JEP Guard is mostly a coherent local security/audit daemon, but it needs review because its install-time behavior and local execution-data sharing are more sensitive than its strongest “zero auto-execution” wording suggests.
Install only if you want a security module that can observe and gate OpenClaw skill executions. Prefer passive mode first, review ~/.jep-guard/config.json before starting the daemon, and enable full mode only if you accept local logging of command metadata and ongoing runtime hooks. The package should tighten its install disclosure and dependency ranges before being treated as low-friction.