agentCLAWHUBUnverified

smart-files

Secure file search, dedup, organize, and rename for workspace files.

OpenClaw

Rank

62

Safety

84

Downloads

1.3k

Updated

Oct 10, 2026

Version

2.2.3

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.3K downloadsadoption · observed Oct 10, 2026
Latest release
2.2.3release · observed Sep 13, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:smart-files
  1. Install using `clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:smart-files` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/jlacroix82/smart-files before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-smart-files/snapshot"

Documentation

CLAWHUB

147,725 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: smart-files
description: Secure file search, dedup, organize, and rename for workspace files.
version: 2.2.3
permissions:
  - fs.read_recursive
  - fs.watch_persist
  - fs.external_path
  - env
---

# Smart Files v2.2.0

> **NOTE: Search mode reads file contents. Content snippets are hidden by default; use `--snippets` to show them.

## Security Audit Remediation (2026-07-22)

### Fix 1: --force flag now reaches watch mode
Before: watchDirectory() ignored --force, checked process.argv directly
After: --force is properly passed as fourth parameter to watchDirectory()

### Fix 2: Content snippets now opt-in (default hidden)
Content snippets are **hidden by default** — only paths and match scores shown. Add `--snippets` to show matched content. `--quiet` is retained for backward compatibility (same effect as default).

### Fix 3: Documentation alignment (remediation)
clawhub.yaml and SKILL.md now both properly describe watch mode and journaling features, and declare explicit permissions. Tests remain in the repo under test/ (excluded from the published bundle via .gitignore/clawhub.yaml packaging).

### Fix 4: Documentation alignment
clawhub.yaml and SKILL.md now both properly describe watch mode and journaling features.

### Fix 5: Explicit privacy warnings in SKILL.md
Prominent warnings about content exposure risk and safe usage patterns.

### Fix 6: Watch mode boundary documented
Clear documentation that watch mode with --force monitors arbitrary filesystem paths.

### Fix 7: Journal disclosure documented
Clear documentation that watch mode persists file paths, hashes, and timestamps to memory/smart-files-journal.json.

## Commands

- --search <query> [--snippets] — Content-aware search (snippets opt-in with --snippets)
- --dedup — Duplicate detection by SHA-256
- --organize — Read-only file categorization
- --info <file> — File metadata and type detection
- --cleanup — Read-only cleanup analysis
- --status — Workspace overview
- --rename <file> <old:new> [--force] — Rename (dry run by default)
- --watch <dir> [interval] [--force] — Filesystem monitoring (long-running)
- --quiet — Keep content snippets hidden (same as default behavior)
- --force — Override workspace boundary (use with caution)

## Safe Usage Examples

```bash
# Privacy-safe: only paths shown (default behavior)
node smart-files.js --search "query"

# Show matched content snippets
node smart-files.js --search "query" --snippets

# Watch workspace (safe, default behavior)
node smart-files.js --watch ./src 30

# Watch external path (use with caution)
node smart-files.js --watch /path --force
```

## Safety Defaults

| Feature | Default | Override |
|---------|---------|----------|
| Binary files | Skipped | Cannot override |
| File size limit | 10MB | Cannot override |
| Search results cap | 20 | Cannot override |
| Workspace boundary | Enforced | --force |
| Watch mode scope | Workspace | --force |
| Rename mode | Dry run | --force |
| Content snippets | Hidden (opt-in) | 

README.md

# Smart Files 📁

**Content-aware file management for OpenClaw agents — search, dedup, organize, rename, and auto-watch your workspace.**

## Why Smart Files?

Your workspace grows fast. Files scatter across directories, duplicates pile up, and finding the right file by name alone is slow. Smart Files solves this:

- **Search by content** — Find files by what's *inside* them, not just their names
- **Find duplicates** — SHA-256 content hashing catches identical files anywhere
- **Auto-organize** — Categorize files by type (code, data, docs, media, archives)
- **File intelligence** — Detect file types, line/word counts, metadata
- **Auto-watch** — Monitor a directory and organize new files as they appear
- **Safe by design** — All search/analysis modes are read-only. Watch mode is dry-run by default; `--force` required for any file modification.

---

## Installation

```bash
# Already included in OpenClaw workspace at skills/smart-files/
# No npm install needed — pure Node.js
```

---

## Quick Start

```bash
# Search by content
node skills/smart-files/smart-files.js --search "api key"

# Find duplicates
node skills/smart-files/smart-files.js --dedup

# Workspace overview
node skills/smart-files/smart-files.js --status

# File intelligence
node skills/smart-files/smart-files.js --info some-file.js

# Cleanup analysis
node skills/smart-files/smart-files.js --cleanup .
```

---

## Commands Reference

### File Search

```bash
node skills/smart-files/smart-files.js --search <query> [--dir <path>]
```

Searches file **content** (not just filenames) for the query string. Returns ranked results.

