Tweek stops your AI coding tools from touching your credentials, keys, and secrets.
Install once. Forget about it.
curl -sSL https://raw.githubusercontent.com/gettweek/tweek/main/scripts/install.sh | bash
Open Source · Apache 2.0 · 100% Local · Your code never leaves your machine
The installer handles everything. Python, pipx, tool detection.
curl -sSL ... | bash
Tweek auto-detects your AI tools and asks to protect each one.
y ↵
Tweek runs invisibly. You never think about it again.
Every command your AI runs passes through six independent security checks. An attacker would have to beat all of them.
249 known attack signatures catch credential theft, data exfiltration, and prompt injection on sight.
Detects rapid-fire attack sequences and shuts them down before they get anywhere.
Custom-trained prompt injection classifier running entirely on your machine. Catches encoding tricks, social engineering, and novel injection techniques that rules miss. No API calls. No cloud. No data leaves your computer.
Watches for multi-step attacks that look innocent individually but form a dangerous pattern over time.
Runs risky commands in an isolated environment first to see what they actually do before letting them touch your system.
Scans what comes back from tools too. Hidden instructions in web pages, emails, or API responses get caught at the door.
Critical threats are hard-blocked. Suspicious ones ask you first. Low-risk signals are logged quietly.
Auto-detects and protects all your AI coding assistants. No configuration needed.
Runs silently between your AI assistant and your system. You never notice it until it blocks something dangerous.
100% local execution. No cloud. No telemetry. Your code, credentials, and keys stay exactly where they are.
Open source under Apache 2.0. All 249 attack patterns. All 9 tool integrations. No trial. No credit card. No catch.
One command. Say yes. Go back to coding.
Tweek handles the rest.
curl -sSL https://raw.githubusercontent.com/gettweek/tweek/main/scripts/install.sh | bash
A security-hardened Docker distribution of OpenClaw with Tweek built in. Full stack, pre-hardened, ready to go.
curl -fsSL https://raw.githubusercontent.com/gettweek/hard-shell/master/install.sh | bash
OpenClaw + Tweek bundled in a hardened container. Install once, everything works.
Read-only filesystem, dropped capabilities, non-root, resource limits, immutable configs.
Auto-generates auth tokens, configures security presets, locks configs after startup.
Apache 2.0. All 249 patterns, all defense layers, all 9 tool integrations. Free forever.
Everything. No limits. Apache 2.0.
For teams of 2-50 developers.
SSO, custom patterns, SLA support.