workspace-integrity-guardian
SkillFiles & storageDetects drift or tampering in SOUL.md, AGENTS.md, MEMORY.md, and other critical workspace files and prompts recovery
Use workspace-integrity-guardian in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add workspace-integrity-guardian and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the workspace-integrity-guardian skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by archieindian/openclaw-superpowers in skills/openclaw-native/workspace-integrity-guardian/SKILL.md and read by Ahel’s review.
SOUL.md, AGENTS.md, MEMORY.md, and IDENTITY.md define the agent's persistent identity. These files can be accidentally overwritten by the agent itself, corrupted during a failed skill execution, or modified by a malicious installed skill. The SOUL.md documentation warns: "A compromised SOUL.md means a permanently hijacked agent that survives restarts."
This skill hashes all critical workspace files on first run, then checks for drift on a weekly schedule and on demand.
Protected files
By default, the following files are monitored:
~/.openclaw/workspace/SOUL.md~/.openclaw/workspace/AGENTS.md~/.openclaw/workspace/MEMORY.md~/.openclaw/workspace/IDENTITY.md
Add custom files:
python3 guard.py --add-file ~/.openclaw/workspace/MY_RULES.md
Cron Wakeup Behaviour
Runs weekly on Sunday at 03:00 (cron: "0 3 * * 0"). On each wakeup:
- Read stored baseline hashes from state
- Re-hash all monitored files
- Compare — if any hash changed, classify the change
- Surface drift to user; ask whether to accept or restore
Drift classification
| Change type | Indicator | Action |
|---|---|---|
| Append-only | File grew, existing content intact | Review + accept |
| Truncation | File shrank significantly | High-priority alert |
| Full replacement | Hash completely different | Critical alert |
| Deletion | File missing | Attempt restore from baseline |
Recovery protocol
When drift is detected:
- Show a diff summary: what changed, how much, when (file mtime)
- Ask user: "Accept this change?" or "Restore from baseline?"
- If restore: write the baseline content back to the file
- If accept: update the stored baseline hash to the new hash
- Log the decision to state
Difference from persistent-memory-hygiene
persistent-memory-hygiene enforces formatting and structure discipline in memory files (keeping them clean and useful). This skill is purely about integrity: detecting unauthorised or accidental changes to the agent's identity and configuration files.
Signals
- GitHub stars
- 72
- Forks
- 14
- Last commit
- May 2026
Advanced
- Item type
- skill
- Key
workspace-integrity-guardian- Source
- github.com/archieindian/openclaw-superpowers
github.com/archieindian/openclaw-superpowers
Related picks
Skill · countbot-ai
The pick for Croncron-packs
Skill · profbernardoj
The pick for Cronsecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretssupply-chain-risk-auditor
Skill · trailofbits
The pick for Supply Chainsupply-chain-digital-twin
Skill · a5c-ai
The pick for Supply Chain