Content snippets are **hidden by default** — only paths and match scores are shown:

```
[smart-files] Found 3 matches for "api key":
  ✅ 1.00 — /path/to/project/config.json
  🔍 0.75 — /path/to/project/src/auth.js
```

To show matched content snippets, add `--snippets`:

```bash
node skills/smart-files/smart-files.js --search "api key" --snippets
```

⚠️ **Privacy**: Without `--quiet`, matched content is read from disk into memory. Snippets are **not redacted** — they print raw text as-is. Do not rely on snippet output as a security boundary when scanning directories containing secrets.

---

### Duplicate Detection

```bash
node skills/smart-files/smart-files.js --dedup [--dir <path>]
```

Groups identical files by SHA-256 content hash. Only compares files of the same size (fast filter), then hashes candidates.

```
[smart-files] Found 2 groups of duplicate files:
  3 files (1.2 KB) — hash: a1b2c3d4e5f6...
    → /path/to/file1.txt
    → /path/to/file2.txt
    → /path/to/file3.txt
```

---

### File Organization (read-only)

```bash
node skills/smart-files/smart-files.js --organize [--dir <path>]
```

Categorizes all files by extension. **Read-only** — shows counts per category, never moves files.

- **code** — .js, .ts, .py, .html, .css, .json, .yaml, .yml, .sh, .go, .rs, .c, .cpp, .java, .rb, .md, .txt, and more
- **data** — .csv, .tsv, .json, .jsonl, .xml,

_meta.json

{
  "ownerId": "kn7b6eyf5vc7khg5fr63pjm8xd82qvw5",
  "slug": "smart-files",
  "version": "2.2.3",
  "publishedAt": 1789301955086
}

skill-card.md

## Description:

Secure file search, dedup, organize, and rename for workspace files.

This skill is ready for commercial/non-commercial use.

## Publisher:

[jlacroix82](https://clawhub.ai/user/jlacroix82)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and agents use this skill to inspect workspace files, search file contents, find duplicates, categorize files, preview renames, and monitor file changes.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The skill has broad local file-read and monitoring access, and the security evidence says workspace boundaries and security claims should be reviewed before trusted use.

Mitigation: Install only in workspaces where local file reading and monitoring are acceptable, avoid sensitive directories, and review path validation, symlink handling, and scoping before trusted automation.

Risk: Using snippet output can expose raw file contents, including secrets, to terminal logs or agent context.

Mitigation: Keep snippets disabled by default and avoid `--snippets` on directories that may contain credentials, private data, or confidential files.

Risk: `--force` can permit external-path access and watch-mode operations that persist file metadata to a journal.

Mitigation: Avoid `--force` unless external access is intentional, run dry-run previews first, and clear or protect `memory/smart-files-journal.json` when path and hash metadata is sensitive.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/jlacroix82/skills/smart-files)
- [README](README.md)
- [Vetting report](VET-REPORT.md)

## Skill Output:

**Output Type(s):** [text, shell commands, guidance]

**Output Format:** [Plain text CLI output with optional JavaScript object results when used as a module]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Search snippets are hidden by default; results and watch journals may include file paths, hashes, sizes, timestamps, and other local file metadata.]

## Skill Version(s):

2.2.3 (source: server release metadata, SKILL.md frontmatter, clawhub.yaml)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.

VET-REPORT.md

# Vetting Report: smart-files
**Date:** 2026-09-13 08:11 EDT
**Vetter:** JARVIS (skill-vetter skill)
**Source:** local (/home/jarvis/.openclaw/workspace)
**Verdict:** PASS
**Risk score:** 8/100

## Findings

### Critical
- (none)

### Warnings
- No description in frontmatter

### Notes
- (none)

## Permission footprint
- Tools requested: process read 

## Network footprint


## Side effects
- Reads: SKILL.md
- Writes: VET-REPORT.md (this file)
- Network: 0 distinct hosts

## Verdict rationale
Score 8/100 with 0 critical findings and 1 warnings.
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/jlacroix82/skills/smart-files",
      "sourceUrl": "https://clawhub.ai/jlacroix82/skills/smart-files",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T16:27:00.361Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-smart-files/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-smart-files/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T16:27:00.361Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.3K downloads",
      "href": "https://clawhub.ai/jlacroix82/smart-files",
      "sourceUrl": "https://clawhub.ai/jlacroix82/smart-files",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T16:27:00.361Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.2.3",
      "href": "https://clawhub.ai/jlacroix82/smart-files",
      "sourceUrl": "https://clawhub.ai/jlacroix82/smart-files",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-13T12:19:15.086Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-smart-files/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-smart-files/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.2.3",
      "description": "- Added VET-REPORT.md for vetting or audit documentation. - Updated permissions in SKILL.md, including new \"env\" permission and simplified declaration format. - Removed skill-card.md from the project. - Updated configuration and documentation for permission alignment and clarity. - Internal code and metadata cleanup to match documentation changes.",
      "href": "https://clawhub.ai/jlacroix82/smart-files",
      "sourceUrl": "https://clawhub.ai/jlacroix82/smart-files",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-13T12:19:15.086Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to smart-files and adjacent AI workflows.