{"id":"8e48dbfc-5517-4e95-a4dc-6f098f959e6c","entityType":"agent","slug":"clawhub-jovancoding-network-ai","name":"Network-AI","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jovancoding-network-ai","canonicalPath":"/agent/clawhub-jovancoding-network-ai","generatedAt":"2026-10-09T18:06:10.976Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T03:06:51.147Z","emptyReason":null},"description":"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Skill: Network-AI Owner: jovancoding Summary: Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Tags: audit:4.0.4, autogen:4.0.4, b","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 7.1K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s171ekwxgx1x85ga807c8zc0ws840q1k:network-ai","sourceUrl":"https://clawhub.ai/jovancoding/network-ai","homepage":"https://clawhub.ai/jovancoding/skills/network-ai","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jovancoding/network-ai","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jovancoding/skills/network-ai","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":66,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:06:51.147Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:06:51.147Z","emptyReason":null},"stars":null,"forks":null,"downloads":7093,"packageName":null,"latestVersion":"5.15.4","tractionLabel":"7.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T03:06:51.147Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T03:06:51.147Z","lastCrawledAt":"2026-10-09T03:06:51.147Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T03:06:51.147Z","lastVerifiedAt":null,"highlights":[{"version":"5.15.4","createdAt":"2026-09-29T16:21:51.387Z","changelog":"Security: context_manager.py validates writes and scans every field for injection and role-delimiter patterns (A.I.G T02); inject output is delimited reference data. check_permission.py help aligned with HIGH_RISK_RESOURCES. SKILL.md declares allowed-tools and bundle-only capabilities, removes unpinned npx.","fileCount":12,"zipByteSize":66254},{"version":"5.15.3","createdAt":"2026-09-27T21:54:19.456Z","changelog":"v5.15.3: per-instance orchestrator token, MCP server-held identity, shell-free git provenance","fileCount":12,"zipByteSize":63166},{"version":"5.15.2","createdAt":"2026-09-27T20:38:14.229Z","changelog":"v5.15.2: security fixes GHSA-9p2w-prp8-5722, GHSA-hr6v-mfxm-4438, GHSA-4pvg-m42h-c3x2, CodeQL 179/180","fileCount":12,"zipByteSize":63146},{"version":"5.15.1","createdAt":"2026-07-28T19:04:05.882Z","changelog":"v5.15.1 security patch: fix GHSA-743h-jr5x-mpcr (ClaudeHookBridge deny-pattern bypass via truncation before the security decision) and GHSA-9v4f-j8cv-fhxw (SandboxPolicy blocklist/approval-gate bypass via quote/whitespace matcher mismatch); 3638 tests across 41 suites","fileCount":12,"zipByteSize":63236},{"version":"5.15.0","createdAt":"2026-07-06T21:15:53.745Z","changelog":"v5.15.0 context signal-over-noise: ContextComposer (token-budgeted, relevance-ranked context assembly with recency decay and scope affinity) plus context_pack and blackboard_search MCP tools (24 tools total); 3603 tests across 40 suites","fileCount":12,"zipByteSize":63282},{"version":"5.14.0","createdAt":"2026-07-05T20:21:52.136Z","changelog":"v5.14.0 ecosystem expansion: Gemini, OpenAI Responses, and Claude Agent SDK adapters (32 total); Claude Code hooks gating via AuthGuardian; MCP elicitation approvals; A2A server mode; Gemini CLI extension; AGENTS.md; MCP Registry manifest","fileCount":12,"zipByteSize":63295},{"version":"5.13.4","createdAt":"2026-07-05T19:07:05.171Z","changelog":"Security fixes: GHSA-m4jg-6w3q-gm86 (ApprovalInbox auth+CORS) and GHSA-3jf7-33vc-hgf4 (APSAdapter fail-closed signature verification)","fileCount":12,"zipByteSize":63294},{"version":"5.13.3","createdAt":"2026-06-26T19:55:47.271Z","changelog":"fix: correct display name to Network-AI","fileCount":12,"zipByteSize":63270}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171ekwxgx1x85ga807c8zc0ws840q1k:network-ai","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T18:06:10.969Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jovancoding-network-ai/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T03:06:51.147Z","emptyReason":null},"readme":"Skill: Network-AI\n\nOwner: jovancoding\n\nSummary: Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle).\n\nTags: audit:4.0.4, autogen:4.0.4, blackboard:4.0.4, crewai:4.0.4, langchain:4.0.4, latest:5.15.4, mcp:4.0.4, multi-agent:4.0.4, orchestration:4.0.4, permissions:4.0.4, security:4.0.4, swarm:4.0.4\n\nVersion history:\n\nv5.15.4 | 2026-09-29T16:21:51.387Z | user\n\nSecurity: context_manager.py validates writes and scans every field for injection and role-delimiter patterns (A.I.G T02); inject output is delimited reference data. check_permission.py help aligned with HIGH_RISK_RESOURCES. SKILL.md declares allowed-tools and bundle-only capabilities, removes unpinned npx.\n\nv5.15.3 | 2026-09-27T21:54:19.456Z | user\n\nv5.15.3: per-instance orchestrator token, MCP server-held identity, shell-free git provenance\n\nv5.15.2 | 2026-09-27T20:38:14.229Z | user\n\nv5.15.2: security fixes GHSA-9p2w-prp8-5722, GHSA-hr6v-mfxm-4438, GHSA-4pvg-m42h-c3x2, CodeQL 179/180\n\nv5.15.1 | 2026-07-28T19:04:05.882Z | user\n\nv5.15.1 security patch: fix GHSA-743h-jr5x-mpcr (ClaudeHookBridge deny-pattern bypass via truncation before the security decision) and GHSA-9v4f-j8cv-fhxw (SandboxPolicy blocklist/approval-gate bypass via quote/whitespace matcher mismatch); 3638 tests across 41 suites\n\nv5.15.0 | 2026-07-06T21:15:53.745Z | user\n\nv5.15.0 context signal-over-noise: ContextComposer (token-budgeted, relevance-ranked context assembly with recency decay and scope affinity) plus context_pack and blackboard_search MCP tools (24 tools total); 3603 tests across 40 suites\n\nv5.14.0 | 2026-07-05T20:21:52.136Z | user\n\nv5.14.0 ecosystem expansion: Gemini, OpenAI Responses, and Claude Agent SDK adapters (32 total); Claude Code hooks gating via AuthGuardian; MCP elicitation approvals; A2A server mode; Gemini CLI extension; AGENTS.md; MCP Registry manifest\n\nv5.13.4 | 2026-07-05T19:07:05.171Z | user\n\nSecurity fixes: GHSA-m4jg-6w3q-gm86 (ApprovalInbox auth+CORS) and GHSA-3jf7-33vc-hgf4 (APSAdapter fail-closed signature verification)\n\nv5.13.3 | 2026-06-26T19:55:47.271Z | user\n\nfix: correct display name to Network-AI\n\nv5.13.2 | 2026-06-26T19:48:38.003Z | user\n\nfix: correct ClawHub display name\n\nv5.13.1 | 2026-06-26T19:38:35.863Z | user\n\nfix: reword audit-log privacy note to clear SkillSpector YARA false positive\n\nv5.13.0 | 2026-06-26T17:30:50.718Z | user\n\nv5.13.0: model-interaction lifecycle governance — GovernedModelGateway (refusal->fallback->billing), ModelBudget fallback-credit repricing, RefusalTelemetry, EffortPolicy, per-sub-agent fallback, ThinkingBlockManager, OWASP Agentic Top 10 coverage matrix\n\nv5.12.7 | 2026-06-22T15:55:53.009Z | user\n\nv5.12.7: fix recurring SkillSpector finding — comment.txt draft note no longer bundled (ClawHub honours .clawhubignore); added npm run clawhub:check bundle-hygiene guard; closed data/, .env, *.log and other bundle leaks\n\nv5.12.6 | 2026-06-21T13:30:35.063Z | user\n\nv5.12.6: CodeQL security fixes — resolve #177 (indirect command injection in socket-check.js: spawnSync + semver validation), #176 and #175 (unused imports). New scripts/codeql-check.js monitor + npm run codeql:check. SKILL.md: 3 new SkillSpector by-design findings documented. RELEASING.md: CodeQL gate step added.\n\nv5.12.5 | 2026-06-19T21:39:19.967Z | user\n\nv5.12.5: Supply-chain security hardening. Remove gptSecurity (debugAccess) alerts — replaced String.fromCharCode obfuscation pattern in blackboard-validator with named EVAL_FN constant. Explicit policy gate at shell exec call sites in bin/console.ts. SUPPLY_CHAIN.md sections 5a (shell surface) and 5b (telemetry). New scripts/socket-check.js score monitor. Supply Chain Score: 75 → ~80.\n\nv5.12.4 | 2026-06-19T19:39:15.322Z | user\n\n5.12.4 - SkillSpector findings resolved (.clawignore excludes comment.txt, SKILL.md trigger hardening), Socket.dev scan gap closed (9 missing entries: d.ts decls, ESM adapter mirrors, example/run shellAccess). networkAccess 64, shellAccess 10.\n\nv5.12.3 | 2026-06-18T22:07:33.625Z | user\n\n5.12.3 - Socket.dev supply-chain triage for the dual CJS+ESM build (gptSecurity console pipe-mode entry plus dist/esm networkAccess and shellAccess mirrors) and console pipe-mode approval hardening (fail-closed: approval-required operations are denied unless --auto-approve).\n\nv5.12.2 | 2026-06-18T21:19:27.299Z | user\n\n5.12.2: Security patch - fix 5 CVEs: symlink escape in backup (GHSA-6x2m), restore() path traversal (GHSA-48x2), poisoned manifest pruning (GHSA-2fmp), sandbox path-prefix bypass (GHSA-jvcm), unauthenticated ApprovalInbox (GHSA-mxjx).\n\nv5.12.1 | 2026-06-17T20:36:47.990Z | user\n\n5.12.1: OpenAI Codex MCP integration (.codex/config.toml), PRIVACY.md privacy policy, CI npm publish race fix, and version/doc resync. 