EN
返回档案库

档案库 · 开发与企业工具 · 产品决策 · 2026

ClawSecure押注OpenClaw代理需要自己的CrowdStrike:PH #2上线

前Web3创始人J.D. Salbego为OpenClaw技能生态构建安全层——PH第2名,338赞,24小时内1498次扫描

ClawSecure (ClawSecure, Inc.)

它在赌什么代理成为核心攻击面,因此OpenClaw需要自己的CrowdStrike:安装前扫描技能,全天候监控,并将信任层卖给市场。已上线

做的是什么生意

ClawSecure is the security layer for OpenClaw, the open-source AI-agent ecosystem: a free scanner audits a community skill before installation (3-layer audit, OWASP ASI Top-10 coverage, 55+ OpenClaw-specific threat patterns), Watchtower re-verifies installed skills whenever their code changes, and a Security Clearance API plus verified-agent marketplace extend the trust layer to platforms.

起因

J.D. Salbego, a two-time exited founder with a decade in AI and Web3 (previous roles at or with JP Morgan, Galaxy Digital, Bloomberg and NYSE), watched OpenClaw grow into an open-source agent ecosystem where anyone could install community skills that inherit the agent's access. Finding 41% of popular skills dangerous, he founded ClawSecure in early 2026 as an independent integrity layer for agent skills and workflows.

经过

ClawSecure shipped a free OpenClaw skill scanner in Feb 2026, then launched on Product Hunt on 2026-03-15, finishing #2 Product of the Day behind DynamicLake and ahead of Google Workspace CLI with 338 upvotes and 72 comments; the company reports 1,498 users scanned agents in the first 24 hours. Its audit of 2,890+ community skills (published 2026-03-26) found 41% with at least one vulnerability, 30.6% rated high or critical, 18.7% with ClawHavoc malware indicators and 99.3% shipping without a permissions manifest. The same week it announced formal NIST AI RMF alignment plus 24/7 Watchtower hash-drift monitoring (661 code changes detected) and Cloud Security Alliance STAR Registry membership.

结果

Still live as of 2026-09-04 and expanding beyond OpenClaw: the free scanner, Watchtower monitoring, Security Clearance API and an AI CISO now cover Claude Code, Cursor, OpenAI agents and more, with paid runtime tiers in pre-launch; no funding round or shutdown disclosed.

背景

ClawSecure是开源AI代理生态OpenClaw的安全平台。其免费扫描器在用户安装前审计社区编写的技能——三层审计,覆盖OWASP ASI Top-10,55+个OpenClaw特定威胁模式——而Watchtower全天候监控已安装的技能,并在代码变更时重新审计。付费的深度服务包括深层审计、持续监控和安全许可API,让市场嵌入信任检查。

创始人J.D. Salbego是一位两次成功退出的创始人,在AI和Web3领域有十年经验(摩根大通、Galaxy Digital、彭博、纽交所),在得出结论OpenClaw技能注册表是一个开放的安全缺口后于2026年初创立ClawSecure:用户安装的社区技能继承全部代理访问权,他的审计发现41%的流行技能危险。2026年3月15日的PH发布以338票和72条评论成为当日第二,公司称首24小时有1498名用户扫描代理。

ClawSecure发布的2890+个技能审计(2026年3月26日)发现41%有至少一个漏洞,30.6%为高危或严重,18.7%有ClawHavoc恶意软件迹象,99.3%未附带权限清单。同周宣布正式符合NIST AI RMF并推出24/7 Watchtower哈希漂移监控。截至2026年9月,平台已上线,提供扫描器、Watchtower、API和验证市场开发中;所有漏洞统计均为公司自身的发现。

这件事要成立,得有什么

  • OpenClaw的注册表允许任何人安装具有代理级访问权限的技能,而没有真正的审查——这是具体的、非捏造的安全缺口。
  • 安装后的持续监控(Watchtower)解决了一次性扫描器可能遗漏的潜伏代理问题,让用户有理由在免费扫描后继续付费。
  • 框架符合——NIST AI RMF和OWASP ASI Top-10全面覆盖——让一家小型初创公司能进入受监管环境,而不会被忽视。
  • 在OpenClaw自身炒作周期中于PH发布,带来了即时分发:首日第2,24小时1500次扫描。

可借鉴之处

新平台以功能为先、安全为后;提供扫描器加持续监控的供应商可以拥有信任层,并借助平台自身的热度而非与老牌厂商竞争。

后续进展

截至2026年9月4日,ClawSecure在clawsecure.ai上线:免费无需注册扫描器(三层审计,OWASP ASI Top-10,55+威胁模式),Watchtower 24/7监控,安全许可API,以及AI CISO(Claw)支持聊天、终端和MCP,付费的Shield/Sentinel/Fortress层已预上线。据EveryDev.ai,验证的OpenClaw市场原计划于2026年第二季度推出。2026年3月获得NIST AI RMF符合和CSA STAR注册;Watchtower在2890+技能中记录了661次代码变更。统计数据为ClawSecure自身研究,非独立研究;未披露融资或关闭。

资料来源

发现哪里写错了?告诉我们。

轮到你了

你刚读完一家。说说你在做什么,看看谁在赌同一件事。

免费账号 · 3 次免费提问 · 不用绑卡

相关案例