Skip to content

Uninstall

bash scripts/ShadowclawAI stop stops the stack and leaves it installed. scripts/uninstall.sh removes ShadowClaw from the host entirely — including, and this is the part worth reading, the changes it made inside other products.

bash scripts/uninstall.sh --dry-run   # print the plan, change nothing
bash scripts/uninstall.sh             # do it, after a typed confirmation

Always read the dry run first

It prints exactly what is running, what will be deleted with sizes, what will be reverted in another product, and what will be kept. The real run applies that same plan through the same code path, so the two cannot drift apart.

Flags

Flag Effect
--dry-run Print the plan; change nothing.
--yes, -y Skip the typed confirmation.
--purge-evidence Also delete the ledger and /etc/shadowclaw.
--keep-o11y Leave ~/.shadowclaw-o11y in place, logs and data with it.
--remove-otelcol Also delete bin/otelcol from the checkout.
--grafana-url URL Clean the dashboard out of a Grafana we did not install.
--grafana-token TOKEN Credential for that Grafana.

Three properties that make it safe on a working machine

Property 1

Nothing pre-existing is removed

Every process lookup is anchored to ShadowClaw's own directory rather than to a program name.

  • A bare pkill -f grafana would take a colleague's Grafana with it
  • eslogger processes are matched by having our sensor as their parent
  • Another tool's ESF client is left running

Property 2

Other products are reverted through themselves

Never by editing their config files.

  • The shadowclaw-loki destination goes via defenseclaw setup observability remove
  • That file usually holds destinations that are not ours
  • Hand-editing would mean guessing which

Property 3

The ledger survives

Deleting the record is a separate decision that has to be said out loud.

  • --purge-evidence, plus a typed sentence
  • Uninstalling is exactly the move someone makes when they would rather the record were not read
  • Off-box copies are unaffected either way

Why the ledger stays by default

A security tool that erases its own audit trail on the way out is more dangerous than one that leaves files behind. The hash-chained record of what was detected on this host is kept unless you explicitly ask for it to go.

What it does not undo

Python. Left in place. If installing ShadowClaw put an interpreter on the host, other things depend on it by now.

Full Disk Access. Granted to your terminal or IDE rather than to ShadowClaw, and it lives in a SIP-protected database no script may edit. Revoke it yourself in System Settings → Privacy & Security, and only if nothing else you run needs it.

A .pkg install

An installer-based install is removed by the uninstaller that ships inside it:

/usr/local/libexec/shadowclaw/uninstall.sh

scripts/uninstall.sh detects that install and delegates to it rather than duplicating its knowledge of the payload, so either entry point is correct.

Removing just the Grafana dashboard

If you only want the dashboard out of a Grafana you already had:

python3 integrations/defenseclaw/install_dashboard.py --remove

That deletes the ShadowClaw dashboard, plus the ShadowClaw folder — and only if you have not filed anything else in it. See DefenseClaw integration.

Verifying it is gone

bash scripts/uninstall.sh --dry-run

Run after the fact, the dry run is also the check: an empty plan is the confirmation that nothing of ours is left.

If you kept the evidence, the ledger is still readable with no ShadowClaw installed at all:

sqlite3 ~/Library/Application\ Support/ShadowClaw/ledger.db \
  "SELECT count(*), max(ts) FROM events;"

Next