3269 tests across 33 suites.\n\nv5.12.0 | 2026-06-17T19:13:15.080Z | user\n\nv5.12.0 - Claude Code plugin support. Network-AI is now installable as a Claude Code plugin (self-hosted marketplace): /plugin marketplace add Jovancoding/Network-AI. Wires the existing network-ai-server MCP server (stdio) into Claude Code so all tools load natively. Version bump 5.11.0 to 5.12.0 across manifests and docs.\n\nv5.11.0 | 2026-06-13T18:36:32.834Z | user\n\nESM dual-build, McpStreamableServer MCP 2025-03-26 Streamable HTTP + resources/prompts, PhasePipeline checkpoint/resume, SemanticMemory file-backed persistence. 3,269 tests across 33 suites.\n\nv5.10.2 | 2026-06-08T21:46:54.470Z | user\n\nv5.10.2: CodeQL #174 CWE-377 root cause fix — eliminate os.tmpdir() taint sources in test-claim-verifier.ts\n\nv5.10.1 | 2026-06-08T21:29:01.619Z | user\n\nv5.10.1: CodeQL #174 CWE-377 fix (AuthGuardian trustConfigPath), SkillSpector FILE_EXPORT in HIGH_RISK_RESOURCES, ensure_data_dir() env-scope fix\n\nv5.10.0 | 2026-06-08T20:39:12.350Z | user\n\nv5.10.0: ClaimVerifier Tier 1 agent honesty — HMAC-signed ExecutionReceipts, UNSUPPORTED_CLAIM/UNDISCLOSED_ACTION violations, trust decay, 3211 tests across 32 suites\n\nv5.9.1 | 2026-06-02T20:35:48.746Z | user\n\nv5.9.1 Critical: GHSA-qw6v-5fcf-5666 shell command injection (CWE-78) fixed via shell-free spawn + metacharacter rejection; permission_denied audit logging; socket.json telemetry-provider declaration.\n\nv5.9.0 | 2026-06-01T18:18:11.248Z | user\n\nSkillSpector Intent-Code Divergence fix: audit_summary now counts explicit permission_denied log events instead of inferring denials; SKILL.md ASI01 description updated\n\nv5.8.9 | 2026-05-30T21:49:28.916Z | user\n\nCodeQL #170/#173 TOCTOU fresh-var taint break, UTF-8 BOM fix for CI, claude-project-prompt hardcoded-3 refs removed\n\nv5.8.8 | 2026-05-30T20:12:42.507Z | user\n\nCodeQL #169-#172 TOCTOU data-flow break (getStatus/O_EXCL), unused writeFileSync import removed, SkillSpector NLP guard in claude-project-prompt.md, test warn scoping fix\n\nv5.8.7 | 2026-05-30T18:02:05.704Z | user\n\nCodeQL #165-#168 fixes (CWE-367 TOCTOU fd-based writes in test helpers, unused var); SkillSpector Intent-Code Divergence resolved (blackboard.py --path comment accurately describes scope).\n\nv5.8.6 | 2026-05-30T17:44:16.966Z | user\n\nLockedBlackboard correctness fixes: stale-lock compare-and-delete, ownership-verified release, atomic snapshot via tmp+rename, WAL/pending reconciliation, priority-aware eviction. 3 new test suites (55 assertions). NFS/durability limits documented.\n\nv5.8.5 | 2026-05-24T14:27:40.437Z | user\n\nSecurity: justification strings truncated to 200 chars before audit log write; justification field stripped from --audit-summary --json recent entries to prevent secondary re-exposure (Ssd3 x3)\n\nv5.8.4 | 2026-05-24T11:19:09.536Z | user\n\nSecurity: blackboard.py --path now validated against project root at runtime; paths outside the project directory are rejected (CWE-22 path traversal fix)\n\nv5.8.3 | 2026-05-24T10:27:05.258Z | user\n\nFix: capabilities.filesystem now lists all files touched (swarm-blackboard.md, pending_changes/); clawhub_python_scripts corrected to actual 6 scripts (validate_token.py, revoke_token.py added; phantom token_manager.py, check_context.py removed)\n\nv5.8.2 | 2026-05-24T09:45:14.335Z | user\n\nSecurity: mask full tokens in --active-grants --json (token_full removed); context_manager inject blocks on prompt-injection warnings (--force override). Doc: SKILL.md capabilities manifest, split bundle_scope/network_calls, claude-tools.json deny conditions, auto-approve + justification PII warnings in SECURITY.md.\n\nv5.8.1 | 2026-05-24T08:59:34.719Z | user\n\nv5.8.1: SkillSpector accuracy fixes — SKILL.md bundle_scope/network_calls, THREAT_MODEL.md hosted-service wording, swarm_guard.py READS/WRITES header\n\nv5.8.0 | 2026-05-23T17:24:26.045Z | user\n\nv5.8.0: doctor/inspect/pause/resume CLI, --why scoring breakdown, --minimal mode, AuthGuardian.scoreRequest, LockedBlackboard.disableWal, THREAT_MODEL, DATA_LOCATIONS, SUPPLY_CHAIN docs, Disclosure SLA\n\nv5.7.2 | 2026-05-23T15:58:35.871Z | user\n\nSecurity fix GHSA-r78r-rwrf-rjwp: McpSseServer fail-closed on empty secret (CWE-306/CWE-862). _isAuthorized() now returns false when no secret configured; listen() rejects if secret is empty; McpSseTransport accepts secret param.\n\nv5.7.1 | 2026-05-19T20:27:44.858Z | user\n\nfix: resolve 4 CodeQL alerts — race condition in compactWAL (CWE-367, js/file-system-race #160) fixed with fd-based atomic truncation; unused imports CircuitOpenError (#161) and existsSync (#162) removed from test-phase11.ts; useless assignment in runAfter call removed (#163); zero functional changes; all 3136 tests pass\n\nv5.7.0 | 2026-05-19T19:31:38.883Z | user\n\nfeat: ITelemetryProvider BYOT abstraction — NullTelemetryProvider (no-op default), CapturingTelemetryProvider (in-memory for tests), createOtelHooks(provider) factory wires beforeExecute/afterExecute/onError spans into AdapterHookManager; plug in any OTel SDK without modifying adapters; zero new runtime dependencies; 16 new tests\n\nv5.6.1 | 2026-05-19T19:20:01.193Z | user\n\nfeat: Circuit Breaker on AdapterRegistry — CircuitBreaker class (CLOSED/OPEN/HALF_OPEN), CircuitOpenError, per-adapter breakers, fallbackChain, getCircuitState(), resetCircuit(); circuit:open/half-open/close events on AdapterEventType; zero new runtime dependencies; 13 new tests\n\nv5.6.0 | 2026-05-19T19:10:08.208Z | user\n\nfeat: LockedBlackboard WAL crash recovery — append-before-write + checkpoint pattern; replayWAL() on startup recovers uncommitted ops; compactWAL() for manual truncation; malformed tail bytes silently skipped; 7 new tests\n\nv5.5.9 | 2026-05-19T19:06:06.469Z | user\n\nfeat: LockedBlackboard TTL background sweep — purgeExpired() on-demand eviction, startSweep(intervalMs) / stopSweep() background timer (unref'd; default 60 s); closes the gap for keys written with TTL but never read again; 8 new tests\n\nv5.5.8 | 2026-05-19T16:38:26.511Z | user\n\nfeat: approvalTimeoutMs fail-closed approval gate timeout; enforcePromotionChain strict promotion enforcement; onCompact archived phase results; CLI --json structured error output; adapter discovery warn; FederatedBudget persist warn; AuthGuardian advisory token JSDoc; FileAccessor error contract JSDoc; LockedBlackboard dirty-read + tie-break + env-freeze JSDoc; streaming auth once-at-start JSDoc; SECURITY.md v5.5.8 entries\n\nv5.5.7 | 2026-05-18T20:46:36.154Z | user\n\nv5.5.7: socket.json — added shellAccess ignore entries for AgentRuntime (lib/agent-runtime.ts, dist/lib/agent-runtime.js) and McpToolConsumer (lib/mcp-tool-consumer.ts, dist/lib/mcp-tool-consumer.js). Socket.dev uses shellAccess (child_process module import) and shellExec (execution calls) as separate alert type IDs; both entries are required. AgentRuntime child_process usage is opt-in sandboxed ShellExecutor under SandboxPolicy; McpToolConsumer spawns caller-configured MCP stdio server subprocesses. Chore-only release — no code changes, all 3,093 tests pass.\n\nv5.5.6 | 2026-05-18T19:56:14.887Z | user\n\nv5.5.6: socket.json — added networkAccess false-positive ignore entries for ContextThrottler (lib/context-throttler.ts, dist/lib/context-throttler.js). Pure in-memory blackboard-pruning utility with zero fetch usage; flagged incorrectly by Socket.dev transitive import-graph analysis. All other scan entries already documented. Chore-only release.\n\nv5.5.5 | 2026-05-17T17:09:38.992Z | user\n\nv5.5.5: SKILL.md — new MAESTRO/OWASP AST security framework assessment section. AST03 (Over-Privileged Skills, High): permission manifest, least-privilege gating, HMAC tokens, SandboxPolicy. AST06 (Weak Isolation, High): zero subprocesses/network, ShellExecutor allowlist, SourceProtectionError, env isolation. AST07 (Update Drift, Medium): exact version pinning, zero transitive deps, signed releases, Socket.dev monitoring. Docs-only release.\n\nv5.5.4 | 2026-05-17T16:20:27.486Z | user\n\nv5.5.4: SKILL.md scan findings table updated — Severity column (was Confidence); ASI03 advisory tokens Medium, ASI06 context Medium; new Low ASI03 local grant state row; new Low ASI06 audit log free text row. SECURITY.md v5.5.3 scan summary added. Docs-only release.\n\nv5.5.3 | 2026-05-17T15:28:33.115Z | user\n\nv5.5.3: CodeQL fixes — useless-assignment-to-local dead stores in transport-agent.ts (#155-#158), unused origGet in test-transport.ts (#154), empty-except comment in check_permission.py (#159). Code quality patch, no functional changes.\n\nv5.5.2 | 2026-05-17T13:59:56.048Z | user\n\nv5.5.2: HMAC-SHA256 grant token integrity — check_permission.py now signs every grant with _sig (stdlib hmac+hashlib, key at data/.signing_key); validate_token.py verifies before accepting; tampered records rejected. Backward-compatible. Zero new deps. Addresses ClawScan ASI03 token-integrity finding.\n\nv5.5.1 | 2026-05-17T13:39:38.471Z | user\n\nv5.5.1: Fix ClawScan ASI03 — revoke_token.py now uses _resolve_data_dir() + --env CLI arg so token revocation and TTL cleanup target the correct data/<env>/ path, consistent with check_permission.py and validate_token.py. All doc version refs bumped. No breaking changes.\n\nv5.5.0 | 2026-05-17T13:10:21.696Z | user\n\nv5.5.0: Basis Transport Tier — TransportAgent state machine (pending→draining→promoting→canary→complete/rolled_back/failed), LandscapeAgent health tracker, AgentPool.setDispatchPause, ENVIRONMENT_PROMOTE AuthGuardian resource profile, 117 new tests (3,093 total across 30 suites)\n\nArchive index:\n\nArchive v5.15.4: 12 files, 66254 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34745b), scripts/check_permission.py (35737b), scripts/context_manager.py (25476b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (1995b), skill.json (10289b), SKILL.md (49801b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nFile v5.15.4:SKILL.md\n\n---\r\nname: network-ai\r\ndescription: \"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle).\"\r\nallowed-tools: Read Bash(python3 scripts/blackboard.py:*) Bash(python3 scripts/check_permission.py:*) Bash(python3 scripts/context_manager.py:*) Bash(python3 scripts/swarm_guard.py:*) Bash(python3 scripts/validate_token.py:*) Bash(python3 scripts/revoke_token.py:*)\r\nmetadata:\r\n  openclaw:\r\n    emoji: \"\\U0001F41D\"\r\n    homepage: https://network-ai.org\r\n    capabilities:\r\n      filesystem: \"read/write — project root `swarm-blackboard.md` (blackboard state), `data/pending_changes/<id>.json` (WAL entries), `data/audit_log.jsonl`, `data/active_grants.json`, `data/.signing_key`, `data/project-context.json`, `data/task_tracking.json`, `data/agent_health.json`, `data/budget_tracking.json`, `data/swarm_budgets.json`, `data/heartbeats.json`, `data/.blackboard.lock`. All paths are local; no data leaves the local filesystem. When NETWORK_AI_ENV is set, data paths are rooted at `data/<env>/` instead of `data/`. The `--path` argument in blackboard.py is validated against the project root at runtime — paths outside the project directory are rejected (CWE-22).\"\r\n      env_vars: \"read — NETWORK_AI_ENV only (environment routing for data paths). No other env vars are read and none are written.\"\r\n      tools: \"Only the six bundled scripts, run via python3 (see allowed-tools), plus reading local state files. No other commands, binaries, or tools are required or invoked.\"\r\n      shell_exec: \"none — the bundled scripts spawn no subprocesses and execute no shell commands.\"\r\n      tcp_port: \"none — the bundled scripts open no sockets and bind no ports.\"\r\n      autonomous_actions: \"none — every script is a single invocation by the calling agent or operator; nothing is scheduled, auto-approved, or run in the background. Permission grants are advisory scores the caller must enforce.\"\r\n    bundle_scope:\r\n      clawhub_python_scripts: \"Python stdlib only — scripts/*.py (blackboard.py, check_permission.py, context_manager.py, swarm_guard.py, validate_token.py, revoke_token.py). Zero network calls, zero subprocesses, zero third-party packages. This is the scope scanned by SkillSpector.\"\r\n      not_in_bundle: \"The separate npm package (network-ai: TypeScript library, CLI, optional MCP server) is not part of this skill. This skill never installs, imports, or starts it.\"\r\n    network_calls:\r\n      python_scripts: none\r\n    inter_agent_comms: \"none — this skill does not implement, invoke, or control inter-agent messaging or sessions_send. All coordination is via local file-based blackboard only.\"\r\n    sessions_send: \"NOT implemented or invoked by this skill. sessions_send is a host-platform built-in entirely outside this skill's control. See data-flow notice below.\"\r\n    sessions_ops: \"platform-provided — outside this skill's control\"\r\n    requires:\r\n      bins:\r\n        - python3\r\n      optional_bins: []\r\n    env: {}\r\n    privacy:\r\n      audit_log:\r\n        path: data/audit_log.jsonl\r\n        scope: local-only\r\n        description: \"Local append-only JSONL file recording operation metadata. No data leaves the machine.\"\r\n        pii_warning: \"Justification strings are truncated to 200 characters before being written to the audit log. Audit summary output (--audit-summary --json) omits justification text from returned entries. Do not include PII, credentials, or secrets in justification fields — the truncated text still persists on disk. Grant tokens are masked to a short prefix in all listing outputs; full tokens appear only at issuance time.\"\r\n      data_directory:\r\n        path: data/\r\n        scope: local-only\r\n        files: [\"audit_log.jsonl\", \"active_grants.json\", \".signing_key\", \"project-context.json\", \"task_tracking.json\", \"agent_health.json\", \"budget_tracking.json\", \"swarm_budgets.json\", \"heartbeats.json\", \".blackboard.lock\", \"pending_changes/<id>.json\"]\r\n        description: \"All persistent state is local-only. No data leaves the local filesystem.\"\r\n      blackboard_file:\r\n        path: swarm-blackboard.md\r\n        scope: local-only\r\n        description: \"Shared coordination state written by scripts/blackboard.py (project root). Contains task results, grant tokens, status flags, and TTL-scoped cache entries. Access should be restricted to the local user running the swarm.\"\r\n---\r\n\r\n# Swarm Orchestrator Skill\r\n\r\n> **Scope:** The bundled Python scripts (`scripts/*.py`) make **no network calls**, use only the Python standard library, and have **zero third-party dependencies**. Tokens are UUID-based (`grant_{uuid4().hex}`) stored in `data/active_grants.json`. Audit logging is plain JSONL (`data/audit_log.jsonl`).\r\n\r\n> **Advisory tokens notice:** Grant tokens issued by `check_permission.py` are **advisory scoring outputs only** — the caller-supplied `--agent` identity is not cryptographically verified. Downstream systems must not treat these tokens as authenticated credentials without adding a separate identity-verification step or human approval gate, especially for PAYMENTS, DATABASE, and FILE_EXPORT resources.\r\n\r\n> **Data-flow notice (host platform — not this skill):** This skill does NOT implement, invoke, or control `sessions_send` or any inter-agent messaging. All bundled Python scripts are local-only tools (budget guard, blackboard, permission scorer, context manager). If your platform has a `sessions_send` built-in, whether and how it is used is entirely the **host platform’s** responsibility and is outside this skill’s scope. If you need to prevent external network calls, disable or reroute delegation in your **platform settings** before installing this skill.\r\n\r\n> **Context file integrity:** `context_manager.py` validates every field of `data/project-context.json` (project, goals, stack, milestones, decisions, banned approaches, agents) for prompt-injection and role-delimiter patterns, size, and nesting. `init` and `update` reject unsafe values before they are written; `inject` blocks on any warning and emits the context as single-line values inside a `<project_context type=\"reference-data\">` block that labels it as data, not instructions. Treat injected context as untrusted reference material.\r\n\r\n> **PII / sensitive-data warning:** The `justification` field in permission requests and the audit log (`data/audit_log.jsonl`) store free-text strings provided by agents. **Do not include PII, secrets, or credentials in justification text.** Consider restricting file permissions on `data/` or running this skill in an isolated workspace.\r\n\r\n## Setup\r\n\r\n**No pip install required.** All 6 scripts use Python standard library only — zero third-party packages.\r\n\r\n> **Note on `requirements.txt`:** The file exists for documentation purposes only — it lists the stdlib modules used and has **no required packages**. All listed deps are commented out as optional. You do not need to run `pip install -r requirements.txt`.\r\n\r\n```bash\r\n# Prerequisite: python3 (any version ≥ 3.8)\r\npython3 --version\r\n\r\n# Run only the six bundled scripts (no other tools are needed):\r\npython3 scripts/blackboard.py list\r\npython3 scripts/swarm_guard.py budget-init --task-id \"task_001\" --budget 10000\r\n\r\n# Optional: for cross-platform file locking on Windows production hosts\r\npip install filelock  # only needed if you see locking issues on Windows\r\n```\r\n\r\nThe `data/` directory is created automatically on first run. No configuration files, environment variables, or credentials are required.\r\n\r\n> **Multi-environment support (v5.4.0):** All five Python scripts now read the `NETWORK_AI_ENV` environment variable at startup and accept a `--env <name>` CLI argument. When set, all data paths are routed to `data/<env>/` instead of the root `data/` directory. Use this to isolate dev, staging, and production state.