Mallary Openclaw Skill
Use this skill only when the user explicitly asks to inspect, set up, or act through Mallary, the Mallary CLI, the Mallary API, Mallary MCP, or an existing Mallary workflow. This guide includes read-only discovery and one-step OAuth setup with full Mallary access. A clear request to publish, schedule, upload media for a post, or send a reply authorizes that action without a redundant confirmation; clarify only material details that are missing. Executable write syntax is intentionally omitted.
Rank
62
Safety
84
Downloads
2.2k
Updated
Oct 9, 2026
Version
1.1.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.2K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.2K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.1.6release · observed Oct 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s1772rrgd00r595atcvfwnk6qd84rkdg:mallary- Install using `clawhub skill install s1772rrgd00r595atcvfwnk6qd84rkdg:mallary` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/sammydigits/mallary before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/snapshot"
Documentation
CLAWHUB
146,814 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: mallary
description: Use this skill only when the user explicitly asks to inspect, set up, or act through Mallary, the Mallary CLI, the Mallary API, Mallary MCP, or an existing Mallary workflow. This guide includes read-only discovery and one-step OAuth setup with full Mallary access. A clear request to publish, schedule, upload media for a post, or send a reply authorizes that action without a redundant confirmation; clarify only material details that are missing. Executable write syntax is intentionally omitted.
version: 1.0.19
homepage: https://mallary.ai/
metadata:
openclaw:
emoji: "🌎"
requires:
bins:
- mallary
---
# Mallary Agent Skill
## Safety Contract
Start with minimum read-only discovery unless the user clearly asks Mallary to perform an action. OAuth login is limited to an explicit setup or authentication request and grants read, publish, engage, and manage access in one browser approval.
- Treat profile, account, post, comment, job, analytics, settings, and webhook output as sensitive.
- Request only the data needed for the user's stated Mallary task.
- Redact API keys, tokens, account identifiers, profile identifiers, post metadata, and customer data before sharing output.
- A CLI capability is not authorization to use it.
- Do not suggest or run a state-changing action during discovery.
- Treat a clear current request to publish, schedule, upload media for a post, or send a reply as authorization for that action. Do not ask for a second confirmation.
- A setup or authentication request alone is not a request to publish or change Mallary.
The Mallary product can transfer local files, publish or schedule content, post public replies, remove queued work, attach final URLs, change webhooks or settings, and disconnect accounts. Those actions can affect remote data, public content, or account access. Executable syntax for these actions is intentionally omitted from this skill.
## Local Setup Boundary
The `mallary` binary must already be available. Checking the binary and the current authentication status is read-only and does not print credentials:
```bash
command -v mallary >/dev/null
mallary auth status
```
If the binary is missing, stop and ask the user to install it or explicitly approve a local installation. Do not run a package-manager install automatically.
If the user explicitly asks to set up or authenticate Mallary, use `mallary auth login`. It requests all Mallary capabilities in one flow. Show the Mallary verification URL and one-time code, then wait for the user to approve access in their browser. Never ask for or print their Mallary password, OAuth tokens, or API key.
Do not ask the user to choose OAuth scopes or add scope flags. OAuth consent gives the CLI capabilities; it does not cause any post or account change by itself.
