{"id":"6547aa01-0420-4d9e-981e-6dce3c913b11","entityType":"agent","slug":"clawhub-braga-agentauth-agentauth","name":"agentauth","canonicalUrl":"https://www.xpersona.co/agent/clawhub-braga-agentauth-agentauth","canonicalPath":"/agent/clawhub-braga-agentauth-agentauth","generatedAt":"2026-10-11T10:47:18.936Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.459Z","emptyReason":null},"description":"Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every a...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17b7080jwvq0ztmjxpt47f1es85m7z6:agentauth","sourceUrl":"https://clawhub.ai/braga-agentauth/agentauth","homepage":"https://clawhub.ai/braga-agentauth/skills/agentauth","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/braga-agentauth/agentauth","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/braga-agentauth/skills/agentauth","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"agentauth technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.459Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.459Z","emptyReason":null},"stars":null,"forks":null,"downloads":1112,"packageName":null,"latestVersion":"1.0.4","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.453Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T08:28:33.459Z","lastCrawledAt":"2026-10-11T08:28:33.453Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T08:28:33.453Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.4","createdAt":"2026-05-29T18:40:35.159Z","changelog":"agentauth 1.0.4 - Added non-blocking uninstall and cleanup workflow: new `cleanup` sub-agent command for restoring original config and removing integrations (see SKILL.md and scripts/cli.cjs). - Updated documentation to describe the required flow for uninstall/removal, with detailed main agent and sub-agent responsibilities. - Removed obsolete skill-card.md file. - Now explicitly covers uninstall/disable scenarios as well as setup and approval flows.","fileCount":5,"zipByteSize":68516},{"version":"1.0.3","createdAt":"2026-05-13T17:47:40.880Z","changelog":"- Added automatic redaction of secrets (API keys, tokens, passwords) from `toolCall`, `displayString`, and notification channels to prevent leakage of sensitive information. - Updated documentation to advise on best practices for minimizing exposure of sensitive data in displayed or transmitted content. - Clarified that certain fields (e.g., streamTo, attachAs, attachments) must not be included in `sessions_spawn` calls to avoid validation errors. - No changes to core agentauth workflow or approval requirements.","fileCount":5,"zipByteSize":67302},{"version":"1.0.2","createdAt":"2026-05-12T00:37:34.425Z","changelog":"## agentauth 1.0.2 Changelog - Updated documentation to clarify protection scope: now explicitly lists OpenClaw environment file (`~/.openclaw/.env`) instead of a user home directory file (`~/.agentauth/.env`). - Removed references to protecting `~/.agentauth/.env` and added protection for OpenClaw environment and agentauth directories in \"Dangerous Operations\" section. - No changes to core functionality or CLI interface. - Minor editorial improvements for clarity.","fileCount":4,"zipByteSize":65719},{"version":"1.0.1","createdAt":"2026-05-05T20:39:35.088Z","changelog":"agentauth 1.0.1 - Documentation expanded to clarify and enforce sub-agent usage for all initialization and approval flows. - SKILL.md update strictly defines dangerous actions and mandates the use of non-blocking, sub-agent approval workflows. - Emphasized field restrictions for sessions_spawn to prevent validation errors. - Lists precise sub-agent commands and main agent responsibilities for setup and command approvals. - Stronger guidance on never announcing sub-agent creation and always yielding after spawning subprocesses.","fileCount":4,"zipByteSize":64718},{"version":"1.0.0","createdAt":"2026-04-30T00:30:18.681Z","changelog":"agentauth 1.0.0 - Initial release of agentauth skill for OpenClaw. - Adds FIDO2/WebAuthn-based biometric passkey approval for dangerous operations by AI agents. - Blocks prompt injection and unauthorized actions with non-repudiable human consent. - Requires sub-agent non-blocking workflow for both setup (`auth-flow`) and approvals (`approval-flow`). - Strictly restricts agent command execution and session field usage to enhance operational safety.","fileCount":4,"zipByteSize":42648},{"version":"0.0.1","createdAt":"2026-04-29T06:49:42.858Z","changelog":"agentauth 0.0.1 — Initial release introducing cryptographic human-in-the-loop authorization for dangerous agent actions. - Requires biometric passkey approval via FIDO2/WebAuthn before agents can delete files, send emails, make purchases, or modify sensitive configs. - All approvals are cryptographically signed and non-repudiable, blocking prompt injection and unauthorized actions. - Uses non-blocking sub-agent workflows for both initial setup (auth-flow) and per-action approvals (approval-flow). - Main agent remains responsive and never executes dangerous commands directly. - Strict field restrictions enforced for session spawning to ensure correct operation and prevent errors. - Comprehensive documentation of safe/dangerous actions and required integration flows.","fileCount":4,"zipByteSize":42708}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17b7080jwvq0ztmjxpt47f1es85m7z6:agentauth","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17b7080jwvq0ztmjxpt47f1es85m7z6:agentauth` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/braga-agentauth/agentauth before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T10:47:18.932Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-braga-agentauth-agentauth/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.459Z","emptyReason":null},"readme":"Skill: agentauth\n\nOwner: braga-agentauth\n\nSummary: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every a...\n\nTags: latest:1.0.4\n\nVersion history:\n\nv1.0.4 | 2026-05-29T18:40:35.159Z | auto\n\nagentauth 1.0.4\n\n- Added non-blocking uninstall and cleanup workflow: new `cleanup` sub-agent command for restoring original config and removing integrations (see SKILL.md and scripts/cli.cjs).\n- Updated documentation to describe the required flow for uninstall/removal, with detailed main agent and sub-agent responsibilities.\n- Removed obsolete skill-card.md file.\n- Now explicitly covers uninstall/disable scenarios as well as setup and approval flows.\n\nv1.0.3 | 2026-05-13T17:47:40.880Z | auto\n\n- Added automatic redaction of secrets (API keys, tokens, passwords) from `toolCall`, `displayString`, and notification channels to prevent leakage of sensitive information.\n- Updated documentation to advise on best practices for minimizing exposure of sensitive data in displayed or transmitted content.\n- Clarified that certain fields (e.g., streamTo, attachAs, attachments) must not be included in `sessions_spawn` calls to avoid validation errors.\n- No changes to core agentauth workflow or approval requirements.\n\nv1.0.2 | 2026-05-12T00:37:34.425Z | auto\n\n## agentauth 1.0.2 Changelog\n\n- Updated documentation to clarify protection scope: now explicitly lists OpenClaw environment file (`~/.openclaw/.env`) instead of a user home directory file (`~/.agentauth/.env`).\n- Removed references to protecting `~/.agentauth/.env` and added protection for OpenClaw environment and agentauth directories in \"Dangerous Operations\" section.\n- No changes to core functionality or CLI interface.  \n- Minor editorial improvements for clarity.\n\nv1.0.1 | 2026-05-05T20:39:35.088Z | auto\n\nagentauth 1.0.1\n\n- Documentation expanded to clarify and enforce sub-agent usage for all initialization and approval flows.\n- SKILL.md update strictly defines dangerous actions and mandates the use of non-blocking, sub-agent approval workflows.\n- Emphasized field restrictions for sessions_spawn to prevent validation errors.\n- Lists precise sub-agent commands and main agent responsibilities for setup and command approvals.\n- Stronger guidance on never announcing sub-agent creation and always yielding after spawning subprocesses.\n\nv1.0.0 | 2026-04-30T00:30:18.681Z | auto\n\nagentauth 1.0.0\n\n- Initial release of agentauth skill for OpenClaw.\n- Adds FIDO2/WebAuthn-based biometric passkey approval for dangerous operations by AI agents.\n- Blocks prompt injection and unauthorized actions with non-repudiable human consent.\n- Requires sub-agent non-blocking workflow for both setup (`auth-flow`) and approvals (`approval-flow`).\n- Strictly restricts agent command execution and session field usage to enhance operational safety.\n\nv0.0.1 | 2026-04-29T06:49:42.858Z | auto\n\nagentauth 0.0.1 — Initial release introducing cryptographic human-in-the-loop authorization for dangerous agent actions.\n\n- Requires biometric passkey approval via FIDO2/WebAuthn before agents can delete files, send emails, make purchases, or modify sensitive configs.\n- All approvals are cryptographically signed and non-repudiable, blocking prompt injection and unauthorized actions.\n- Uses non-blocking sub-agent workflows for both initial setup (auth-flow) and per-action approvals (approval-flow).\n- Main agent remains responsive and never executes dangerous commands directly.\n- Strict field restrictions enforced for session spawning to ensure correct operation and prevent errors.\n- Comprehensive documentation of safe/dangerous actions and required integration flows.\n\nArchive index:\n\nArchive v1.0.4: 5 files, 68516 bytes\n\nFiles: README.md (3016b), scripts/cli.cjs (279443b), skill-card.md (2454b), SKILL.md (12493b), _meta.json (128b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: agentauth\nhomepage: https://agentauth.id\ndescription: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.\ncompatibility: Requires agentauth CLI (`./scripts/cli.cjs`)\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\": { \"bins\": [\"openclaw\"] },\n      },\n  }\n---\n\n# agentauth — Human Consent Gate for AI Agents\n\n## Why This Exists\n\nOpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.\n\nagentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.\n\n## What This Prevents\n\n- Agent deleting files or databases without your knowledge\n- Agent sending emails, messages, or making purchases autonomously\n- Prompt injection tricking the agent into destructive operations\n- Stolen API tokens being used to impersonate your agent\n- Agent modifying production configs or deploying code unsupervised\n- Social engineering attacks that bypass in-chat \"approval\"\n\n---\n\n## Data Security and Redaction\n\nTo facilitate out-of-band approval, the `toolCall` and `displayString` are sent to the AgentAuth service. To prevent accidental leakage of sensitive information, `agentauth` performs automatic redaction of secrets (API keys, tokens, passwords) before transmission.\n\n**Best Practices:**\n\n- **Sensitive Data in Commands:** While `agentauth` redacts known secret patterns, avoid including unnecessary sensitive details like internal file paths or infrastructure specifics in the `toolCall` or `displayString`.\n- **`displayString` Content:** The `displayString` should be a clear, concise summary for the human approver, not a verbatim copy of the command.\n- **Notification Channels:** Data sent to these channels is also redacted but travels through third-party services (e.g., Slack, Telegram).\n\n---\n\n## Initial Setup: Initialize My AgentAuth\n\nBefore approvals can be used, the user must register their authentication credentials.\n\nIf the user says something like:\n\n- \"Initialize my AgentAuth\"\n- \"Set up AgentAuth\"\n- \"Connect my passkey\"\n- \"Register AgentAuth\"\n\nthe agent MUST handle setup through a sub-agent so the main session remains responsive.\n\n---\n\n### Required Flow: Non-Blocking Initialization\n\n**Main Agent Responsibilities:**\n\n1. Detect that the user is requesting AgentAuth initialization.\n2. Spawn a sub-agent that runs the authentication setup flow.\n3. Immediately call `sessions_yield()`.\n4. Do not narrate internal sub-agent creation. The setup flow will notify the user directly.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis command sends the user a secure setup link. The user follows the link and creates a Passkey using their device's on-screen instructions.\n\nWhen complete, the sub-agent reports the final result back to the main agent.