# Shamash local AI security documentation

Shamash is an embeddable security scanner for AI products. Its default runtime evaluates model inputs, retrieved content, tool-call payloads, and model outputs locally, without a required network dependency.

Shamash is one defense layer, not a complete security boundary. Deploy it with host authorization, least privilege, audit logging, and incident response.

## Install or upgrade

The supported OpenClaw installer requires Python 3.9 or newer, an existing OpenClaw home, and Linux or macOS on x86-64 or ARM64.

```shell
python -m pip install --upgrade shamash-openclaw
shamash-openclaw-setup
```

Restart the OpenClaw gateway, then run `openclaw plugins inspect shamash-openclaw --runtime --json`. Run `/shamash` in a connected channel to confirm the enabled protection points and enforcement mode.

## Protection points

- **Input:** Scans model input before model resolution.
- **Retrieved content:** Scans web or retrieved content before persistence.
- **Tool calls:** Checks tool arguments before execution.
- **Output:** Checks complete assistant output before delivery.

## Configuration

- `mode`: block, warn, or log.
- `sensitivity`: low, medium, or high.
- `gates`: enable each protection point independently.
- `customPatternsPath`: add a user policy file without replacing embedded policy.
- `binaryPath`: select an explicit Shamash executable.
- `telemetryPath`: write local JSONL decisions, or leave empty to disable.

## Security boundary

- Policy and scanner behavior are owned by the current Shamash runtime.
- Host permissions and tool policy remain the operator's responsibility.
- Complete output is scanned. Streamed tokens require separate controls.
- Custom policy files must be protected like other security configuration.
- No detection, false-positive, latency, footprint, or compatibility metrics are claimed without dated, reproducible evidence.

## Official links

- [Shamash](https://shamash.uruk.space/)
- [Projects](https://shamash.uruk.space/projects)
- [Security reports](mailto:security@uruk.space)
