Data source
skills.status(gateway) returns all skills plus eligibility and missing requirements, including allowlist blocks for bundled skills.- Requirements come from
metadata.openclaw.requiresin eachSKILL.md.
Install actions
metadata.openclaw.installdefines install options (brew/node/go/uv/download).- The app calls
skills.installto run installers on the gateway host. - Install on This Mac explicitly selects Local mode and the Mac’s local Gateway.
- Operator-owned
security.installPolicy(enabled,targets,exec) runs before installer metadata.blockresults and policy failures stop the install. Awarnresult also stops the gateway-backed request: review it with the matching direct CLI when one exists, or change the policy to allow the reviewed request, then retry. - If every install option is
download, the gateway surfaces all download choices. - Otherwise the gateway picks one preferred installer using current install preferences (
skills.install.preferBrew,skills.install.nodeManager) and host binaries: Homebrew first whenpreferBrewis enabled andbrewis present, thenuv, then the configured node manager, then Homebrew again if available (even withoutpreferBrew), thengo, thendownload. - Node install labels reflect the configured node manager, including
yarn.
Browse ClawHub
In Skills > Browse, search ClawHub and choose Review to see the skill’s metadata, publisher, and release version. Verify and install sends that exact reference and version to the connected Gateway. The review sheet is a metadata review; the Gateway owns the pre-download security check during installation. Official ClawHub publishers and packages skip the security-verdict fetch, as described in ClawHub release trust. A ClawHub Review audit outcome allows installation and returns audit text in the result warning. The app displays that warning with the install result. Blocked or unavailable security checks stop installation; the app displays the Gateway error and any warning details without an acknowledgement retry. These audit outcomes do not override the operator-owned install policy described above. Install-only search results offer Install instead of a detail review. The app sends their exact source reference without a version selector and labels unscanned sources. After installation, it readsskills.status on the same Gateway route
to confirm the reviewed version or the recorded install-only reference.
If that refresh fails after the Gateway confirms installation, the app keeps the
completed install message and any audit warning. Open Skills > Installed and
choose Refresh to load the installed entry.
A later connection or search failure appears separately from the completed install
and its warning. No skills found means a successful search returned no matches.
Env/API keys
- The app stores keys in
~/.openclaw/openclaw.jsonunderskills.entries.<skillKey>. skills.updatepatchesenabled,apiKey, andenv.
Remote mode
- Install and config updates happen on the gateway host, not the local Mac.
- When skill files, config, Mac-node connectivity, its catalog, or its executable
inventory changes, the gateway emits
skills.changedafter invalidating its authoritative snapshot. An open Skills pane then refetchesskills.status, including changes that finish while an earlier request is still in flight.