agentauth
Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every a...
Rank
62
Safety
84
Downloads
1.1k
Updated
Oct 11, 2026
Version
1.0.4
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.0.4release · observed May 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17b7080jwvq0ztmjxpt47f1es85m7z6:agentauth- Install using `clawhub skill install s17b7080jwvq0ztmjxpt47f1es85m7z6:agentauth` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/braga-agentauth/agentauth before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/snapshot"
Documentation
CLAWHUB
90,806 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: agentauth
homepage: https://agentauth.id
description: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.
compatibility: Requires agentauth CLI (`./scripts/cli.cjs`)
metadata:
{
"openclaw":
{
"requires": { "bins": ["openclaw"] },
},
}
---
# agentauth — Human Consent Gate for AI Agents
## Why This Exists
OpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.
agentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.
## What This Prevents
- Agent deleting files or databases without your knowledge
- Agent sending emails, messages, or making purchases autonomously
- Prompt injection tricking the agent into destructive operations
- Stolen API tokens being used to impersonate your agent
- Agent modifying production configs or deploying code unsupervised
- Social engineering attacks that bypass in-chat "approval"
---
## Data Security and Redaction
To facilitate out-of-band approval, the `toolCall` and `displayString` are sent to the AgentAuth service. To prevent accidental leakage of sensitive information, `agentauth` performs automatic redaction of secrets (API keys, tokens, passwords) before transmission.
**Best Practices:**
- **Sensitive Data in Commands:** While `agentauth` redacts known secret patterns, avoid including unnecessary sensitive details like internal file paths or infrastructure specifics in the `toolCall` or `displayString`.
- **`displayString` Content:** The `displayString` should be a clear, concise summary for the human approver, not a verbatim copy of the command.
- **Notification Channels:** Data sent to these channels is also redacted but travels through third-party services (e.g., Slack, Telegram).
---
## Initial Setup: Initialize My AgentAuth
Before approvals can be used, the user must register their authentication credentials.
If the user says something like:
- "Initialize my AgentAuth"
- "Set up AgentAuth"
- "Connect my passkey"
- "Register AgentAuth"
the agent MUST handle setup through a sub-agent so the main session remains responsive.
---
### Required Flow: Non-Blocking Initialization
**Main Agent Responsibilities:**
1. Detect that the user is requesting AgentAuth initialiREADME.md
# agentauth (Approval Flow for OpenClaw) This skill adds **human approval + identity verification** before OpenClaw performs dangerous actions. OpenClaw will automatically use this when it detects a **high-risk action**, such as: - Deleting files or data - Sending emails or external writes - Database changes - Deployments or production changes - Security or permission updates --- ## Installation You can install this skill into OpenClaw using the provided script or manually. ### Option 1 — Using the install script (recommended) ```bash npm run deploy:local ``` Optionally, you can pass a custom OpenClaw directory: ```bash npm run deploy:local -- /path/to/openclaw ``` If no path is provided, the script will use: ```bash ~/.openclaw ``` The script will: - Build the project - Package the skill - Install it into your OpenClaw `skills` directory ### Option 2 — Manual installation If you prefer to install manually: ```bash npm install npm run build ``` If you prefer to install manually: 1. **Build the project** ```bash npm install npm run build ``` 2. **Package and install the skill** ```bash mkdir agentauth cp SKILL.md agentauth cp -r scripts agentauth mv agentauth ~/.openclaw/skills ``` If using a custom OpenClaw directory: ```bash mv agentauth <openclaw-directory>/skills/ ``` Restart OpenClaws gateway and it will automatically detect and use the skill when needed. --- ## Initialize the Skill Once the skill is installed, ask OpenClaw to initialize it by saying something like: ``` Initialize my AgentAuth ``` OpenClaw will send you a secure link where you can: - Create a passkey - Automatically configure your credentials No manual credential setup is required. --- ## Cleanup the Skill Before uninstalling the skill, ask OpenClaw to clean it up by saying something like: ``` Cleanup my AgentAuth ``` OpenClaw will send you a secure link where you can: - Approve the cleanup process This will restore any modified configuration files to their original state and remove integrations. ## Command Used by OpenClaw ```bash node ./scripts/cli.cjs approval-flow "<toolCall>" "<displayString>" [--notify <channel:target>] ``` --- ## What Happens 1. **When OpenClaw detects a dangerous action that it needs to use** 2. It runs: ```bash node ./scripts/cli.cjs approval-flow ... ``` 3. The script: - Creates an approval session with agentauth - Generates an approval URL 4. The user is notified: - If `--notify` is set → message is sent (Telegram, Slack, etc.) - If notification fails → browser opens automatically 5. The user: - Opens the approval link - Sees the required action - Approves or denies using a **passkey** 6. OpenClaw **waits** until one of these happens: - Approved - Denied - Timeout 7. OpenClaw continues based on the result: - **Approved** → action is executed - **Denied** → action is ignored - **Timeout** → action is ignored --- ## License MIT-0 © LoginID Inc.