\r\n>\r\n> ```bash\r\n> # Run against the dev environment\r\n> NETWORK_AI_ENV=dev python3 scripts/blackboard.py list\r\n> python3 scripts/check_permission.py --active-grants --env dev\r\n> ```\r\n\r\nMulti-agent coordination system for complex workflows requiring task delegation, parallel execution, and permission-controlled access to sensitive APIs.\r\n\r\n## 🎯 Orchestrator System Instructions\r\n\r\n**You are the Orchestrator Agent** responsible for decomposing complex tasks, delegating to specialized agents, and synthesizing results. Follow this protocol:\r\n\r\n### Core Responsibilities\r\n\r\n1. **DECOMPOSE** complex prompts into 3 specialized sub-tasks\r\n2. **DELEGATE** using the budget-aware handoff protocol\r\n3. **VERIFY** results on the blackboard before committing\r\n4. **SYNTHESIZE** final output only after all validations pass\r\n\r\n### Task Decomposition Protocol\r\n\r\nWhen you receive a complex request, decompose it into exactly **3 sub-tasks**:\r\n\r\n```\r\n┌─────────────────────────────────────────────────────────────────┐\r\n│                     COMPLEX USER REQUEST                        │\r\n└─────────────────────────────────────────────────────────────────┘\r\n                              │\r\n                              ▼\r\n        ┌─────────────────────┼─────────────────────┐\r\n        │                     │                     │\r\n        ▼                     ▼                     ▼\r\n┌───────────────┐   ┌───────────────┐   ┌───────────────┐\r\n│  SUB-TASK 1   │   │  SUB-TASK 2   │   │  SUB-TASK 3   │\r\n│ data_analyst  │   │ risk_assessor │   │strategy_advisor│\r\n│    (DATA)     │   │   (VERIFY)    │   │  (RECOMMEND)  │\r\n└───────────────┘   └───────────────┘   └───────────────┘\r\n        │                     │                     │\r\n        └─────────────────────┼─────────────────────┘\r\n                              ▼\r\n                    ┌───────────────┐\r\n                    │  SYNTHESIZE   │\r\n                    │ orchestrator  │\r\n                    └───────────────┘\r\n```\r\n\r\n**Decomposition Template:**\r\n```\r\nTASK DECOMPOSITION for: \"{user_request}\"\r\n\r\nSub-Task 1 (DATA): [data_analyst]\r\n  - Objective: Extract/process raw data\r\n  - Output: Structured JSON with metrics\r\n\r\nSub-Task 2 (VERIFY): [risk_assessor]  \r\n  - Objective: Validate data quality & compliance\r\n  - Output: Validation report with confidence score\r\n\r\nSub-Task 3 (RECOMMEND): [strategy_advisor]\r\n  - Objective: Generate actionable insights\r\n  - Output: Recommendations with rationale\r\n```\r\n\r\n### Budget Check Protocol\r\n\r\n**Run the budget interceptor before any task delegation:**\r\n\r\n```bash\r\n# Run this before delegating to any sub-agent\r\npython {baseDir}/scripts/swarm_guard.py intercept-handoff \\\r\n  --task-id \"task_001\" \\\r\n  --from orchestrator \\\r\n  --to data_analyst \\\r\n  --message \"Analyze Q4 revenue data\"\r\n```\r\n\r\n**Decision Logic:**\r\n```\r\nIF result.allowed == true:\r\n    → Budget check passed — proceed with the delegated task\r\n    → Note tokens_spent and remaining_budget\r\nELSE:\r\n    → STOP — budget exceeded or handoff limit reached\r\n    → Report blocked reason to user\r\n    → Consider: reduce scope or abort task\r\n```\r\n\r\n### Pre-Commit Verification Workflow\r\n\r\nBefore returning final results to the user:\r\n\r\n```bash\r\n# Step 1: Check all sub-task results on blackboard\r\npython {baseDir}/scripts/blackboard.py read \"task:001:data_analyst\"\r\npython {baseDir}/scripts/blackboard.py read \"task:001:risk_assessor\"\r\npython {baseDir}/scripts/blackboard.py read \"task:001:strategy_advisor\"\r\n\r\n# Step 2: Validate each result\r\npython {baseDir}/scripts/swarm_guard.py validate-result \\\r\n  --task-id \"task_001\" \\\r\n  --agent data_analyst \\\r\n  --result '{\"status\":\"success\",\"output\":{...},\"confidence\":0.85}'\r\n\r\n# Step 3: Supervisor review (checks all issues)\r\npython {baseDir}/scripts/swarm_guard.py supervisor-review --task-id \"task_001\"\r\n\r\n# Step 4: Only if APPROVED, commit final state\r\npython {baseDir}/scripts/blackboard.py write \"task:001:final\" \\\r\n  '{\"status\":\"SUCCESS\",\"output\":{...}}'\r\n```\r\n\r\n**Verdict Handling:**\r\n| Verdict | Action |\r\n|---------|--------|\r\n| `APPROVED` | Commit and return results to user |\r\n| `WARNING` | Review issues, fix if possible, then commit |\r\n| `BLOCKED` | Do NOT return results. Report failure. |\r\n\r\n---\r\n\r\n## The 3-Layer Memory Model\r\n\r\nEvery agent in the swarm operates with three memory layers, each with a different scope and lifetime:\r\n\r\n| Layer | Name | Lifetime | Managed by |\r\n|-------|------|----------|------------|\r\n| **1** | Agent context | Ephemeral — current task only | Platform (per-session) |\r\n| **2** | Blackboard | TTL-scoped — shared across agents | `scripts/blackboard.py` |\r\n| **3** | Project context | Persistent — survives all sessions | `scripts/context_manager.py` |\r\n\r\n### Layer 1 — Agent Context\r\nEach agent's own context window: the current task instructions, conversation history, and immediate working memory. Managed automatically by the OpenClaw/LLM platform. Nothing to configure.\r\n\r\n### Layer 2 — Blackboard (Shared Coordination State)\r\nA shared markdown file (`swarm-blackboard.md`) for real-time cross-agent coordination: task results, grant tokens, status flags, and TTL-scoped cache entries. Agents read and write via `scripts/blackboard.py`. Entries expire automatically.\r\n\r\n### Layer 3 — Project Context (Persistent Long-Term Memory)\r\nA JSON file (`data/project-context.json`) that holds information every agent should know, regardless of what session or task is running:\r\n- **Goals** — long-term objectives of the project\r\n- **Tech stack** — languages, frameworks, infrastructure\r\n- **Milestones** — completed, in-progress, and planned work\r\n- **Architecture decisions** — design choices and their rationales\r\n- **Banned approaches** — approaches that have been ruled out\r\n\r\n#### Initialising Project Context\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py init \\\r\n  --name \"MyProject\" \\\r\n  --description \"Multi-agent workflow automation\" \\\r\n  --version \"1.0.0\"\r\n```\r\n\r\n#### Injecting Context into an Agent System Prompt\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py inject\r\n```\r\n\r\nCopy the output block to the top of your agent's system prompt. Every agent that receives this block shares the same long-term project awareness.\r\n\r\n#### Recording a Decision\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section decisions \\\r\n  --add '{\"decision\": \"Use atomic blackboard commits\", \"rationale\": \"Prevent race conditions in parallel agents\"}'\r\n```\r\n\r\n#### Updating Milestones\r\n\r\n```bash\r\n# Mark a milestone complete\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section milestones --complete \"Ship v2.0\"\r\n\r\n# Add a planned milestone\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section milestones --add '{\"planned\": \"Integrate vector memory\"}'\r\n```\r\n\r\n#### Setting the Tech Stack\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section stack \\\r\n  --set '{\"language\": \"Python\", \"runtime\": \"Python 3.11\", \"framework\": \"SwarmOrchestrator\"}'\r\n```\r\n\r\n#### Banning an Approach\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section banned \\\r\n  --add \"Direct database writes from agent scripts (use permission gating)\"\r\n```\r\n\r\n---\r\n\r\n## When to Use This Skill\r\n\r\nUse this skill when the task requires **local, file-based** multi-agent coordination within a single trusted workspace. All 6 bundled Python scripts run locally with zero network calls, zero subprocesses, and zero third-party packages.\r\n\r\n### Use for\r\n- **Task Delegation** — decompose complex work into sub-tasks routed to named in-session agents (`data_analyst`, `strategy_advisor`, `risk_assessor`)\r\n- **Parallel Execution** — run multiple local agents simultaneously and synthesize results via the shared blackboard\r\n- **Permission Wall** — score and gate access to abstract resource labels (`DATABASE`, `PAYMENTS`, `EMAIL`, `FILE_EXPORT`) before performing sensitive local operations\r\n- **Shared Blackboard** — coordinate ephemeral task state across in-session agents via a persistent markdown file\r\n\r\n### Do NOT use for\r\n- External API or network service calls — the bundled Python scripts make **zero outbound network calls**\r\n- Production identity or authorization — grant tokens are **advisory scoring outputs only**, not authenticated credentials; do not use as real access control\r\n- Shell command execution or agent spawning — those capabilities require the TypeScript library (`npm install network-ai`) with operator-level `AgentRuntime` + `SandboxPolicy` configuration; they are **never activated by this skill**\r\n- Starting an MCP or HTTP server — the optional MCP server (`bin/mcp-server.ts`) is an npm-package feature that must be explicitly started by the operator; it is **not part of this skill bundle**\r\n- Any task solvable with a single direct tool call — this skill adds coordination overhead and is only appropriate when multiple agents must share state\r\n\r\n## Quick Start\r\n\r\n### 1. Initialize Budget (FIRST!)\r\n\r\n**Always initialize a budget before any multi-agent task:**\r\n\r\n```bash\r\npython {baseDir}/scripts/swarm_guard.py budget-init \\\r\n  --task-id \"task_001\" \\\r\n  --budget 10000 \\\r\n  --description \"Q4 Financial Analysis\"\r\n```\r\n\r\n### 2. Check Budget Before Task Delegation\r\n\r\n\r\nAlways run the budget guard before delegating any task:\r\n\r\n```bash\r\n# 1. Check budget (this skill's Python script)\r\npython {baseDir}/scripts/swarm_guard.py intercept-handoff \\\r\n  --task-id \"task_001\" --from orchestrator --to data_analyst \\\r\n  --message \"Analyze Q4 revenue data\"\r\n\r\n# 2. If result.allowed == true, proceed with delegation via your platform's built-in tools.\r\n# If result.allowed == false, stop — budget exceeded or handoff limit reached.\r\n```\r\n\r\n### 3. Check Permission Before API Access\r\n\r\nBefore accessing SAP or Financial APIs, evaluate the request:\r\n\r\n```bash\r\n# Run the permission checker script\r\npython {baseDir}/scripts/check_permission.py \\\r\n  --agent \"data_analyst\" \\\r\n  --resource \"DATABASE\" \\\r\n  --justification \"Need Q4 invoice data for quarterly report\" \\\r\n  --scope \"read:invoices\"\r\n```\r\n\r\nThe script will output a grant token if approved, or denial reason if rejected.\r\n\r\n### 4. Use the Shared Blackboard\r\n\r\nRead/write coordination state:\r\n\r\n```bash\r\n# Write to blackboard\r\npython {baseDir}/scripts/blackboard.py write \"task:q4_analysis\" '{\"status\": \"in_progress\", \"agent\": \"data_analyst\"}'\r\n\r\n# Read from blackboard  \r\npython {baseDir}/scripts/blackboard.py read \"task:q4_analysis\"\r\n\r\n# List all entries\r\npython {baseDir}/scripts/blackboard.py list\r\n```\r\n\r\n## Agent-to-Agent Handoff Protocol\r\n\r\nWhen delegating tasks between agents, always run the budget guard first.\r\n\r\n### Step 1: Initialize Budget & Check Capacity\r\n```bash\r\n# Initialize budget (if not already done)\r\npython {baseDir}/scripts/swarm_guard.py budget-init --task-id \"task_001\" --budget 10000\r\n\r\n# Check current status\r\npython {baseDir}/scripts/swarm_guard.py budget-check --task-id \"task_001\"\r\n```\r\n\r\n### Step 2: Identify Target Agent\r\n\r\nCommon agent types:\r\n| Agent | Specialty |\r\n|-------|-----------|\r\n| `data_analyst` | Data processing, SQL, analytics |\r\n| `strategy_advisor` | Business strategy, recommendations |\r\n| `risk_assessor` | Risk analysis, compliance checks |\r\n| `orchestrator` | Coordination, task decomposition |\r\n\r\n### Step 3: Run Budget Guard Before Delegation\r\n\r\n```bash\r\n# Check budget AND handoff limits before delegating\r\npython {baseDir}/scripts/swarm_guard.py intercept-handoff \\\r\n  --task-id \"task_001\" \\\r\n  --from orchestrator \\\r\n  --to data_analyst \\\r\n  --message \"Analyze Q4 data\" \\\r\n  --artifact  # Include if expecting output\r\n```\r\n\r\n**If ALLOWED:** Proceed with delegation via your platform's own tools\r\n**If BLOCKED:** Stop — budget exceeded or handoff limit reached; do not delegate\r\n\r\n### Step 4: Construct Handoff Message\r\n\r\nInclude these fields in your delegation:\r\n- **instruction**: Clear task description\r\n- **context**: Relevant background information\r\n- **constraints**: Any limitations or requirements\r\n- **expectedOutput**: What format/content you need back\r\n\r\n### Step 5: Check Results\r\n\r\nAfter delegation completes, read results from the blackboard:\r\n\r\n```bash\r\npython {baseDir}/scripts/blackboard.py read \"task:001:data_analyst\"\r\n```\r\n\r\n## Permission Scoring\r\n\r\n> **Tokens are audit scoring outputs only.** Grant tokens from `check_permission.py` are NOT authenticated credentials and must NOT be used as real access control. They are advisory hints based on a local scoring model. Require a separate authenticated identity and explicit human approval before accessing PAYMENTS, DATABASE, or FILE_EXPORT resources.\r\n\r\n**Always score permission before accessing:**\r\n- `DATABASE` — Internal database / data store (abstract label — no external credentials)\r\n- `PAYMENTS` — Financial/payment data services (abstract label — requires `--confirm-high-risk`)\r\n- `EMAIL` — Email sending capability (abstract label)\r\n- `FILE_EXPORT` — Exporting data to local files (abstract label — requires `--confirm-high-risk`)\r\n\r\n> **Note**: These are abstract local resource type names used by `check_permission.py`. No external API credentials are required or used — all evaluation runs locally.\r\n\r\n### Permission Evaluation Criteria\r\n\r\n| Factor | Weight | Criteria |\r\n|--------|--------|----------|\r\n| Justification | 40% | Must explain specific task need |\r\n| Trust Level | 30% | Agent's established trust score |\r\n| Risk Assessment | 30% | Resource sensitivity + scope breadth |\r\n\r\n### Using the Permission Script\r\n\r\n```bash\r\n# Request permission\r\npython {baseDir}/scripts/check_permission.py \\\r\n  --agent \"your_agent_id\" \\\r\n  --resource \"PAYMENTS\" \\\r\n  --justification \"Generating quarterly financial summary for board presentation\" \\\r\n  --scope \"read:revenue,read:expenses\"\r\n\r\n# Output if approved:\r\n# ✅ GRANTED\r\n# Token: grant_a1b2c3d4e5f6\r\n# Expires: 2026-02-04T15:30:00Z\r\n# Restrictions: read_only, no_pii_fields, audit_required\r\n\r\n# Output if denied:\r\n# ❌ DENIED\r\n# Reason: Justification is insufficient. Please provide specific task context.\r\n```\r\n\r\n### Restriction Types\r\n\r\n| Resource | Default Restrictions |\r\n|----------|---------------------|\r\n| DATABASE | `read_only`, `max_records:100` |\r\n| PAYMENTS | `read_only`, `no_pii_fields`, `audit_required` |\r\n| EMAIL | `rate_limit:10_per_minute` |\r\n| FILE_EXPORT | `anonymize_pii`, `local_only` |\r\n\r\n## Shared Blackboard Pattern\r\n\r\nThe blackboard (`swarm-blackboard.md`) is a markdown file for agent coordination:\r\n\r\n```markdown\r\n# Swarm Blackboard\r\nLast Updated: 2026-02-04T10:30:00Z\r\n\r\n## Knowledge Cache\r\n### task:q4_analysis\r\n{\"status\": \"completed\", \"result\": {...}, \"agent\": \"data_analyst\"}\r\n\r\n### cache:revenue_summary  \r\n{\"q4_total\": 1250000, \"growth\": 0.15}\r\n```\r\n\r\n### Blackboard Operations\r\n\r\n```bash\r\n# Write with TTL (expires after 1 hour)\r\npython {baseDir}/scripts/blackboard.py write \"cache:temp_data\" '{\"value\": 123}' --ttl 3600\r\n\r\n# Read (returns null if expired)\r\npython {baseDir}/scripts/blackboard.py read \"cache:temp_data\"\r\n\r\n# Delete\r\npython {baseDir}/scripts/blackboard.py delete \"cache:temp_data\"\r\n\r\n# Get full snapshot\r\npython {baseDir}/scripts/blackboard.py snapshot\r\n```\r\n\r\n## Parallel Execution\r\n\r\nFor tasks requiring multiple agent perspectives:\r\n\r\n### Strategy 1: Merge (Default)\r\nCombine all agent outputs into unified result.\r\n```\r\nAsk data_analyst AND strategy_advisor to both analyze the dataset.\r\nMerge their insights into a comprehensive report.\r\n```\r\n\r\n### Strategy 2: Vote\r\nUse when you need consensus - pick the result with highest confidence.\r\n\r\n### Strategy 3: First-Success\r\nUse for redundancy - take first successful result.\r\n\r\n### Strategy 4: Chain\r\nSequential processing - output of one feeds into next.\r\n\r\n> **TypeScript engine (v4.15.0):** These strategies map directly to the `FanOutFanIn` module (`lib/fan-out.ts`) which provides `merge`, `vote`, `firstSuccess`, and `consensus` fan-in strategies with concurrency control. For multi-phase workflows with approval gates, see `PhasePipeline` (`lib/phase-pipeline.ts`). For result scoring and threshold filtering, see `ConfidenceFilter` (`lib/confidence-filter.ts`). Matcher-based hooks (`lib/adapter-hooks.ts`) can target specific agents or tools via glob patterns. For sandboxed agent execution, see `AgentRuntime` (`lib/agent-runtime.ts`). For large-scale agent coordination, see `StrategyAgent` (`lib/strategy-agent.ts`).\r\n\r\n### Example Parallel Workflow\r\n\r\n```\r\n# For each delegation below, first run the budget guard:\r\n#   python {baseDir}/scripts/swarm_guard.py intercept-handoff --task-id \"task_001\" --from orchestrator --to <agent> --message \"<task>\"\r\n# If result.allowed == true, delegate via your platform's own tools.\r\n1. Delegate to data_analyst: \"Extract key metrics from Q4 data\"\r\n2. Delegate to risk_assessor: \"Identify compliance risks in Q4 data\"\r\n3. Delegate to strategy_advisor: \"Recommend actions based on Q4 trends\"\r\n4. Wait for all results and read them from the blackboard\r\n5. Synthesize: Combine metrics + risks + recommendations into executive summary\r\n```\r\n\r\n## Security Considerations\r\n\r\n1. **Never bypass the permission wall** for gated resources\r\n2. **Always include justification** explaining the business need\r\n3. **Use minimal scope** - request only what you need\r\n4. **Check token expiry** - tokens are valid for 5 minutes\r\n5. **Validate tokens** - use `python {baseDir}/scripts/validate_token.py TOKEN` to verify grant tokens before use\r\n6. **Audit trail** - all permission requests are logged\r\n\r\n## 📝 Audit Trail Requirements (MANDATORY)\r\n\r\n**Every sensitive action MUST be logged to `data/audit_log.jsonl`** to maintain compliance and enable forensic analysis.\r\n\r\n> **Privacy note:** Audit log entries contain agent-provided free-text fields (justifications, descriptions). These are stored locally in `data/audit_log.jsonl` and kept on this machine only by this skill — no audit data leaves the local filesystem. However, **do not put PII, passwords, or API keys in justification strings** — they persist on disk. Consider periodic log rotation and restricting OS file permissions on the `data/` directory.\r\n\r\n### What Gets Logged Automatically\r\n\r\nThe scripts automatically log these events:\r\n- `permission_granted` - When access is approved\r\n- `permission_denied` - When access is rejected\r\n- `permission_revoked` - When a token is manually revoked\r\n- `ttl_cleanup` - When expired tokens are purged\r\n- `result_validated` / `result_rejected` - Swarm Guard validations\r\n\r\n### Log Entry Format\r\n\r\n```json\r\n{\r\n  \"timestamp\": \"2026-02-04T10:30:00+00:00\",\r\n  \"action\": \"permission_granted\",\r\n  \"details\": {\r\n    \"agent_id\": \"data_analyst\",\r\n    \"resource_type\": \"DATABASE\",\r\n    \"justification\": \"Q4 revenue analysis\",\r\n    \"token\": \"grant_abc123...\",\r\n    \"restrictions\": [\"read_only\", \"max_records:100\"]\r\n  }\r\n}\r\n```\r\n\r\n### Reading the Audit Log\r\n\r\n```bash\r\n# View recent entries (last 10)\r\ntail -10 {baseDir}/data/audit_log.jsonl\r\n\r\n# Search for specific agent\r\ngrep \"data_analyst\" {baseDir}/data/audit_log.jsonl\r\n\r\n# Count actions by type\r\ncat {baseDir}/data/audit_log.jsonl | jq -r '.action' | sort | uniq -c\r\n```\r\n\r\n### Custom Audit Entries\r\n\r\nIf you perform a sensitive action manually, log it:\r\n\r\n```python\r\nimport json\r\nfrom datetime import datetime, timezone\r\nfrom pathlib import Path\r\n\r\naudit_file = Path(\"{baseDir}/data/audit_log.jsonl\")\r\nentry = {\r\n    \"timestamp\": datetime.now(timezone.utc).isoformat(),\r\n    \"action\": \"manual_data_access\",\r\n    \"details\": {\r\n        \"agent\": \"orchestrator\",\r\n        \"description\": \"Direct database query for debugging\",\r\n        \"justification\": \"Investigating data sync issue #1234\"\r\n    }\r\n}\r\nwith open(audit_file, \"a\") as f:\r\n    f.write(json.dumps(entry) + \"\\n\")\r\n```\r\n\r\n## 🧹 TTL Enforcement (Token Lifecycle)\r\n\r\nExpired permission tokens are automatically tracked. Run periodic cleanup:\r\n\r\n```bash\r\n# Validate a grant token\r\npython {baseDir}/scripts/validate_token.py grant_a1b2c3d4e5f6\r\n\r\n# List expired tokens (without removing)\r\npython {baseDir}/scripts/revoke_token.py --list-expired\r\n\r\n# Remove all expired tokens\r\npython {baseDir}/scripts/revoke_token.py --cleanup\r\n\r\n# Output:\r\n# 🧹 TTL Cleanup Complete\r\n#    Removed: 3 expired token(s)\r\n#    Remaining active grants: 2\r\n```\r\n\r\n**Best Practice**: Run `--cleanup` at the start of each multi-agent task to ensure a clean permission state.\r\n\r\n## ⚠️ Swarm Guard: Preventing Common Failures\r\n\r\nTwo critical issues can derail multi-agent swarms:\r\n\r\n### 1. The Handoff Tax 💸\r\n\r\n**Problem**: Agents waste tokens \"talking about\" work instead of doing it.\r\n\r\n**Prevention**:\r\n```bash\r\n# Before each handoff, check your budget:\r\npython {baseDir}/scripts/swarm_guard.py check-handoff --task-id \"task_001\"\r\n\r\n# Output:\r\n# 🟢 Task: task_001\r\n#    Handoffs: 1/3\r\n#    Remaining: 2\r\n#    Action Ratio: 100%\r\n```\r\n\r\n**Rules enforced**:\r\n- **Max 3 handoffs per task** - After 3, produce output or abort\r\n- **Max 500 chars per message** - Be concise: instruction + constraints + expected output\r\n- **60% action ratio** - At least 60% of handoffs must produce artifacts\r\n- **2-minute planning limit** - No output after 2min = timeout\r\n\r\n```bash\r\n# Record a handoff (with tax checking):\r\npython {baseDir}/scripts/swarm_guard.py record-handoff \\\r\n  --task-id \"task_001\" \\\r\n  --from orchestrator \\\r\n  --to data_analyst \\\r\n  --message \"Analyze sales data, output JSON summary\" \\\r\n  --artifact  # Include if this handoff produces output\r\n```\r\n\r\n### 2. Silent Failure Detection 👻\r\n\r\n**Problem**: One agent fails silently, others keep working on bad data.\r\n\r\n**Prevention - Heartbeats**:\r\n```bash\r\n# Agents must send heartbeats while working:\r\npython {baseDir}/scripts/swarm_guard.py heartbeat --agent data_analyst --task-id \"task_001\"\r\n\r\n# Check if an agent is healthy:\r\npython {baseDir}/scripts/swarm_guard.py health-check --agent data_analyst\r\n\r\n# Output if healthy:\r\n# 💚 Agent 'data_analyst' is HEALTHY\r\n#    Last seen: 15s ago\r\n\r\n# Output if failed:\r\n# 💔 Agent 'data_analyst' is UNHEALTHY\r\n#    Reason: STALE_HEARTBEAT\r\n#    → Do NOT use any pending results from this agent.\r\n```\r\n\r\n**Prevention - Result Validation**:\r\n```bash\r\n# Before using another agent's result, validate it:\r\npython {baseDir}/scripts/swarm_guard.py validate-result \\\r\n  --task-id \"task_001\" \\\r\n  --agent data_analyst \\\r\n  --result '{\"status\": \"success\", \"output\": {\"revenue\": 125000}, \"confidence\": 0.85}'\r\n\r\n# Output:\r\n# ✅ RESULT VALID\r\n#    → APPROVED - Result can be used by other agents\r\n```\r\n\r\n**Required result fields**: `status`, `output`, `confidence`\r\n\r\n### Supervisor Review\r\n\r\nBefore finalizing any task, run supervisor review:\r\n```bash\r\npython {baseDir}/scripts/swarm_guard.py supervisor-review --task-id \"task_001\"\r\n\r\n# Output:\r\n# ✅ SUPERVISOR VERDICT: APPROVED\r\n#    Task: task_001\r\n#    Age: 1.5 minutes\r\n#    Handoffs: 2\r\n#    Artifacts: 2\r\n```\r\n\r\n**Verdicts**:\r\n- `APPROVED` - Task healthy, results usable\r\n- `WARNING` - Issues detected, review recommended\r\n- `BLOCKED` - Critical failures, do NOT use results\r\n\r\n## Troubleshooting\r\n\r\n### Permission Denied\r\n- Provide more specific justification (mention task, purpose, expected outcome)\r\n- Narrow the requested scope\r\n- Check agent trust level\r\n\r\n### Blackboard Read Returns Null\r\n- Entry may have expired (check TTL)\r\n- Key may be misspelled\r\n- Entry was never written\r\n\r\n### Session Not Found\r\n- Run `sessions_list` (OpenClaw platform built-in) to see available sessions\r\n- Session may need to be started first\r\n\r\n## Security Framework Assessment (MAESTRO / OWASP AST)\r\n\r\nThe following findings are drawn from the **MAESTRO Agent Security Threat** framework (OWASP LLM / ASVS mapping). They are addressed by existing architectural controls in Network-AI — not open vulnerabilities.\r\n\r\n> **Engine-level OWASP Agentic AI Top 10 (2026):** the TypeScript orchestration engine maps all 10 OWASP Agentic risk categories (ASI-01 … ASI-10) to deterministic controls, verifiable programmatically via `verifyOwaspCoverage()` (`lib/owasp-compliance.ts`, exported from `network-ai`). See the coverage table in the README. The MAESTRO/AST findings below scope the bundled Python skill scripts.\r\n\r\n### AST03 — Over-Privileged Skills · Severity: High\r\n\r\n> *Skills are granted broader permissions than their stated function requires, creating excessive blast radius if prompt-injected.*\r\n\r\n| Control | How Network-AI addresses it |\r\n|---|---|\r\n| **Permission manifest** | `metadata.openclaw` in SKILL.md frontmatter explicitly declares `capabilities` (filesystem paths, `NETWORK_AI_ENV` only, no shell, no ports, no autonomous actions), `bundle_scope`, `network_calls: none`, and `requires.bins: [python3]`; `allowed-tools` limits the tool scope to the six bundled scripts plus `Read` — no API credentials, no external services |\r\n| **Least-privilege resource gating** | `check_permission.py` uses a weighted scoring model (justification 40 %, trust 30 %, risk 30 %); PAYMENTS, DATABASE, and FILE_EXPORT (`HIGH_RISK_RESOURCES`) require `--confirm-high-risk` acknowledgment before any token is issued; `--scope` limits every grant to minimum required access |\r\n| **Abstract resource labels only** | PAYMENTS, DATABASE, EMAIL, FILE_EXPORT are local scoring labels — no external credentials exist in the skill; there is nothing to leak to an external service |\r\n| **HMAC-signed grant tokens** | Since v5.5.2, every grant record carries `_sig` (HMAC-SHA256 over canonical fields); `validate_token.py` rejects tampered records — privilege escalation via forged grants is detected at validation time |\r\n| **Advisory-only tokens** | All grant tokens are explicitly marked `advisory: true`; downstream systems must add a separate authenticated identity check and human approval before any real sensitive action — documented in frontmatter and throughout SKILL.md |\r\n\r\n### AST06 — Weak Isolation · Severity: High\r\n\r\n> *Skills execute in the host agent's security context with full filesystem, shell, and network access.