agentCLAWHUBUnverified

Skill

Route tool requests through Clawvisor for credential vaulting, task-scoped authorization, and human approval flows. Use for Gmail, Calendar, Drive, Contacts,...

OpenClaw

Rank

62

Safety

84

Downloads

2.2k

Updated

Oct 9, 2026

Version

0.9.10

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2.2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2.2K downloadsadoption · observed Oct 9, 2026
Latest release
0.9.10release · observed Jun 22, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s177dph7s0j0c0hmn4t8qp1sc18488my:clawvisor
  1. Install using `clawhub skill install s177dph7s0j0c0hmn4t8qp1sc18488my:clawvisor` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/ericlevine/clawvisor before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-ericlevine-clawvisor/snapshot"

Documentation

CLAWHUB

149,997 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: clawvisor
description: >
  Route tool requests through Clawvisor for credential vaulting, task-scoped
  authorization, and human approval flows. Use for Gmail, Calendar, Drive,
  Contacts, GitHub, and iMessage (macOS). Clawvisor enforces restrictions,
  manages task scopes, and injects credentials — the agent never handles
  secrets directly.
version: dev
published_at: dev
homepage: https://github.com/clawvisor/clawvisor
metadata:
  {
    "openclaw":
      {
        "emoji": "🔐",
        "requires": { "env": ["CLAWVISOR_URL", "CLAWVISOR_AGENT_TOKEN", "OPENCLAW_HOOKS_URL"] },
        "primaryEnv": "CLAWVISOR_AGENT_TOKEN",
      },
  }
---
# Clawvisor Skill

## Setup

This skill assumes Clawvisor is already running and your agent has `CLAWVISOR_URL` and `CLAWVISOR_AGENT_TOKEN` configured. If you don't yet have Clawvisor running, sign up at [clawvisor.com](https://clawvisor.com) for hosted access, or self-host from the [GitHub repo](https://github.com/clawvisor/clawvisor).

> ⚠️ **`CLAWVISOR_AGENT_TOKEN` is a high-privilege credential.** It grants the agent access to every service activated in Clawvisor. Use a dedicated token scoped to only the services you need, and rotate or revoke it immediately if compromised.

---

## Overview

Clawvisor is a gatekeeper between you and external services. Every action goes
through Clawvisor, which checks restrictions, validates task scopes, injects
credentials, optionally routes to the user for approval, and returns a clean
semantic result. You never hold API keys.

The authorization model has two layers — applied in order:
1. **Restrictions** — hard blocks the user sets. If a restriction matches, the action is blocked immediately.
2. **Tasks** — scopes you declare. Every request must be attached to an approved task. If the action is in scope with `auto_execute`, it runs without approval. Actions with `auto_execute: false` still go to the user for per-request approval within the task.

---

## Typical Flow

> **Execute all curl commands as a single line.** The examples below are formatted for readability, but when you run them, inline everything — URL, headers, and JSON body — into one `curl` command. Do not use `\` line continuations, heredocs, shell variables, or separate assignment statements. Multi-line commands trigger a separate approval prompt for each line.

1. Fetch the catalog — confirm the service is active and the action isn't restricted
2. Create a task with `POST /api/tasks?wait=true` — this blocks until the user approves
3. Make gateway requests with `POST /api/gateway/request?wait=true` — in-scope auto-execute actions return immediately; actions requiring approval block until approved and return the result
4. Mark the task complete when done
---

## Getting Your Service Catalog

At the start of each session, fetch your personalized service catalog:

```
GET $CLAWVISOR_URL/api/skill/catalog
X-Clawvisor-Agent-Token: $CLAWVISOR_AGENT_TOKEN
```

This returns the services available to you, 

README.md

# Clawvisor — OpenClaw Skill

Route tool requests through [Clawvisor](https://github.com/clawvisor/clawvisor)
for policy enforcement, credential vaulting, and human approval flows.

The agent never holds API keys. Every action is logged and auditable. The user
controls what is allowed via dashboard policies.

## Supported services

- **Google Gmail** — list, read, send, draft, delete
- **Google Calendar** — list, get, create, update, delete events
- **Google Drive** — list, get, create, update, delete files
- **Google Contacts** — list, get, create, update contacts
- **GitHub** — issues, pull requests, repositories

## Quick start

**1. Run Clawvisor**

```bash
# Local (SQLite, no Docker)
git clone https://github.com/clawvisor/clawvisor
cd clawvisor
JWT_SECRET=your-secret make run-sqlite
```

Or deploy to Cloud Run — see `deploy/` in the repository.

**2. Set up your account**

Open http://localhost:25297, register, then:
- **Services** → connect Google (covers Gmail, Calendar, Drive, Contacts) and/or GitHub
- **Agents** → create an agent, copy the token
- **Policies** → optionally add policies to control what the agent can do

**3. Install the skill**

```bash
clawhub install clawvisor
```

**4. Configure credentials**

```bash
openclaw credentials set CLAWVISOR_URL http://localhost:25297
openclaw credentials set CLAWVISOR_AGENT_TOKEN <token from dashboard>
```

**5. Use it**

Ask your agent to send an email, check your calendar, create a GitHub issue —
it routes everything through Clawvisor automatically.