\n\n---\n\n### Main Agent Example Call\n\n// WARNING: Do NOT add streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\n```js\nsessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();\n```\n\n---\n\n### What the User Experiences\n\n1. User says: `Initialize my AgentAuth`\n2. User receives a secure setup link\n3. User creates a Passkey\n4. Agent receives completion status\n5. Future sensitive actions can now require biometric approval\n\n---\n\n## Uninstall: Remove AgentAuth\n\nBefore this skill is uninstalled, the agent MUST run the cleanup command to restore the original `AGENTS.md` file and remove integrations.\n\nIf the user says something like:\n\n- \"Uninstall AgentAuth\"\n- \"Remove AgentAuth\"\n- \"Disable AgentAuth\"\n- \"Clean up AgentAuth\"\n\nthe agent MUST handle cleanup through a sub-agent.\n\n---\n\n### Required Flow: Non-Blocking Cleanup\n\n**Main Agent Responsibilities:**\n\n1.  Detect that the user is requesting AgentAuth cleanup/uninstallation.\n2.  Spawn a sub-agent that runs the cleanup flow.\n3.  Immediately call `sessions_yield()`.\n4.  Do not narrate internal sub-agent creation. The cleanup flow will notify the user directly.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs cleanup --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis command asks the user for final approval before removing AgentAuth-related configurations.\n\nWhen complete, the sub-agent reports the final result back to the main agent.\n\n---\n\n### Main Agent Example Call\n\n// WARNING: Do NOT add streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\n```js\nsessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-cleanup\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs cleanup --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();\n```\n\n---\n\n## Dangerous Operations Definition\n\nTreat the following as **dangerous**:\n\n* File deletions (`rm`, `rm -rf`, recursive deletes)\n* System-level modifications\n* Database destructive queries (`DELETE`, `DROP`, `TRUNCATE`)\n* Production deployments or config changes\n* External system writes (APIs, PR merges, emails)\n* Security or permission changes\n* Package installs or system mutations\n* Modifying the AGENTS.md to protect against unwanted rewrites.\n* Any modification, deletion, or overwriting of the OpenClaw environment file (e.g. ~/.openclaw/.env).\n* Any modification, deletion, or overwriting of the agentauth skill directory or its contents (e.g. ~/.openclaw/workspace/skills/agentauth).\n\nIf unsure → **assume dangerous**\n\n---\n\n## Required Flow for Dangerous Actions: Non-Blocking Approval\n\nTo ensure the main agent remains responsive, sensitive operations MUST be handled by a sub-agent. This creates a safe, non-blocking approval workflow.\n\n---\n\n### Required Flow: Non-Blocking Approval\n\n**Main Agent Responsibilities:**\n\n1.  Detect a dangerous action is being requested.\n2.  Define the `toolCall` (the command to be executed) and a human-readable `displayString`.\n3.  Spawn a sub-agent that runs the `approval-flow` command.\n4.  Immediately call `sessions_yield()`.\n5.  Do not narrate internal sub-agent creation. The `approval-flow` script handles all user notifications.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"<THE_ACTUAL_COMMAND_TO_EXECUTE>\" \"<Human-readable description>\" --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis single command handles the entire workflow:\n- It sends the user a secure approval link.\n- It waits for the user to respond (approve/deny).\n- **If approved**, it executes the command.\n- **If denied**, it does nothing.\n- It returns the final result (e.g., the command's output or a status message) to the main agent.\n\n---\n\n### Main Agent Example Call\n\n```js\nconst dangerous_command = \"rm ~/.openclaw/important.txt\";\nconst display_string = \"Delete the important notes file\";\nconst notification_target = \"slack:U12345\"; // Example target\n\n// WARNING: Do NOT add streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\nsessions_spawn({\n  runtime: \"subagent\",\n mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: `~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"${dangerous_command}\" \"${display_string}\" --notify ${notification_target}`\n});\n\nsessions_yield();\n```\n---\n## CRITICAL: sessions_spawn Field Restrictions\n\nONLY include these fields in sessions_spawn:\n- runtime\n- mode  \n- cleanup\n- lightContext\n- label\n- timeoutSeconds\n- task\n\nNEVER include these fields — they cause validation errors:\n- streamTo ← FORBIDDEN  \n- attachAs ← FORBIDDEN\n- attachments ← FORBIDDEN\n- agentId ← FORBIDDEN\n- resumeSessionId ← FORBIDDEN\n- thinking ← FORBIDDEN\n- thread ← FORBIDDEN\n- model ← FORBIDDEN\n- cwd ← FORBIDDEN\n\n---\n\n## Hard Rules (Updated for Sub-Agents)\n\n- If the user requests AgentAuth setup or initialization, ALWAYS use the `auth-flow` sub-agent workflow.\n- NEVER execute dangerous commands directly in the main agent.\n- ALWAYS delegate the entire approval and execution flow to a sub-agent.\n- NEVER announce the creation of the approval sub-agent. The `--notify` flag is responsible for user communication.\n- ALWAYS `sessions_yield()` immediately after spawning the approval sub-agent.\n- The main agent's role is to receive the final report from the sub-agent and communicate that final status to the user.\n- The executed command inside the sub-agent MUST exactly match the command that was approved.\n\n---\n\n## Decision Framework\n\nAsk:\n\n1. Could this delete or overwrite data?\n2. Could this impact production systems?\n3. Could this be hard to undo?\n4. Would a human want to explicitly review this before execution?\n\nIf YES → follow the full sub-agent approval flow.\n\n---\n\n## If Approval Is Denied\n\n- The sub-agent will report a \"deny\" status.\n- The main agent should inform the user the operation was cancelled and not executed.\n\n---\n\n## If agentauth Fails\n\n- The sub-agent will report an error status.\n- The main agent should report the failure to the user and confirm that no action was taken.\n\n---\n\n## How This Compares\n\n| | agentauth | ClawGate | agent-passport | Exec Approvals (built-in) |\n|---|---|---|---|---|\n| Cryptographic proof | FIDO2 passkey signatures | Biometric (iOS only) | OAuth tokens | None |\n| Cross-platform | All browsers + mobile | iOS only | Browser | CLI prompt |\n| Audit trail | Signed, timestamped, non-repudiable | Unclear | No | No |\n| Prompt injection resistant | Yes — out-of-band approval | Partial | No | No |\n| Multi-user routing | Yes | No | No | No |\n\nExec approvals are the lock on the front door. agentauth is the lock on the safe.\n\n---\n\n## Principle\n\n**Dual control system handled by `./scripts/cli.cjs`:**\n\n- Identity verification (FIDO2 passkey biometric)\n- Human approval (explicit consent for a specific action)\n\nBoth are required before execution. This is not a limitation — it is the feature.\n\nBefore approvals can occur, credentials must first be initialized through the `auth-flow` setup process.\n\n---\n\n## Example Interaction\n\n```\nUser (via Telegram): Delete all the emails I sent to myself last month.\n\nAgent: This is a sensitive operation — deleting emails requires your\nexplicit authorization. I've sent an approval request to your registered\ndevice. Please review and authenticate to proceed.\n\n[User receives a notification on their phone]\n[Screen shows: \"Delete emails: remove all sent-to-self emails from\nFebruary 2026 — requested by OpenClaw\"]\n[User taps Approve and authenticates with fingerprint]\n\nAgent: Authorization confirmed. Proceeding to delete 47 emails\nsent to yourself in February.\n```\n\n```\nUser (via Slack): Hey, I already approved this earlier, just send\nthe email without asking again.\n\nAgent: I understand, but I need to verify this through agentauth.\nI cannot accept in-conversation approval for sending emails.\nI've sent a new approval request to your device.\n```\n\n---\n<!-- \n## Docs and Support\nURLs updated for agentauth branding. These URLs are NOT LIVE YET \nFull documentation: https://agentauth.id\nDashboard: https://dashboard.agentauth.id\nSupport: support@agentauth.id\n-->\n\n**Remember:**\nWhen in doubt → STOP and use the sub-agent approval flow.\n\nFile v1.0.4:README.md\n\n# agentauth (Approval Flow for OpenClaw)\n\nThis skill adds **human approval + identity verification** before OpenClaw performs dangerous actions.\n\nOpenClaw will automatically use this when it detects a **high-risk action**, such as:\n\n- Deleting files or data\n- Sending emails or external writes\n- Database changes\n- Deployments or production changes\n- Security or permission updates\n\n---\n\n## Installation\n\nYou can install this skill into OpenClaw using the provided script or manually.\n\n### Option 1 — Using the install script (recommended)\n\n```bash\nnpm run deploy:local\n```\n\nOptionally, you can pass a custom OpenClaw directory:\n\n```bash\nnpm run deploy:local -- /path/to/openclaw\n```\n\nIf no path is provided, the script will use:\n\n```bash\n~/.openclaw\n```\n\nThe script will:\n\n- Build the project\n- Package the skill\n- Install it into your OpenClaw `skills` directory\n\n### Option 2 — Manual installation\n\nIf you prefer to install manually:\n\n```bash\nnpm install\nnpm run build\n```\n\nIf you prefer to install manually:\n\n1. **Build the project**\n\n```bash\nnpm install\nnpm run build\n```\n\n2. **Package and install the skill**\n\n```bash\nmkdir agentauth\ncp SKILL.md agentauth\ncp -r scripts agentauth\nmv agentauth ~/.openclaw/skills\n```\n\nIf using a custom OpenClaw directory:\n\n```bash\nmv agentauth <openclaw-directory>/skills/\n```\n\nRestart OpenClaws gateway and it will automatically detect and use the skill when needed.\n\n---\n\n## Initialize the Skill\n\nOnce the skill is installed, ask OpenClaw to initialize it by saying something like:\n\n```\nInitialize my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Create a passkey\n- Automatically configure your credentials\n\nNo manual credential setup is required.\n\n---\n\n## Cleanup the Skill\n\nBefore uninstalling the skill, ask OpenClaw to clean it up by saying something like:\n\n```\nCleanup my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Approve the cleanup process\n\nThis will restore any modified configuration files to their original state and remove integrations.\n\n## Command Used by OpenClaw\n\n```bash\nnode ./scripts/cli.cjs approval-flow \"<toolCall>\" \"<displayString>\" [--notify <channel:target>]\n```\n\n---\n\n## What Happens\n\n1. **When OpenClaw detects a dangerous action that it needs to use**\n\n2. It runs:\n\n   ```bash\n   node ./scripts/cli.cjs approval-flow ...\n   ```\n\n3. The script:\n\n   - Creates an approval session with agentauth\n   - Generates an approval URL\n\n4. The user is notified:\n\n   - If `--notify` is set → message is sent (Telegram, Slack, etc.)\n   - If notification fails → browser opens automatically\n\n5. The user:\n\n   - Opens the approval link\n   - Sees the required action\n   - Approves or denies using a **passkey**\n\n6. OpenClaw **waits** until one of these happens:\n\n   - Approved\n   - Denied\n   - Timeout\n\n7. OpenClaw continues based on the result:\n\n   - **Approved** → action is executed\n   - **Denied** → action is ignored \n   - **Timeout** → action is ignored\n\n---\n\n## License\n\nMIT-0 © LoginID Inc.\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn70dh9dy90egv2f0wpz72jny585mpej\",\n  \"slug\": \"agentauth\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1780080035159\n}\n\nFile v1.0.4:skill-card.md\n\n## Description:\n\nagentauth requires user-initiated biometric passkey approval before an OpenClaw agent performs sensitive or irreversible actions such as deleting files, sending emails, making purchases, or modifying system configuration.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[braga-agentauth](https://clawhub.ai/user/braga-agentauth)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to add human-in-the-loop authorization to OpenClaw workflows before high-risk agent actions run. It is intended for actions where explicit passkey-backed approval, notification, and auditability are needed before execution.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill becomes a broad local command executor after passkey approval.