*\r\n\r\n| Control | How Network-AI addresses it |\r\n|---|---|\r\n| **Zero network calls, no shell** | All bundled Python scripts use Python stdlib only, spawn no subprocesses, execute no shell commands, open no sockets, and make no network calls — declared in `metadata.openclaw.capabilities`, `network_calls`, and `bundle_scope`. No server, runtime, or package is installed or started by this skill. |\r\n| **Environment isolation** | `NETWORK_AI_ENV` / `--env` routes all state to `data/<env>/`; dev, staging, and production state are fully separated; live state (`audit_log.jsonl`, `active_grants.json`) never promotes across environments |\r\n| **Human-driven execution** | Every script is a single, explicit invocation; nothing is scheduled, run in the background, or auto-approved. Permission grants are advisory scores that the caller (or a human) must decide to enforce. |\r\n| **No hot-reload surface** | Bundled scripts do not implement or respond to a SkillsWatcher; skill updates require explicit `clawhub install` — no mid-session reload is possible |\r\n\r\n> Sandboxed shell execution (`AgentRuntime`, `SandboxPolicy`, `ApprovalGate` — manual approval by default) lives only in the separate TypeScript npm package and is not part of this skill bundle.\r\n\r\n### AST07 — Update Drift · Severity: Medium\r\n\r\n> *Installed skills drift out of sync — either unpatched (leaving known CVEs open) or blindly auto-updated (potentially receiving malicious patches).*\r\n\r\n| Control | How Network-AI addresses it |\r\n|---|---|\r\n| **Exact version pinning** | npm `package.json` uses exact `\"version\": \"5.15.4\"` — no semver range specifiers; `clawhub install network-ai` pins to a specific published version |\r\n| **Zero transitive dependency drift** | All bundled Python scripts use Python stdlib only — `pip install` is never required; there are no third-party packages to drift, be compromised upstream, or introduce CVEs |\r\n| **Signed, tagged releases** | Every release is committed with a signed Git tag (`v5.7.x`); commit hash is verifiable against CHANGELOG.md; GitHub releases link tag → diff → changelog entry |\r\n| **Supply chain monitoring** | npm package continuously scored by Socket.dev (score A); any new dependency or permission change triggers an alert |\r\n| **No auto-update mechanism** | Updates require explicit user action (`clawhub install`, `npm install network-ai@latest`); there is no background updater or hot-reload path |\r\n| **CHANGELOG.md audit trail** | Every change — including docs-only patches — is tracked with version, date, and rationale; operators can diff any two versions to assess update risk before applying |\r\n\r\n## Security Scan Findings (ClawHub)\r\n\r\nThis skill is scanned on every publish. The following Notes are flagged by design and will recur on every scan. They are acknowledged and mitigated with documented controls — they are not bugs or vulnerabilities.\r\n\r\n| Finding | Severity | Why it recurs | Documented control |\r\n|---------|----------|---------------|--------------------|  \r\n| **ASI01** Agent Goal Hijack | High | Orchestrator skill performs multi-step decomposition and delegation by design | Use this skill only when multi-agent orchestration is desired; for simple requests the scope guard responds directly without decomposing |\r\n| **ASI03** Identity and Privilege Abuse (advisory tokens) | Medium | Grant tokens are advisory scoring outputs only — caller-supplied `--agent` identity is not cryptographically verified; skill explicitly warns tokens must not be used as real authorization for PAYMENTS, DATABASE, or FILE_EXPORT | Tokens are explicitly marked advisory in SKILL.md and source; require separate platform auth and human approval before any real database, payment, email, or export action |\r\n| **ASI03** Identity and Privilege Abuse (local grant state) | Low | The permission system creates persistent local state (`active_grants.json`, `audit_log.jsonl`, `.signing_key`) — security-relevant files that are purpose-aligned but accessible to anyone with `data/` access | Keep the skill directory private; back up or delete local grant state when no longer needed; do not share `data/` casually; restrict OS-level permissions on `data/` on shared machines |\r\n| **ASI03** Identity and Privilege Abuse (token integrity) | ~~High~~ Resolved | Token payload had no integrity protection — active_grants.json could be edited to forge elevated grants | Fixed in v5.5.2 — `check_permission.py` HMAC-SHA256 signs each grant (`_sig` field, stdlib `hmac`+`hashlib`, key at `data/.signing_key`); `validate_token.py` verifies before accepting; tampered tokens rejected with `\"Token signature invalid\"` |\r\n| **ASI03** Identity and Privilege Abuse (env-scoped paths) | ~~High~~ Resolved | `revoke_token.py` resolved `GRANTS_FILE`/`AUDIT_LOG` at module load from root `data/`, ignoring `NETWORK_AI_ENV` — revoking tokens in one env could silently miss env-specific grant files | Fixed in v5.5.1 — `_resolve_data_dir()` added, `--env` CLI argument introduced, paths re-resolved in `main()` before file I/O; consistent with `check_permission.py` and `validate_token.py` |\r\n| **ASI06** Memory and Context Poisoning (project context) | Medium | Persistent `data/project-context.json` is injected into every agent session by design — inaccurate or malicious context could steer future agent behavior | `_validate_context()` scans every field and key (injection and role-delimiter patterns, size, nesting, types) and `inject` blocks on any warning; since v5.15.4 `init`/`update` also reject unsafe values before writing, and injected values are flattened to single lines inside a `<project_context type=\"reference-data\">` block. Do not store secrets; review `data/project-context.json` before use; clear `data/` between projects |\r\n| **ASI06** Memory and Context Poisoning (audit log free text) | Low | `justification` field in permission requests and `data/audit_log.jsonl` store agent-provided free-text strings locally — PII or secrets placed there will persist on disk | Do not include PII, secrets, or credentials in justification text; restrict access to `data/` on shared machines; rotate/delete `audit_log.jsonl` when no longer needed |\r\n| **ASI07** Insecure Inter-Agent Communication | High | Blackboard is local file-based; origin/identity depends on local file access, not authenticated messaging | Run in a trusted workspace; restrict file permissions on `data/`; review blackboard changes before relying on them for important decisions |\r\n| **ASI08** Cascading Failures | ~~High~~ Resolved | `os` was referenced before import in `swarm_guard.py` — fixed in v5.4.4; `import os` now present | Fixed — `swarm_guard.py` now imports `os` at module level; budget/health guard starts correctly |\r\n| **SkillSpector** Description-Behavior Mismatch (`McpStreamableServer` network exposure) | ~~Medium~~ Resolved | The trigger was `comment.txt` — an in-progress draft GitHub-issue note describing the optional `McpStreamableServer` HTTP/MCP server (a native server binding a TCP port) — being bundled into the published ClawHub skill. Its prose contradicted the bundle's 'zero network calls' / local-only positioning. | Fixed in v5.12.7 — `comment.txt` added to `.clawhubignore` (the ignore file ClawHub actually honours; the earlier `.clawignore` entry was never read by the CLI). New `scripts/clawhub-check.js` guard (`npm run clawhub:check`) fails the release if any non-allowlisted file would be bundled, so draft notes can no longer leak. The Python skill bundle itself still makes zero network calls; `McpStreamableServer` is in the optional npm package only and is never auto-started. |\r\n| **SkillSpector** Context-Inappropriate Capability (MCP control surface breadth) | ~~Medium~~ Resolved | Same root cause — `comment.txt` enumerated the HTTP MCP server's 22 privileged tools (blackboard write, token ops, agent_spawn, fsm_transition, audit_query), which the scanner read as a broad remote-control surface inside a local skill. | Fixed in v5.12.7 — `comment.txt` excluded from the bundle (see row above) and enforced by the `clawhub:check` guard. The HTTP MCP server is not part of this skill; it lives in the separate npm package, requires a non-empty bearer secret before `listen()` binds (fail-closed), binds `127.0.0.1` by default, and is documented in `SUPPLY_CHAIN.md §5a`. |\r\n| **SkillSpector** Context-Inappropriate