Docs
Docs/Compare

Clawkeeper vs ClawSec

How Clawkeeper compares to ClawSec by Prompt Security, an OpenClaw skill suite for advisory monitoring and skill reputation.

25
Clawkeeper only
1
Both
5
ClawSec only
Key Differentiator

ClawSec runs inside the agent to monitor skill advisories. Clawkeeper runs outside the agent to scan the entire deployment stack — host OS, network, containers, config, and credentials. They're complementary, not competing.

At a Glance

ClawkeeperClawSec
TypeExternal scanner + dashboardOpenClaw skill (runs inside agent)
Checks55 automated across 5 phases~12 (advisory + reputation + audit)
ScopeFull-stack: host + network + container + configOpenClaw-only: skills + advisories
PlatformmacOS + Linux (bare metal, Docker, K8s)Any OS with Node.js
RemediationInteractive auto-fix for 20+ issuesAdvisory-gated skill removal only
DashboardPro web dashboard with fleet monitoringNone (CLI output only)
DeploymentIndependent bash script (zero deps)Installed as OpenClaw skill
PricingFree (1 workstation) / Pro $19/mo / Team $29/seat/mo (min 3) / EnterpriseFree (open source)

Feature-by-Feature Comparison

FeatureClawkeeperClawSec
Host OS hardening (firewall, disk encryption, users)
Network security (mDNS, ports, SSH, screen sharing)
Container security (13 Docker sub-checks)
Gateway config audit (bind, auth, UI, mDNS)
Advanced gateway (elevated tools, browser, proxies)
Sandbox & execution policy
DM scope & policy
Credential scanning (config, history, memory, sessions)
Credential store permissions
SOUL.md integrity (injection, steganography, base64)
Skills static analysis (install cmds, exfiltration)
.env file security
Session prompt injection detection
Session rogue command scanning
MEMORY.md prompt injection detection
Skills prompt injection detection
Log file content scanning
CVE / version vulnerability check
Cryptographic advisory feed
Skill reputation scoring (7-check system)
Guarded skill installation hook
Real-time advisory monitoring (heartbeat)
Advisory suppression config
A-F letter grade + scoring
Interactive auto-fix (20+ remediations)
Fleet monitoring dashboard
AI-powered security insights
Email & webhook alerting
Score trend tracking
Skill Marketplace (13K+ community skills)
Enterprise plan with SSO & SLA

Where ClawSec Excels

Cryptographic advisory feed — ClawSec maintains a signed JSON feed with Ed25519 signatures and SHA-256 checksums, automatically polling NVD for new OpenClaw CVEs via GitHub Actions.

Skill reputation scoring — A 7-check system (existence, age, staleness, author reputation, downloads, VirusTotal, version validation) with a 0-100 score and configurable threshold.

Guarded installation — Intercepts clawhub install to block unsafe skills before they're installed. Clawkeeper scans post-installation.

Real-time monitoring — Hook-based heartbeat runs every 5 minutes inside the agent, checking for new advisories matching installed skills.

Where Clawkeeper Excels

Full-stack coverage — 55 checks across host OS, network, containers, OpenClaw config, credentials, skills, CVEs, and SOUL.md. ClawSec only covers skills and advisories.

External trust boundary — Clawkeeper runs outside the agent as an independent bash script. If the agent is compromised, the scanner still works. ClawSec runs inside the agent.

Interactive remediation — Auto-fix for 20+ issues with user confirmation: firewalls, permissions, SSH hardening, skill quarantine, and more. ClawSec only removes skills matching advisories.

Fleet dashboard — Centralized web dashboard with historical trends, A-F grades, alert rules, and team management. ClawSec has no monitoring UI.

Enterprise path — Unlimited hosts, SSO/SAML, dedicated support, and SLA. ClawSec has no enterprise offering.

Claude Code SecurityClawkeeper only

ClawSec is an OpenClaw skill — it has no support for Claude Code whatsoever. Clawkeeper is the only platform providing real-time security monitoring for Claude Code workstations.

FeatureClawkeeperClawSec
Claude Code Runtime Shield (55+ patterns, PreToolUse blocking)
Claude Code workstation fleet management
Claude Code team policies (blocked tools, paths, commands, skills)
MCP skill monitoring and policy enforcement
GitHub integration (auto-PR hooks config)
JAMF / MDM deployment support
Identity provider sync (Entra, Google, Okta)

ClawSec operates entirely within the OpenClaw agent runtime. It cannot monitor, manage, or enforce policies on Claude Code sessions.

Recommendation

Use both. ClawSec and Clawkeeper are complementary — they cover different layers of the security stack with essentially zero overlap. ClawSec handles real-time advisory monitoring and supply-chain gating inside the agent. Clawkeeper handles full-stack security posture scanning from the outside. For Claude Code security, Clawkeeper is the only option.