_meta.json
{
"ownerId": "kn70dh9dy90egv2f0wpz72jny585mpej",
"slug": "agentauth",
"version": "1.0.4",
"publishedAt": 1780080035159
}skill-card.md
## Description: agentauth requires user-initiated biometric passkey approval before an OpenClaw agent performs sensitive or irreversible actions such as deleting files, sending emails, making purchases, or modifying system configuration. This skill is ready for commercial/non-commercial use. ## Publisher: [braga-agentauth](https://clawhub.ai/user/braga-agentauth) ### License/Terms of Use: MIT-0 ## Use Case: Developers and operators use this skill to add human-in-the-loop authorization to OpenClaw workflows before high-risk agent actions run. It is intended for actions where explicit passkey-backed approval, notification, and auditability are needed before execution. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill becomes a broad local command executor after passkey approval. Mitigation: Install only in environments where approved commands are still reviewed carefully and limited to the intended OpenClaw workspace. Risk: Command metadata is sent to AgentAuth-hosted services and notification channels. Mitigation: Keep display strings concise, avoid unnecessary sensitive details, and rely on the skill's redaction guidance before sending approval requests. Risk: Credentials are stored in the shared OpenClaw .env file. Mitigation: Restrict access to the OpenClaw environment file and rotate AgentAuth credentials if the file may have been exposed. Risk: Cleanup may not fully restore the original policy file byte-for-byte. Mitigation: Review AGENTS.md manually after cleanup and remove any remaining AgentAuth instruction block if uninstalling. ## Reference(s): - [AgentAuth Homepage](https://agentauth.id) - [ClawHub Skill Page](https://clawhub.ai/braga-agentauth/skills/agentauth) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, configuration, guidance] **Output Format:** [Markdown guidance with inline shell commands and JSON status output from the CLI] **Output Parameters:** [1D] **Other Properties Related to Output:** [Uses auth-flow, approval-flow, notification, and cleanup commands around OpenClaw actions.] ## Skill Version(s): 1.0.4 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/braga-agentauth/skills/agentauth",
"sourceUrl": "https://clawhub.ai/braga-agentauth/skills/agentauth",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T08:28:33.459Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T08:28:33.459Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/braga-agentauth/agentauth",
"sourceUrl": "https://clawhub.ai/braga-agentauth/agentauth",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T08:28:33.459Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.4",
"href": "https://clawhub.ai/braga-agentauth/agentauth",
"sourceUrl": "https://clawhub.ai/braga-agentauth/agentauth",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-29T18:40:35.159Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.4",
"description": "agentauth 1.0.4 - Added non-blocking uninstall and cleanup workflow: new `cleanup` sub-agent command for restoring original config and removing integrations (see SKILL.md and scripts/cli.cjs). - Updated documentation to describe the required flow for uninstall/removal, with detailed main agent and sub-agent responsibilities. - Removed obsolete skill-card.md file. - Now explicitly covers uninstall/disable scenarios as well as setup and approval flows.",
"href": "https://clawhub.ai/braga-agentauth/agentauth",
"sourceUrl": "https://clawhub.ai/braga-agentauth/agentauth",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-29T18:40:35.159Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
