Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

OpenClaw plugin for Agent Control

Agent Control cat plus OpenClaw lobster
npm versionNode 24 or newerCICodecov

This plugin integrates OpenClaw with Agent Control, a security and policy layer for agent tool use. It registers OpenClaw tools with Agent Control and can block unsafe tool invocations before they execute.

Why use this?

  • Enforce policy before tool execution, so unsafe or disallowed actions never run.
  • Carry session and channel context into evaluations, so policies can reason about where a request came from and how the agent is being used.
    • Example: Only allow specific tools in slack channels, but allow fully if DM from an approved user.
      • Allow read tool, but only from an allowlist of paths.
  • Policies can be updated and propagated to your OpenClaw without having to reboot the gateway.

How it works

When the gateway starts, the plugin loads the OpenClaw tool catalog and syncs it to Agent Control. On every tool call, the plugin intercepts the invocation through a before_tool_call hook, builds an evaluation context (session, channel, provider, agent identity), and sends it to Agent Control for a policy decision. If the evaluation comes back safe the call proceeds normally. If it comes back denied the call is blocked and the user sees a rejection message.

The plugin handles multiple agents, caches the resolved tool catalog briefly to keep the pre-tool hook fast, and re-syncs automatically when the catalog drifts.

Quick start

Install and configure with the minimum required settings:

openclaw plugins install agent-control-openclaw-plugin
openclaw config set plugins.entries.agent-control-openclaw-plugin.enabled true
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.serverUrl "http://localhost:8000"

Restart the gateway. The plugin is now active with fail-open defaults and warn-level logging.

For authenticated setups, also set:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.apiKey "ac_your_api_key"

Example policy

Here is an example policy which blocks all tools except read and memory for anyone who is not an admin. For read you can specify approved files and folders.

To use it, make sure your OpenClaw agent is already registered with Agent Control, then go to your agent in Agent Contorl UI, click "Add Control" -> "Create Contorl" -> "Write your own" and copy paste JSON.

Configuration

SettingTypeDefaultDescription
serverUrlstringBase URL for the Agent Control server. Required.
apiKeystringAPI key for authenticating with Agent Control.
agentNamestringopenclaw-agentBase name used when registering agents with Agent Control.
agentVersionstringVersion string sent to Agent Control during agent sync.
timeoutMsintegerSDK defaultClient timeout in milliseconds.
failClosedbooleanfalseBlock tool calls when Agent Control is unreachable. See Fail-open vs fail-closed.
observabilityEnabledbooleantrueEmit pre-tool control execution events to Agent Control observability. Enabled by default unless explicitly set to false.
logLevelstringwarnLogging verbosity. See Logging.
userAgentstringopenclaw-agent-control-plugin/0.1Custom User-Agent header for requests to Agent Control.

All settings are configured through the OpenClaw CLI:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.<key><value>

Environment variables

serverUrl and apiKey can also be set through environment variables. This is useful in container or CI environments where you do not want secrets in the OpenClaw config file.

VariableEquivalent config
AGENT_CONTROL_SERVER_URLserverUrl
AGENT_CONTROL_API_KEYapiKey

Config values take precedence over environment variables when both are set.

Fail-open vs fail-closed

By default, the plugin is fail-open: if Agent Control is unreachable or the evaluation request fails, tool calls are allowed through. This avoids breaking your gateway when Agent Control has a transient outage.

Set failClosed to true if you need the guarantee that no tool call executes without a policy decision. In fail-closed mode, a sync failure or evaluation error will block the tool call.

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.failClosed true

Observability

Observability is enabled by default. Unless observabilityEnabled is explicitly set to false, the plugin sends control execution events to Agent Control's observability API after each before_tool_call evaluation.

  • Events are emitted only for the pre stage because the current OpenClaw plugin SDK typings expose a pre-tool hook but no post-tool hook.
  • Emission is best-effort and non-blocking. Ingest failures are logged at warn and do not change allow/block behavior.
  • The plugin stamps OpenTelemetry trace and span IDs when an active span exists, otherwise it generates OTEL-compatible IDs locally.

Disable it with:

openclaw config set plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled false

Logging

The plugin stays quiet by default and only emits warnings, errors, and tool block events.

LevelWhat it logs
warnWarnings, errors, and block events. This is the default.
infoAdds lifecycle events: client init, gateway warmup, agent syncs.
debugAdds verbose diagnostics: phase timings, context building, evaluation details.
openclaw config set plugins.entries.agent-control-openclaw-plugin.config.logLevel "debug"

OpenClaw CLI reference

Inspect plugin state

openclaw plugins list
openclaw plugins info agent-control-openclaw-plugin
openclaw plugins doctor

Enable or disable

openclaw plugins enable agent-control-openclaw-plugin
openclaw plugins disable agent-control-openclaw-plugin

Remove optional config keys

openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.apiKey
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.logLevel
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.agentVersion
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.observabilityEnabled
openclaw config unset plugins.entries.agent-control-openclaw-plugin.config.userAgent

Uninstall

openclaw plugins uninstall agent-control-openclaw-plugin --force

Local development

  1. Clone this repo anywhere on disk.
  2. Install dependencies and run the verification stack:
npm install
npm run lint
npm run typecheck
npm test
  1. Link the plugin into your OpenClaw checkout:
openclaw plugins install -l /absolute/path/to/openclaw-plugin
  1. Restart the gateway.

npm run coverage generates a report under coverage/ including coverage/lcov.info for Codecov uploads.

Contributing

See AGENTS.md for project conventions, testing patterns, and the verification checklist.

License

Apache 2.0

About

No description, website, or topics provided.

Resources

Stars

32 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages