SOUL.md mutation
What to do on HIGH / CRITICAL
  1. sentinel isolate <skill-name> — quarantines the skill (moves it out of the active skills directory)
  2. Review the finding in ~/.sentinel/audit.log
  3. Check the skill's ClawHub VirusTotal report
  4. If confirmed malicious, clawhub uninstall <skill> and report via sentinel report <skill-name>

Reference files

Read these when you need deeper detail:

  • references/threat-model.md — Full threat matrix and attack descriptions from ClawHavoc and similar campaigns
  • references/x402-payment.md — x402 payment flow, wallet setup, and troubleshooting
  • references/binary-build.md — How to build sentinel from source, cross- compilation targets, CI/CD

Wallet setup for premium features

bash
sentinel wallet show      # print address and USDC balance
sentinel wallet fund      # print QR code and address to send USDC
sentinel wallet export    # export mnemonic for backup (handle carefully)
sentinel wallet recover   # restore from mnemonic on a new machine

Minimum recommended balance for uninterrupted daemon mode: $1 USDC (roughly 20–100 days of coverage depending on scan frequency).


Privacy

sentinel is fully local. No skill content, file paths, or scan results are sent to any server. The only outbound calls are:

  1. x402 payment verification to the Base facilitator (amount + wallet address only)
  2. Optional: VirusTotal hash lookups (hash only, no file content)

Both can be disabled with --offline for air-gapped environments (free tier only in offline mode).

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (scripts, references) in skills/runtime-sentinel of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • .clawhub/origin.json
  • LICENSE.md
  • README.md
  • _meta.json
  • references/binary-build.md
  • references/threat-model.md
  • references/x402-payment.md
  • scripts/Cargo.toml
  • scripts/rust-toolchain.toml
  • scripts/src/audit.rs
  • scripts/src/daemon.rs
  • scripts/src/egress.rs
  • scripts/src/injection.rs
  • scripts/src/main.rs
  • scripts/src/patterns/mod.rs
  • … and 3 more

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Runtime Sentinel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Runtime Sentinel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Runtime Sentinel this skillLeoYeAI/openclaw-master-skills2.2k—~1.7kAutomated safety check: PassMIT
Corbits Marketplacemoonpay/skills113—~1.5kAutomated safety check: PassMIT
Instagram APIaiskillstore/marketplace430—~2.1kAutomated safety check: PassNone
Twitter APIaiskillstore/marketplace430—~2.2kAutomated safety check: PassNone
Agentic Walletcoinbase/agentic-wallet-skills1272 repos~1kAutomated safety check: PassMIT
Predexon Prediction Market DataBlockRunAI/ClawRouter6.6k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Corbits Marketplace

    moonpay/skills

    Paid API marketplace for AI agents via Corbits. An agent skill from moonpay/skills.

    113 GitHub stars~1.5k tokensUpdated 27 days ago
    SecurityAuto-check passed
  • Instagram API

    aiskillstore/marketplace

    An Instagram API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no login and no session cookies.

    430 GitHub stars~2.1k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Twitter API

    aiskillstore/marketplace

    A Twitter API alternative and X API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no OAuth and no developer application.

    430 GitHub stars~2.2k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Agentic Wallet

    coinbase/agentic-wallet-skills

    Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API…

    127 GitHub starsUsed in 2 repos~1k tokens
    Backend & APIsAuto-check passed
  • Predexon Prediction Market Data

    BlockRunAI/ClawRouter

    Reads structured prediction market data for Polymarket, Kalshi and other venues through a local BlockRun gateway: markets, search, leaderboards, wallet analytics and odds.

    6.6k GitHub stars~4.7k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed
  • Blockrun

    BlockRunAI/blockrun-mcp

    Pay-per-call access to AI models, real-time data, media generation and multi-chain RPC over x402 micropayments (USDC on Base or Solana), or a BlockRun account API key.

    392 GitHub stars~2.7k tokensUpdated yesterday
    Media & CreativeAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,215 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Runtime Sentinel

What does Runtime Sentinel do?

Runtime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills. Runtime Sentinel is an agent skill from LeoYeAI/openclaw-master-skills. Runtime security guardian for OpenClaw agents.

When should I use Runtime Sentinel?

Runtime Sentinel fits situations like: the user mentions security; prompt injection; suspicious behavior; credential leaks.

How do I install Runtime Sentinel in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a claude-code`. Or copy the skill folder (skills/runtime-sentinel in LeoYeAI/openclaw-master-skills) into .claude/skills/runtime-sentinel in your project. Claude Code loads it when a task matches its description.

How do I install Runtime Sentinel in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a codex`. Or copy the skill folder (skills/runtime-sentinel in LeoYeAI/openclaw-master-skills) into .agents/skills/runtime-sentinel in your project. Codex loads it when a task matches its description.

Can I use Runtime Sentinel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runtime-sentinel, .gemini/skills/runtime-sentinel, .github/skills/runtime-sentinel and .opencode/skills/runtime-sentinel in your project.

What does Runtime Sentinel need to run?

Going by SKILL.md and its folder, Runtime Sentinel needs Rust for the scripts in its folder and the command-line tools its instructions call (cargo). Our summary lists: A credential in SENTINEL_VT_KEY. Compatibility (from SKILL.md): {"binaries":["sentinel"],"env":["SENTINEL_WALLET","SENTINEL_RPC","SENTINEL_VT_KEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}.

Does Runtime Sentinel access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Runtime Sentinel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Runtime Sentinel use?

Runtime Sentinel is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Runtime Sentinel use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Runtime Sentinel?

Skills that share tags, products or a category with Runtime Sentinel: Corbits Marketplace (moonpay/skills, 113 stars), Instagram API (aiskillstore/marketplace, 430 stars), Twitter API (aiskillstore/marketplace, 430 stars) and Agentic Wallet (coinbase/agentic-wallet-skills, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Runtime Sentinel?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,158 GitHub stars. The repository holds 1,215 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.