EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2026

ClawSecure bets OpenClaw agents need their own CrowdStrike: PH #2 launch

Ex-Web3 founder J.D. Salbego builds the security layer for OpenClaw's skill ecosystem — PH #2, 338 upvotes, 1,498 scans in 24h

ClawSecure (ClawSecure, Inc.)

The betThat agents become a core attack surface, so OpenClaw needs its own CrowdStrike: scan skills before install, monitor them 24/7, and sell that trust layer to marketplaces.Live

What the business is

ClawSecure is the security layer for OpenClaw, the open-source AI-agent ecosystem: a free scanner audits a community skill before installation (3-layer audit, OWASP ASI Top-10 coverage, 55+ OpenClaw-specific threat patterns), Watchtower re-verifies installed skills whenever their code changes, and a Security Clearance API plus verified-agent marketplace extend the trust layer to platforms.

How it started

J.D. Salbego, a two-time exited founder with a decade in AI and Web3 (previous roles at or with JP Morgan, Galaxy Digital, Bloomberg and NYSE), watched OpenClaw grow into an open-source agent ecosystem where anyone could install community skills that inherit the agent's access. Finding 41% of popular skills dangerous, he founded ClawSecure in early 2026 as an independent integrity layer for agent skills and workflows.

What happened

ClawSecure shipped a free OpenClaw skill scanner in Feb 2026, then launched on Product Hunt on 2026-03-15, finishing #2 Product of the Day behind DynamicLake and ahead of Google Workspace CLI with 338 upvotes and 72 comments; the company reports 1,498 users scanned agents in the first 24 hours. Its audit of 2,890+ community skills (published 2026-03-26) found 41% with at least one vulnerability, 30.6% rated high or critical, 18.7% with ClawHavoc malware indicators and 99.3% shipping without a permissions manifest. The same week it announced formal NIST AI RMF alignment plus 24/7 Watchtower hash-drift monitoring (661 code changes detected) and Cloud Security Alliance STAR Registry membership.

How it ended up

Still live as of 2026-09-04 and expanding beyond OpenClaw: the free scanner, Watchtower monitoring, Security Clearance API and an AI CISO now cover Claude Code, Cursor, OpenAI agents and more, with paid runtime tiers in pre-launch; no funding round or shutdown disclosed.

Background

ClawSecure is a security platform for OpenClaw, the open-source AI-agent ecosystem. Its free scanner audits a community-written skill before a user installs it — 3-layer audit, OWASP ASI Top-10 coverage, 55+ OpenClaw-specific threat patterns — while Watchtower monitors installed skills around the clock and re-audits them whenever their code changes. Paid depth comes from deep audits, continuous monitoring and a Security Clearance API that lets marketplaces embed trust checks.

Founder J.D. Salbego, a two-time exited founder with a decade in AI and Web3 (JP Morgan, Galaxy Digital, Bloomberg, NYSE), founded ClawSecure in early 2026 after concluding the OpenClaw skill registry was an open security gap: users installed community skills that inherited full agent access, and his audits found 41% of popular skills dangerous. The PH launch on 2026-03-15 finished #2 Product of the Day with 338 upvotes and 72 comments, and the company says 1,498 users scanned agents in the first 24 hours.

ClawSecure's published audit of 2,890+ skills (2026-03-26) found 41% with at least one vulnerability, 30.6% rated high or critical, 18.7% with ClawHavoc malware indicators and 99.3% without a permissions manifest. The same week it announced formal NIST AI RMF alignment and 24/7 Watchtower hash-drift monitoring. As of Sept 2026 the platform is live with a scanner, Watchtower, API and a verified marketplace in progress; all vulnerability statistics are the company's own findings.

What has to be true

  • OpenClaw's registry let anyone install skills with agent-level access and no real review — a concrete security gap, not a manufactured one.
  • Continuous post-install monitoring (Watchtower) addressed the sleeper-agent problem one-time scanners miss, giving users a reason to keep paying after the free scan.
  • Framework alignment — NIST AI RMF and full OWASP ASI Top-10 coverage — let a tiny startup sell into regulated environments that would ignore an uncredentialed agent scanner.
  • Launching on PH during OpenClaw's own hype cycle delivered instant distribution: #2 Product of the Day with ~1,500 scans in the first 24 hours.

What can be applied

New platforms grow feature-first and security-last; the vendor that ships a scanner plus continuous monitoring can own the trust layer and ride the platform's own hype instead of fighting incumbents.

Aftermath

As of 2026-09-04 ClawSecure is live at clawsecure.ai: a free no-signup scanner (3-layer audit, OWASP ASI Top-10, 55+ threat patterns), Watchtower 24/7 monitoring, a Security Clearance API, and an AI CISO (Claw) in chat, terminal and MCP, with paid Shield/Sentinel/Fortress tiers in pre-launch. A verified OpenClaw marketplace was expected Q2 2026 per EveryDev.ai. March 2026 brought NIST AI RMF alignment and CSA STAR Registry membership; Watchtower logged 661 code changes across 2,890+ skills. Statistics are ClawSecure's own findings, not independent research; no funding or shutdown disclosed.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases