Closed Beta|HexaClaw is in private early access — limited spots available
HexaClawHexaClaw

163 Rules. 157 Attacks. Zero Compromises.

Guardian intercepts credential theft, data exfiltration, prompt injection, and persistence attacks before they execute — and red-teams your AI system to find gaps before attackers do.

Why Security Matters

AI Agents Are Under Attack. We Built for That.

Recent attacks exposed how vulnerable AI agents are to malicious plugins and prompt injection. HexaClaw includes security by default so you don't have to worry.

0
Malicious plugins found
Discovered in a major supply chain attack
0+
Users affected
Installed at least one compromised plugin
0%
Contain hidden attacks
Of community plugins tested by security researchers
0%
Designed to steal data
Built to exfiltrate credentials or personal info
Sources: Koi Security analysis, Snyk ToxicSkills study (Feb 2026)

6 Attack Vectors. Handled.

HexaClaw handles every known attack vector in the AI agent ecosystem so you don't have to worry about them. Including CVE-2026-25253 (CVSS 8.8) and CVE-2025-54135 MCP config injection.

Malicious Install Hooks

Skills that run arbitrary shell commands during installation, compromising your system before you even use them.

Credential Harvesting

Skills designed to extract API keys, SSH keys, wallet keys, and other secrets from your environment.

Prompt Injection

Hidden instructions in skill definitions that hijack the AI agent to perform unintended actions.

Data Exfiltration

Skills that silently send your data to attacker-controlled servers through covert network requests.

Typosquatting

Fake skills that mimic popular ones with slightly different names to trick users into installing them.

Dependency Hijacking

Malicious code hidden in the dependencies of otherwise legitimate-looking skills.

Bundled · Standalone API Coming Soon

HexaClaw Guardian

Runtime security built for AI agents. Guardian intercepts credential theft, data exfiltration, prompt injection, and persistence attacks before they execute — with sub-5ms overhead.

0
Security rules
Regex + heuristics + ML across 13 categories
4 tiers
Defense in depth
Regex (<5ms), heuristics (<50ms), ML (<200ms), Cloud API
0%
Detection rate
85 real-world attacks tested, 0 false positives
0
Red team attacks
15 categories, AI-generated variants, self-eval mode

Real-World Attacks Tested in Isolated VM

Attack PatternSourceWithout GuardianWith Guardian
SSH key injection + exfiltrationClawHub evilweatherKeys stolenBLOCKED (9)
Credential bundling + webhook exfilClawHub rankajCreds leakedBLOCKED (6)
SOUL.md cognitive rootkitVirusTotal analysisAgent hijackedBLOCKED (3)
HEARTBEAT.md C2 injectionVirusTotal analysisBackdoor installedBLOCKED (6)
MCP tool description poisoningInvariant LabsKeys exfiltratedBLOCKED (12)
MCP config injection (RCE)CVE-2025-54135Code executedBLOCKED (6)
0
Credentials leaked
0
Persistence achieved
16
Fake credentials planted, none stolen

Guardian Cloud API — Tier 3 Deep Analysis

When local rules need backup, the Cloud API provides LLM-powered threat analysis and proactive red teaming. 28 endpoints covering skills, MCP manifests, code, prompts, IO scanning, compliance, and adversarial simulation.

Skill Scanner

Deep analysis of SKILL.md files for hidden instructions, credential theft, and cognitive rootkits. Detects all 6 ClawHavoc attack vectors.

MCP Tool Poisoning

Catches hidden instructions in tool descriptions, cross-origin shadowing, rug-pull patterns, and schema-level injection (Invariant Labs, CyberArk).

Prompt Classifier

Blocks prompt injection, jailbreaks (DAN, Skeleton Key, Crescendo), social engineering, and cross-lingual attacks with 0.85-0.98 confidence.

Code Analysis

Detects reverse shells, persistence mechanisms, privilege escalation, DNS exfiltration, and obfuscated payloads across Python, Bash, Perl.

IO Scanner

Catches API keys, SSH keys, JWTs, PII (SSN, credit cards, medical records), and Stripe keys in tool output before they leave your machine.

Threat Intelligence

Live feeds from URLhaus, PhishTank, and ThreatFox. Domain reputation via VirusTotal and Google Safe Browsing.

Red Team Engine

157 curated attacks across 15 OWASP-mapped categories. Self-eval mode audits your own AI system's defenses — showing which tier caught each attack and what slipped through. Expand to 1,500+ AI-generated variants.

Defense in depth: even when a model refuses 95% of attacks, Guardian catches the 5% that slip through. Tested against Claude Opus 4, Gemini 2.0 Flash, and Gemini 2.0 Flash Lite.