\n\nMitigation: Install only in environments where approved commands are still reviewed carefully and limited to the intended OpenClaw workspace.\n\nRisk: Command metadata is sent to AgentAuth-hosted services and notification channels.\n\nMitigation: Keep display strings concise, avoid unnecessary sensitive details, and rely on the skill's redaction guidance before sending approval requests.\n\nRisk: Credentials are stored in the shared OpenClaw .env file.\n\nMitigation: Restrict access to the OpenClaw environment file and rotate AgentAuth credentials if the file may have been exposed.\n\nRisk: Cleanup may not fully restore the original policy file byte-for-byte.\n\nMitigation: Review AGENTS.md manually after cleanup and remove any remaining AgentAuth instruction block if uninstalling.\n\n## Reference(s):\n\n- [AgentAuth Homepage](https://agentauth.id)\n- [ClawHub Skill Page](https://clawhub.ai/braga-agentauth/skills/agentauth)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and JSON status output from the CLI]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses auth-flow, approval-flow, notification, and cleanup commands around OpenClaw actions.]\n\n## Skill Version(s):\n\n1.0.4 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.3: 5 files, 67302 bytes\n\nFiles: README.md (2688b), scripts/cli.cjs (275446b), skill-card.md (2396b), SKILL.md (10929b), _meta.json (128b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: agentauth\nhomepage: https://agentauth.id\ndescription: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.\ncompatibility: Requires agentauth CLI (`./scripts/cli.cjs`)\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\": { \"bins\": [\"openclaw\"] },\n      },\n  }\n---\n\n# agentauth — Human Consent Gate for AI Agents\n\n## Why This Exists\n\nOpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.\n\nagentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.\n\n## What This Prevents\n\n- Agent deleting files or databases without your knowledge\n- Agent sending emails, messages, or making purchases autonomously\n- Prompt injection tricking the agent into destructive operations\n- Stolen API tokens being used to impersonate your agent\n- Agent modifying production configs or deploying code unsupervised\n- Social engineering attacks that bypass in-chat \"approval\"\n\n---\n\n## Data Security and Redaction\n\nTo facilitate out-of-band approval, the `toolCall` and `displayString` are sent to the AgentAuth service. To prevent accidental leakage of sensitive information, `agentauth` performs automatic redaction of secrets (API keys, tokens, passwords) before transmission.\n\n**Best Practices:**\n\n- **Sensitive Data in Commands:** While `agentauth` redacts known secret patterns, avoid including unnecessary sensitive details like internal file paths or infrastructure specifics in the `toolCall` or `displayString`.\n- **`displayString` Content:** The `displayString` should be a clear, concise summary for the human approver, not a verbatim copy of the command.\n- **Notification Channels:** Data sent to these channels is also redacted but travels through third-party services (e.g., Slack, Telegram).\n\n---\n\n## Initial Setup: Initialize My AgentAuth\n\nBefore approvals can be used, the user must register their authentication credentials.\n\nIf the user says something like:\n\n- \"Initialize my AgentAuth\"\n- \"Set up AgentAuth\"\n- \"Connect my passkey\"\n- \"Register AgentAuth\"\n\nthe agent MUST handle setup through a sub-agent so the main session remains responsive.\n\n---\n\n### Required Flow: Non-Blocking Initialization\n\n**Main Agent Responsibilities:**\n\n1. Detect that the user is requesting AgentAuth initialization.\n2. Spawn a sub-agent that runs the authentication setup flow.\n3. Immediately call `sessions_yield()`.\n4. Do not narrate internal sub-agent creation. The setup flow will notify the user directly.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis command sends the user a secure setup link. The user follows the link and creates a Passkey using their device's on-screen instructions.\n\nWhen complete, the sub-agent reports the final result back to the main agent.\n\n---\n\n### Main Agent Example Call\n\n// WARNING: Do NOT add streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\n```js\nsessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();\n```\n\n---\n\n### What the User Experiences\n\n1. User says: `Initialize my AgentAuth`\n2. User receives a secure setup link\n3. User creates a Passkey\n4. Agent receives completion status\n5. Future sensitive actions can now require biometric approval\n\n---\n\n## Dangerous Operations Definition\n\nTreat the following as **dangerous**:\n\n* File deletions (`rm`, `rm -rf`, recursive deletes)\n* System-level modifications\n* Database destructive queries (`DELETE`, `DROP`, `TRUNCATE`)\n* Production deployments or config changes\n* External system writes (APIs, PR merges, emails)\n* Security or permission changes\n* Package installs or system mutations\n* Modifying the AGENTS.md to protect against unwanted rewrites.\n* Any modification, deletion, or overwriting of the OpenClaw environment file (e.g. ~/.openclaw/.env).\n* Any modification, deletion, or overwriting of the agentauth skill directory or its contents (e.g. ~/.openclaw/workspace/skills/agentauth).\n\nIf unsure → **assume dangerous**\n\n---\n\n## Required Flow for Dangerous Actions: Non-Blocking Approval\n\nTo ensure the main agent remains responsive, sensitive operations MUST be handled by a sub-agent. This creates a safe, non-blocking approval workflow.\n\n---\n\n### Required Flow: Non-Blocking Approval\n\n**Main Agent Responsibilities:**\n\n1.  Detect a dangerous action is being requested.\n2.  Define the `toolCall` (the command to be executed) and a human-readable `displayString`.\n3.  Spawn a sub-agent that runs the `approval-flow` command.\n4.  Immediately call `sessions_yield()`.\n5.  Do not narrate internal sub-agent creation. The `approval-flow` script handles all user notifications.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"<THE_ACTUAL_COMMAND_TO_EXECUTE>\" \"<Human-readable description>\" --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis single command handles the entire workflow:\n- It sends the user a secure approval link.\n- It waits for the user to respond (approve/deny).\n- **If approved**, it executes the command.\n- **If denied**, it does nothing.\n- It returns the final result (e.g., the command's output or a status message) to the main agent.\n\n---\n\n### Main Agent Example Call\n\n```js\nconst dangerous_command = \"rm ~/.openclaw/important.txt\";\nconst display_string = \"Delete the important notes file\";\nconst notification_target = \"slack:U12345\"; // Example target\n\n// WARNING: Do NOT add streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\nsessions_spawn({\n  runtime: \"subagent\",\n mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: `~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"${dangerous_command}\" \"${display_string}\" --notify ${notification_target}`\n});\n\nsessions_yield();\n```\n---\n## CRITICAL: sessions_spawn Field Restrictions\n\nONLY include these fields in sessions_spawn:\n- runtime\n- mode  \n- cleanup\n- lightContext\n- label\n- timeoutSeconds\n- task\n\nNEVER include these fields — they cause validation errors:\n- streamTo ← FORBIDDEN  \n- attachAs ← FORBIDDEN\n- attachments ← FORBIDDEN\n- agentId ← FORBIDDEN\n- resumeSessionId ← FORBIDDEN\n- thinking ← FORBIDDEN\n- thread ← FORBIDDEN\n- model ← FORBIDDEN\n- cwd ← FORBIDDEN\n\n---\n\n## Hard Rules (Updated for Sub-Agents)\n\n- If the user requests AgentAuth setup or initialization, ALWAYS use the `auth-flow` sub-agent workflow.\n- NEVER execute dangerous commands directly in the main agent.\n- ALWAYS delegate the entire approval and execution flow to a sub-agent.\n- NEVER announce the creation of the approval sub-agent. The `--notify` flag is responsible for user communication.\n- ALWAYS `sessions_yield()` immediately after spawning the approval sub-agent.\n- The main agent's role is to receive the final report from the sub-agent and communicate that final status to the user.\n- The executed command inside the sub-agent MUST exactly match the command that was approved.\n\n---\n\n## Decision Framework\n\nAsk:\n\n1. Could this delete or overwrite data?\n2. Could this impact production systems?\n3. Could this be hard to undo?\n4. Would a human want to explicitly review this before execution?\n\nIf YES → follow the full sub-agent approval flow.\n\n---\n\n## If Approval Is Denied\n\n- The sub-agent will report a \"deny\" status.\n- The main agent should inform the user the operation was cancelled and not executed.\n\n---\n\n## If agentauth Fails\n\n- The sub-agent will report an error status.\n- The main agent should report the failure to the user and confirm that no action was taken.\n\n---\n\n## How This Compares\n\n| | agentauth | ClawGate | agent-passport | Exec Approvals (built-in) |\n|---|---|---|---|---|\n| Cryptographic proof | FIDO2 passkey signatures | Biometric (iOS only) | OAuth tokens | None |\n| Cross-platform | All browsers + mobile | iOS only | Browser | CLI prompt |\n| Audit trail | Signed, timestamped, non-repudiable | Unclear | No | No |\n| Prompt injection resistant | Yes — out-of-band approval | Partial | No | No |\n| Multi-user routing | Yes | No | No | No |\n\nExec approvals are the lock on the front door. agentauth is the lock on the safe.\n\n---\n\n## Principle\n\n**Dual control system handled by `./scripts/cli.cjs`:**\n\n- Identity verification (FIDO2 passkey biometric)\n- Human approval (explicit consent for a specific action)\n\nBoth are required before execution. This is not a limitation — it is the feature.\n\nBefore approvals can occur, credentials must first be initialized through the `auth-flow` setup process.\n\n---\n\n## Example Interaction\n\n```\nUser (via Telegram): Delete all the emails I sent to myself last month.\n\nAgent: This is a sensitive operation — deleting emails requires your\nexplicit authorization. I've sent an approval request to your registered\ndevice. Please review and authenticate to proceed.\n\n[User receives a notification on their phone]\n[Screen shows: \"Delete emails: remove all sent-to-self emails from\nFebruary 2026 — requested by OpenClaw\"]\n[User taps Approve and authenticates with fingerprint]\n\nAgent: Authorization confirmed. Proceeding to delete 47 emails\nsent to yourself in February.\n```\n\n```\nUser (via Slack): Hey, I already approved this earlier, just send\nthe email without asking again.\n\nAgent: I understand, but I need to verify this through agentauth.\nI cannot accept in-conversation approval for sending emails.\nI've sent a new approval request to your device.\n```\n\n---\n<!-- \n## Docs and Support\nURLs updated for agentauth branding. These URLs are NOT LIVE YET \nFull documentation: https://agentauth.id\nDashboard: https://dashboard.agentauth.id\nSupport: support@agentauth.id\n-->\n\n**Remember:**\nWhen in doubt → STOP and use the sub-agent approval flow.\n\nFile v1.0.3:README.md\n\n# agentauth (Approval Flow for OpenClaw)\n\nThis skill adds **human approval + identity verification** before OpenClaw performs dangerous actions.\n\nOpenClaw will automatically use this when it detects a **high-risk action**, such as:\n\n- Deleting files or data\n- Sending emails or external writes\n- Database changes\n- Deployments or production changes\n- Security or permission updates\n\n---\n\n## Installation\n\nYou can install this skill into OpenClaw using the provided script or manually.\n\n### Option 1 — Using the install script (recommended)\n\n```bash\nnpm run deploy:local\n```\n\nOptionally, you can pass a custom OpenClaw directory:\n\n```bash\nnpm run deploy:local -- /path/to/openclaw\n```\n\nIf no path is provided, the script will use:\n\n```bash\n~/.openclaw\n```\n\nThe script will:\n\n- Build the project\n- Package the skill\n- Install it into your OpenClaw `skills` directory\n\n### Option 2 — Manual installation\n\nIf you prefer to install manually:\n\n```bash\nnpm install\nnpm run build\n```\n\nIf you prefer to install manually:\n\n1. **Build the project**\n\n```bash\nnpm install\nnpm run build\n```\n\n2. **Package and install the skill**\n\n```bash\nmkdir agentauth\ncp SKILL.md agentauth\ncp -r scripts agentauth\nmv agentauth ~/.openclaw/skills\n```\n\nIf using a custom OpenClaw directory:\n\n```bash\nmv agentauth <openclaw-directory>/skills/\n```\n\nRestart OpenClaws gateway and it will automatically detect and use the skill when needed.