agentCLAWHUBUnverified

endpoint-aiops

Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint). Always use this skill for "endpoint fleet overview", "list managed endpoints", "which endpoints are worst", "endpoint health score", "rank endpoints by risk", "why is login slow this morning", "login storm", "boot time analysis", "patch drift", "config drift", "which endpoints are behind on patches", "assign a profile to an endpoint", or "reboot a thin client" when the context is an endpoint-management fleet. Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only). Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).

OpenClaw

Rank

62

Safety

84

Downloads

1.5k

Updated

Oct 10, 2026

Version

0.10.3

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.5K downloadsadoption · observed Oct 10, 2026
Latest release
0.10.3release · observed Sep 15, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:endpoint-aiops
  1. Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:endpoint-aiops` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/endpoint-aiops before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/snapshot"

Documentation

CLAWHUB

149,845 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: endpoint-aiops
slug: endpoint-aiops
displayName: "Endpoint AIops"
summary: "Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo."
license: MIT
homepage: https://github.com/AIops-tools/Endpoint-AIops
tags: [aiops, mcp, governance, endpoint]
description: >
  Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint).
  Always use this skill for "endpoint fleet overview", "list managed endpoints", "which endpoints are worst", "endpoint health score", "rank endpoints by risk", "why is login slow this morning", "login storm", "boot time analysis", "patch drift", "config drift", "which endpoints are behind on patches", "assign a profile to an endpoint", or "reboot a thin client" when the context is an endpoint-management fleet.
  Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only).
  Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).
installer:
  kind: uv
  package: endpoint-aiops
argument-hint: "[endpoint id or describe your fleet task]"
allowed-tools:
  - Bash
metadata: {"openclaw":{"requires":{"anyBins":["endpoint-aiops","uvx"]},"optional":{"env":["ENDPOINT_AIOPS_CONFIG","ENDPOINT_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Endpoint-AIops","emoji":"💻","os":["macos","linux"]}}
compatibility: >
  Standalone, self-governed managed-endpoint operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
  All write operations are audited to a local SQLite DB under ~/.endpoint-aiops/ (relocatable via ENDPOINT_AIOPS_HOME).
  Credentials: the endpoint-management server's API key is stored ENCRYPTED in ~/.endpoint-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'endpoint-aiops init' to onboard, or 'endpoint-aiops secret set <target>' to add one. The store is unlocked by a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var ENDPOINT_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'endpoint-aiops s

_meta.json

{
  "ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
  "slug": "endpoint-aiops",
  "version": "0.10.3",
  "publishedAt": 1789451698702
}

references/agent-guardrails.md

# Agent guardrails — running endpoint-aiops with a smaller / local model

If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.

The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.

## Authorization is not this tool's job — decide it where it belongs

Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:

- **The account you connect with.** Give it a management-console account or API
  token scoped to a read-only role. A write then fails at the server, which is
  the only place the permission actually lives — no skill-side flag can be
  argued around by a model, but a revoked permission cannot be.
- **Your agent's system prompt.** If you want an observe-only session, tell the
  model not to call the write tools (they are clearly tagged `[WRITE]`).

What the tool *does* guarantee is that you can always see what happened:

## What the tool enforces — do not waste prompt budget on these

| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Log everything you do, over both MCP and the CLI" | Every call is audited to `~/.endpoint-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |
| "Don't invent a value when a field is missing" | A field the management server did not return comes back as `null`, never as `""`. An endpoint with no reported `patchLevel` is distinguishable from one reporting a blank level, and the key is always present. |
| "Tell me if the output was cut off" | Every capped list is `{"items": [...], "returned": N, "limit": L, "truncated": true/false}`. Truncation is measured against the full result, not guessed from the row count matching the limit. |
| "Give me the real totals, not just what you can see" | Counts are computed over the whole fleet, never over the capped list: `driftedCount`, `behindCount`, `nonCompliantCount`, `stormCount`, and the health-score `summary` are all uncapped. `complianceRatePct` is likewise a whole-fleet figure. |
| "Explain why something was flagged" | Every flag carries its number: each health-score deduction is cited in that endpoint's `reasons`, each drift row states `expected` vs `actual`, and `login_storm_analysis` returns the `thresholds` it used. |
| "Confirm before anything destructive" | `endpoint assign-profile` and `endpoint reboot` require `--dry-run`-a

references/capabilities.md

# endpoint-aiops capabilities

> 13 MCP tools (10 read, 3 write). REST paths are modelled generically against
> an endpoint-management API and have not yet been exercised live
> (see docs/VERIFICATION.md).

