Code Pluginsource linked

Gen Sagev0.12.0

Safety for Agents — ADR layer for OpenClaw

@gendigital/sage-openclaw·runtime sage-openclaw·by @gendigital
Community code plugin. Review compatibility and verification before install.
openclaw plugins install clawhub:@gendigital/sage-openclaw
Latest release: v0.12.0Download zip

Compatibility

Built With Open Claw Version
2026.3.28
Plugin Api Range
>=2026.3.28
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Credentials
The plugin reads local OpenClaw extension and skill folders, writes logs/cache under ~/.sage, contacts Sage/Avast backend services for reputation checks, and can upload unknown skill folders after a one-time notice; this is sensitive but coherent with the security-scanning purpose and configurable via ~/.sage/config.json.
Install Mechanism
Installation is a normal OpenClaw plugin package with a declared extension entrypoint and no install-time script execution in package.json.
Instruction Scope
The bundled skill gives defensive security guidance and false-positive reporting instructions; it does not contain prompt-injection attempts or unrelated instructions.
Persistence & Privilege
It registers persistent OpenClaw hooks, keeps local approval exceptions/cache/audit logs, and may spawn detached workers for model download or queued skill upload; these behaviors are disclosed and bounded to Sage functionality.
Purpose & Capability
The stated purpose is agent security, and the artifacts implement matching protections: before-tool-call checks for shell commands, file operations, URL fetches, package installs, prompt injection, and installed plugin/skill scanning.
Assessment
Install only if you want Sage to inspect agent commands, URLs, file operations, installed plugins, and skills. Review ~/.sage/config.json if you want to disable community telemetry, backend URL/file/package checks, or unknown skill uploads before use.
dist/index.cjs:14801
Shell command execution detected (child_process).
dist/mcp-server.cjs:16641
Dynamic code execution detected.
dist/index.cjs:4486
Environment variable access combined with network send.
dist/mcp-server.cjs:4540
Environment variable access combined with network send.
dist/model-download-worker.cjs:1079
Environment variable access combined with network send.
dist/index.cjs.map:4
File appears to expose a hardcoded API secret or token.
dist/mcp-server.cjs.map:4
File appears to expose a hardcoded API secret or token.
dist/skill-upload-worker.cjs.map:4
File appears to expose a hardcoded API secret or token.
Patterns worth reviewing
These patterns may indicate risky behavior. Check the VirusTotal and OpenClaw results above for context-aware analysis before installing.

Verification

Tier
source linked
Scope
artifact only
Summary
Validated package structure and linked the release to source metadata.
Commit
7fe650a0c0df
Tag
v0.12.0
Provenance
No
Scan status
clean

Tags

latest
0.12.0

Sage — Safety for Agents

<p align="center"> <img src="https://raw.githubusercontent.com/gendigitalinc/sage/main/images/logo-shaded.png" alt="Sage" width="250"> </p> <p align="center"> Protect your AI coding agent from dangerous commands, malicious URLs, and harmful file operations. </p>
<p align="center"> <img src="https://raw.githubusercontent.com/gendigitalinc/sage/main/images/block-openclaw-allow.gif" alt="Sage blocking a dangerous command in OpenClaw" width="700"> </p>

What is Sage?

Sage is a security layer for OpenClaw. It intercepts tool calls — shell commands, URL fetches, file writes — and checks them for threats before they execute. If something looks dangerous, Sage blocks it with a native approval dialog.

What it protects against

  • Malicious URLs — phishing, malware, and scam sites detected via cloud reputation
  • Dangerous commands — reverse shells, pipe-to-curl, credential theft, data exfiltration
  • Prompt injection — heuristics + a fine-tuned ML model detect injected instructions in fetched content
  • Suspicious file operations — writes to sensitive paths, credential files, system configs
  • Supply-chain attacks — malicious or typosquatted npm/PyPI packages
  • Compromised plugins — automatic scanning of installed plugins at session start

Install

See the install guide for step-by-step instructions, or run:

openclaw plugins install @gendigital/sage-openclaw

Sage loads automatically — no configuration needed.

To verify it's working, ask your agent to run echo diagmark_cmd_a75bf229. Sage should block this harmless canary command.

What Sage intercepts

Sage hooks into OpenClaw's before_tool_call lifecycle:

  • exec — shell commands
  • write / edit — file modifications
  • read — file reads (sensitive paths)
  • web_fetch — URL fetches and downloads
  • apply_patch — patch application

How it works

When your agent makes a tool call, Sage evaluates it and returns a verdict:

VerdictWhat happens
AllowNo threats detected — the action proceeds normally
AskSuspicious activity — you're prompted via native approval dialog
DenyThreat detected — the action is blocked

Sage is designed to fail open: if anything goes wrong internally, the action proceeds. Your agent is never blocked due to a Sage error.

Configuration

Sage works out of the box with no configuration. To customize behavior, edit ~/.sage/config.json:

{
  "sensitivity": "balanced",
  "url_check": { "enabled": true },
  "heuristics_enabled": true
}

See Configuration for all options.

Links