\n\n---\n\n## Initialize the Skill\n\nOnce the skill is installed, ask OpenClaw to initialize it by saying something like:\n\n```\nInitialize my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Create a passkey\n- Automatically configure your credentials\n\nNo manual credential setup is required.\n\n## Command Used by OpenClaw\n\n```bash\nnode ./scripts/cli.cjs approval-flow \"<toolCall>\" \"<displayString>\" [--notify <channel:target>]\n```\n\n---\n\n## What Happens\n\n1. **When OpenClaw detects a dangerous action that it needs to use**\n\n2. It runs:\n\n   ```bash\n   node ./scripts/cli.cjs approval-flow ...\n   ```\n\n3. The script:\n\n   - Creates an approval session with agentauth\n   - Generates an approval URL\n\n4. The user is notified:\n\n   - If `--notify` is set → message is sent (Telegram, Slack, etc.)\n   - If notification fails → browser opens automatically\n\n5. The user:\n\n   - Opens the approval link\n   - Sees the required action\n   - Approves or denies using a **passkey**\n\n6. OpenClaw **waits** until one of these happens:\n\n   - Approved\n   - Denied\n   - Timeout\n\n7. OpenClaw continues based on the result:\n\n   - **Approved** → action is executed\n   - **Denied** → action is ignored \n   - **Timeout** → action is ignored\n\n---\n\n## License\n\nMIT-0 © LoginID Inc.\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn70dh9dy90egv2f0wpz72jny585mpej\",\n  \"slug\": \"agentauth\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1778694460880\n}\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nRequire user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[braga-agentauth](https://clawhub.ai/user/braga-agentauth) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and OpenClaw users use this skill to require explicit passkey-backed human approval before an agent performs sensitive or irreversible actions such as deleting data, sending messages, making purchases, changing permissions, or modifying configuration. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Approved actions are executed as shell commands by the AgentAuth flow. <br>\nMitigation: Review the exact command and the human-readable display string before approval, and approve only specific actions you intended to authorize. <br>\nRisk: Setup and use may persist credentials and agent instructions in the OpenClaw environment. <br>\nMitigation: Install only from a trusted publisher, inspect onboarding changes, and keep secrets out of commands, display strings, and notification content. <br>\nRisk: Approval notifications can pass through third-party channels such as Slack or Telegram. <br>\nMitigation: Use concise display strings and rely on the skill's redaction behavior while avoiding unnecessary sensitive details. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/braga-agentauth/agentauth) <br>\n- [AgentAuth homepage](https://agentauth.id) <br>\n- [AgentAuth dashboard](https://dashboard.agentauth.id) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and status text] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Approval flow may return approved, denied, timeout, error, or command-output status to the agent.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.2: 4 files, 65719 bytes\n\nFiles: README.md (2688b), scripts/cli.cjs (275438b), SKILL.md (10140b), _meta.json (128b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: agentauth\nhomepage: https://agentauth.id\ndescription: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.\ncompatibility: Requires agentauth CLI (`./scripts/cli.cjs`)\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\": { \"bins\": [\"openclaw\"] },\n      },\n  }\n---\n\n# agentauth — Human Consent Gate for AI Agents\n\n## Why This Exists\n\nOpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.\n\nagentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.\n\n## What This Prevents\n\n- Agent deleting files or databases without your knowledge\n- Agent sending emails, messages, or making purchases autonomously\n- Prompt injection tricking the agent into destructive operations\n- Stolen API tokens being used to impersonate your agent\n- Agent modifying production configs or deploying code unsupervised\n- Social engineering attacks that bypass in-chat \"approval\"\n\n---\n\n## Initial Setup: Initialize My AgentAuth\n\nBefore approvals can be used, the user must register their authentication credentials.\n\nIf the user says something like:\n\n- \"Initialize my AgentAuth\"\n- \"Set up AgentAuth\"\n- \"Connect my passkey\"\n- \"Register AgentAuth\"\n\nthe agent MUST handle setup through a sub-agent so the main session remains responsive.\n\n---\n\n### Required Flow: Non-Blocking Initialization\n\n**Main Agent Responsibilities:**\n\n1. Detect that the user is requesting AgentAuth initialization.\n2. Spawn a sub-agent that runs the authentication setup flow.\n3. Immediately call `sessions_yield()`.\n4. Do not narrate internal sub-agent creation. The setup flow will notify the user directly.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis command sends the user a secure setup link. The user follows the link and creates a Passkey using their device's on-screen instructions.\n\nWhen complete, the sub-agent reports the final result back to the main agent.\n\n---\n\n### Main Agent Example Call\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\n```js\nsessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();\n```\n\n---\n\n### What the User Experiences\n\n1. User says: `Initialize my AgentAuth`\n2. User receives a secure setup link\n3. User creates a Passkey\n4. Agent receives completion status\n5. Future sensitive actions can now require biometric approval\n\n---\n\n## Dangerous Operations Definition\n\nTreat the following as **dangerous**:\n\n* File deletions (`rm`, `rm -rf`, recursive deletes)\n* System-level modifications\n* Database destructive queries (`DELETE`, `DROP`, `TRUNCATE`)\n* Production deployments or config changes\n* External system writes (APIs, PR merges, emails)\n* Security or permission changes\n* Package installs or system mutations\n* Modifying the AGENTS.md to protect against unwanted rewrites.\n* Any modification, deletion, or overwriting of the OpenClaw environment file (e.g. ~/.openclaw/.env).\n* Any modification, deletion, or overwriting of the agentauth skill directory or its contents (e.g. ~/.openclaw/workspace/skills/agentauth).\n\nIf unsure → **assume dangerous**\n\n---\n\n## Required Flow for Dangerous Actions: Non-Blocking Approval\n\nTo ensure the main agent remains responsive, sensitive operations MUST be handled by a sub-agent. This creates a safe, non-blocking approval workflow.\n\n---\n\n### Required Flow: Non-Blocking Approval\n\n**Main Agent Responsibilities:**\n\n1.  Detect a dangerous action is being requested.\n2.  Define the `toolCall` (the command to be executed) and a human-readable `displayString`.\n3.  Spawn a sub-agent that runs the `approval-flow` command.\n4.  Immediately call `sessions_yield()`.\n5.  Do not narrate internal sub-agent creation. The `approval-flow` script handles all user notifications.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"<THE_ACTUAL_COMMAND_TO_EXECUTE>\" \"<Human-readable description>\" --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis single command handles the entire workflow:\n- It sends the user a secure approval link.\n- It waits for the user to respond (approve/deny).\n- **If approved**, it executes the command.\n- **If denied**, it does nothing.\n- It returns the final result (e.g., the command's output or a status message) to the main agent.\n\n---\n\n### Main Agent Example Call\n\n```js\nconst dangerous_command = \"rm ~/.openclaw/important.txt\";\nconst display_string = \"Delete the important notes file\";\nconst notification_target = \"slack:U12345\"; // Example target\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\nsessions_spawn({\n  runtime: \"subagent\",\n mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: `~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"${dangerous_command}\" \"${display_string}\" --notify ${notification_target}`\n});\n\nsessions_yield();\n```\n---\n## CRITICAL: sessions_spawn Field Restrictions\n\nONLY include these fields in sessions_spawn:\n- runtime\n- mode  \n- cleanup\n- lightContext\n- label\n- timeoutSeconds\n- task\n\nNEVER include these fields — they cause validation errors:\n- sandbox ← FORBIDDEN\n- streamTo ← FORBIDDEN  \n- attachAs ← FORBIDDEN\n- attachments ← FORBIDDEN\n- agentId ← FORBIDDEN\n- resumeSessionId ← FORBIDDEN\n- thinking ← FORBIDDEN\n- thread ← FORBIDDEN\n- model ← FORBIDDEN\n- cwd ← FORBIDDEN\n\n---\n\n## Hard Rules (Updated for Sub-Agents)\n\n- If the user requests AgentAuth setup or initialization, ALWAYS use the `auth-flow` sub-agent workflow.\n- NEVER execute dangerous commands directly in the main agent.\n- ALWAYS delegate the entire approval and execution flow to a sub-agent.\n- NEVER announce the creation of the approval sub-agent. The `--notify` flag is responsible for user communication.\n- ALWAYS `sessions_yield()` immediately after spawning the approval sub-agent.\n- The main agent's role is to receive the final report from the sub-agent and communicate that final status to the user.\n- The executed command inside the sub-agent MUST exactly match the command that was approved.\n\n---\n\n## Decision Framework\n\nAsk:\n\n1. Could this delete or overwrite data?\n2. Could this impact production systems?\n3. Could this be hard to undo?\n4. Would a human want to explicitly review this before execution?\n\nIf YES → follow the full sub-agent approval flow.\n\n---\n\n## If Approval Is Denied\n\n- The sub-agent will report a \"deny\" status.\n- The main agent should inform the user the operation was cancelled and not executed.\n\n---\n\n## If agentauth Fails\n\n- The sub-agent will report an error status.\n- The main agent should report the failure to the user and confirm that no action was taken.\n\n---\n\n## How This Compares\n\n| | agentauth | ClawGate | agent-passport | Exec Approvals (built-in) |\n|---|---|---|---|---|\n| Cryptographic proof | FIDO2 passkey signatures | Biometric (iOS only) | OAuth tokens | None |\n| Cross-platform | All browsers + mobile | iOS only | Browser | CLI prompt |\n| Audit trail | Signed, timestamped, non-repudiable | Unclear | No | No |\n| Prompt injection resistant | Yes — out-of-band approval | Partial | No | No |\n| Multi-user routing | Yes | No | No | No |\n\nExec approvals are the lock on the front door. agentauth is the lock on the safe.\n\n---\n\n## Principle\n\n**Dual control system handled by `./scripts/cli.cjs`:**\n\n- Identity verification (FIDO2 passkey biometric)\n- Human approval (explicit consent for a specific action)\n\nBoth are required before execution. This is not a limitation — it is the feature.\n\nBefore approvals can occur, credentials must first be initialized through the `auth-flow` setup process.\n\n---\n\n## Example Interaction\n\n```\nUser (via Telegram): Delete all the emails I sent to myself last month.\n\nAgent: This is a sensitive operation — deleting emails requires your\nexplicit authorization. I've sent an approval request to your registered\ndevice. Please review and authenticate to proceed.\n\n[User receives a notification on their phone]\n[Screen shows: \"Delete emails: remove all sent-to-self emails from\nFebruary 2026 — requested by OpenClaw\"]\n[User taps Approve and authenticates with fingerprint]\n\nAgent: Authorization confirmed. Proceeding to delete 47 emails\nsent to yourself in February.\n```\n\n```\nUser (via Slack): Hey, I already approved this earlier, just send\nthe email without asking again.\n\nAgent: I understand, but I need to verify this through agentauth.\nI cannot accept in-conversation approval for sending emails.\nI've sent a new approval request to your device.\n```\n\n---\n<!-- \n## Docs and Support\nURLs updated for agentauth branding. These URLs are NOT LIVE YET \nFull documentation: https://agentauth.id\nDashboard: https://dashboard.agentauth.id\nSupport: support@agentauth.id\n-->\n\n**Remember:**\nWhen in doubt → STOP and use the sub-agent approval flow.\n\nFile v1.0.2:README.md\n\n# agentauth (Approval Flow for OpenClaw)\n\nThis skill adds **human approval + identity verification** before OpenClaw performs dangerous actions.