Uninstall¶
bash scripts/ShadowclawAI stop stops the stack and leaves it installed. scripts/uninstall.sh removes ShadowClaw from the host entirely — including, and this is the part worth reading, the changes it made inside other products.
bash scripts/uninstall.sh --dry-run # print the plan, change nothing
bash scripts/uninstall.sh # do it, after a typed confirmation
Always read the dry run first
It prints exactly what is running, what will be deleted with sizes, what will be reverted in another product, and what will be kept. The real run applies that same plan through the same code path, so the two cannot drift apart.
Flags¶
| Flag | Effect |
|---|---|
--dry-run |
Print the plan; change nothing. |
--yes, -y |
Skip the typed confirmation. |
--purge-evidence |
Also delete the ledger and /etc/shadowclaw. |
--keep-o11y |
Leave ~/.shadowclaw-o11y in place, logs and data with it. |
--remove-otelcol |
Also delete bin/otelcol from the checkout. |
--grafana-url URL |
Clean the dashboard out of a Grafana we did not install. |
--grafana-token TOKEN |
Credential for that Grafana. |
Three properties that make it safe on a working machine¶
Property 1
Nothing pre-existing is removed
Every process lookup is anchored to ShadowClaw's own directory rather than to a program name.
- A bare
pkill -f grafanawould take a colleague's Grafana with it esloggerprocesses are matched by having our sensor as their parent- Another tool's ESF client is left running
Property 2
Other products are reverted through themselves
Never by editing their config files.
- The
shadowclaw-lokidestination goes viadefenseclaw setup observability remove - That file usually holds destinations that are not ours
- Hand-editing would mean guessing which
Property 3
The ledger survives
Deleting the record is a separate decision that has to be said out loud.
--purge-evidence, plus a typed sentence- Uninstalling is exactly the move someone makes when they would rather the record were not read
- Off-box copies are unaffected either way
Why the ledger stays by default¶
A security tool that erases its own audit trail on the way out is more dangerous than one that leaves files behind. The hash-chained record of what was detected on this host is kept unless you explicitly ask for it to go.
What it does not undo¶
Python. Left in place. If installing ShadowClaw put an interpreter on the host, other things depend on it by now.
Full Disk Access. Granted to your terminal or IDE rather than to ShadowClaw, and it lives in a SIP-protected database no script may edit. Revoke it yourself in System Settings → Privacy & Security, and only if nothing else you run needs it.
A .pkg install¶
An installer-based install is removed by the uninstaller that ships inside it:
scripts/uninstall.sh detects that install and delegates to it rather than duplicating its knowledge of the payload, so either entry point is correct.
Removing just the Grafana dashboard¶
If you only want the dashboard out of a Grafana you already had:
That deletes the ShadowClaw dashboard, plus the ShadowClaw folder — and only if you have not filed anything else in it. See DefenseClaw integration.
Verifying it is gone¶
Run after the fact, the dry run is also the check: an empty plan is the confirmation that nothing of ours is left.
If you kept the evidence, the ledger is still readable with no ShadowClaw installed at all:
sqlite3 ~/Library/Application\ Support/ShadowClaw/ledger.db \
"SELECT count(*), max(ts) FROM events;"