## Read tools (10)

| Tool | REST path | Returns |
|------|----------------|---------|
| `overview` | `GET /endpoints` (fold) | total, online, offline, stale[], agentVersionSpread, patchLevelSpread |
| `endpoint_list` | `GET /endpoints` | id, hostname, os, osBuild, agentVersion, patchLevel, profileId, online, lastSeenHours |
| `endpoint_get` | `GET /endpoints/{id}` | single endpoint detail (normalised) |
| `endpoint_health_score` | injected only | endpointsEvaluated, baseline{agentVersion,patchLevel,source}, summary{healthy,degraded,critical}, worst{items[]{endpoint,score,band,reasons[]},returned,limit,truncated}, note |
| `session_list` | `GET /sessions?since_hours=` | endpoint, user, loginMs, bootMs, timestamp, result |
| `login_storm_analysis` | `GET /sessions` or injected | stormCount, storms/slowestByLogin/slowestByBoot (each {items[],returned,limit,truncated}), slowLoginCount, failedLogins, thresholds |
| `drift_report` | `GET /endpoints` or injected | baseline, driftByField, driftedEndpoints{items[],returned,limit,truncated}, drifted/compliant counts |
| `patch_status` | `GET /endpoints` or injected | targetPatch, distribution, behind{items[],returned,limit,truncated}, behindCount |
| `patch_compliance` | injected only | endpointsEvaluated, targetPatch, targetSource, slaTargetPct, complianceRatePct, compliantCount, verdict, nonCompliantCount, nonCompliant{items[],returned,limit,truncated}, note |
| `undo_list` | local undo store | recorded, not-yet-applied reversible writes: undos[]{undoId, ts, originalTool, inverseTool, note}, returned, limit, truncated |

The analysis tools accept an injected `sessions=` / `endpoints=` list for
pure/offline analysis. `login_storm_analysis`, `drift_report` and `patch_status`
also pull live from a configured `target`; `endpoint_health_score` and
`patch_compliance` are injected-only (they score rows you already hold, e.g.
from `endpoint_list`).

## Write tools (3)

| Tool | Risk | REST path | Undo / safety |
|------|------|----------------|---------------|
| `endpoint_assign_profile` | **high** | `POST /endpoints/{id}/profile` | captures the prior profile; records an inverse "reassign prior profile" undo descriptor; CLI double-confirm + dry-run |
| `endpoint_reboot` | medium | `POST /endpoints/{id}/reboot` | captures prior online state; no safe inverse, no undo; CLI double-confirm + dry-run |
| `undo_apply` | medium | local undo store → inverse tool | executes a recorded inverse; the inverse runs through its own governed tool (its real risk tier is recorded there); single-use token; supports `dry_run` |

## Out of scope (by design)

- Endpoint **enrollment / de-enrollment**
- Image / OTA / firmware push
- Profile CRUD (create/delete config profiles) and user/group management
- OT / industrial equipment (

references/cli-reference.md

# endpoint-aiops CLI reference

> REST paths are modelled generically against an endpoint-management API and
> have not yet been exercised live (see docs/VERIFICATION.md).

## Setup & diagnostics

```bash
endpoint-aiops init                      # interactive onboarding wizard
endpoint-aiops doctor [--skip-auth]      # config + secret store + connectivity (/version)
endpoint-aiops mcp                       # start the MCP server (stdio transport)
```

## Secrets (encrypted store ~/.endpoint-aiops/secrets.enc)

```bash
endpoint-aiops secret set <target> [--value <key>]   # store API key (hidden prompt if no --value)
endpoint-aiops secret list                            # names only — values never shown
endpoint-aiops secret rm <target>
endpoint-aiops secret migrate                         # import legacy plaintext .env (ENDPOINT_<T>_APIKEY)
endpoint-aiops secret rotate-password                 # re-encrypt under a new master password
```

## Read commands

```bash
endpoint-aiops overview [--target <t>]        # online/offline, stale endpoints, agent/patch spread
endpoint-aiops endpoint list                  # all managed endpoints
endpoint-aiops endpoint get <endpoint_id>     # one endpoint detail
endpoint-aiops session list [--since-hours 24]           # recent login/boot sessions
endpoint-aiops session storm [--since-hours 24] [--window-s 300] [--min-concurrent 10]
endpoint-aiops drift report                   # endpoints drifted from the fleet-majority baseline
endpoint-aiops drift patch [--target-patch <level>]      # patch-level distribution + who's behind
```

## Write commands (governed; risk tier in parentheses)

```bash
endpoint-aiops endpoint assign-profile <endpoint_id> <profile_id> [--dry-run]   # (high) reversible; double confirm
endpoint-aiops endpoint reboot <endpoint_id> [--dry-run]                        # (medium) no undo; double confirm
```

## Common options

- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target)
- `--dry-run` — print the API call that would be made, change nothing
- State-changing commands (`endpoint assign-profile`, `endpoint reboot`) require two confirmations
Github ReposUpdated 19h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/zw008/skills/endpoint-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/skills/endpoint-aiops",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T11:40:15.748Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T11:40:15.748Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.5K downloads",
      "href": "https://clawhub.ai/zw008/endpoint-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/endpoint-aiops",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T11:40:15.748Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.10.3",
      "href": "https://clawhub.ai/zw008/endpoint-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/endpoint-aiops",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-15T05:54:58.702Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.10.3",
      "description": "- Removed the skill-card.md file from the project. - No changes to skill features, code, or user experience. - Documentation updated by removing a sample file.",
      "href": "https://clawhub.ai/zw008/endpoint-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/endpoint-aiops",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-15T05:54:58.702Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to endpoint-aiops and adjacent AI workflows.