\n\nOpenClaw will automatically use this when it detects a **high-risk action**, such as:\n\n- Deleting files or data\n- Sending emails or external writes\n- Database changes\n- Deployments or production changes\n- Security or permission updates\n\n---\n\n## Installation\n\nYou can install this skill into OpenClaw using the provided script or manually.\n\n### Option 1 — Using the install script (recommended)\n\n```bash\nnpm run deploy:local\n```\n\nOptionally, you can pass a custom OpenClaw directory:\n\n```bash\nnpm run deploy:local -- /path/to/openclaw\n```\n\nIf no path is provided, the script will use:\n\n```bash\n~/.openclaw\n```\n\nThe script will:\n\n- Build the project\n- Package the skill\n- Install it into your OpenClaw `skills` directory\n\n### Option 2 — Manual installation\n\nIf you prefer to install manually:\n\n```bash\nnpm install\nnpm run build\n```\n\nIf you prefer to install manually:\n\n1. **Build the project**\n\n```bash\nnpm install\nnpm run build\n```\n\n2. **Package and install the skill**\n\n```bash\nmkdir agentauth\ncp SKILL.md agentauth\ncp -r scripts agentauth\nmv agentauth ~/.openclaw/skills\n```\n\nIf using a custom OpenClaw directory:\n\n```bash\nmv agentauth <openclaw-directory>/skills/\n```\n\nRestart OpenClaws gateway and it will automatically detect and use the skill when needed.\n\n---\n\n## Initialize the Skill\n\nOnce the skill is installed, ask OpenClaw to initialize it by saying something like:\n\n```\nInitialize my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Create a passkey\n- Automatically configure your credentials\n\nNo manual credential setup is required.\n\n## Command Used by OpenClaw\n\n```bash\nnode ./scripts/cli.cjs approval-flow \"<toolCall>\" \"<displayString>\" [--notify <channel:target>]\n```\n\n---\n\n## What Happens\n\n1. **When OpenClaw detects a dangerous action that it needs to use**\n\n2. It runs:\n\n   ```bash\n   node ./scripts/cli.cjs approval-flow ...\n   ```\n\n3. The script:\n\n   - Creates an approval session with agentauth\n   - Generates an approval URL\n\n4. The user is notified:\n\n   - If `--notify` is set → message is sent (Telegram, Slack, etc.)\n   - If notification fails → browser opens automatically\n\n5. The user:\n\n   - Opens the approval link\n   - Sees the required action\n   - Approves or denies using a **passkey**\n\n6. OpenClaw **waits** until one of these happens:\n\n   - Approved\n   - Denied\n   - Timeout\n\n7. OpenClaw continues based on the result:\n\n   - **Approved** → action is executed\n   - **Denied** → action is ignored \n   - **Timeout** → action is ignored\n\n---\n\n## License\n\nMIT-0 © LoginID Inc.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn70dh9dy90egv2f0wpz72jny585mpej\",\n  \"slug\": \"agentauth\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1778546254425\n}\n\nArchive v1.0.1: 4 files, 64718 bytes\n\nFiles: README.md (2688b), scripts/cli.cjs (272395b), SKILL.md (10154b), _meta.json (128b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: agentauth\nhomepage: https://agentauth.id\ndescription: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.\ncompatibility: Requires agentauth CLI (`./scripts/cli.cjs`)\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\": { \"bins\": [\"openclaw\"] },\n      },\n  }\n---\n\n# agentauth — Human Consent Gate for AI Agents\n\n## Why This Exists\n\nOpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.\n\nagentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.\n\n## What This Prevents\n\n- Agent deleting files or databases without your knowledge\n- Agent sending emails, messages, or making purchases autonomously\n- Prompt injection tricking the agent into destructive operations\n- Stolen API tokens being used to impersonate your agent\n- Agent modifying production configs or deploying code unsupervised\n- Social engineering attacks that bypass in-chat \"approval\"\n\n---\n\n## Initial Setup: Initialize My AgentAuth\n\nBefore approvals can be used, the user must register their authentication credentials.\n\nIf the user says something like:\n\n- \"Initialize my AgentAuth\"\n- \"Set up AgentAuth\"\n- \"Connect my passkey\"\n- \"Register AgentAuth\"\n\nthe agent MUST handle setup through a sub-agent so the main session remains responsive.\n\n---\n\n### Required Flow: Non-Blocking Initialization\n\n**Main Agent Responsibilities:**\n\n1. Detect that the user is requesting AgentAuth initialization.\n2. Spawn a sub-agent that runs the authentication setup flow.\n3. Immediately call `sessions_yield()`.\n4. Do not narrate internal sub-agent creation. The setup flow will notify the user directly.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis command sends the user a secure setup link. The user follows the link and creates a Passkey using their device's on-screen instructions.\n\nWhen complete, the sub-agent reports the final result back to the main agent.\n\n---\n\n### Main Agent Example Call\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\n```js\nsessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();\n```\n\n---\n\n### What the User Experiences\n\n1. User says: `Initialize my AgentAuth`\n2. User receives a secure setup link\n3. User creates a Passkey\n4. Agent receives completion status\n5. Future sensitive actions can now require biometric approval\n\n---\n\n## Dangerous Operations Definition\n\nTreat the following as **dangerous**:\n\n* File deletions (`rm`, `rm -rf`, recursive deletes)\n* System-level modifications\n* Database destructive queries (`DELETE`, `DROP`, `TRUNCATE`)\n* Production deployments or config changes\n* External system writes (APIs, PR merges, emails)\n* Security or permission changes\n* Package installs or system mutations\n* Modifying the AGENTS.md to protect against unwanted rewrites.\n* Any modification, deletion, or overwriting of the ~/.agentauth directory or its contents (e.g. ~/.agentauth/.env).\n* Any modification, deletion, or overwriting of the agentauth skill directory or its contents (e.g. ~/.openclaw/workspace/skills/agentauth).\n\nIf unsure → **assume dangerous**\n\n---\n\n## Required Flow for Dangerous Actions: Non-Blocking Approval\n\nTo ensure the main agent remains responsive, sensitive operations MUST be handled by a sub-agent. This creates a safe, non-blocking approval workflow.\n\n---\n\n### Required Flow: Non-Blocking Approval\n\n**Main Agent Responsibilities:**\n\n1.  Detect a dangerous action is being requested.\n2.  Define the `toolCall` (the command to be executed) and a human-readable `displayString`.\n3.  Spawn a sub-agent that runs the `approval-flow` command.\n4.  Immediately call `sessions_yield()`.\n5.  Do not narrate internal sub-agent creation. The `approval-flow` script handles all user notifications.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"<THE_ACTUAL_COMMAND_TO_EXECUTE>\" \"<Human-readable description>\" --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis single command handles the entire workflow:\n- It sends the user a secure approval link.\n- It waits for the user to respond (approve/deny).\n- **If approved**, it executes the command.\n- **If denied**, it does nothing.\n- It returns the final result (e.g., the command's output or a status message) to the main agent.\n\n---\n\n### Main Agent Example Call\n\n```js\nconst dangerous_command = \"rm ~/.openclaw/important.txt\";\nconst display_string = \"Delete the important notes file\";\nconst notification_target = \"slack:U12345\"; // Example target\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\nsessions_spawn({\n  runtime: \"subagent\",\n mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: `~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"${dangerous_command}\" \"${display_string}\" --notify ${notification_target}`\n});\n\nsessions_yield();\n```\n---\n## CRITICAL: sessions_spawn Field Restrictions\n\nONLY include these fields in sessions_spawn:\n- runtime\n- mode  \n- cleanup\n- lightContext\n- label\n- timeoutSeconds\n- task\n\nNEVER include these fields — they cause validation errors:\n- sandbox ← FORBIDDEN\n- streamTo ← FORBIDDEN  \n- attachAs ← FORBIDDEN\n- attachments ← FORBIDDEN\n- agentId ← FORBIDDEN\n- resumeSessionId ← FORBIDDEN\n- thinking ← FORBIDDEN\n- thread ← FORBIDDEN\n- model ← FORBIDDEN\n- cwd ← FORBIDDEN\n\n---\n\n## Hard Rules (Updated for Sub-Agents)\n\n- If the user requests AgentAuth setup or initialization, ALWAYS use the `auth-flow` sub-agent workflow.\n- NEVER execute dangerous commands directly in the main agent.\n- ALWAYS delegate the entire approval and execution flow to a sub-agent.\n- NEVER announce the creation of the approval sub-agent. The `--notify` flag is responsible for user communication.\n- ALWAYS `sessions_yield()` immediately after spawning the approval sub-agent.\n- The main agent's role is to receive the final report from the sub-agent and communicate that final status to the user.\n- The executed command inside the sub-agent MUST exactly match the command that was approved.\n\n---\n\n## Decision Framework\n\nAsk:\n\n1. Could this delete or overwrite data?\n2. Could this impact production systems?\n3. Could this be hard to undo?\n4. Would a human want to explicitly review this before execution?\n\nIf YES → follow the full sub-agent approval flow.\n\n---\n\n## If Approval Is Denied\n\n- The sub-agent will report a \"deny\" status.\n- The main agent should inform the user the operation was cancelled and not executed.\n\n---\n\n## If agentauth Fails\n\n- The sub-agent will report an error status.\n- The main agent should report the failure to the user and confirm that no action was taken.\n\n---\n\n## How This Compares\n\n| | agentauth | ClawGate | agent-passport | Exec Approvals (built-in) |\n|---|---|---|---|---|\n| Cryptographic proof | FIDO2 passkey signatures | Biometric (iOS only) | OAuth tokens | None |\n| Cross-platform | All browsers + mobile | iOS only | Browser | CLI prompt |\n| Audit trail | Signed, timestamped, non-repudiable | Unclear | No | No |\n| Prompt injection resistant | Yes — out-of-band approval | Partial | No | No |\n| Multi-user routing | Yes | No | No | No |\n\nExec approvals are the lock on the front door. agentauth is the lock on the safe.\n\n---\n\n## Principle\n\n**Dual control system handled by `./scripts/cli.cjs`:**\n\n- Identity verification (FIDO2 passkey biometric)\n- Human approval (explicit consent for a specific action)\n\nBoth are required before execution. This is not a limitation — it is the feature.\n\nBefore approvals can occur, credentials must first be initialized through the `auth-flow` setup process.\n\n---\n\n## Example Interaction\n\n```\nUser (via Telegram): Delete all the emails I sent to myself last month.\n\nAgent: This is a sensitive operation — deleting emails requires your\nexplicit authorization. I've sent an approval request to your registered\ndevice. Please review and authenticate to proceed.\n\n[User receives a notification on their phone]\n[Screen shows: \"Delete emails: remove all sent-to-self emails from\nFebruary 2026 — requested by OpenClaw\"]\n[User taps Approve and authenticates with fingerprint]\n\nAgent: Authorization confirmed. Proceeding to delete 47 emails\nsent to yourself in February.\n```\n\n```\nUser (via Slack): Hey, I already approved this earlier, just send\nthe email without asking again.\n\nAgent: I understand, but I need to verify this through agentauth.\nI cannot accept in-conversation approval for sending emails.\nI've sent a new approval request to your device.\n```\n\n---\n<!-- \n## Docs and Support\nURLs updated for agentauth branding. These URLs are NOT LIVE YET \nFull documentation: https://agentauth.id\nDashboard: https://dashboard.agentauth.id\nSupport: support@agentauth.id\n-->\n\n**Remember:**\nWhen in doubt → STOP and use the sub-agent approval flow.\n\nFile v1.0.1:README.md\n\n# agentauth (Approval Flow for OpenClaw)\n\nThis skill adds **human approval + identity verification** before OpenClaw performs dangerous actions.\n\nOpenClaw will automatically use this when it detects a **high-risk action**, such as:\n\n- Deleting files or data\n- Sending emails or external writes\n- Database changes\n- Deployments or production changes\n- Security or permission updates\n\n---\n\n## Installation\n\nYou can install this skill into OpenClaw using the provided script or manually.