magento-admin
Complete Magento 2 store administration via SSH key auth, REST API, GraphQL, and direct DB access. For server owners on their own infrastructure. SSH key auth and passwordless sudo required. Skill: magento-admin Owner: nj070574-gif Summary: Complete Magento 2 store administration via SSH key auth, REST API, GraphQL, and direct DB access. For server owners on their own infrastructure. SSH key auth and passwordless sudo required. Tags: latest:5.7.0 Version history: v5.7.0 | 2026-10-03T09:42:59.885Z | user v5.7.0 - Security hardening + fixes (verified against live Magento 2.4.9). Input Handling & Injection
Rank
62
Safety
84
Downloads
1.0k
Updated
Oct 11, 2026
Version
5.7.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 5.7.0release · observed Oct 3, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s1747h3dssx5wbb4xxpn85vtsd83gnax:magento-admin- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-nj070574-gif-magento-admin/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
145,353 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: magento-admin
version: "5.7.0"
description: >
Complete Magento 2 store administration via SSH key auth, REST API, GraphQL,
and direct DB access. For server owners on their own infrastructure.
SSH key auth and passwordless sudo required.
author: openclaw-community
license: MIT
tags: [magento, ecommerce, devops, store-admin, ssh, rest-api, graphql, composer]
requires:
primary_credential: MAGENTO_SSH_KEY
env:
- name: MAGENTO_HOST
description: Magento server IP or hostname
- name: MAGENTO_SSH_USER
description: SSH username (passwordless sudo required on server)
- name: MAGENTO_SSH_KEY
description: Path to SSH private key (e.g. ~/.ssh/magento_deploy)
- name: MAGENTO_WEB_ROOT
description: Magento installation path (e.g. /var/www/html/magento2)
- name: MAGENTO_PHP
description: PHP binary (e.g. /usr/bin/php8.4)
- name: MAGENTO_WEB_USER
description: Web server user (e.g. www-data)
- name: MAGENTO_DB_NAME
description: Database name
- name: MAGENTO_DB_USER
description: Database username
- name: MAGENTO_DB_PASS
description: Database password
- name: MAGENTO_BASE_URL
description: Store base URL (e.g. https://store.example.com)
- name: MAGENTO_ADMIN_USER
description: Magento admin username
- name: MAGENTO_ADMIN_PASS
description: Magento admin password (REST API token generation only)
optional_env:
- name: MAGENTO_CA_CERT
description: CA cert path for HTTPS (e.g. /opt/ssl/ca.crt)
- name: MAGENTO_OS_URL
description: OpenSearch URL (default http://127.0.0.1:9200)
- name: MAGENTO_ADMIN_PATH
description: Admin path (default admin)
- name: COMPOSER_PATH
description: Composer binary path (e.g. /usr/local/bin/composer)
binaries:
- ssh
- mysql
- curl
- redis-cli
- python3
security:
scope: owner-operated
risk_level: high
risk_acknowledged: true
risk_justification: >-
Full store admin requires SSH + DB + REST access by design. High privilege
is inherent and intentional. Install only on infrastructure you own.
auth_method: ssh-key-only
sudo_method: passwordless-sudoers
credential_handling: user-supplied-only
network_access: user-own-server-only
note: >
SSH key auth only. DB password via MYSQL_PWD env var (not in process args).
REST API password in HTTPS body only. All credentials user-supplied.
Connects only to MAGENTO_HOST. Nothing sent to third parties.
prompt_injection_mitigation: >
Connection parameters come only from the fixed MAGENTO_* config variables and
are never taken from chat. User-supplied operands (order IDs, emails, SKUs,
module names, config paths, etc.) are validated against strict allowlist
patterns before substitution and refused if they do not match — see the
"Input Handling & Injection Safety" section. Never interpolate unvalidated
free-form text into a shell command, SQL statement, or URL.
---
# m_meta.json
{
"ownerId": "kn75wmg9n12pjn92x60r99d04983gkgd",
"slug": "magento-admin",
"version": "5.7.0",
"publishedAt": 1791020579885
}skill-card.md
## Description: Helps store owners administer their Magento 2 installations through SSH, REST, GraphQL, and database access. This skill is ready for commercial/non-commercial use. ## Publisher: [nj070574-gif](https://clawhub.ai/user/nj070574-gif) ### License/Terms of Use: MIT-0 ## Use Case: Magento store owners and administrators use this skill to inspect and manage their own stores, including orders, products, configuration, maintenance, and backups. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Broad SSH, database, admin API, and sudo access can change or disrupt a store. Mitigation: Install only on infrastructure you own and administer; limit granted privileges and review high-impact commands before execution. Risk: Refunds, admin-user creation, extension installs, database restores, service restarts, and raw SQL can have significant effects. Mitigation: Require explicit owner approval for these operations before allowing autonomous execution. ## Reference(s): - [Magento Admin skill on ClawHub](https://clawhub.ai/nj070574-gif/skills/magento-admin) - [Publisher profile on ClawHub](https://clawhub.ai/user/nj070574-gif) ## Skill Output: **Output Type(s):** [Shell commands, API calls, Configuration guidance, Text] **Output Format:** [Markdown with command examples and plain-language status summaries] **Output Parameters:** [1D] **Other Properties Related to Output:** [Requires owner-supplied access to the Magento host, database, and admin API.] ## Skill Version(s): 5.7.0 (source: server release and skill frontmatter) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/nj070574-gif/skills/magento-admin",
"sourceUrl": "https://clawhub.ai/nj070574-gif/skills/magento-admin",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T15:56:59.507Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-nj070574-gif-magento-admin/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nj070574-gif-magento-admin/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T15:56:59.507Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1K downloads",
"href": "https://clawhub.ai/nj070574-gif/magento-admin",
"sourceUrl": "https://clawhub.ai/nj070574-gif/magento-admin",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T15:56:59.507Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "5.7.0",
"href": "https://clawhub.ai/nj070574-gif/magento-admin",
"sourceUrl": "https://clawhub.ai/nj070574-gif/magento-admin",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T09:42:59.885Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-nj070574-gif-magento-admin/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nj070574-gif-magento-admin/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 5.7.0",
"description": "v5.7.0 - Security hardening + fixes (verified against live Magento 2.4.9). Input Handling & Injection Safety guidance; TLS/CA-cert conditional handling (never -k); repaired Configuration section; PHP example aligned; health-check service-list superset documented; known_hosts pre-seed added to setup.",
"href": "https://clawhub.ai/nj070574-gif/magento-admin",
"sourceUrl": "https://clawhub.ai/nj070574-gif/magento-admin",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T09:42:59.885Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
