⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
api-dev
Scaffold, test, document, and debug REST and GraphQL APIs. Use when the user needs to create API endpoints, write integration tests, generate OpenAPI specs, test with curl, mock APIs, or troubleshoot HTTP issues.
Use with your AI agent
Open your project in any AI assistant that can read your files. Works with ChatGPT, Claude, Claude Code, Codex, Cursor, Hermes Agent, OpenClaw, Grok Bot, and more.
Your agent needs access to this page’s linked instructions and your project files. Copying does not install or execute anything.
// RATINGS
Not yet listed on ClawHub or SkillsMP
// README
OpenTrApp
Status (2026-06-26): The lean-down campaign has shipped on
main. The Tauri/WebKitGTK desktop GUI is deleted, so OpenTrApp is now the lean, headlessopentrapp-daemonplus an on-demand browser projection (the loopbackviewer-server, rendering in your existing browser only while a dashboard is open), and the build is GTK-free (the 19 GTK3 advisories cleared;Cargo.lockhas 0tauri/wry/webkitentries). The perimeter itself is lean end to end: the credential-holding proxy is now a 15 MB Go chokepoint (elazarl/goproxy) that replaced the leaky Python mitmproxy — putting the Python interpreter out of the keys-holding container (ADR-0026) — and every workload base is Alpine (vault-skills 233→72 MB, vault-social 153→74 MB). The new proxy's full live-boundary self-test is still pending before it is claimed end-to-end correct. Cross-platform installers for the new architecture are pending (cargo-dist, ADR-0023); until they ship, the new build runs from source, and the last tagged release (v0.8.0) is still the previous Tauri desktop app. The CLI-first / registry direction continues per ADR-0020. SeeCLAUDE.mdfor the full target-versus-current framing.
A safer way to run an autonomous CLI agent on your own computer. OpenTrApp wraps the agent in a security perimeter built on two ideas. Privilege separation: no single container holds both your API keys and internet access, so a compromised agent can reach neither directly. Supply-chain defense: every skill the agent loads is vetted in isolation before it can reach the agent, because a malicious skill runs as part of the agent's own reasoning. Open-source under MIT.
It is pre-wired for OpenClaw; the product is the perimeter itself, and the GUI is one optional, on-demand projection of it (see status above). The perimeter is agent-agnostic by design; opencode, Claude Code, and other CLI agents are candidates for support.
For a one-page explainer of how the perimeter works (one contained agent, two guards around it), see docs/perimeter-explained.md. The full architecture, threat model, and per-component capabilities are in docs/trifecta.md.
Author: @albertdobmeyer · Public landing page: opentrapp.com
Try it, lowest commitment first
You do not have to adopt the whole perimeter to get value out of this.
1. Scan your agent's skills in CI (one line, fully offline, no model). The skill scanner runs as a GitHub Action, so any repository can gate its skills or plugins against malware and prompt injection before they ship:
- uses: albertdobmeyer/opentrapp/actions/skill-scan@skill-scan-v1
with: { path: ./skills }
Findings land in your repository's Security tab, and a finding fails the job. Details in actions/skill-scan/.
2. Scan a skill locally before you install it. From a clone of this repo, the same offline check runs as a one-line pre-install gate, with no global install needed:
workloads/skills/skill scan ./that-plugin --strict || echo "blocked by the skill firewall"
3. Run the full perimeter. The latest tagged release (v0.8.0) ships the previous Tauri desktop app with a setup wizard — the end-to-end containment story. The de-Tauri build on main (headless opentrapp-daemon + an on-demand browser dashboard) runs from source today; signed cross-platform installers for it are pending (cargo-dist, ADR-0023).
Purpose
Autonomous CLI agents, such as OpenClaw, execute shell commands, read files, and load skills from third-party registries. Run with default settings, the agent has the same operating-system privileges as the user. The ClawHavoc study (2026-Q1) of one such registry classified 11.9% of published skills as malicious (341 of 2,857). OpenTrApp wraps any such agent in a defense-in-depth perimeter to reduce the impact of agent compromise, malicious skills, and prompt-injection attacks. The shipped integration is OpenClaw, and the perimeter is designed to extend to other CLI agents.
Reasoning is delegated to the agent's vendor API (Anthropic's, for OpenClaw); only the agent's execution layer (file work, tool calls, skill invocations) is local.
Values
These are the principles that shape every design and product decision in this project. They are written down because the alternative, leaving them implicit, is how projects drift.
- Safety-first, safety-always. The perimeter exists because autonomous agents are powerful and powerful tools fail in expensive ways. Every architectural choice is evaluated against its containment effect first; convenience second. Defaults err on the restrictive side and are documented when they do.
- Honest about residual risk. The application can never claim to make running an autonomous agent absolutely safe. It raises the cost of compromise via defense-in-depth and is open about the gaps that remain. What this protects against, and what it doesn't is the plain-language summary; the threat model names every gap; the whitepaper explains them.
- Agent-agnostic, community-driven. The perimeter is not coupled to any single CLI agent. The reference deployment is OpenClaw because OpenClaw exists today; the architecture is designed to extend to others. Contributions that broaden compatibility are welcomed.
- Transparency over marketing. No tracking, no telemetry, no proprietary blobs. Every dependency, every container layer, every external request is documentable from the source tree. Reproducibility steps are in
docs/reproduce.md. - Shared for the safety of the commons. This project is MIT-licensed and developed in the open. Security research findings, hardening recipes, and threat-model deltas land in the repo where everyone running an autonomous CLI agent can benefit, not in private channels.
- Lean by design, runs on modest hardware. OpenTrApp is a lean background app. The full perimeter and its boundary self-test must run on a 7.2 GB laptop, the hard floor; idle auto
// HOW IT'S BUILT
KEY FILES