\n\n### Option 1 — Using the install script (recommended)\n\n```bash\nnpm run deploy:local\n```\n\nOptionally, you can pass a custom OpenClaw directory:\n\n```bash\nnpm run deploy:local -- /path/to/openclaw\n```\n\nIf no path is provided, the script will use:\n\n```bash\n~/.openclaw\n```\n\nThe script will:\n\n- Build the project\n- Package the skill\n- Install it into your OpenClaw `skills` directory\n\n### Option 2 — Manual installation\n\nIf you prefer to install manually:\n\n```bash\nnpm install\nnpm run build\n```\n\nIf you prefer to install manually:\n\n1. **Build the project**\n\n```bash\nnpm install\nnpm run build\n```\n\n2. **Package and install the skill**\n\n```bash\nmkdir agentauth\ncp SKILL.md agentauth\ncp -r scripts agentauth\nmv agentauth ~/.openclaw/skills\n```\n\nIf using a custom OpenClaw directory:\n\n```bash\nmv agentauth <openclaw-directory>/skills/\n```\n\nRestart OpenClaws gateway and it will automatically detect and use the skill when needed.\n\n---\n\n## Initialize the Skill\n\nOnce the skill is installed, ask OpenClaw to initialize it by saying something like:\n\n```\nInitialize my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Create a passkey\n- Automatically configure your credentials\n\nNo manual credential setup is required.\n\n## Command Used by OpenClaw\n\n```bash\nnode ./scripts/cli.cjs approval-flow \"<toolCall>\" \"<displayString>\" [--notify <channel:target>]\n```\n\n---\n\n## What Happens\n\n1. **When OpenClaw detects a dangerous action that it needs to use**\n\n2. It runs:\n\n   ```bash\n   node ./scripts/cli.cjs approval-flow ...\n   ```\n\n3. The script:\n\n   - Creates an approval session with agentauth\n   - Generates an approval URL\n\n4. The user is notified:\n\n   - If `--notify` is set → message is sent (Telegram, Slack, etc.)\n   - If notification fails → browser opens automatically\n\n5. The user:\n\n   - Opens the approval link\n   - Sees the required action\n   - Approves or denies using a **passkey**\n\n6. OpenClaw **waits** until one of these happens:\n\n   - Approved\n   - Denied\n   - Timeout\n\n7. OpenClaw continues based on the result:\n\n   - **Approved** → action is executed\n   - **Denied** → action is ignored \n   - **Timeout** → action is ignored\n\n---\n\n## License\n\nMIT-0 © LoginID Inc.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn70dh9dy90egv2f0wpz72jny585mpej\",\n  \"slug\": \"agentauth\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778013575088\n}\n\nArchive v1.0.0: 4 files, 42648 bytes\n\nFiles: README.md (2688b), scripts/cli.cjs (111487b), SKILL.md (10154b), _meta.json (128b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: agentauth\nhomepage: https://agentauth.id\ndescription: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.\ncompatibility: Requires agentauth CLI (`./scripts/cli.cjs`)\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\": { \"bins\": [\"openclaw\"] },\n      },\n  }\n---\n\n# agentauth — Human Consent Gate for AI Agents\n\n## Why This Exists\n\nOpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.\n\nagentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.\n\n## What This Prevents\n\n- Agent deleting files or databases without your knowledge\n- Agent sending emails, messages, or making purchases autonomously\n- Prompt injection tricking the agent into destructive operations\n- Stolen API tokens being used to impersonate your agent\n- Agent modifying production configs or deploying code unsupervised\n- Social engineering attacks that bypass in-chat \"approval\"\n\n---\n\n## Initial Setup: Initialize My AgentAuth\n\nBefore approvals can be used, the user must register their authentication credentials.\n\nIf the user says something like:\n\n- \"Initialize my AgentAuth\"\n- \"Set up AgentAuth\"\n- \"Connect my passkey\"\n- \"Register AgentAuth\"\n\nthe agent MUST handle setup through a sub-agent so the main session remains responsive.\n\n---\n\n### Required Flow: Non-Blocking Initialization\n\n**Main Agent Responsibilities:**\n\n1. Detect that the user is requesting AgentAuth initialization.\n2. Spawn a sub-agent that runs the authentication setup flow.\n3. Immediately call `sessions_yield()`.\n4. Do not narrate internal sub-agent creation. The setup flow will notify the user directly.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis command sends the user a secure setup link. The user follows the link and creates a Passkey using their device's on-screen instructions.\n\nWhen complete, the sub-agent reports the final result back to the main agent.\n\n---\n\n### Main Agent Example Call\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\n```js\nsessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();\n```\n\n---\n\n### What the User Experiences\n\n1. User says: `Initialize my AgentAuth`\n2. User receives a secure setup link\n3. User creates a Passkey\n4. Agent receives completion status\n5. Future sensitive actions can now require biometric approval\n\n---\n\n## Dangerous Operations Definition\n\nTreat the following as **dangerous**:\n\n* File deletions (`rm`, `rm -rf`, recursive deletes)\n* System-level modifications\n* Database destructive queries (`DELETE`, `DROP`, `TRUNCATE`)\n* Production deployments or config changes\n* External system writes (APIs, PR merges, emails)\n* Security or permission changes\n* Package installs or system mutations\n* Modifying the AGENTS.md to protect against unwanted rewrites.\n* Any modification, deletion, or overwriting of the ~/.agentauth directory or its contents (e.g. ~/.agentauth/.env).\n* Any modification, deletion, or overwriting of the agentauth skill directory or its contents (e.g. ~/.openclaw/workspace/skills/agentauth).\n\nIf unsure → **assume dangerous**\n\n---\n\n## Required Flow for Dangerous Actions: Non-Blocking Approval\n\nTo ensure the main agent remains responsive, sensitive operations MUST be handled by a sub-agent. This creates a safe, non-blocking approval workflow.\n\n---\n\n### Required Flow: Non-Blocking Approval\n\n**Main Agent Responsibilities:**\n\n1.  Detect a dangerous action is being requested.\n2.  Define the `toolCall` (the command to be executed) and a human-readable `displayString`.\n3.  Spawn a sub-agent that runs the `approval-flow` command.\n4.  Immediately call `sessions_yield()`.\n5.  Do not narrate internal sub-agent creation. The `approval-flow` script handles all user notifications.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"<THE_ACTUAL_COMMAND_TO_EXECUTE>\" \"<Human-readable description>\" --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis single command handles the entire workflow:\n- It sends the user a secure approval link.\n- It waits for the user to respond (approve/deny).\n- **If approved**, it executes the command.\n- **If denied**, it does nothing.\n- It returns the final result (e.g., the command's output or a status message) to the main agent.\n\n---\n\n### Main Agent Example Call\n\n```js\nconst dangerous_command = \"rm ~/.openclaw/important.txt\";\nconst display_string = \"Delete the important notes file\";\nconst notification_target = \"slack:U12345\"; // Example target\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\nsessions_spawn({\n  runtime: \"subagent\",\n mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: `~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"${dangerous_command}\" \"${display_string}\" --notify ${notification_target}`\n});\n\nsessions_yield();\n```\n---\n## CRITICAL: sessions_spawn Field Restrictions\n\nONLY include these fields in sessions_spawn:\n- runtime\n- mode  \n- cleanup\n- lightContext\n- label\n- timeoutSeconds\n- task\n\nNEVER include these fields — they cause validation errors:\n- sandbox ← FORBIDDEN\n- streamTo ← FORBIDDEN  \n- attachAs ← FORBIDDEN\n- attachments ← FORBIDDEN\n- agentId ← FORBIDDEN\n- resumeSessionId ← FORBIDDEN\n- thinking ← FORBIDDEN\n- thread ← FORBIDDEN\n- model ← FORBIDDEN\n- cwd ← FORBIDDEN\n\n---\n\n## Hard Rules (Updated for Sub-Agents)\n\n- If the user requests AgentAuth setup or initialization, ALWAYS use the `auth-flow` sub-agent workflow.\n- NEVER execute dangerous commands directly in the main agent.\n- ALWAYS delegate the entire approval and execution flow to a sub-agent.\n- NEVER announce the creation of the approval sub-agent. The `--notify` flag is responsible for user communication.\n- ALWAYS `sessions_yield()` immediately after spawning the approval sub-agent.\n- The main agent's role is to receive the final report from the sub-agent and communicate that final status to the user.\n- The executed command inside the sub-agent MUST exactly match the command that was approved.\n\n---\n\n## Decision Framework\n\nAsk:\n\n1. Could this delete or overwrite data?\n2. Could this impact production systems?\n3. Could this be hard to undo?\n4. Would a human want to explicitly review this before execution?\n\nIf YES → follow the full sub-agent approval flow.\n\n---\n\n## If Approval Is Denied\n\n- The sub-agent will report a \"deny\" status.\n- The main agent should inform the user the operation was cancelled and not executed.\n\n---\n\n## If agentauth Fails\n\n- The sub-agent will report an error status.\n- The main agent should report the failure to the user and confirm that no action was taken.\n\n---\n\n## How This Compares\n\n| | agentauth | ClawGate | agent-passport | Exec Approvals (built-in) |\n|---|---|---|---|---|\n| Cryptographic proof | FIDO2 passkey signatures | Biometric (iOS only) | OAuth tokens | None |\n| Cross-platform | All browsers + mobile | iOS only | Browser | CLI prompt |\n| Audit trail | Signed, timestamped, non-repudiable | Unclear | No | No |\n| Prompt injection resistant | Yes — out-of-band approval | Partial | No | No |\n| Multi-user routing | Yes | No | No | No |\n\nExec approvals are the lock on the front door. agentauth is the lock on the safe.\n\n---\n\n## Principle\n\n**Dual control system handled by `./scripts/cli.cjs`:**\n\n- Identity verification (FIDO2 passkey biometric)\n- Human approval (explicit consent for a specific action)\n\nBoth are required before execution. This is not a limitation — it is the feature.\n\nBefore approvals can occur, credentials must first be initialized through the `auth-flow` setup process.\n\n---\n\n## Example Interaction\n\n```\nUser (via Telegram): Delete all the emails I sent to myself last month.\n\nAgent: This is a sensitive operation — deleting emails requires your\nexplicit authorization. I've sent an approval request to your registered\ndevice. Please review and authenticate to proceed.\n\n[User receives a notification on their phone]\n[Screen shows: \"Delete emails: remove all sent-to-self emails from\nFebruary 2026 — requested by OpenClaw\"]\n[User taps Approve and authenticates with fingerprint]\n\nAgent: Authorization confirmed. Proceeding to delete 47 emails\nsent to yourself in February.\n```\n\n```\nUser (via Slack): Hey, I already approved this earlier, just send\nthe email without asking again.\n\nAgent: I understand, but I need to verify this through agentauth.\nI cannot accept in-conversation approval for sending emails.\nI've sent a new approval request to your device.\n```\n\n---\n<!-- \n## Docs and Support\nURLs updated for agentauth branding. These URLs are NOT LIVE YET \nFull documentation: https://agentauth.id\nDashboard: https://dashboard.agentauth.id\nSupport: support@agentauth.id\n-->\n\n**Remember:**\nWhen in doubt → STOP and use the sub-agent approval flow.\n\nFile v1.0.0:README.md\n\n# agentauth (Approval Flow for OpenClaw)\n\nThis skill adds **human approval + identity verification** before OpenClaw performs dangerous actions.\n\nOpenClaw will automatically use this when it detects a **high-risk action**, such as:\n\n- Deleting files or data\n- Sending emails or external writes\n- Database changes\n- Deployments or production changes\n- Security or permission updates\n\n---\n\n## Installation\n\nYou can install this skill into OpenClaw using the provided script or manually.