AIOS File Transfer
通过兼容 AWS S3 的 SDK 为 OpenClaw 和 AIOS agent 处理文件传输。当 agent 收到 `file_input://...` URI、需要按当前 `senderId` 把输入文件下载到工作区,或需要把当前 `senderId` 目录内的本地文件上传后以 `file_output:/...
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
1.0.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.0.1release · observed Jul 6, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17c9yyt2sff7jk8nmf7ptf3r183g8kf:aios-transfer-file- Install using `clawhub skill install s17c9yyt2sff7jk8nmf7ptf3r183g8kf:aios-transfer-file` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/kadbbz/aios-transfer-file before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-kadbbz-aios-transfer-file/snapshot"
Documentation
CLAWHUB
146,135 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: aios-transfer-file description: 通过兼容 AWS S3 的 SDK 为 OpenClaw 和 AIOS agent 处理文件传输。当 agent 收到 `file_input://...` URI、需要按当前 `senderId` 把输入文件下载到工作区,或需要把当前 `senderId` 目录内的本地文件上传后以 `file_output://...` URI 返回给用户时,必须使用这个 skill。不要使用 `aws` CLI 或任何外部 S3 客户端程序完成这些传输。 --- # AIOS 文件传输 > 本技能只适用于受控 AIOS 部署。它可能访问真实业务系统,必须按最小权限配置。只读操作可以自动执行;任何会改变状态的操作,包括创建、更新、提交、审批、驳回、删除或触发,都必须先预览目标应用、命令和请求体,并获得明确人工确认。CLI 必须固定到经过评审的版本,Ontology 来源必须可信且可审计。 在 OpenClaw 中,所有文件和图片传输,包括接受用户发来的文件,和给用户发送文件,都必须使用兼容 AWS S3 的 SDK。这适用于附件、`file_input://` 消息,以及任何需要把文件返回给用户的场景。 所有本地文件必须按当前通道提供的 `senderId` 隔离。`senderId` 是 workspace 文件目录的唯一隔离标识;`topic_id` 只用于业务系统 SessionId,不得替代 `senderId` 作为文件目录。 当前工作区内的目录结构固定为: - `<senderId>/upload`:S3 或通道传入的文件,例如 `file_input://...` 下载结果。 - `<senderId>/download`:OpenClaw 通过互联网、第三方系统、业务应用等方式下载得到的文件。 - `<senderId>/generated`:AI 自己生成、转换、分析、渲染或准备返回给用户的文件。 ## 不可违反的规则 - 始终使用 S3 SDK。不要调用 `aws`、`s3cmd`、`mc` 或任何其他外部客户端程序。 - 本项目统一使用 TypeScript 和 JavaScript。不要为这个 skill 添加 Python 脚本或基于 Python 的传输流程。 - 在处理任何 `file_input://...` URI 之前,或在发送任何本地文件给用户之前,先触发这个 skill。 - 传输操作优先使用内置脚本 `scripts/transfer_s3.mjs`,不要在对话中临时写新的传输脚本。 - 每次运行脚本都必须显式传入当前通道的 `--sender-id <senderId>`;如果无法确认 `senderId`,停止文件传输,不得用 `topic_id`、用户名或推测值替代。 - 如果工作区中还没有 `<senderId>/upload`、`<senderId>/download`、`<senderId>/generated` 目录,使用前先创建当前需要的目录。 - 下载和上传的本地文件都必须限制在当前工作区的 `<senderId>` 目录内进行。 - 禁止读取、查询、写入、上传或暴露其他 `senderId` 目录中的文件。 - 在 SDK 上传成功之前,不要声称文件已经发送完成。 - 当你需要返回一个可下载文件时,最终回复必须是单独一条 `file_output://...` 消息,不能附带其他文字。 ## 运行时配置 使用 AIOS 环境变量构建 S3 客户端: - `AIOS_S3_ENDPOINT` - `AIOS_S3_REGION` - `AIOS_S3_ACCESS_KEY_ID` - `AIOS_S3_SECRET_ACCESS_KEY` - `AIOS_S3_FORCE_PATH_STYLE` 使用以下 bucket 变量: - 收件箱 bucket:`AIOS_S3_AGENT_INBOX_BUCKET` - 发件箱 bucket:`AIOS_S3_AGENT_OUTBOX_BUCKET` 发件箱变量统一使用 `AIOS_S3_AGENT_OUTBOX_BUCKET`,不要引入其他别名。 构造 SDK 客户端时: - 从 `AIOS_S3_ENDPOINT` 设置自定义 endpoint。 - 从 `AIOS_S3_REGION` 设置 region。 - 显式传入 `AIOS_S3_ACCESS_KEY_ID` 和 `AIOS_S3_SECRET_ACCESS_KEY` 作为访问凭证。 - 当 `AIOS_S3_FORCE_PATH_STYLE` 为真值时启用 path-style,例如 `1`、`true` 或 `TRUE`。 与 `aios-agent-management-console` 保持一致,使用 TypeScript 或 JavaScript,并采用 AWS SDK for JavaScript v3,具体为 `@aws-sdk/client-s3`。 ## 内置脚本 优先使用内置 JavaScript 工具: ```bash node scripts/transfer_s3.mjs download-uri --uri "file_input://bucket/path/to/file.bin" --workspace . --sender-id "<senderId>" node scripts/transfer_s3.mjs upload-file --source "/abs/path/to/file.bin" --workspace . --sender-id "<senderId>" ``` 内置脚本的行为: - 使用 `@aws-sdk/client-s3` 和上面的 AIOS S3 环境变量。 - 与 `aios-agent-management-console` 保持同样风格:ESM、动态导入本地安装的包、显式构造 `S3Client`、显式传入凭证,并且 `AIOS_S3_FORCE_PATH_STYLE` 默认取 `true`。 - 自动创建当前 `senderId` 下需要的 `upload` 或 `generated` 目录。 - 把 `file_input://...` URI 下载到 `<senderId>/upload`。 - 把待发送文件复制到 `<senderId>/generated`,重命名为要求的时间戳前缀格式,并上传到发件箱 bucket 根目录。 - 输出描述传输结果的 JSON。 - 支持 `--uri-only`,用于最终上传回复步骤。 依赖位置: - 这个 skill 在 `package.json` 中声明了 `@aws-sdk/client-s3`。 - 在一个全新的工作区首次传输前,先检查这个 skill 的本地依赖是否已经安装。 -
README.md
# aios-transfer-file > 本技能只适用于受控 AIOS 部署。它可能访问真实业务系统,必须按最小权限配置。只读操作可以自动执行;任何会改变状态的操作,包括创建、更新、提交、审批、驳回、删除或触发,都必须先预览目标应用、命令和请求体,并获得明确人工确认。CLI 必须固定到经过评审的版本,Ontology 来源必须可信且可审计。 OpenClaw/AIOS 文件传输 skill。使用 `scripts/transfer_s3.mjs` 动态加载当前目录本地安装的 `@aws-sdk/client-s3`,按当前通道的 `senderId` 把 `file_input://...` 对象下载到工作区 `<senderId>/upload`,或把当前 `<senderId>` 目录内的本地文件上传到发件箱 bucket。 workspace 中的会话文件必须按 `senderId` 隔离: - `<senderId>/upload`:S3 或通道传入的文件。 - `<senderId>/download`:OpenClaw 通过互联网、第三方系统、业务应用等方式下载得到的文件。 - `<senderId>/generated`:AI 自己生成、转换、分析、渲染或准备返回给用户的文件。 ## 依赖要求 - Node.js - `@aws-sdk/client-s3` - `AIOS_S3_ENDPOINT` - `AIOS_S3_REGION` - `AIOS_S3_ACCESS_KEY_ID` - `AIOS_S3_SECRET_ACCESS_KEY` - `AIOS_S3_FORCE_PATH_STYLE` - `AIOS_S3_AGENT_INBOX_BUCKET` - `AIOS_S3_AGENT_OUTBOX_BUCKET` ## 用法 ```bash npm install node scripts/transfer_s3.mjs download-uri --uri "file_input://bucket/path/to/file.bin" --workspace . --sender-id "<senderId>" node scripts/transfer_s3.mjs upload-file --source "/abs/path/to/file.bin" --workspace . --sender-id "<senderId>" ``` ## Docker 推荐做法:在 Docker 镜像内预装依赖,但仍然把它作为这个 skill 的本地依赖,而不是使用 `npm install -g`。 Dockerfile 示例模式: ```dockerfile # 把 skill 复制进镜像 COPY skills/aios-transfer-file /opt/aios/skills/aios-transfer-file # 在镜像构建阶段安装这个 skill 的本地依赖 WORKDIR /opt/aios/skills/aios-transfer-file RUN npm ci ``` 运行时要求: - `package.json`、`package-lock.json` 和 `node_modules/` 必须保留在同一个 skill 目录下。 - 从这个 skill 目录运行脚本,或者确保启动脚本的进程模块解析路径能够看到这个本地 `node_modules`。 - 不要依赖 `npm install -g @aws-sdk/client-s3`;这个脚本的设计就是动态导入本地安装的包。
_meta.json
{
"ownerId": "kn74st1pqb0wkrbhpw4yh0kb2982c201",
"slug": "aios-transfer-file",
"version": "1.0.1",
"publishedAt": 1783327383647
}skill-card.md
## Description: AIOS File Transfer handles OpenClaw and AIOS agent file transfers through an S3-compatible SDK, downloading file_input:// objects into the current senderId workspace or uploading files from that workspace as file_output:// URIs. This skill is ready for commercial/non-commercial use. ## Publisher: [kadbbz](https://clawhub.ai/user/kadbbz) ### License/Terms of Use: MIT-0 ## Use Case: Developers and AIOS/OpenClaw operators use this skill when an agent must receive a user-provided file or return a generated file while preserving per-sender workspace isolation. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Sender workspace isolation can be bypassed in the current implementation. Mitigation: Reject or canonicalize symlinked sender, upload, and generated paths before transfer operations, and deploy only with trusted per-sender workspaces until that containment is fixed. Risk: S3 credentials can be used against caller-named buckets. Mitigation: Scope credentials tightly, restrict downloads to approved inbox buckets or prefixes, and avoid runtime bucket creation unless it is explicitly required and separately authorized. ## Reference(s): - [README](README.md) - [ClawHub skill page](https://clawhub.ai/kadbbz/skills/aios-transfer-file) ## Skill Output: **Output Type(s):** [text, shell commands, configuration, guidance] **Output Format:** [Markdown guidance with shell commands; transfer script returns JSON or a file_output:// URI] **Output Parameters:** [1D] **Other Properties Related to Output:** [Requires a current senderId, AIOS S3 environment variables, local Node.js dependencies, and S3 credentials scoped for the intended inbox and outbox buckets.] ## Skill Version(s): 1.0.1 (source: ClawHub server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
package-lock.json
{
"name": "aios-transfer-file",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "aios-transfer-file",
"dependencies": {
"@aws-sdk/client-s3": "^3.1045.0",
"dayjs": "^1.11.21",
"pino": "^10.3.1"
}
},
"node_modules/@aws-crypto/crc32": {
"version": "5.2.0",
"resolved": "https://registry.npmjs.org/@aws-crypto/crc32/-/crc32-5.2.0.tgz",
"integrity": "sha512-nLbCWqQNgUiwwtFsen1AdzAtvuLRsQS8rYgMuxCrdKf9kOssamGLuPwyTY9wyYblNr9+1XM8v6zoDTPPSIeANg==",
"license": "Apache-2.0",
"dependencies": {
"@aws-crypto/util": "^5.2.0",
"@aws-sdk/types": "^3.222.0",
"tslib": "^2.6.2"
},
"engines": {
"node": ">=16.0.0"
}
},
"node_modules/@aws-crypto/crc32c": {
"version": "5.2.0",
"resolved": "https://registry.npmjs.org/@aws-crypto/crc32c/-/crc32c-5.2.0.tgz",
"integrity": "sha512-+iWb8qaHLYKrNvGRbiYRHSdKRWhto5XlZUEBwDjYNf+ly5SVYG6zEoYIdxvf5R3zyeP16w4PLBn3rH1xc74Rag==",
"license": "Apache-2.0",
"dependencies": {
"@aws-crypto/util": "^5.2.0",
"@aws-sdk/types": "^3.222.0",
"tslib": "^2.6.2"
}
},
"node_modules/@aws-crypto/sha1-browser": {
"version": "5.2.0",
"resolved": "https://registry.npmjs.org/@aws-crypto/sha1-browser/-/sha1-browser-5.2.0.tgz",
"integrity": "sha512-OH6lveCFfcDjX4dbAvCFSYUjJZjDr/3XJ3xHtjn3Oj5b9RjojQo8npoLeA/bNwkOkrSQ0wgrHzXk4tDRxGKJeg==",
"license": "Apache-2.0",
"dependencies": {
"@aws-crypto/supports-web-crypto": "^5.2.0",
"@aws-crypto/util": "^5.2.0",
"@aws-sdk/types": "^3.222.0",
"@aws-sdk/util-locate-window": "^3.0.0",
"@smithy/util-utf8": "^2.0.0",
"tslib": "^2.6.2"
}
},
"node_modules/@aws-crypto/sha256-browser": {
"version": "5.2.0",
"resolved": "https://registry.npmjs.org/@aws-crypto/sha256-browser/-/sha256-browser-5.2.0.tgz",