---

## How it works

```
Agent → POST /api/gateway/request → Policy check → Vault inject → Adapter → Result
                                          ↓
                                   Approval queue (if policy requires)
                                          ↓
                                   Dashboard / Notification → Human approves/denies
                                          ↓
                                   Callback to agent session
```

Actions that require approval (`require_approval: true` in policy, or default
for new services) go to an approval queue. The user gets a Telegram message or
can approve from the dashboard. The result is delivered back to the agent via
`callback_url`.

## Environment variables

| Variable | Description |
|---|---|
| `CLAWVISOR_URL` | Base URL of your Clawvisor instance |
| `CLAWVISOR_AGENT_TOKEN` | Agent bearer token from the dashboard — treat as a high-privilege credential |
| `OPENCLAW_HOOKS_URL` | OpenClaw gateway URL for callbacks (default: `http://localhost:18789`) |

## Links

- [Repository](https://github.com/clawvisor/clawvisor)
- [Dashboard](http://localhost:25297) (local) / your Cloud Run URL
- [Phase docs](https://github.com/clawvisor/clawvisor/tree/main/docs)

_meta.json

{
  "ownerId": "kn755jj2yskgch7ps2n4st7b1n823xbp",
  "slug": "clawvisor",
  "version": "0.9.10",
  "publishedAt": 1782154590741
}

skill-card.md

## Description:

Route tool requests through Clawvisor for credential vaulting, task-scoped authorization, and human approval flows for Gmail, Calendar, Drive, Contacts, GitHub, and iMessage.

This skill is ready for commercial/non-commercial use.

## Publisher:

[ericlevine](https://clawhub.ai/user/ericlevine)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and agent operators use this skill to route service actions through Clawvisor so credentials stay vaulted, task scopes are approved, restrictions are enforced, and risky actions can require human approval.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The agent token is a high-privilege credential for services activated in Clawvisor.

Mitigation: Use a dedicated scoped token, keep task scopes narrow, and rotate or revoke the token immediately if it is exposed.

Risk: Standing or broad task scopes can permit persistent access to sensitive Gmail, Calendar, Drive, Contacts, GitHub, or iMessage data.

Mitigation: Prefer short-lived tasks, avoid standing all-mailbox authorizations unless necessary, and use session identifiers for standing workflows.

Risk: Write or destructive service actions can affect email, calendar events, files, issues, or messages.

Mitigation: Review and apply the included safe policies so writes and sensitive reads require approval, email deletion is blocked, and iMessage sending remains disabled unless explicitly enabled.

Risk: Self-hosted Clawvisor setup commands depend on the deployed service version and trust boundary.

Mitigation: Pin or verify the self-hosted Clawvisor version before running setup commands and install only when the Clawvisor deployment is trusted.

## Reference(s):

- [ClawHub skill listing](https://clawhub.ai/ericlevine/skills/clawvisor)
- [Clawvisor repository](https://github.com/clawvisor/clawvisor)
- [Task and request examples](https://github.com/clawvisor/clawvisor/blob/main/docs/TASK_EXAMPLES.md)
- [Clawvisor docs](https://github.com/clawvisor/clawvisor/tree/main/docs)
- [Clawvisor hosted access](https://clawvisor.com)

## Skill Output:

**Output Type(s):** [guidance, markdown, shell commands, configuration, API calls]

**Output Format:** [Markdown guidance with JSON and bash examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Requires CLAWVISOR_URL, CLAWVISOR_AGENT_TOKEN, and OPENCLAW_HOOKS_URL; routes service actions through Clawvisor task scopes, restrictions, and approval flows.]

## Skill Version(s):

0.9.10 (source: server release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.

policies/github-read-only.yaml

id: github-readonly
name: GitHub — read only
description: >
  Read access to issues, pull requests, repositories, and code search.
  Creating issues and adding comments requires approval.
  No destructive actions permitted.

rules:
  # Read operations — always allowed
  - service: github
    actions: [list_issues, get_issue, list_prs, get_pr, list_repos, search_code]
    allow: true

  # Write operations — require approval
  - service: github
    actions: [create_issue, comment_issue]
    require_approval: true
    reason: Creating issues and comments requires your approval
Github ReposUpdated 4h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/ericlevine/skills/clawvisor",
      "sourceUrl": "https://clawhub.ai/ericlevine/skills/clawvisor",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T17:18:40.182Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-ericlevine-clawvisor/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ericlevine-clawvisor/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T17:18:40.182Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2.2K downloads",
      "href": "https://clawhub.ai/ericlevine/clawvisor",
      "sourceUrl": "https://clawhub.ai/ericlevine/clawvisor",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T17:18:40.182Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.9.10",
      "href": "https://clawhub.ai/ericlevine/clawvisor",
      "sourceUrl": "https://clawhub.ai/ericlevine/clawvisor",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-22T18:56:30.741Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-ericlevine-clawvisor/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ericlevine-clawvisor/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.9.10",
      "description": "clawvisor 0.9.10 - Documentation updated: SKILL.md expanded with new details about the `lifetime` attribute for task-scoped access, including `\"sliding\"` support and usage guidelines. - Guidance added for setting `\"lifetime\": \"sliding\"` in long-running workflows to auto-extend task TTL. - Removed outdated skill-card.md file.",
      "href": "https://clawhub.ai/ericlevine/clawvisor",
      "sourceUrl": "https://clawhub.ai/ericlevine/clawvisor",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-22T18:56:30.741Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Skill and adjacent AI workflows.