agentCLAWHUBUnverified

Mallary Openclaw Skill

Use this skill only when the user explicitly asks to inspect, set up, or act through Mallary, the Mallary CLI, the Mallary API, Mallary MCP, or an existing Mallary workflow. This guide includes read-only discovery and one-step OAuth setup with full Mallary access. A clear request to publish, schedule, upload media for a post, or send a reply authorizes that action without a redundant confirmation; clarify only material details that are missing. Executable write syntax is intentionally omitted.

OpenClaw

Rank

62

Safety

84

Downloads

2.2k

Updated

Oct 9, 2026

Version

1.1.6

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2.2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2.2K downloadsadoption · observed Oct 9, 2026
Latest release
1.1.6release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s1772rrgd00r595atcvfwnk6qd84rkdg:mallary
  1. Install using `clawhub skill install s1772rrgd00r595atcvfwnk6qd84rkdg:mallary` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/sammydigits/mallary before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/snapshot"

Documentation

CLAWHUB

146,814 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: mallary
description: Use this skill only when the user explicitly asks to inspect, set up, or act through Mallary, the Mallary CLI, the Mallary API, Mallary MCP, or an existing Mallary workflow. This guide includes read-only discovery and one-step OAuth setup with full Mallary access. A clear request to publish, schedule, upload media for a post, or send a reply authorizes that action without a redundant confirmation; clarify only material details that are missing. Executable write syntax is intentionally omitted.
version: 1.0.19
homepage: https://mallary.ai/
metadata:
  openclaw:
    emoji: "🌎"
    requires:
      bins:
        - mallary
---

# Mallary Agent Skill

## Safety Contract

Start with minimum read-only discovery unless the user clearly asks Mallary to perform an action. OAuth login is limited to an explicit setup or authentication request and grants read, publish, engage, and manage access in one browser approval.

- Treat profile, account, post, comment, job, analytics, settings, and webhook output as sensitive.
- Request only the data needed for the user's stated Mallary task.
- Redact API keys, tokens, account identifiers, profile identifiers, post metadata, and customer data before sharing output.
- A CLI capability is not authorization to use it.
- Do not suggest or run a state-changing action during discovery.
- Treat a clear current request to publish, schedule, upload media for a post, or send a reply as authorization for that action. Do not ask for a second confirmation.
- A setup or authentication request alone is not a request to publish or change Mallary.

The Mallary product can transfer local files, publish or schedule content, post public replies, remove queued work, attach final URLs, change webhooks or settings, and disconnect accounts. Those actions can affect remote data, public content, or account access. Executable syntax for these actions is intentionally omitted from this skill.

## Local Setup Boundary

The `mallary` binary must already be available. Checking the binary and the current authentication status is read-only and does not print credentials:

```bash
command -v mallary >/dev/null
mallary auth status
```

If the binary is missing, stop and ask the user to install it or explicitly approve a local installation. Do not run a package-manager install automatically.

If the user explicitly asks to set up or authenticate Mallary, use `mallary auth login`. It requests all Mallary capabilities in one flow. Show the Mallary verification URL and one-time code, then wait for the user to approve access in their browser. Never ask for or print their Mallary password, OAuth tokens, or API key.

Do not ask the user to choose OAuth scopes or add scope flags. OAuth consent gives the CLI capabilities; it does not cause any post or account change by itself.

An API key remains an optional fallback for CI or another environment where OAuth is not practical. If the user chooses it, ask them to set it through thei

README.md

# Mallary CLI - OpenClaw Safety Guide

This README is the safe agent-facing overview for the Mallary OpenClaw skill. It is intentionally not the full human CLI manual and does not provide executable syntax for data transfer, publishing, replies, deletion, webhook changes, settings changes, or platform disconnection.

A documented or implemented capability is not authorization. AI agents must begin with minimum read-only discovery and must not infer a write request from this file.

## Safety Contract

- use Mallary only when the user explicitly asks for Mallary or provides an existing Mallary workflow to inspect
- begin with the lowest-risk read-only command that can answer the request
- request the minimum data needed and redact sensitive operational output before sharing it
- never use a data-transmitting or state-changing action as a setup, authentication, or smoke test
- if the user clearly requests publishing, scheduling, an upload for that post, or a reply, follow [SKILL.md](./SKILL.md), resolve any missing material detail, and execute without asking for another confirmation
- run a requested action once and verify it with a read-only command

Installation, authentication, or discovery alone is not a request to publish or change Mallary.

