clawpatrol
Security firewall that gates AI agent traffic
TLDR
SYNOPSIS
clawpatrol subcommand [options]
DESCRIPTION
clawpatrol is a security firewall for AI agents. It sits between an agent and the systems it talks to, parses the traffic at the wire level, and evaluates each action against rules you write in HCL before letting it through. Because it inspects protocol facts rather than just URLs, rules can react to specifics such as a destructive SQL statement or a dangerous Kubernetes call and block them or require human approval.It runs in three shapes. The gateway loads a policy file and proxies traffic for everything pointed at it; join connects a host to a gateway over a WireGuard tunnel; and run wraps a single process so only that program's traffic is filtered, using network namespaces on Linux and the Network Extension framework on macOS.
PARAMETERS
gateway CONFIG
Run the proxy, loading policy from the given HCL file.join GATEWAY-URL
Connect this host to a running gateway through a WireGuard tunnel.run COMMAND
Launch COMMAND with its network traffic routed through clawpatrol.
CAVEATS
Policies are written in HCL and enforce wire-level protocol facts, so coverage depends on clawpatrol understanding the protocol in use. Per-process wrapping relies on platform-specific networking (network namespaces on Linux, Network Extension on macOS).
