arifOS: A $15 MCP Governance Kernel for OpenClaw Tool Security

✍️ OpenClawRadar📅 Published: March 1, 2026🔗 Source
arifOS: A $15 MCP Governance Kernel for OpenClaw Tool Security
Ad

What arifOS Does

arifOS is a tiny MCP governance kernel that sits between OpenClaw models and their tools/skills. The creator, Arif (a geologist, not a coder), built it to prevent AI agents from "free-styling" his tools without proper security checks.

Core Architecture

The system uses a simple metaphor: treat the LLM like a "brain in a jar," treat tools like "hands," and put a "$15 VPS in the middle as the bouncer." Every OpenClaw tool call goes through this chain: jar → MCP server → scoring → security check.

Security Implementation

Each tool call gets scored 000-999 and must pass 13 hard Floors including:

  • Amanah
  • Truth
  • Safety
  • Injection
  • Sovereignty

If a call fails any Floor, it returns "VOID" and nothing touches your filesystem, API, or database. The blocking logic is straightforward:

if verdict == "VOID":
    return "Action Blocked by Floor 1: Amanah"

As Arif puts it: "That's the whole joke: billion-dollar model, $15 lock."

Ad

Installation and Availability

Available via pip: pip install arifos

Repository: https://github.com/ariffazil/arifOS

The creator invites testing: "If you're running OpenClaw agents and want a paranoid bouncer in front of your skills, feel free to break this and tell me where it leaks."

Development Context

Arif notes that all Python code was written by AI agents, and he doesn't "even know how to spell phython"—highlighting the paradox of non-coders building security tools with AI assistance.

📖 Read the full source: r/openclaw

Ad

👀 See Also

AI Agent Guardrails Decay Over Time Without Active Maintenance
Security

AI Agent Guardrails Decay Over Time Without Active Maintenance

AI agent guardrails degrade over time as system prompts accumulate updates, model versions change, and new tools are added, often resulting in contradictory or ignored safety rules that require regular review and testing.

OpenClawRadar
OpenClaw User Shares Strategy for Balancing Agent Autonomy and Web Security
Security

OpenClaw User Shares Strategy for Balancing Agent Autonomy and Web Security

An OpenClaw user describes their current challenge: balancing agent autonomy with security, particularly regarding web access and prompt injection risks. They propose a solution using 'low trust' and 'high trust' agent segments with a human approval gate.

OpenClawRadar
MCPwner AI Pentesting Tool Finds Multiple 0-Day Vulnerabilities in OpenClaw
Security

MCPwner AI Pentesting Tool Finds Multiple 0-Day Vulnerabilities in OpenClaw

MCPwner, an MCP server that orchestrates AI agents for automated penetration testing, identified several critical 0-day vulnerabilities in OpenClaw including environment variable injection, permission bypass, and information disclosure flaws that standard scanners missed.

OpenClawRadar
OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
Security

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems

A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.

OpenClawRadar