An API key remains an optional fallback for CI or another environment where OAuth is not practical. If the user chooses it, ask them to set it through theiREADME.md
# Mallary CLI - OpenClaw Safety Guide This README is the safe agent-facing overview for the Mallary OpenClaw skill. It is intentionally not the full human CLI manual and does not provide executable syntax for data transfer, publishing, replies, deletion, webhook changes, settings changes, or platform disconnection. A documented or implemented capability is not authorization. AI agents must begin with minimum read-only discovery and must not infer a write request from this file. ## Safety Contract - use Mallary only when the user explicitly asks for Mallary or provides an existing Mallary workflow to inspect - begin with the lowest-risk read-only command that can answer the request - request the minimum data needed and redact sensitive operational output before sharing it - never use a data-transmitting or state-changing action as a setup, authentication, or smoke test - if the user clearly requests publishing, scheduling, an upload for that post, or a reply, follow [SKILL.md](./SKILL.md), resolve any missing material detail, and execute without asking for another confirmation - run a requested action once and verify it with a read-only command Installation, authentication, or discovery alone is not a request to publish or change Mallary. ## Install Only When Requested Installation changes the local environment. An AI agent must not install or update the package unless the user explicitly asks for or approves it. ```bash npm install -g @mallary/cli # Or inspect help through a temporary npx invocation: npx @mallary/cli --help ``` ## OAuth and Credential Safety For an explicit Mallary setup or authentication request, use browser-based OAuth. One login grants all Mallary capabilities: ```bash mallary auth login mallary auth status ``` Show the user only the Mallary verification URL and one-time code, then wait for browser approval. Never ask the user to paste a password, API key, access token, or refresh token into chat. Do not ask the user to choose scopes or add scope flags. OAuth access does not publish or change anything during setup. `MALLARY_API_KEY` remains an optional fallback for CI or another environment where OAuth is not practical. It is a bearer secret. If the user intentionally chooses an API key: - load it from a password manager, locked-down untracked environment file, or masked CI secret - never paste it into prompts, tickets, screenshots, documentation, or shell commands that enter history - never print it with `echo`, `printenv`, shell tracing, debug logs, or CI output - rotate or revoke it if exposed When `MALLARY_API_KEY` is set, it takes precedence over stored OAuth access. ## Lowest-Risk Verification Use general help and service health for installation or connectivity checks: ```bash mallary --help mallary health ``` `mallary health` is read-only and does not require authentication. ## Read-Only Discovery Commands Run only the command needed for the user's request: ```bash mallary profiles list mallary pla
_meta.json
{
"ownerId": "kn76b3gakkp8xdk4rrcaewvadx84s1fy",
"slug": "mallary",
"version": "1.1.6",
"publishedAt": 1791551851714
}FEATURES.md
# Mallary CLI - Feature Summary ## Complete Feature Set Mallary CLI is the official command-line interface for Mallary.ai. Its read-only commands let developers, operators, CI jobs, and AI agents inspect jobs, analytics, settings, profiles, webhooks, and connected platforms. It also has write-capable commands for uploads, publishing, replies, webhook changes, settings updates, post deletion, TikTok URL attachment, and platform disconnection. Those capabilities do not give an AI agent permission to use them. The CLI mirrors the public Mallary API. It does not bypass plan limits, feature gates, connected-account requirements, or platform validation rules. ## AI Agent Safety Contract This feature list describes what the CLI can do. It is not a user request to run a state-changing command. - Start with the minimum read-only discovery needed for the request. Prefer `mallary health`, `mallary profiles list`, `mallary platforms list`, `mallary posts list`, `mallary jobs get`, `mallary analytics list`, `mallary audience list`, `mallary settings get`, or `mallary webhooks list`. - Treat discovery output as sensitive. Request only needed fields and redact profile IDs, account labels, post data, settings, and webhook details before sharing them. - Run an upload, post, reply, delete, TikTok URL attachment, webhook change, settings update, or platform disconnect only when the user clearly requests that type of action. - A clear request to publish, schedule, upload media for that post, or send a reply authorizes that action. Ask only for a material detail that is missing or ambiguous; do not ask for a second confirmation. - Keep the action within the request, run it once, and use a read-only command to verify the result. Never use a write command as a smoke test. For unattended CI, the owner must define the exact command, profile, destinations, payload source, and intended side effect in that workflow. Do not broaden that authorization at runtime. ### Posts with Comments and Media - FULLY SUPPORTED Mallary supports both simple post creation and advanced payload-based publishing. #### Posts with Comments - You can attach follow-up comments with repeatable `--comment` flags in flag mode. - In file mode, use `comments_under_post` in the JSON payload. - The public API currently limits follow-up comments to 3 items. #### Multiple Media per Post/Comment - Mallary supports multi-media posts where the target platform allows it. - The CLI uploads local file paths before it sends the post request. - The CLI also uploads local video thumbnail paths in `media[].thumbnail_url`. - The CLI rejects remote third-party media URLs. - The CLI accepts `https://files.mallary.ai/...` URLs. #### Multi-Platform Posting - One `posts create` request can target multiple platforms at once. - Use repeatable `--platform` flags in flag mode. - Use `--post-type` in flag mode when every selected platform should use the same supported type, such as `story` for Facebook and Instag
HOW_TO_RUN.md
# How to Run the Mallary CLI
You can run the CLI in several ways.
