Agent Execution Guard
Agent Execution Guard by WorldLoops — a safe-by-default responsibility layer for AI agents that turns scattered work signals into governed open loops while p...
Rank
62
Safety
84
Downloads
2.5k
Updated
Oct 9, 2026
Version
1.13.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.5K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.5K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.13.0release · observed May 22, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s177k598qdpx8sgq8ng5mwwpbh86xsyr:worldloops- Install using `clawhub skill install s177k598qdpx8sgq8ng5mwwpbh86xsyr:worldloops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/swit001/worldloops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-swit001-worldloops/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: worldloops
description: Agent Execution Guard by WorldLoops — a safe-by-default responsibility layer for AI agents that turns scattered work signals into governed open loops while preserving externalWrite:false.
version: "1.12.0"
homepage: https://github.com/swit001/worldloops
metadata: {"openclaw":{"requires":{"bins":["node","npm"]},"envVars":[{"name":"WORLDLOOPS_API_BASE_URL","required":false,"description":"Optional WorldLoops API base URL override. Defaults to https://api.worldloops.ai."},{"name":"WORLDLOOPS_API_KEY","required":false,"description":"Optional bearer token for hosted WorldLoops API."}],"emoji":"🌐","homepage":"https://github.com/swit001/worldloops","skillKey":"worldloops","tags":["openclaw","clawhub","agentic-ai","world-model","executable-world","open-loops","open-loop-management","workflow","human-in-the-loop","safe-by-default","auditable-runtime","stateful-loop-management","agent-execution-guard","execution-governance","execution-contracts","proposal-engine","workflow-governance"]}}
---
# Agent Execution Guard
Agent Execution Guard is a WorldLoops skill for OpenClaw.
It turns signals from tools, messages, and workflows into governed open loops:
Signal → Open Loop → Proposal → Approval → Local Transition → Receipt
It helps agents avoid unsafe or premature execution by keeping action proposals inside a safe, auditable boundary.
---
## Why it matters
Most agents answer from a snapshot.
WorldLoops tracks what remains unresolved.
When an email, calendar event, Slack message, or GitHub notification implies unfinished responsibility, Agent Execution Guard surfaces it as a governed open loop — not a silent side effect.
Every proposed action requires approval before any local transition is committed.
No external system is changed.
`externalWrite:false` is preserved throughout.
---
## Quick Start
```bash
clawhub install worldloops
cd ~/.openclaw/workspace/skills/worldloops
npm run demo
```
### Optional Safety Check
```bash
npm run doctor
```
---
## Example demo output
```bash
npm run demo
```
```
🦞 Agent Execution Guard
🚨 High — Gmail callback requested
State: open
Proposal:
Review claim context and decide whether to call back or prepare a written response. This is a local planning action only — do not initiate any call, email, or external communication without an explicit decision.
Adjudication:
requires_approval
✅ Safe
externalWrite:false
No email, draft, call, or external change made.
```
---
## Safety posture
Agent Execution Guard does not send emails.
Agent Execution Guard does not post chat messages.
Agent Execution Guard does not create calendar events.
Agent Execution Guard does not modify external systems.
```
✅ 0 emails sent
✅ 0 calendar events changed
✅ 0 chat messages posted
✅ 0 files modified
✅ 0 project changes made
✅ externalWrite:false enforced
```
OpenClaw reads signals.
WorldLoops guards execution.
WorldLoops does not need to own every connector.
If a host agent can read a signalREADME.md
# 🦞 WorldLoops — Agent Execution Guard
AI agents can answer from a snapshot.
WorldLoops tracks what remains unresolved.
It turns real work signals into governed open loops — detecting unfinished responsibility, classifying severity, proposing the next transition, adjudicating whether approval is required, recording decisions, and committing local state transitions with receipts.
`externalWrite:false` is preserved throughout.
**WorldLoops is an execution guard for AI agents — not a todo list.**
---
## Architecture
OpenClaw reads signals.
WorldLoops guards execution.
WorldLoops does not need to own every connector.
If a host agent can read a signal, it can pass it to Agent Execution Guard.
OpenClaw observes and interprets source signals (Gmail, Calendar, Slack, GitHub) into `ObservedSignal[]`.
WorldLoops reads those OpenClaw-authored interpreted observations and adjudicates their lifecycle state — into active open loops, attached context, suppression receipts, and transitions.
WorldLoops does not connect to Gmail, Calendar, or Slack directly. `externalWrite:false` is preserved throughout.
```
OpenClaw (reads Gmail, Calendar, Slack, GitHub)
↓
already-read payload
↓
Agent Execution Guard (WorldLoops)
↓
governed open loop → proposal → approval → local transition → receipt
```
---
## OpenClaw Signal Handoff
OpenClaw reads. Agent Execution Guard governs.