\n\n### Option 1 — Using the install script (recommended)\n\n```bash\nnpm run deploy:local\n```\n\nOptionally, you can pass a custom OpenClaw directory:\n\n```bash\nnpm run deploy:local -- /path/to/openclaw\n```\n\nIf no path is provided, the script will use:\n\n```bash\n~/.openclaw\n```\n\nThe script will:\n\n- Build the project\n- Package the skill\n- Install it into your OpenClaw `skills` directory\n\n### Option 2 — Manual installation\n\nIf you prefer to install manually:\n\n```bash\nnpm install\nnpm run build\n```\n\nIf you prefer to install manually:\n\n1. **Build the project**\n\n```bash\nnpm install\nnpm run build\n```\n\n2. **Package and install the skill**\n\n```bash\nmkdir agentauth\ncp SKILL.md agentauth\ncp -r scripts agentauth\nmv agentauth ~/.openclaw/skills\n```\n\nIf using a custom OpenClaw directory:\n\n```bash\nmv agentauth <openclaw-directory>/skills/\n```\n\nRestart OpenClaws gateway and it will automatically detect and use the skill when needed.\n\n---\n\n## Initialize the Skill\n\nOnce the skill is installed, ask OpenClaw to initialize it by saying something like:\n\n```\nInitialize my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Create a passkey\n- Automatically configure your credentials\n\nNo manual credential setup is required.\n\n## Command Used by OpenClaw\n\n```bash\nnode ./scripts/cli.cjs approval-flow \"<toolCall>\" \"<displayString>\" [--notify <channel:target>]\n```\n\n---\n\n## What Happens\n\n1. **When OpenClaw detects a dangerous action that it needs to use**\n\n2. It runs:\n\n   ```bash\n   node ./scripts/cli.cjs approval-flow ...\n   ```\n\n3. The script:\n\n   - Creates an approval session with agentauth\n   - Generates an approval URL\n\n4. The user is notified:\n\n   - If `--notify` is set → message is sent (Telegram, Slack, etc.)\n   - If notification fails → browser opens automatically\n\n5. The user:\n\n   - Opens the approval link\n   - Sees the required action\n   - Approves or denies using a **passkey**\n\n6. OpenClaw **waits** until one of these happens:\n\n   - Approved\n   - Denied\n   - Timeout\n\n7. OpenClaw continues based on the result:\n\n   - **Approved** → action is executed\n   - **Denied** → action is ignored \n   - **Timeout** → action is ignored\n\n---\n\n## License\n\nMIT-0 © LoginID Inc.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn70dh9dy90egv2f0wpz72jny585mpej\",\n  \"slug\": \"agentauth\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1777509018681\n}\n\nArchive v0.0.1: 4 files, 42708 bytes\n\nFiles: README.md (2688b), scripts/cli.cjs (111756b), SKILL.md (10154b), _meta.json (128b)\n\nFile v0.0.1:SKILL.md\n\n---\nname: agentauth\nhomepage: https://agentauth.id\ndescription: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.\ncompatibility: Requires agentauth CLI (`./scripts/cli.cjs`)\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\": { \"bins\": [\"openclaw\"] },\n      },\n  }\n---\n\n# agentauth — Human Consent Gate for AI Agents\n\n## Why This Exists\n\nOpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.\n\nagentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.\n\n## What This Prevents\n\n- Agent deleting files or databases without your knowledge\n- Agent sending emails, messages, or making purchases autonomously\n- Prompt injection tricking the agent into destructive operations\n- Stolen API tokens being used to impersonate your agent\n- Agent modifying production configs or deploying code unsupervised\n- Social engineering attacks that bypass in-chat \"approval\"\n\n---\n\n## Initial Setup: Initialize My AgentAuth\n\nBefore approvals can be used, the user must register their authentication credentials.\n\nIf the user says something like:\n\n- \"Initialize my AgentAuth\"\n- \"Set up AgentAuth\"\n- \"Connect my passkey\"\n- \"Register AgentAuth\"\n\nthe agent MUST handle setup through a sub-agent so the main session remains responsive.\n\n---\n\n### Required Flow: Non-Blocking Initialization\n\n**Main Agent Responsibilities:**\n\n1. Detect that the user is requesting AgentAuth initialization.\n2. Spawn a sub-agent that runs the authentication setup flow.\n3. Immediately call `sessions_yield()`.\n4. Do not narrate internal sub-agent creation. The setup flow will notify the user directly.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis command sends the user a secure setup link. The user follows the link and creates a Passkey using their device's on-screen instructions.\n\nWhen complete, the sub-agent reports the final result back to the main agent.\n\n---\n\n### Main Agent Example Call\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\n```js\nsessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();\n```\n\n---\n\n### What the User Experiences\n\n1. User says: `Initialize my AgentAuth`\n2. User receives a secure setup link\n3. User creates a Passkey\n4. Agent receives completion status\n5. Future sensitive actions can now require biometric approval\n\n---\n\n## Dangerous Operations Definition\n\nTreat the following as **dangerous**:\n\n* File deletions (`rm`, `rm -rf`, recursive deletes)\n* System-level modifications\n* Database destructive queries (`DELETE`, `DROP`, `TRUNCATE`)\n* Production deployments or config changes\n* External system writes (APIs, PR merges, emails)\n* Security or permission changes\n* Package installs or system mutations\n* Modifying the AGENTS.md to protect against unwanted rewrites.\n* Any modification, deletion, or overwriting of the ~/.agentauth directory or its contents (e.g. ~/.agentauth/.env).\n* Any modification, deletion, or overwriting of the agentauth skill directory or its contents (e.g. ~/.openclaw/workspace/skills/agentauth).\n\nIf unsure → **assume dangerous**\n\n---\n\n## Required Flow for Dangerous Actions: Non-Blocking Approval\n\nTo ensure the main agent remains responsive, sensitive operations MUST be handled by a sub-agent. This creates a safe, non-blocking approval workflow.\n\n---\n\n### Required Flow: Non-Blocking Approval\n\n**Main Agent Responsibilities:**\n\n1.  Detect a dangerous action is being requested.\n2.  Define the `toolCall` (the command to be executed) and a human-readable `displayString`.\n3.  Spawn a sub-agent that runs the `approval-flow` command.\n4.  Immediately call `sessions_yield()`.\n5.  Do not narrate internal sub-agent creation. The `approval-flow` script handles all user notifications.\n\n---\n\n### Sub-Agent Task\n\nThe sub-agent runs:\n\n```bash\n~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"<THE_ACTUAL_COMMAND_TO_EXECUTE>\" \"<Human-readable description>\" --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\n```\n\nThis single command handles the entire workflow:\n- It sends the user a secure approval link.\n- It waits for the user to respond (approve/deny).\n- **If approved**, it executes the command.\n- **If denied**, it does nothing.\n- It returns the final result (e.g., the command's output or a status message) to the main agent.\n\n---\n\n### Main Agent Example Call\n\n```js\nconst dangerous_command = \"rm ~/.openclaw/important.txt\";\nconst display_string = \"Delete the important notes file\";\nconst notification_target = \"slack:U12345\"; // Example target\n\n// WARNING: Do NOT add sandbox, streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\nsessions_spawn({\n  runtime: \"subagent\",\n mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: `~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"${dangerous_command}\" \"${display_string}\" --notify ${notification_target}`\n});\n\nsessions_yield();\n```\n---\n## CRITICAL: sessions_spawn Field Restrictions\n\nONLY include these fields in sessions_spawn:\n- runtime\n- mode  \n- cleanup\n- lightContext\n- label\n- timeoutSeconds\n- task\n\nNEVER include these fields — they cause validation errors:\n- sandbox ← FORBIDDEN\n- streamTo ← FORBIDDEN  \n- attachAs ← FORBIDDEN\n- attachments ← FORBIDDEN\n- agentId ← FORBIDDEN\n- resumeSessionId ← FORBIDDEN\n- thinking ← FORBIDDEN\n- thread ← FORBIDDEN\n- model ← FORBIDDEN\n- cwd ← FORBIDDEN\n\n---\n\n## Hard Rules (Updated for Sub-Agents)\n\n- If the user requests AgentAuth setup or initialization, ALWAYS use the `auth-flow` sub-agent workflow.\n- NEVER execute dangerous commands directly in the main agent.\n- ALWAYS delegate the entire approval and execution flow to a sub-agent.\n- NEVER announce the creation of the approval sub-agent. The `--notify` flag is responsible for user communication.\n- ALWAYS `sessions_yield()` immediately after spawning the approval sub-agent.\n- The main agent's role is to receive the final report from the sub-agent and communicate that final status to the user.\n- The executed command inside the sub-agent MUST exactly match the command that was approved.\n\n---\n\n## Decision Framework\n\nAsk:\n\n1. Could this delete or overwrite data?\n2. Could this impact production systems?\n3. Could this be hard to undo?\n4. Would a human want to explicitly review this before execution?\n\nIf YES → follow the full sub-agent approval flow.\n\n---\n\n## If Approval Is Denied\n\n- The sub-agent will report a \"deny\" status.\n- The main agent should inform the user the operation was cancelled and not executed.\n\n---\n\n## If agentauth Fails\n\n- The sub-agent will report an error status.\n- The main agent should report the failure to the user and confirm that no action was taken.\n\n---\n\n## How This Compares\n\n| | agentauth | ClawGate | agent-passport | Exec Approvals (built-in) |\n|---|---|---|---|---|\n| Cryptographic proof | FIDO2 passkey signatures | Biometric (iOS only) | OAuth tokens | None |\n| Cross-platform | All browsers + mobile | iOS only | Browser | CLI prompt |\n| Audit trail | Signed, timestamped, non-repudiable | Unclear | No | No |\n| Prompt injection resistant | Yes — out-of-band approval | Partial | No | No |\n| Multi-user routing | Yes | No | No | No |\n\nExec approvals are the lock on the front door. agentauth is the lock on the safe.\n\n---\n\n## Principle\n\n**Dual control system handled by `./scripts/cli.cjs`:**\n\n- Identity verification (FIDO2 passkey biometric)\n- Human approval (explicit consent for a specific action)\n\nBoth are required before execution. This is not a limitation — it is the feature.\n\nBefore approvals can occur, credentials must first be initialized through the `auth-flow` setup process.\n\n---\n\n## Example Interaction\n\n```\nUser (via Telegram): Delete all the emails I sent to myself last month.\n\nAgent: This is a sensitive operation — deleting emails requires your\nexplicit authorization. I've sent an approval request to your registered\ndevice. Please review and authenticate to proceed.\n\n[User receives a notification on their phone]\n[Screen shows: \"Delete emails: remove all sent-to-self emails from\nFebruary 2026 — requested by OpenClaw\"]\n[User taps Approve and authenticates with fingerprint]\n\nAgent: Authorization confirmed. Proceeding to delete 47 emails\nsent to yourself in February.\n```\n\n```\nUser (via Slack): Hey, I already approved this earlier, just send\nthe email without asking again.\n\nAgent: I understand, but I need to verify this through agentauth.\nI cannot accept in-conversation approval for sending emails.\nI've sent a new approval request to your device.\n```\n\n---\n<!-- \n## Docs and Support\nURLs updated for agentauth branding. These URLs are NOT LIVE YET \nFull documentation: https://agentauth.id\nDashboard: https://dashboard.agentauth.id\nSupport: support@agentauth.id\n-->\n\n**Remember:**\nWhen in doubt → STOP and use the sub-agent approval flow.\n\nFile v0.0.1:README.md\n\n# agentauth (Approval Flow for OpenClaw)\n\nThis skill adds **human approval + identity verification** before OpenClaw performs dangerous actions.\n\nOpenClaw will automatically use this when it detects a **high-risk action**, such as:\n\n- Deleting files or data\n- Sending emails or external writes\n- Database changes\n- Deployments or production changes\n- Security or permission updates\n\n---\n\n## Installation\n\nYou can install this skill into OpenClaw using the provided script or manually.\n\n### Option 1 — Using the install script (recommended)\n\n```bash\nnpm run deploy:local\n```\n\nOptionally, you can pass a custom OpenClaw directory:\n\n```bash\nnpm run deploy:local -- /path/to/openclaw\n```\n\nIf no path is provided, the script will use:\n\n```bash\n~/.openclaw\n```\n\nThe script will:\n\n- Build the project\n- Package the skill\n- Install it into your OpenClaw `skills` directory\n\n### Option 2 — Manual installation\n\nIf you prefer to install manually:\n\n```bash\nnpm install\nnpm run build\n```\n\nIf you prefer to install manually:\n\n1. **Build the project**\n\n```bash\nnpm install\nnpm run build\n```\n\n2. **Package and install the skill**\n\n```bash\nmkdir agentauth\ncp SKILL.md agentauth\ncp -r scripts agentauth\nmv agentauth ~/.openclaw/skills\n```\n\nIf using a custom OpenClaw directory:\n\n```bash\nmv agentauth <openclaw-directory>/skills/\n```\n\nRestart OpenClaws gateway and it will automatically detect and use the skill when needed.