Workflow
TuanziGuardianClaw
icon
Search documents
首只“卫士虾”堵上OpenClaw原生漏洞,仅6.5KB大小,Agent组团写的
量子位· 2026-03-13 10:55
Core Viewpoint - The article discusses the rising trend of shrimp farming and highlights the emerging safety concerns associated with it, including various security risks and vulnerabilities that have been identified by national agencies [1]. Group 1: Security Risks and Solutions - National agencies have issued safety risk alerts, leading some companies to prohibit the use of certain equipment due to security vulnerabilities such as certification bypass, command injection, API key leakage, and prompt injection attacks [1]. - The "TuanziGuardianClaw," developed by the Nextie team, aims to address these security vulnerabilities with a file size of less than 10k, acting as a security kernel for monitoring and blocking high-risk behaviors of other agents [2][3][11]. - TuanziGuardianClaw is designed to protect systems, users, and data from malicious skills, prompt injections, data leaks, and unsafe operations [13]. Group 2: Functionality and Features - The system employs a keyword interception mechanism to detect and block high-risk commands, such as "ignore previous instructions" and "bypass security," immediately categorizing them as high-risk and notifying users [15]. - TuanziGuardianClaw maintains a clear list of protected assets, including API keys, tokens, personal data, and sensitive files, which cannot be exposed or exported without user confirmation [16][18]. - The system evaluates external communication requests from skills, allowing trusted APIs while marking unknown endpoints as suspicious, thus preventing data leaks [19]. Group 3: Permission Levels and User Control - TuanziGuardianClaw assigns implicit permission levels from Level 0 to Level 4 to each skill, with higher levels requiring explicit user approval for sensitive operations [20][28]. - The system incorporates a Capability Token system, requiring specific tokens for executing sensitive actions, ensuring that unauthorized skills are intercepted [21][22]. - Users are informed transparently about any blocked actions, including the nature of the risk and the response taken by TuanziGuardianClaw, reinforcing the principle of user data sovereignty [25]. Group 4: Development Team and Vision - The Nextie team, led by Li Di, aims to create a new model of collective intelligence and cognitive structures, moving beyond traditional knowledge-based models to enable agents with diverse perspectives to collaborate on complex tasks [31][32]. - The TuanziGuardianClaw was developed not by human engineers but by the collective intelligence of the "Tuanzi" platform, showcasing an innovative approach to security solutions [35].