Safe-Web
by @adamnaghs
Securely fetch and search web content by scanning and blocking prompt injection threats using PromptGuard before returning results.
clawhub install safe-webπ About This Skill
safe-web
Secure web fetch and search with PromptGuard scanning.
Status
β Working
Purpose
Protects against prompt injection attacks hidden in web content before returning it to the AI. Wraps web fetching and searching with security scanning.
Installation
Requires PromptGuard and Python dependencies:
# Install PromptGuard first
cd /home/linuxbrew/.openclaw/workspace/skills/prompt-guard
pip3 install --break-system-packages -e .Install web dependencies (if not present)
pip3 install --break-system-packages requests beautifulsoup4
Usage
Fetch Command
Fetch a URL and scan the content:
# Basic fetch
safe-web fetch https://example.com/articleSave to file
safe-web fetch https://example.com --output article.txtJSON output for automation
safe-web fetch https://example.com --jsonStrict mode (block on MEDIUM)
safe-web fetch https://example.com --strict
Search Command
Search the web and scan results:
# Basic search
safe-web search "AI safety research"More results
safe-web search "stock market news" --count 10JSON output
safe-web search "machine learning" --json
Exit Codes
| Code | Meaning | |------|---------| | 0 | Success - content/results are clean | | 1 | Error (network, parsing, etc.) | | 2 | Threat detected - content blocked |
Configuration
Environment Variables
BRAVE_API_KEY - API key for Brave Search (optional, enables search command)Symlink (Recommended)
Create a system-wide symlink so safe-web works from any directory:
sudo ln -s /home/linuxbrew/.openclaw/workspace/skills/safe-web/scripts/safe-web.py /usr/local/bin/safe-web
After creating the symlink, you can use safe-web directly without specifying the full path.
How It Works
Fetch Flow
1. Downloads URL content with requests 2. Extracts text using BeautifulSoup (removes scripts, styles) 3. Scans extracted text with PromptGuard 4. Returns clean content or blocks with SHIELD reportSearch Flow
1. Queries Brave Search API (requires API key) 2. Scans each result title and description 3. Filters out suspicious results 4. Returns only clean resultsSecurity Model
Fail-closed: If PromptGuard cannot be loaded or scanning fails, the tool reports an error rather than returning unverified content.
Content sanitization: HTML is parsed and scripts/styles are removed before scanning to reduce false positives.
No execution: This tool only fetches and scans. It never executes JavaScript or runs commands found in web content.
Example Output
Clean Fetch
Fetching: https://site.com/article
Fetched 1523 characters
Scanning with PromptGuard...Article content here...
Blocked Content
Fetching: https://suspicious-site.com
Fetched 2048 characters
Scanning with PromptGuard...
============================================================
π‘οΈ SAFE-WEB SECURITY ALERT
============================================================
Source: https://suspicious-site.com
Severity: CRITICAL
Action: BLOCK_NOTIFY
Patterns Matched: 8Detected Patterns:
- instruction_override_en
- role_manipulation_en
- system_impersonation_en
============================================================
Content from https://suspicious-site.com has been blocked.
Search Results
Searching: AI research
Found 5 results, scanning...Showing 3 clean results:
1. Latest AI Research Papers
URL: https://arxiv.org/list/ai/recent
Recent submissions in artificial intelligence...
2. AI Safety Institute
URL: https://www.safe.ai/
Research and development for safe AI systems...
When to Use
Use safe-web when:
Use standard web_fetch/web_search tools only for:
Comparison with Native Tools
| Feature | Native web_fetch | safe-web fetch |
|---------|-------------------|------------------|
| Fetches HTML | β
| β
|
| Extracts text | β
| β
|
| Injection scanning | β | β
|
| JSON output | β
| β
|
| Save to file | β | β
|
| Exit codes | 0/1 | 0/1/2 (security) |
Dependencies
Limitations
β‘ When to Use
π‘ Examples
Fetch Command
Fetch a URL and scan the content:
# Basic fetch
safe-web fetch https://example.com/articleSave to file
safe-web fetch https://example.com --output article.txtJSON output for automation
safe-web fetch https://example.com --jsonStrict mode (block on MEDIUM)
safe-web fetch https://example.com --strict
Search Command
Search the web and scan results:
# Basic search
safe-web search "AI safety research"More results
safe-web search "stock market news" --count 10JSON output
safe-web search "machine learning" --json
βοΈ Configuration
Environment Variables
BRAVE_API_KEY - API key for Brave Search (optional, enables search command)Symlink (Recommended)
Create a system-wide symlink so safe-web works from any directory:
sudo ln -s /home/linuxbrew/.openclaw/workspace/skills/safe-web/scripts/safe-web.py /usr/local/bin/safe-web
After creating the symlink, you can use safe-web directly without specifying the full path.