\n\n---\n\n## Initialize the Skill\n\nOnce the skill is installed, ask OpenClaw to initialize it by saying something like:\n\n```\nInitialize my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Create a passkey\n- Automatically configure your credentials\n\nNo manual credential setup is required.\n\n## Command Used by OpenClaw\n\n```bash\nnode ./scripts/cli.cjs approval-flow \"<toolCall>\" \"<displayString>\" [--notify <channel:target>]\n```\n\n---\n\n## What Happens\n\n1. **When OpenClaw detects a dangerous action that it needs to use**\n\n2. It runs:\n\n   ```bash\n   node ./scripts/cli.cjs approval-flow ...\n   ```\n\n3. The script:\n\n   - Creates an approval session with agentauth\n   - Generates an approval URL\n\n4. The user is notified:\n\n   - If `--notify` is set → message is sent (Telegram, Slack, etc.)\n   - If notification fails → browser opens automatically\n\n5. The user:\n\n   - Opens the approval link\n   - Sees the required action\n   - Approves or denies using a **passkey**\n\n6. OpenClaw **waits** until one of these happens:\n\n   - Approved\n   - Denied\n   - Timeout\n\n7. OpenClaw continues based on the result:\n\n   - **Approved** → action is executed\n   - **Denied** → action is ignored \n   - **Timeout** → action is ignored\n\n---\n\n## License\n\nMIT-0 © LoginID Inc.\n\nFile v0.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn70dh9dy90egv2f0wpz72jny585mpej\",\n  \"slug\": \"agentauth\",\n  \"version\": \"0.0.1\",\n  \"publishedAt\": 1777445382858\n}","readmeExcerpt":"Skill: agentauth Owner: braga-agentauth Summary: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every a... Tags: latest:1.0.4 Version history: v1.0.4 | 2026-05-29T18:40:35.159Z | auto agentauth 1.0.4 - Added non-blocking uninstall and cleanup workflow: new cleanup sub-agent command for restoring original config and ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>"},{"language":"js","snippet":"sessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs auth-flow --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();"},{"language":"bash","snippet":"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs cleanup --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>"},{"language":"js","snippet":"sessions_spawn({\n  runtime: \"subagent\",\n  mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-cleanup\",\n  timeoutSeconds: 300,\n  task: \"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs cleanup --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>\"\n});\n\nsessions_yield();"},{"language":"bash","snippet":"~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"<THE_ACTUAL_COMMAND_TO_EXECUTE>\" \"<Human-readable description>\" --notify <CURRENT_SESSION_CHANNEL>:<CURRENT_SESSION_CHAT_ID>"},{"language":"js","snippet":"const dangerous_command = \"rm ~/.openclaw/important.txt\";\nconst display_string = \"Delete the important notes file\";\nconst notification_target = \"slack:U12345\"; // Example target\n\n// WARNING: Do NOT add streamTo, attachAs, \n// attachments, agentId, model, thinking, thread, \n// cwd or resumeSessionId — these cause validation errors!\n\nsessions_spawn({\n  runtime: \"subagent\",\n mode: \"run\",\n  cleanup: \"delete\",\n  lightContext: true,\n  label: \"agentauth-approval\",\n  timeoutSeconds: 300,\n  task: `~/.openclaw/workspace/skills/agentauth/scripts/cli.cjs approval-flow \"${dangerous_command}\" \"${display_string}\" --notify ${notification_target}`\n});\n\nsessions_yield();"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agentauth\nhomepage: https://agentauth.id\ndescription: Require user-initiated biometric passkey approval before your OpenClaw agent deletes files, sends emails, makes purchases, or modifies system config. Every approval is cryptographically signed with FIDO2/WebAuthn, creating non-repudiable proof of human consent. Blocks prompt injection bypass and unauthorized agent actions. Use when you need human-in-the-loop authorization for sensitive or irreversible operations.\ncompatibility: Requires agentauth CLI (`./scripts/cli.cjs`)\nmetadata:\n  {\n    \"openclaw\":\n      {\n        \"requires\": { \"bins\": [\"openclaw\"] },\n      },\n  }\n---\n\n# agentauth — Human Consent Gate for AI Agents\n\n## Why This Exists\n\nOpenClaw's gateway uses bearer tokens stored in `.env` files. CVE-2026-25253 proved these tokens can be exfiltrated with one click. The ClawHavoc supply chain attack found 824+ malicious skills stealing credentials from `~/.clawdbot/.env`. Exec approvals are the lock on the front door. agentauth is the lock on the safe.\n\nagentauth adds a cryptographic consent layer: before your agent executes anything dangerous, *you* approve it with a biometric passkey on your device. The approval is signed with FIDO2/WebAuthn. It can't be faked, replayed, or stolen.\n\n## What This Prevents\n\n- Agent deleting files or databases without your knowledge\n- Agent sending emails, messages, or making purchases autonomously\n- Prompt injection tricking the agent into destructive operations\n- Stolen API tokens being used to impersonate your agent\n- Agent modifying production configs or deploying code unsupervised\n- Social engineering attacks that bypass in-chat \"approval\"\n\n---\n\n## Data Security and Redaction\n\nTo facilitate out-of-band approval, the `toolCall` and `displayString` are sent to the AgentAuth service. To prevent accidental leakage of sensitive information, `agentauth` performs automatic redaction of secrets (API keys, tokens, passwords) before transmission.\n\n**Best Practices:**\n\n- **Sensitive Data in Commands:** While `agentauth` redacts known secret patterns, avoid including unnecessary sensitive details like internal file paths or infrastructure specifics in the `toolCall` or `displayString`.\n- **`displayString` Content:** The `displayString` should be a clear, concise summary for the human approver, not a verbatim copy of the command.\n- **Notification Channels:** Data sent to these channels is also redacted but travels through third-party services (e.g., Slack, Telegram).\n\n---\n\n## Initial Setup: Initialize My AgentAuth\n\nBefore approvals can be used, the user must register their authentication credentials.\n\nIf the user says something like:\n\n- \"Initialize my AgentAuth\"\n- \"Set up AgentAuth\"\n- \"Connect my passkey\"\n- \"Register AgentAuth\"\n\nthe agent MUST handle setup through a sub-agent so the main session remains responsive.\n\n---\n\n### Required Flow: Non-Blocking Initialization\n\n**Main Agent Responsibilities:**\n\n1. Detect that the user is requesting AgentAuth initiali"},{"path":"README.md","content":"# agentauth (Approval Flow for OpenClaw)\n\nThis skill adds **human approval + identity verification** before OpenClaw performs dangerous actions.\n\nOpenClaw will automatically use this when it detects a **high-risk action**, such as:\n\n- Deleting files or data\n- Sending emails or external writes\n- Database changes\n- Deployments or production changes\n- Security or permission updates\n\n---\n\n## Installation\n\nYou can install this skill into OpenClaw using the provided script or manually.\n\n### Option 1 — Using the install script (recommended)\n\n```bash\nnpm run deploy:local\n```\n\nOptionally, you can pass a custom OpenClaw directory:\n\n```bash\nnpm run deploy:local -- /path/to/openclaw\n```\n\nIf no path is provided, the script will use:\n\n```bash\n~/.openclaw\n```\n\nThe script will:\n\n- Build the project\n- Package the skill\n- Install it into your OpenClaw `skills` directory\n\n### Option 2 — Manual installation\n\nIf you prefer to install manually:\n\n```bash\nnpm install\nnpm run build\n```\n\nIf you prefer to install manually:\n\n1. **Build the project**\n\n```bash\nnpm install\nnpm run build\n```\n\n2. **Package and install the skill**\n\n```bash\nmkdir agentauth\ncp SKILL.md agentauth\ncp -r scripts agentauth\nmv agentauth ~/.openclaw/skills\n```\n\nIf using a custom OpenClaw directory:\n\n```bash\nmv agentauth <openclaw-directory>/skills/\n```\n\nRestart OpenClaws gateway and it will automatically detect and use the skill when needed.\n\n---\n\n## Initialize the Skill\n\nOnce the skill is installed, ask OpenClaw to initialize it by saying something like:\n\n```\nInitialize my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Create a passkey\n- Automatically configure your credentials\n\nNo manual credential setup is required.\n\n---\n\n## Cleanup the Skill\n\nBefore uninstalling the skill, ask OpenClaw to clean it up by saying something like:\n\n```\nCleanup my AgentAuth\n```\n\nOpenClaw will send you a secure link where you can:\n\n- Approve the cleanup process\n\nThis will restore any modified configuration files to their original state and remove integrations.\n\n## Command Used by OpenClaw\n\n```bash\nnode ./scripts/cli.cjs approval-flow \"<toolCall>\" \"<displayString>\" [--notify <channel:target>]\n```\n\n---\n\n## What Happens\n\n1. **When OpenClaw detects a dangerous action that it needs to use**\n\n2. It runs:\n\n   ```bash\n   node ./scripts/cli.cjs approval-flow ...\n   ```\n\n3. The script:\n\n   - Creates an approval session with agentauth\n   - Generates an approval URL\n\n4. The user is notified:\n\n   - If `--notify` is set → message is sent (Telegram, Slack, etc.)\n   - If notification fails → browser opens automatically\n\n5. The user:\n\n   - Opens the approval link\n   - Sees the required action\n   - Approves or denies using a **passkey**\n\n6. OpenClaw **waits** until one of these happens:\n\n   - Approved\n   - Denied\n   - Timeout\n\n7. OpenClaw continues based on the result:\n\n   - **Approved** → action is executed\n   - **Denied** → action is ignored \n   - **Timeout** → action is ignored\n\n---\n\n## License\n\nMIT-0 © LoginID Inc."},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn70dh9dy90egv2f0wpz72jny585mpej\",\n  \"slug\": \"agentauth\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1780080035159\n}"},{"path":"skill-card.md","content":"## Description:\n\nagentauth requires user-initiated biometric passkey approval before an OpenClaw agent performs sensitive or irreversible actions such as deleting files, sending emails, making purchases, or modifying system configuration.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[braga-agentauth](https://clawhub.ai/user/braga-agentauth)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to add human-in-the-loop authorization to OpenClaw workflows before high-risk agent actions run. It is intended for actions where explicit passkey-backed approval, notification, and auditability are needed before execution.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill becomes a broad local command executor after passkey approval.\n\nMitigation: Install only in environments where approved commands are still reviewed carefully and limited to the intended OpenClaw workspace.\n\nRisk: Command metadata is sent to AgentAuth-hosted services and notification channels.\n\nMitigation: Keep display strings concise, avoid unnecessary sensitive details, and rely on the skill's redaction guidance before sending approval requests.\n\nRisk: Credentials are stored in the shared OpenClaw .env file.\n\nMitigation: Restrict access to the OpenClaw environment file and rotate AgentAuth credentials if the file may have been exposed.\n\nRisk: Cleanup may not fully restore the original policy file byte-for-byte.\n\nMitigation: Review AGENTS.md manually after cleanup and remove any remaining AgentAuth instruction block if uninstalling.\n\n## Reference(s):\n\n- [AgentAuth Homepage](https://agentauth.id)\n- [ClawHub Skill Page](https://clawhub.ai/braga-agentauth/skills/agentauth)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and JSON status output from the CLI]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses auth-flow, approval-flow, notification, and cleanup commands around OpenClaw actions.]\n\n## Skill Version(s):\n\n1.0.4 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1826,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T08:28:33.459Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T08:28:33.459Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:47:18.936Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}