A fully containerized, local-first behavioral analysis and kinetic response SOC for Agentic AI infrastructure. Powered by deterministic DRIFT policies and a probabilistic LLM judge.
🦞 ButterClaw Exoskeleton v0.6.3.2 is ONLINE.
Routing: Nginx TLS Reverse Proxy
Active Model: gemma4:e4b (Local GPU Bridged)
🔐 [AUTH] Zero-Trust API Gateway Armed.
🛡️ [POLICY] DRIFT Engine initialized: 16 strict guardrails active.
🔔 [ALERT] Air-gapped ntfy push dispatcher ready.
============================================================
📥 [HTTP POST RECEIVED] Live Gateway Log
Payload: Origin: wss://malicious-vibe.net attempting to bind...
🧠 [HTTP 200 OK] Model returned CRITICAL (99%) in 1.2s.
✅ [POLICY] Pre-Tool Gate Passed: execute_gibson_kill allowed.
🔔 [ALERT] Dispatching verdict_critical to 3 channels...
☢️ [VAULT] Gibson Triggered: Active network token assassination in progress...
============================================================
A 6-Node Decoupled Architecture
Traditional security perimeters fail when authorized AI Agents are compromised. ButterClaw enforces **Evaluation before Execution**.
watcher.py
A high-speed Python daemon tailing raw OS-level logs. Features auto-serialization on SIGTERM to prevent log loss during container reboots, securely passing Bearer tokens to the Gateway.
Gemma 4:e4b
The localized reasoning engine. It evaluates a sliding window of recent temporal memory to detect behavioral drift, and can dynamically compose multi-step tool chains to neutralize threats.
server.py / policy_engine.py
The central nervous system shielded by HMAC-SHA256 Auth. Features a deterministic Policy Engine that applies pre-brain, post-brain, and pre-tool guardrails to constrain probabilistic drift.
buttervault.py
Zero-trust credential storage. Instantly obliterates local DB entries on breach, and now fires live HTTP requests to actively assassinate remote GitHub/Google OAuth tokens before local wipe.
alert_dispatcher.py
Air-gapped notification routing. Routes 9 critical event types to 5 distinct channels (ntfy, Discord, SMTP, Gotify, Webhooks). "Alert-then-burn" guarantees you know what happened before the Gibson fires.
Docker + Nginx TLS
A highly polished, class-based Dark Mode control panel entirely isolated behind an Nginx reverse proxy. Control policies, test injection payloads with Double Air-Gaps, and monitor MCP health.
ButterClaw doesn't just block known vulnerabilities. It uses probabilistic reasoning combined with deterministic DRIFT guardrails to assess intent. You control how aggressive the response should be.
Only blocks known 1-click RCE payloads. Background scanning is relaxed. API keys remain static.
Actively monitors SDK logs for plaintext token leaks. Uses Policy Engine blocks to catch suspicious pre-tool calls.
If an external origin breathes on a monitored port, ButterClaw instantly actively assassinates remote OAuth tokens, shreds local Vault ciphertext, and pushes a mobile alert to your phone.
[Gate: Origin] [99% Confidence] External origin attempting to brute-force Gateway.
Status: Armed | Transport: SSE | Active Tools: 5
Tools: scan_port (SSRF Locked), execute_gibson...
Google Cloud tokens sealed & auto-refreshing.
ButterClaw v0.6.3.2 is open-source. Clone the repo, spin up the Docker stack, and arm the Vault.
View on GitHub