From 2cc5ac9b41095e7efccf38339dc4cd72f48cf14a Mon Sep 17 00:00:00 2001 From: ADD-SP Date: Wed, 18 Feb 2026 14:00:42 -0800 Subject: [PATCH] Update README.md --- README.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 1e82c3c..133c907 100644 --- a/README.md +++ b/README.md @@ -12,7 +12,7 @@ ## πŸ“– Introduction -**ClawShell** is a security-privileged process for the **OpenClaw** ecosystem. It sits between OpenClaw and upstream LLM API providers (OpenAI, Anthropic), performing virtual-to-real API key mapping and DLP (Data Loss Prevention) scanning on request and response bodies. It can also expose an Email read endpoint with sender allowlist/denylist filtering. +**ClawShell** is a security-privileged process for the **OpenClaw** ecosystem. It sits between OpenClaw and upstream LLM API providers (OpenAI, Anthropic, OpenRouter), performing virtual-to-real API key mapping and DLP (Data Loss Prevention) scanning on request and response bodies. It can also expose an Email read endpoint with sender allowlist/denylist filtering. OpenClaw never holds real API keys, only virtual keys that ClawShell swaps for real ones before forwarding requests upstream. Real keys are stored in a privileged config directory (`/etc/clawshell`) protected by Unix file system permissions. @@ -67,9 +67,9 @@ ClawShell supports sender-based email filtering so each virtual key only sees ma β•‘ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” REQUEST β•‘ β”‚ β”‚ REQUEST β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”œβ”€β”€(virtual───╫─►│ ClawShell β”œβ”€β”€-(real key,───►│ β”‚ - β”‚ OpenClaw β”‚ key) β•‘ β”‚ β”‚ PII redacted) β”‚ OpenAI β”‚ - β”‚ β”‚ β•‘ β”‚ DLP scan β”‚ β”‚ or β”‚ - β”‚ holds only β”‚ RESPONSE β•‘ β”‚ real-key mapping β”‚ RESPONSE β”‚ Anthropic β”‚ + β”‚ OpenClaw β”‚ key) β•‘ β”‚ β”‚ PII redacted) β”‚ OpenAI / β”‚ + β”‚ β”‚ β•‘ β”‚ DLP scan β”‚ β”‚ Anthropic/ β”‚ + β”‚ holds only β”‚ RESPONSE β•‘ β”‚ real-key mapping β”‚ RESPONSE β”‚ OpenRouter β”‚ β”‚ virtual keys │◄────────────║◄── email sender filtering │◄───────────────── β”‚ β”‚ β”‚ β•‘ β”‚ β”‚ β”‚ β”‚ β”‚ β”‚ EMAIL GET β•‘ β”‚ β”‚ IMAP fetch β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”