档案库 · 开发与企业工具 · 产品决策 · 2026
ClawSecure押注OpenClaw代理需要自己的CrowdStrike:PH #2上线
前Web3创始人J.D. Salbego为OpenClaw技能生态构建安全层——PH第2名,338赞,24小时内1498次扫描
ClawSecure (ClawSecure, Inc.)
做的是什么生意
ClawSecure is the security layer for OpenClaw, the open-source AI-agent ecosystem: a free scanner audits a community skill before installation (3-layer audit, OWASP ASI Top-10 coverage, 55+ OpenClaw-specific threat patterns), Watchtower re-verifies installed skills whenever their code changes, and a Security Clearance API plus verified-agent marketplace extend the trust layer to platforms.
起因
J.D. Salbego, a two-time exited founder with a decade in AI and Web3 (previous roles at or with JP Morgan, Galaxy Digital, Bloomberg and NYSE), watched OpenClaw grow into an open-source agent ecosystem where anyone could install community skills that inherit the agent's access. Finding 41% of popular skills dangerous, he founded ClawSecure in early 2026 as an independent integrity layer for agent skills and workflows.
经过
ClawSecure shipped a free OpenClaw skill scanner in Feb 2026, then launched on Product Hunt on 2026-03-15, finishing #2 Product of the Day behind DynamicLake and ahead of Google Workspace CLI with 338 upvotes and 72 comments; the company reports 1,498 users scanned agents in the first 24 hours. Its audit of 2,890+ community skills (published 2026-03-26) found 41% with at least one vulnerability, 30.6% rated high or critical, 18.7% with ClawHavoc malware indicators and 99.3% shipping without a permissions manifest. The same week it announced formal NIST AI RMF alignment plus 24/7 Watchtower hash-drift monitoring (661 code changes detected) and Cloud Security Alliance STAR Registry membership.
结果
Still live as of 2026-09-04 and expanding beyond OpenClaw: the free scanner, Watchtower monitoring, Security Clearance API and an AI CISO now cover Claude Code, Cursor, OpenAI agents and more, with paid runtime tiers in pre-launch; no funding round or shutdown disclosed.
背景
ClawSecure是开源AI代理生态OpenClaw的安全平台。其免费扫描器在用户安装前审计社区编写的技能——三层审计,覆盖OWASP ASI Top-10,55+个OpenClaw特定威胁模式——而Watchtower全天候监控已安装的技能,并在代码变更时重新审计。付费的深度服务包括深层审计、持续监控和安全许可API,让市场嵌入信任检查。
创始人J.D. Salbego是一位两次成功退出的创始人,在AI和Web3领域有十年经验(摩根大通、Galaxy Digital、彭博、纽交所),在得出结论OpenClaw技能注册表是一个开放的安全缺口后于2026年初创立ClawSecure:用户安装的社区技能继承全部代理访问权,他的审计发现41%的流行技能危险。2026年3月15日的PH发布以338票和72条评论成为当日第二,公司称首24小时有1498名用户扫描代理。
ClawSecure发布的2890+个技能审计(2026年3月26日)发现41%有至少一个漏洞,30.6%为高危或严重,18.7%有ClawHavoc恶意软件迹象,99.3%未附带权限清单。同周宣布正式符合NIST AI RMF并推出24/7 Watchtower哈希漂移监控。截至2026年9月,平台已上线,提供扫描器、Watchtower、API和验证市场开发中;所有漏洞统计均为公司自身的发现。
这件事要成立,得有什么
- OpenClaw的注册表允许任何人安装具有代理级访问权限的技能,而没有真正的审查——这是具体的、非捏造的安全缺口。
- 安装后的持续监控(Watchtower)解决了一次性扫描器可能遗漏的潜伏代理问题,让用户有理由在免费扫描后继续付费。
- 框架符合——NIST AI RMF和OWASP ASI Top-10全面覆盖——让一家小型初创公司能进入受监管环境,而不会被忽视。
- 在OpenClaw自身炒作周期中于PH发布,带来了即时分发:首日第2,24小时1500次扫描。
可借鉴之处
新平台以功能为先、安全为后;提供扫描器加持续监控的供应商可以拥有信任层,并借助平台自身的热度而非与老牌厂商竞争。
后续进展
截至2026年9月4日,ClawSecure在clawsecure.ai上线:免费无需注册扫描器(三层审计,OWASP ASI Top-10,55+威胁模式),Watchtower 24/7监控,安全许可API,以及AI CISO(Claw)支持聊天、终端和MCP,付费的Shield/Sentinel/Fortress层已预上线。据EveryDev.ai,验证的OpenClaw市场原计划于2026年第二季度推出。2026年3月获得NIST AI RMF符合和CSA STAR注册;Watchtower在2890+技能中记录了661次代码变更。统计数据为ClawSecure自身研究,非独立研究;未披露融资或关闭。
资料来源
- ClawSecure Launches NIST AI RMF Alignment for OpenClaw Agents
- ClawSecure - A complete security platform for OpenClaw AI agents | Product Hunt Launch Overview
- Product Hunt Daily | 2026-03-16
- ClawSecure, Inc. - 1 AI Tool | EveryDev.ai
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