๐ชฐ Shoofly
Claude Code is powerful but unprotected. Shoofly adds the safety layer โ blocking prompt injection, malware, credential theft, and runaway token spend before they hit. Free to start.
Works with Claude Code, Cowork, and OpenClaw
No account. No credit card. No data sent.
OpenClaw agents now cost real money per token. Don't let a rogue agent run up your bill.
Stops malicious instructions hidden in web content, emails, and documents from hijacking your agent. Catches 8 injection patterns including jailbreaks, instruction overrides, and base64 payloads.
Intercepts attempts to read or exfiltrate your API keys, GitHub tokens, and AWS credentials before they leave your machine.
Stops writes to sensitive paths โ /etc/, ~/.ssh/, LaunchAgents โ before your system is modified.
Detects agents stuck in loops: repeated tool calls, call floods, read-write cycles, URL hammering. With pay-per-token billing now the norm for third-party harnesses, loop detection isn't just a security feature โ it's cost control.
Catches malicious instructions embedded in web fetches, API responses, and file reads โ the attack vector Anthropic calls their #1 risk.
One-shot scan of your project directory for 10 credential patterns. CI-integrable.
Every tool call logged to local SQLite. Query your agent history, not just threats.
Policy-as-code in YAML. Read it, fork it, audit it. No black box.
No account. No credit card. No data sent.
Basic detects and alerts. Advanced intercepts before the tool call executes โ not after.
Telegram, WhatsApp, macOS notifications, terminal, OpenClaw gateway. You choose where threats surface.
Detection runs on your machine. No cloud API, no DPA, no data retention policy to worry about.
Runtime security for OpenClaw and Claude Code agents. Every token costs real money now โ don't let a runaway agent find out the hard way.
Detects threats, sends notifications, never blocks. See exactly what your agents are doing.
Get started โ Shoofly Basic is free:
Threats intercepted before they execute โ blocked, not detected.
Get updates on new features, security intel, and the occasional Shoofly wisdom. No spam. Unsubscribe anytime.