See what your agent does. Control what it's allowed to do. Prove it on-chain.
Quick Start · Protection · MCP Server · Circuit Breaker · Architecture
Your agent runs 24/7. Do you know what it's doing right now?
agent-shield shows you everything your OpenClaw agent does, blocks dangerous actions before they execute, and masks your personal data. One command. Zero config.
# 1. Install
npm install -g @palveron/agent-shield
# 2. Set your keys
export PALVERON_API_KEY="your-key" # from dashboard signup
export PALVERON_API_URL="your-api-url" # API endpoint
export OPENAI_API_KEY="sk-..." # your own LLM key (BYOM)
# 3. Initialize
npx agent-shield initThat's it. 8 protection rules are now active. Restart your OpenClaw agent.
agent-shield init activates 8 guardrails automatically — no configuration needed:
| Rule | Detects | Action |
|---|---|---|
| High-Speed Circuit Breaker | Agent loops (>100 req/min) | BLOCK + Suspend |
| Destructive Action Shield | rm -rf, DROP TABLE, git push --force |
BLOCK |
| GDPR Privacy Guard | Emails, phone numbers, IBANs, SSNs | ANONYMIZE |
| Fiscal Authority Limit | Transactions > €1,000 | APPROVAL |
| Secret Exfiltration Shield | API keys, private keys, JWTs in output | BLOCK |
| Shell Injection Guard | curl|bash, chmod 777, eval() |
BLOCK |
| Social Media Output Guard | PII + secrets in outbound messages | ANONYMIZE |
| Package Install Watchdog | npm/pip/apt install from unknown sources | APPROVAL |
After installation, open your Palveron Dashboard the next morning. You'll see:
Your agent made 847 tool calls last night. 12 classified as HIGH RISK. 3 were BLOCKED. 47 PII instances masked. Every tool call, every minute, searchable.
That's the moment you understand what your agent actually does — not because we say "governance", but because you see it for the first time.
Every OpenClaw user already has an LLM API key. agent-shield's 2-pass system (Regex + AI) uses your key for the AI pass. Our LLM cost: zero. Your governance cost: zero on the free tier.
agent-shield includes an MCP (Model Context Protocol) server for integration with coding tools like Cursor and Claude Code:
# Start as MCP server
npx agent-shield-mcpThe MCP server exposes a governance_check tool that your coding agent calls before executing high-risk operations. Configure it in your .cursor/mcp.json or Claude Code settings.
agent-shield implements a 3-state circuit breaker to ensure your agent never stops because of a governance outage:
| State | Behavior |
|---|---|
| Closed | Normal operation — every call goes to the Palveron API |
| Open | After 3 consecutive failures — returns ALLOW immediately, agent keeps running |
| Half-Open | After 30s — sends one probe request. Success → Closed. Failure → Open again |
Fail-open by design. If the Palveron gateway is unreachable, your agent continues with { decision: "ALLOW", reason: "circuit_open" }. We never block your agent because of our downtime.
agent-shield init # Initialize shield, activate 8 rules, register agent
agent-shield status # Show connection status, active rules, circuit state
agent-shield test # Send a test prompt through the governance pipeline
agent-shield --help # Show all commandsagent-shield is a thin client. It contains:
- HTTP client with retry logic and circuit breaker
- CLI for initialization and status checks
- MCP server entry point for coding tool integration
- Local tool-risk classification (trivial mapping, no IP)
What it does NOT contain: No PII patterns, no policy evaluation engine, no guardrail logic. All intelligence lives server-side in the Palveron Gateway. This protects our IP and keeps the client small and dependency-free.
Your Agent ──→ agent-shield (HTTP client) ──→ Palveron Gateway
│ │
│ Circuit Breaker │ 8 Guardrails
│ Fail-Open on timeout │ PII Detection
│ │ Blockchain Proof
▼ ▼
Agent continues Trace in Dashboard
| Variable | Required | Description |
|---|---|---|
PALVERON_API_KEY |
✅ | Your project API key (from dashboard) |
PALVERON_API_URL |
✅ | Gateway API endpoint |
OPENAI_API_KEY |
— | Your LLM key for AI-pass (BYOM) |
Legacy fallback: AGENT_SHIELD_API_KEY / AGENT_SHIELD_API_URL are also accepted.
| Community | Pro | Business | Enterprise | |
|---|---|---|---|---|
| Requests/mo | 1,000 | 10,000 | 100,000 | Unlimited |
| Agents | 3 | 10 | 50 | Unlimited |
| Shield Rules | 8 | 8 + custom | Unlimited | Unlimited |
| Blockchain Proof | Own wallet | Managed | Managed | Managed |
| Trace Retention | 30 days | 90 days | 365 days | 365 days |
- Website: palveron.com
- Documentation: docs.palveron.com
- Dashboard: palveron.com/dashboard
- Gateway (Rust backend): github.com/palveron/gateway
- Platform (Dashboard): github.com/palveron/platform
Proprietary — © 2026 Palveron A. Podzus. All rights reserved.