"integrity": "sha512-AXfN/lGotSQwu6HNcEsIASo7kWXZ5HYWvfOmSNKDsEqC4OashTp8alTmaz+F7TC2L083SFv5RdB+qU3Vs1kZqw==",
"license": "Apache-2.0",
"dependencies": {
"@aws-crypto/sha256-js": "^5.2.0",
"@aws-crypto/supports-web-crypto": "^5.2.0",
"@aws-crypto/util": "^5.2.0",
"@aws-sdk/types": "^3.222.0",
"@aws-sdk/util-locate-window": "^3.0.0",
"@smithy/util-utf8": "^2.0.0",
"tslib": "^2.6.2"
}
},
"node_modules/@aws-crypto/sha256-js": {
"version": "5.2.0",
"resolved": "https://registry.npmjs.org/@aws-crypto/sha256-js/-/sha256-js-5.2.0.tgz",
"integrity": "sha512-FFQQyu7edu4ufvIZ+OadFpHHOt+eSTBaYaki44c+akjg7qZg9oOQeLlk77F6tSYqjDAFClrHJk9tMf0HdVyOvA==",
"license": "Apache-2.0",
"dependencies": {
"@aws-crypto/util": "^5.2.0",
"@aws-sdk/types": "^3.222.0",
"tslib": "^2.6.2"
},
"engines": {
"node": ">=16.0.0"
}
},
"node_modules/@aws-crAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/kadbbz/skills/aios-transfer-file",
"sourceUrl": "https://clawhub.ai/kadbbz/skills/aios-transfer-file",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T04:58:34.021Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kadbbz-aios-transfer-file/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kadbbz-aios-transfer-file/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T04:58:34.021Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/kadbbz/aios-transfer-file",
"sourceUrl": "https://clawhub.ai/kadbbz/aios-transfer-file",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T04:58:34.021Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.1",
"href": "https://clawhub.ai/kadbbz/aios-transfer-file",
"sourceUrl": "https://clawhub.ai/kadbbz/aios-transfer-file",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-06T08:43:03.647Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kadbbz-aios-transfer-file/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kadbbz-aios-transfer-file/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.1",
"description": "**Enforces per-senderId file isolation and workspace directory structure.** - All file operations are now strictly isolated by the current channel's senderId; topic_id can no longer be used as a substitute. - Local workspace subdirectories standardized to `<senderId>/upload`, `<senderId>/download`, and `<senderId>/generated`. - All script invocations (download and upload) must require explicit `--sender-id <senderId>`; transfer will not proceed if senderId is missing or ambiguous. - File input/output handling, local file placement, and directory creation updated to follow new senderId-based structure. - Strengthened documentation on forbidden usage, directory access, and failure cases. - Removed legacy references and renamed usage of `file_input`/`file_output` directories.",
"href": "https://clawhub.ai/kadbbz/aios-transfer-file",
"sourceUrl": "https://clawhub.ai/kadbbz/aios-transfer-file",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-06T08:43:03.647Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
