Skip to main content

openclaw skills

Inspect local skills, search ClawHub, install skills from ClawHub/Git/local directories, verify ClawHub skills, and update ClawHub-tracked installs. Use openclaw plugins for plugin packages. The standalone ClawHub CLI handles publishing, registry maintenance, and removing ClawHub skills. Related:

Commands

search, update, and verify use ClawHub directly. install @owner/<slug> installs a native ClawHub skill. install skills-sh:<owner>/<repo>/<slug> asks ClawHub to resolve an external listing to its exact synchronized GitHub commit; OpenClaw does not download from skills.sh. These entries are shown as Not scanned by ClawHub, and that trust state is preserved through updates and verification. Claimed or ClawHub-scanned skills use @owner/<slug>. install git:owner/repo[@ref] clones an unmanaged Git skill, and install ./path copies a local skill directory. By default, install, update, and verify target the active workspace skills/ directory; with --global, they target the shared managed skills directory. list/info/check and bare openclaw skills request the selected Gateway’s authoritative skill inventory. A configured remote Gateway or an explicit OPENCLAW_GATEWAY_URL never falls back to client-local skills: missing URLs, connection failures, and authentication errors remain visible. Only an implicitly selected local Gateway can fall back to local inventory when it is unavailable. Workspace-backed commands resolve the target workspace from --agent <id>, then the current working directory when it is inside a configured agent workspace, then the default agent. The skills table renders horizontal tabs as single spaces so descriptions stay aligned with the neighboring columns. info resolves an exact skill name before a metadata key. Key, case-insensitive, and separator-normalized matches must identify one skill; ambiguous selectors fail instead of choosing discovery order. Workshop reads and update targeting use the same lookup. check reports missing prerequisites independently of agent exclusion: a skill excluded by the agent allowlist can also appear under Missing requirements. Disabled skills and skills blocked by the bundled allowlist keep their separate readiness categories. Curator status, pin, unpin, and restore, plus Workshop apply, preserve the same target boundary. They never read or mutate client-local state after an explicitly selected Gateway fails; intentional offline behavior remains available only for an implicitly selected local Gateway. Git and local directory installs expect SKILL.md at the source root. The install slug comes from SKILL.md frontmatter name when it is valid, then the source directory or repository name; use --as <slug> to override it. --version is ClawHub-only. Skill installs do not support npm package specs or zip/archive paths, and openclaw skills update updates ClawHub-tracked installs only. Gateway-backed skill dependency installs triggered from onboarding or Skills settings use the separate skills.install request path instead. When security.installPolicy returns warn in an interactive terminal, OpenClaw prints the reason and findings, then asks type: '<skill>' to install anyway (or update anyway). If the fully rendered review exceeds 4,000 characters, OpenClaw fails closed before prompting; reduce or coalesce the policy output first. A matching answer evaluates the staged skill again before continuing. Declined and non-interactive direct CLI commands stop before commit; after review, --acknowledge-install-policy-warning is the explicit noninteractive approval for every warning in that command invocation. Every approved warning is re-evaluated before continuing. Automatic and managed skill installs cannot use that flag themselves. Use an equivalent direct CLI command when one exists; otherwise, change security.installPolicy to return allow for the reviewed request, then retry the managed flow. Neither --force nor the acknowledgement overrides block or a policy failure. Notes:

Release trust

Community ClawHub skill installs and updates check trust before downloading. Versioned community archive releases use exact-release trust metadata. Resolver-backed GitHub skills rely on ClawHub’s install resolver to enforce scan and force-install policy before it returns a pinned commit; use --force-install to install a pending GitHub-backed skill before that scan completes. Malicious or blocked community releases are refused. Review outcomes print the exact ClawHub audit overview and details link, then continue. Official ClawHub skill publishers and bundled OpenClaw skill sources bypass this release-trust check.

Remove a ClawHub skill

Use the standalone ClawHub CLI to remove a ClawHub-tracked skill. If the CLI is not installed, install it explicitly first:
The CLI asks for confirmation before deleting the skill directory and its .clawhub/lock.json entry. Use the installed skill’s owner-qualified name or bare slug, not its original skills-sh: reference. Select the same root where the skill was installed: the agent workspace for an agent-specific skill, or the OpenClaw state directory for a shared skill installed with --global:
If OPENCLAW_STATE_DIR is set, use that configured state directory for shared skills instead:
The default skills watcher picks up the removal on the next agent turn. If watching is disabled, start a new session.

Personal skill library

openclaw skills library manages the identified caller’s skills on the selected Gateway. It uses the same owner-aware service as the Control UI and agent workflow; it never writes the library database or revision directories on the CLI host.
List your library:
Create a private skill from a directory containing SKILL.md:
Read its stable ID and current revision before editing:
Update only the instructions while preserving supporting files:
A directory input replaces the complete bundle. A single SKILL.md input preserves the current supporting files; repeat --delete-file <relative-path> to remove files explicitly. Updates compare the revision that was read; a conflict requires reviewing the newer content, not a force overwrite. Supporting files are part of the revision, including binary assets and executable flags. Import a ZIP privately:
Import a ClawHub skill without publishing your library:
--version <version> selects a ClawHub version and requires --clawhub. share, unshare, transfer, enable, disable, remove, and rollback take <skill-id> --expected-revision <hash>. Rollback also requires --revision <retained-hash>. Attach an exact revision to an existing session:
detach takes the same session and skill ID. Refresh one selected skill:
Omitting --skill-id refreshes all selected skills and requires current library access to each one. It never replaces the selection with the current caller’s library. Each operation reports its effect on the next turn. Use list --session <session-key> to inspect selected revisions and the skills you can attach, without changing the session. read --session <session-key> also requires --revision <hash> and reads only that exact selected revision; it does not expose other private revisions or grant permission to edit them. Personal operations require an authenticated Gateway profile. The Control UI on a single-user Gateway uses a durable owner profile, but ephemeral CLI connections do not inherit it. A CLI shared token or password alone still has no personal profile; use the existing workspace commands in that case. An explicitly selected remote Gateway never falls back to a client-local personal library. Sharing makes a skill available to teammates but does not grant edit access. Transfer to team ownership requires administrator authority. Saving affects new sessions by default; attach or refresh a selection explicitly for an existing session. Removal preserves already selected revisions. See personal library ownership and revisions.

Skill Workshop

openclaw skills workshop manages pending skill proposals for the selected agent. Proposals are not active skills until applied. For proposal storage, support-file safeguards, Gateway methods, and approval policy, see Skill Workshop.
propose-create, propose-update, and revise also accept --goal <text> and --evidence <text> to record the proposal’s motivation and supporting notes alongside the --proposal/--proposal-dir content.