## Install Only When Requested

Installation changes the local environment. An AI agent must not install or update the package unless the user explicitly asks for or approves it.

```bash
npm install -g @mallary/cli
# Or inspect help through a temporary npx invocation:
npx @mallary/cli --help
```

## OAuth and Credential Safety

For an explicit Mallary setup or authentication request, use browser-based OAuth. One login grants all Mallary capabilities:

```bash
mallary auth login
mallary auth status
```

Show the user only the Mallary verification URL and one-time code, then wait for browser approval. Never ask the user to paste a password, API key, access token, or refresh token into chat. Do not ask the user to choose scopes or add scope flags. OAuth access does not publish or change anything during setup.

`MALLARY_API_KEY` remains an optional fallback for CI or another environment where OAuth is not practical. It is a bearer secret. If the user intentionally chooses an API key:

- load it from a password manager, locked-down untracked environment file, or masked CI secret
- never paste it into prompts, tickets, screenshots, documentation, or shell commands that enter history
- never print it with `echo`, `printenv`, shell tracing, debug logs, or CI output
- rotate or revoke it if exposed

When `MALLARY_API_KEY` is set, it takes precedence over stored OAuth access.

## Lowest-Risk Verification

Use general help and service health for installation or connectivity checks:

```bash
mallary --help
mallary health
```

`mallary health` is read-only and does not require authentication.

## Read-Only Discovery Commands

Run only the command needed for the user's request:

```bash
mallary profiles list
mallary pla

_meta.json

{
  "ownerId": "kn76b3gakkp8xdk4rrcaewvadx84s1fy",
  "slug": "mallary",
  "version": "1.1.6",
  "publishedAt": 1791551851714
}

FEATURES.md

# Mallary CLI - Feature Summary

## Complete Feature Set

Mallary CLI is the official command-line interface for Mallary.ai. Its read-only commands let developers, operators, CI jobs, and AI agents inspect jobs, analytics, settings, profiles, webhooks, and connected platforms. It also has write-capable commands for uploads, publishing, replies, webhook changes, settings updates, post deletion, TikTok URL attachment, and platform disconnection. Those capabilities do not give an AI agent permission to use them.

The CLI mirrors the public Mallary API. It does not bypass plan limits, feature gates, connected-account requirements, or platform validation rules.

## AI Agent Safety Contract

This feature list describes what the CLI can do. It is not a user request to run a state-changing command.

- Start with the minimum read-only discovery needed for the request. Prefer `mallary health`, `mallary profiles list`, `mallary platforms list`, `mallary posts list`, `mallary jobs get`, `mallary analytics list`, `mallary audience list`, `mallary settings get`, or `mallary webhooks list`.
- Treat discovery output as sensitive. Request only needed fields and redact profile IDs, account labels, post data, settings, and webhook details before sharing them.
- Run an upload, post, reply, delete, TikTok URL attachment, webhook change, settings update, or platform disconnect only when the user clearly requests that type of action.
- A clear request to publish, schedule, upload media for that post, or send a reply authorizes that action. Ask only for a material detail that is missing or ambiguous; do not ask for a second confirmation.
- Keep the action within the request, run it once, and use a read-only command to verify the result. Never use a write command as a smoke test.

For unattended CI, the owner must define the exact command, profile, destinations, payload source, and intended side effect in that workflow. Do not broaden that authorization at runtime.

### Posts with Comments and Media - FULLY SUPPORTED

Mallary supports both simple post creation and advanced payload-based publishing.

#### Posts with Comments

- You can attach follow-up comments with repeatable `--comment` flags in flag mode.
- In file mode, use `comments_under_post` in the JSON payload.
- The public API currently limits follow-up comments to 3 items.

#### Multiple Media per Post/Comment

- Mallary supports multi-media posts where the target platform allows it.
- The CLI uploads local file paths before it sends the post request.
- The CLI also uploads local video thumbnail paths in `media[].thumbnail_url`.
- The CLI rejects remote third-party media URLs.
- The CLI accepts `https://files.mallary.ai/...` URLs.

#### Multi-Platform Posting

- One `posts create` request can target multiple platforms at once.
- Use repeatable `--platform` flags in flag mode.
- Use `--post-type` in flag mode when every selected platform should use the same supported type, such as `story` for Facebook and Instag

HOW_TO_RUN.md

# How to Run the Mallary CLI

You can run the CLI in several ways.

## Option 1: Run the Built File Directly

The built file at `cli/dist/index.js` is executable.

