FireClaw
Open-source security proxy that protects AI agents from prompt injection attacks
Prompt injection is the #1 vulnerability in AI agents. Malicious websites can hijack your AI's behavior, steal data, or execute unauthorized actions.
Hidden prompt injection in page content
Fetches and processes content
Data theft, unauthorized actions, system compromise
Prompt Injection is ranked as the #1 vulnerability in AI/LLM applications
A four-stage sanitization pipeline that stands between the web and your AI agent
Retrieves content through isolated proxy environment with DNS pre-check and domain reputation scoring
Strips scripts, styles, and suspicious patterns. Removes hidden text, zero-width characters, and encoding tricks
Condenses content to semantic meaning only. The proxy has no tools, no database access โ just text processing
Analyzes for injection patterns using community threat intelligence. Flags suspicious content before it reaches your agent
Even if the proxy gets injected โ dead end.
No tools, no data, no damage. The threat stops at the firewall.
Fetch, sanitize, summarize, and scan every request through isolated layers of protection
Real-time threat intelligence shared across all FireClaw instances (opt-in, privacy-first)
Automatic reputation scoring with whitelist, greylist, and blacklist management
Instant notifications when suspicious activity or injection attempts are detected
Honeypot tokens identify and track malicious actors attempting to exfiltrate data
Validates domains before fetching to block known malicious infrastructure
Complete request history with ability to replay and analyze past interactions
Prevent abuse and control API costs with configurable request throttling
Community-powered threat intelligence. The more FireClaw instances running, the better we protect everyone.
You control what's shared. Threat intelligence sharing is completely optional.
Only threat signatures and domain hashes are shared โ never your data or content.
When one instance detects a threat, all connected instances get protected immediately.
Raspberry Pi, Docker, any machine with Node.js โ protect your AI for the cost of a burrito
git clone https://github.com/fireclaw-security/fireclaw.git
cd fireclaw
docker compose up -d
git clone https://github.com/fireclaw-security/fireclaw.git
cd fireclaw
npm install
npm start
curl -fsSL https://fireclaw.app/install.sh | bash
Real-time monitoring and control from your local network
Free to use, modify, and distribute. If you host it as a service, you must share your source code.
Created by Ralph Perez. Built for the OpenClaw community. Contributions welcome!
Comprehensive docs, examples, and guides to get you started.
FireClaw is free and open source. If it's protecting your AI, consider buying us a coffee โ