No connectors added.
No OAuth added.
No external write.
A host agent (OpenClaw, gog, or any other) places an already-read payload into `.worldloops/inbox/`.
Agent Execution Guard consumes it locally and produces a governed receipt.
```
.worldloops/inbox/openclaw-gmail-live.json ← host agent places this
↓
npm run guard:gmail -- --input .worldloops/inbox/openclaw-gmail-live.json --compact
↓
Agent Execution Guard
↓
governed open loop → proposal → receipt
externalWrite:false
```
### Accepted local payload formats
Agent Execution Guard can consume local payloads in these forms:
- **AdapterSignal JSON** — fully normalized signal with `source`, `sourceType`, `text`, `observedAt`, `externalWrite:false`
- **OpenClaw-style handoff payloads** — already-normalized payloads from OpenClaw host agents
- **gog-style Gmail payloads** — `{ "messages": [...] }` output from gog Gmail reads
- **gog-style Calendar payloads** — `{ "events": [...] }` output from gog Calendar reads
- **Slack host/plugin payloads** — `{ "channel": "...", "messages": [...] }` output from Slack host tools
gog and OpenClaw read Gmail, Calendar, and Slack.
Agent Execution Guard only consumes the local JSON output they produce.
No Gmail, Calendar, or Slack API call is made by WorldLoops.
`externalWrite:false` is preserved throughout.
Supported handoff paths:
```
.worldloops/inbox/openclaw-gmail-live.json
.worldloops/inbox/openclaw-calendar-live.json
.worldloops/inbox/openclaw-slack-live.json
.worldloops/inbox/openclaw-github-live.json
```
Redacted payload examples: [`examples/handoff/`](./examples_meta.json
{
"ownerId": "kn75v4md26j4p9yzt5kh46a5ws86xec5",
"slug": "worldloops",
"version": "1.13.0",
"publishedAt": 1779487590194
}scripts/fixtures/gog-calendar-events.json
{
"events": [
{
"id": "cal-event-001",
"summary": "LG pricing strategy review",
"description": "No agenda attached yet. Prepare pricing assumptions and promotion scenarios before the meeting.",
"start": "2026-05-18T17:00:00.000Z",
"end": "2026-05-18T18:00:00.000Z",
"location": "Zoom",
"htmlLink": "https://calendar.google.com/calendar/event?eid=example"
},
{
"id": "cal-event-002",
"summary": "Customer workshop follow-up",
"description": "Send recap and next-step proposal after the workshop.",
"start": "2026-05-19T19:00:00.000Z",
"end": "2026-05-19T20:00:00.000Z"
}
],
"count": 2
}scripts/fixtures/gog-gmail-messages.json
{
"messages": [
{
"id": "gmail-msg-001",
"threadId": "thread-001",
"subject": "Follow-up on the LG proposal",
"from": "Sarah Chen <[email protected]>",
"snippet": "Just checking if you had a chance to review the proposal and send next steps.",
"date": "2026-05-16T10:30:00.000Z",
"labelIds": ["INBOX", "IMPORTANT"]
},
{
"id": "gmail-msg-002",
"threadId": "thread-002",
"subject": "Deck prep before tomorrow",
"from": "David Kim <[email protected]>",
"snippet": "Can you prepare the pricing deck before tomorrow's meeting?",
"date": "2026-05-16T11:30:00.000Z",
"labelIds": ["INBOX"]
}
],
"count": 2
}activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/swit001/skills/worldloops",
"sourceUrl": "https://clawhub.ai/swit001/skills/worldloops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T13:52:21.106Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-swit001-worldloops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-swit001-worldloops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T13:52:21.106Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.5K downloads",
"href": "https://clawhub.ai/swit001/worldloops",
"sourceUrl": "https://clawhub.ai/swit001/worldloops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T13:52:21.106Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.13.0",
"href": "https://clawhub.ai/swit001/worldloops",
"sourceUrl": "https://clawhub.ai/swit001/worldloops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-22T22:06:30.194Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-swit001-worldloops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-swit001-worldloops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.13.0",
"description": "Adds stateful lifecycle brief UX and language-aware rendering. WorldLoops now surfaces already tracked loops, aging open loops, recently closed loops, needs-review/escalated items, context, suppressed noise, and safe execution boundaries in the Telegram reference brief. Korean requests can render Korean section and field labels. This reinforces the core positioning: OpenClaw observes and interprets; WorldLoops adjudicates lifecycle state. externalWrite:false preserved.",
"href": "https://clawhub.ai/swit001/worldloops",
"sourceUrl": "https://clawhub.ai/swit001/worldloops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-22T22:06:30.194Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