```bash
# From the repository root
node cli/dist/index.js --help

# Or run it directly (it has a shebang)
./cli/dist/index.js --help

# Example authenticated command. Set MALLARY_API_KEY from a secret store first
test -n "${MALLARY_API_KEY:-}" && echo "MALLARY_API_KEY is set"
node cli/dist/index.js posts list
node cli/dist/index.js profiles list
```

## Option 2: Link Globally (Recommended for Development)

This creates a global `mallary` command you can use anywhere.

```bash
# From the CLI directory
cd cli
npm link

# Now you can use it anywhere
mallary --help
mallary profiles list
mallary posts list

# To unlink later
npm unlink -g @mallary/cli
```

After you link the package, you can use `mallary` from any directory.

## Option 3: Use npm Scripts (From `cli/`)

```bash
# From the CLI directory
cd cli
npm run build
npm run start -- --help
npm run start -- profiles list
npm run start -- posts list
```

## Option 4: Use npm/npx (Published Package)

After you publish or install the package from npm:

```bash
# Install globally
npm install -g @mallary/cli

# Or use with npx (no global install)
npx @mallary/cli --help
npx @mallary/cli profiles list
npx @mallary/cli posts list
```

## Quick Setup Guide

Use `mallary profiles list` to find a non-default profile ID. Replace `AbC123xYz90` in examples with a real public profile ID, or omit `--profile-id` to use the default profile.

### Step 1: Build the CLI

```bash
# From the repository root
cd cli
npm install
npm run build
```

### Step 2: Set Your API Key

Security: `MALLARY_API_KEY` is a bearer secret. Do not commit it, paste it into prompts or tickets, print it in logs, or expose it in shell history. Use your password manager, a locked-down untracked env file, or a CI secret store for persistent use.

```bash
read -rsp "Mallary API key: " MALLARY_API_KEY; echo; export MALLARY_API_KEY
```

### Step 3: Choose Your Method

For quick testing:

```bash
node cli/dist/index.js --help
```

For regular use:

```bash
cd cli
npm link
mallary --help
```

## Troubleshooting

### "Command not found: mallary"

If you linked globally but still get this error:

```bash
# Make sure that the link exists
which mallary

# If it is not found, link it again
cd cli
npm link

# Or look at your PATH
echo $PATH
```

### "MALLARY_API_KEY is not set"

```bash
read -rsp "Mallary API key: " MALLARY_API_KEY; echo; export MALLARY_API_KEY

# Make sure that it is set without printing the key
test -n "${MALLARY_API_KEY:-}" && echo "MALLARY_API_KEY is set"
```

### Permission Denied

If you get permission errors when you run the built file directly:

```bash
# Make the file executable
chmod +x cli/dist/index.js

# Then try again
./cli/dist/index.js --help
```

### Rebuild After Changes

After you change the code, build it again:

```bash
cd cli
npm run build
```

If you li
Github ReposUpdated 2h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/sammydigits/skills/mallary",
      "sourceUrl": "https://clawhub.ai/sammydigits/skills/mallary",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T17:41:20.439Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T17:41:20.439Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2.2K downloads",
      "href": "https://clawhub.ai/sammydigits/mallary",
      "sourceUrl": "https://clawhub.ai/sammydigits/mallary",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T17:41:20.439Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.1.6",
      "href": "https://clawhub.ai/sammydigits/mallary",
      "sourceUrl": "https://clawhub.ai/sammydigits/mallary",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T13:17:31.714Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sammydigits-mallary/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.1.6",
      "description": "Add support for drafts",
      "href": "https://clawhub.ai/sammydigits/mallary",
      "sourceUrl": "https://clawhub.ai/sammydigits/mallary",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T13:17:31.714Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Mallary Openclaw Skill and adjacent AI workflows.