## Option 1: Run the Built File Directly
The built file at `cli/dist/index.js` is executable.
```bash
# From the repository root
node cli/dist/index.js --help
# Or run it directly (it has a shebang)
./cli/dist/index.js --help
# Example authenticated command. Set MALLARY_API_KEY from a secret store first
test -n "${MALLARY_API_KEY:-}" && echo "MALLARY_API_KEY is set"
node cli/dist/index.js posts list
node cli/dist/index.js profiles list
```
## Option 2: Link Globally (Recommended for Development)
This creates a global `mallary` command you can use anywhere.
```bash
# From the CLI directory
cd cli
npm link
# Now you can use it anywhere
mallary --help
mallary profiles list
mallary posts list
# To unlink later
npm unlink -g @mallary/cli
```
After you link the package, you can use `mallary` from any directory.
## Option 3: Use npm Scripts (From `cli/`)
```bash
# From the CLI directory
cd cli
npm run build
npm run start -- --help
npm run start -- profiles list
npm run start -- posts list
```
## Option 4: Use npm/npx (Published Package)
After you publish or install the package from npm:
```bash
# Install globally
npm install -g @mallary/cli
# Or use with npx (no global install)
npx @mallary/cli --help
npx @mallary/cli profiles list
npx @mallary/cli posts list
```
## Quick Setup Guide
Use `mallary profiles list` to find a non-default profile ID. Replace `AbC123xYz90` in examples with a real public profile ID, or omit `--profile-id` to use the default profile.
### Step 1: Build the CLI
```bash
# From the repository root
cd cli
npm install
npm run build
```
### Step 2: Set Your API Key
Security: `MALLARY_API_KEY` is a bearer secret. Do not commit it, paste it into prompts or tickets, print it in logs, or expose it in shell history. Use your password manager, a locked-down untracked env file, or a CI secret store for persistent use.
```bash
read -rsp "Mallary API key: " MALLARY_API_KEY; echo; export MALLARY_API_KEY
```
### Step 3: Choose Your Method
For quick testing:
```bash
node cli/dist/index.js --help
```
For regular use:
```bash
cd cli
npm link
mallary --help
```
## Troubleshooting
### "Command not found: mallary"
If you linked globally but still get this error:
```bash
# Make sure that the link exists
which mallary
# If it is not found, link it again
cd cli
npm link
# Or look at your PATH
echo $PATH
```
### "MALLARY_API_KEY is not set"
```bash
read -rsp "Mallary API key: " MALLARY_API_KEY; echo; export MALLARY_API_KEY
# Make sure that it is set without printing the key
test -n "${MALLARY_API_KEY:-}" && echo "MALLARY_API_KEY is set"
```
### Permission Denied
If you get permission errors when you run the built file directly:
```bash
# Make the file executable
chmod +x cli/dist/index.js
# Then try again
./cli/dist/index.js --help
```
### Rebuild After Changes
After you change the code, build it again:
```bash
cd cli
npm run build
```
If you liAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/sammydigits/skills/mallary",
"sourceUrl": "https://clawhub.ai/sammydigits/skills/mallary",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T17:41:20.439Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T17:41:20.439Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.2K downloads",
"href": "https://clawhub.ai/sammydigits/mallary",
"sourceUrl": "https://clawhub.ai/sammydigits/mallary",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T17:41:20.439Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.1.6",
"href": "https://clawhub.ai/sammydigits/mallary",
"sourceUrl": "https://clawhub.ai/sammydigits/mallary",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T13:17:31.714Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.1.6",
"description": "Add support for drafts",
"href": "https://clawhub.ai/sammydigits/mallary",
"sourceUrl": "https://clawhub.ai/sammydigits/mallary",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-09T13:17:31.714Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