Four Tiers of Defense

Every request passes through Guardian's multi-layer security pipeline. Most threats are caught in under 5ms.

Tier 1

Regex Engine

<5ms

Pattern matching against 163 rules. Catches known attack signatures instantly.

Tier 2

Heuristic Analysis

<50ms

Behavioral analysis detects obfuscation, encoding tricks, and tool-native attacks.

Tier 3

ML Classification

<200ms

Machine learning model classifies novel attack patterns and zero-day threats.

Tier 4

Cloud API

<500ms

LLM-powered deep analysis for complex attack chains. Includes 157-attack red team engine across 15 OWASP categories — audit your own AI system's defenses with self-eval mode.

Deep skill scanning

Why HexaClaw Scans Every Skill

Basic antivirus catches malware signatures in binaries. But prompt injection — the #1 attack vector — lives in SKILL.md text files, not binaries. HexaClaw goes deeper.

Basic Scanning

  • Scans for malware signatures in binaries
  • Catches known malware families
  • Cannot catch prompt injection payloads
  • No behavioral analysis
  • No runtime protection
  • No config hardening

Basic binary scanning cannot catch prompt injection payloads in text-based skill definitions.

HexaClaw

  • Custom YARA rules for prompt injection
  • Heuristic behavioral analysis
  • Guardian runtime security (58 rules)
  • Hardened security config
  • Pre-verified skill bundles
  • Real-time threat blocking (sub-5ms)

Built on Cisco AI Defense. 42 confirmed blocks against real ClawHub attack patterns. Zero false positives.

36% of skills on public registries contain prompt injection vulnerabilities that basic scanning cannot detect. HexaClaw scans for these by default.

Source: Snyk ToxicSkills study (Feb 2026)

Pricing

Simple Pricing. Cancel Anytime.

Start free with 1,000 credits. Pro gives you every AI service on one bill. Max adds full security and 2.5x more credits.

Free

1,000 welcome credits. All models. Buy more anytime.

$0/forever
  • 1,000 welcome credits
  • All models unlocked
  • No credit card required
  • Buy more credits anytime
Request Early Access
Most Popular

Pro

Every AI service on one account. Credits, smart routing, and basic security.

$19.99/month
  • Everything in Free, plus:
  • 20,000 credits/month
  • All 30+ models (Claude, Gemini, GPT, etc.)
  • Full API: LLMs, search, images, voice, browser, vectors
  • Smart routing across providers
  • Guardian security (basic rules)
  • Basic hardened config
  • Community skills
  • Bring your own API keys
  • Priority email support
Request Early Access
Full Security

Max

Full Guardian protection. More credits. No API keys needed.

$49/month
  • Everything in Pro, plus:
  • 50,000 credits/month (2.5x more)
  • Built-in credits — no API key needed
  • Guardian Tier 2 (full heuristics + tool-native detection)
  • Guardian Tier 3 Cloud API (LLM-powered threat analysis)
  • OTA rule updates (new CVEs pushed within hours)
  • 3 curated skill packs (10 verified skills)
  • Skill scanner (detects ClawHavoc-style attacks)
  • MCP tool poisoning detection (Invariant Labs patterns)
  • HexaClaw Verify scanner CLI
  • Hardened config with advanced toggles
  • Threat intelligence feeds (URLhaus, PhishTank, ThreatFox)
  • Domain reputation checking (VirusTotal + Safe Browsing)
  • Higher relay session limits
  • Early access to new skills and rule updates
Request Early Access
Coming Soon

Enterprise

Private cloud routing. Zero data retention. Full compliance.

Custom
  • Everything in Max, plus:
  • Private cloud routing (Ollama, vLLM, TGI)
  • Zero data retention
  • Customizable PII detection policies
  • API key & secret scanning (14 patterns)
  • Team management with RBAC
  • SSO / SAML (coming soon)
  • Compliance dashboard & audit logs
  • Custom SLA
  • Dedicated account manager
Contact Sales

Need More Credits?

Credit packs work with any plan. Use Gemini Flash for thousands of runs, or Claude/GPT for targeted tasks.

Starter
10,000
$10
Standard
27,500
$25(10% off)
Power
57,500
$50(13% off)
Bulk
125,000
$100(20% off)
14-day money-back guarantee on all plans.

Protect Your Agent. Test Your Defenses.

Full Guardian security with the Max plan. 163 rules, real-time defense, 157-attack red team engine, zero overhead.

Currently in closed beta. Free to start when you get access.