Capability (`_load_signing_key()` token minting) | Medium, 92% | `scripts/check_permission.py` mints, HMAC-signs, persists, and lists grant tokens — a de facto local authorization artifact that downstream components may be tempted to treat as real credentials. | Token advisory-only warnings appear in source, SKILL.md, and SECURITY.md. Every grant response includes the advisory notice. Tokens are labeled `grant_{uuid4().hex}`; the HMAC signature only proves local origin, not external identity. Platform-level authentication is required before any destructive action (PAYMENTS, DATABASE, FILE_EXPORT). See ASI03 rows above. |\r\n| **SkillSpector** Intent-Code Divergence (`FILE_EXPORT` missing from `HIGH_RISK_RESOURCES`) | ~~Low~~ Resolved | Comment stated `FILE_EXPORT` requires `--confirm-high-risk` but `HIGH_RISK_RESOURCES` only contained `PAYMENTS` and `DATABASE`; file export requests could receive advisory grants without the extra acknowledgment | Fixed in v5.11.0 — `FILE_EXPORT` added to `HIGH_RISK_RESOURCES` in `check_permission.py`; now requires `--confirm-high-risk` consistent with the documented policy |\r\n| **SkillSpector** YARA `agent_skill_mcp_tool_poisoning_metadata` (MCP/tool metadata poisoning indicators) | ~~High~~ Resolved | SKILL.md frontmatter `description:` retained an older phrasing that referenced the optional TypeScript network server alongside \"zero network calls\" — a combination the YARA rule flags. A privacy-note sentence also used wording adjacent to file/data references that the exfiltration sub-rule flagged. | Fixed in v5.13.1 — frontmatter `description:` confirmed clean (server reference removed; TypeScript engine noted as parent repository only). Privacy note reworded to remove the flagged phrase. VirusTotal 64/64 clean throughout. |\r\n| **SkillSpector** Description-Behavior Mismatch (`ensure_data_dir()` ignoring env scope) | ~~Medium~~ Resolved | `ensure_data_dir()` always created the fixed top-level `data/` directory instead of the active env-specific path, breaking environment isolation when `NETWORK_AI_ENV` is set | Fixed in v5.11.0 — `ensure_data_dir()` now delegates to `_resolve_data_dir()` so audit log and grant files are always written to the correct env-scoped directory |\r\n| **A.I.G T02** Agent Memory Poisoning (`context_manager.py`) | ~~High~~ Resolved | `update`/`init` stored values without validation, and `_validate_context()` only scanned goals, decisions, and banned approaches, so `project`, `stack`, `milestones`, and `agents` could carry injected instructions into every session | Fixed in v5.15.4: write-time validation with type checks, recursive scanning of every field and key, role-delimiter patterns, size/nesting/count caps, and delimited single-line `inject` output (see ASI06 row) |\r\n| **SkillSpector** Tp4 Description-Behavior Mismatch (`check_permission.py`) | ~~High~~ Resolved | Docstring said the script \"evaluates permission requests for accessing sensitive resources\", which reads as real access to databases or payments | Fixed in v5.15.4: docstring and `--help` state it is an advisory local scorer over abstract labels that holds no credentials and touches no real resource |\r\n| **SkillSpector** Intent-Code Divergence (`--confirm-high-risk` help text) | ~~Low~~ Resolved | Help text listed only PAYMENTS and DATABASE, while `HIGH_RISK_RESOURCES` also contains FILE_EXPORT | Fixed in v5.15.4: help text, comments, and the AST03 table list PAYMENTS, DATABASE, and FILE_EXPORT |\r\n| **SkillSpector** Undeclared Tool Scope / Unrestricted Tool Access | ~~Medium~~ Resolved | No `allowed-tools` declaration, and Setup said \"run any script directly\" | Fixed in v5.15.4: `allowed-tools` limits the scope to the six bundled scripts plus `Read`; Setup text scoped to the bundled scripts |\r\n| **SkillSpector** Autonomous Decision Making | ~~Medium~~ Resolved | Frontmatter declared npm-only `shell_exec` and `auto_approve` runtime capabilities that are not in this bundle | Fixed in v5.15.4: capabilities declare `shell_exec: none`, `tcp_port: none`, `autonomous_actions: none`; npm-only runtime details removed from the bundle manifest |\r\n| **SkillSpector** Rp1 Unpinned package execution (`npx network-ai-server`) | ~~Medium~~ Resolved | SKILL.md showed unpinned `npx` commands for the separate npm server | Fixed in v5.15.4: `npx` references removed; this skill never installs or runs an npm package |\r\n| **SkillSpector** Ae1 Referenced artifact not completely inspected | Info | The scanner inspects a bounded portion of each referenced script, so it cannot confirm the behavior of the uninspected remainder | Each script's full I/O surface is declared in its header comment and in the Bundled Script Inventory below; all scripts are Python stdlib only and can be reviewed in full in the public repository |\r\n\r\n## Bundled Script Inventory\r\n\r\nComplete I/O surface of every file in this skill. No script makes network calls, opens sockets, spawns subprocesses, or reads environment variables other than `NETWORK_AI_ENV`. Paths below are under `data/` (or `data/<env>/` when `NETWORK_AI_ENV` / `--env` is set).\r\n\r\n| Script | Purpose | Reads | Writes |\r\n|---|---|---|---|\r\n| `scripts/blackboard.py` | Shared blackboard with propose / validate / commit | `swarm-blackboard.md`, `pending_changes/*.json`, `.blackboard.lock` | `swarm-blackboard.md`, `pending_changes/*.json`, `.blackboard.lock` |\r\n| `scripts/check_permission.py` | Advisory permission scoring over abstract labels | `active_grants.json`, `audit_log.jsonl`, `.signing_key` | `active_grants.json`, `audit_log.jsonl`, `.signing_key` (first run) |\r\n| `scripts/validate_token.py` | Verify an advisory grant's HMAC signature and expiry | `active_grants.json`, `.signing_key` | none |\r\n| `scripts/revoke_token.py` | Revoke advisory grants, remove expired ones | `active_grants.json`, `audit_log.jsonl` | `active_grants.json`, `audit_log.jsonl` |\r\n| `scripts/context_manager.py` | Validated project context (Layer-3 memory) | `project-context.json` | `project-context.json`, `audit_log.jsonl` |\r\n| `scripts/swarm_guard.py` | Budget, handoff, and health guards | `swarm_budgets.json`, `heartbeats.json`, `task_tracking.json`, `agent_health.json`, `budget_tracking.json`, `audit_log.jsonl` | same six files |\r\n\r\n## References\r\n\r\nThis skill is part of the larger [Network-AI](https://github.com/Jovancoding/Network-AI) project. See the repository for full documentation on the permission system, blackboard schema, and trust-level calculations.\n\nFile v5.15.4:_meta.json\n\n{\n  \"ownerId\": \"kn75j1xcebk74re38bv714kh1h81804p\",\n  \"slug\": \"network-ai\",\n  \"version\": \"5.15.4\",\n  \"publishedAt\": 1790698911387\n}\n\nFile v5.15.4:skill-card.md\n\n## Description:\n\nHelps agents coordinate multi-agent work through a local shared blackboard, permission checks, budget guards, and persistent project context.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jovancoding](https://clawhub.ai/user/jovancoding)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to coordinate tasks in a shared workspace, manage advisory permission grants and token budgets, and retain local project context.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Local coordination and audit files may expose task data or grant tokens to other workspace users.\n\nMitigation: Restrict access to the skill's data directory and shared blackboard to trusted users.\n\nRisk: Permission justifications and project context can persist sensitive information locally.\n\nMitigation: Do not include secrets or personal information in justifications or project context.\n\nRisk: Advisory grant tokens do not authenticate access to sensitive external services.\n\nMitigation: Use independent authentication and authorization for databases, payments, email, and exports.\n\n## Reference(s):\n\n- [Network-AI homepage](https://network-ai.org)\n- [Network-AI on ClawHub](https://clawhub.ai/jovancoding/skills/network-ai)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, JSON, Shell commands, Guidance]\n\n**Output Format:** [Text and Markdown guidance with Python command examples and structured local state]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Maintains local coordination, grant, audit, and project-context files.]\n\n## Skill Version(s):\n\n5.15.4 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v5.15.4:swarm-blackboard.md\n\n# Swarm Blackboard\nLast Updated: 2026-09-29T15:46:56.169Z\n\n## Active Tasks\n| TaskID | Agent | Status | Started | Description |\n|--------|-------|--------|---------|-------------|\n\n## Knowledge Cache\n### code:auth:implementation\n{\n  \"key\": \"code:auth:implementation\",\n  \"value\": {\n    \"files\": [\n      \"src/auth/login.ts\",\n      \"src/auth/middleware.ts\"\n    ],\n    \"linesChanged\": 245,\n    \"status\": \"complete\"\n  },\n  \"sourceAgent\": \"code_writer\",\n  \"timestamp\": \"2026-09-29T15:46:56.162Z\",\n  \"ttl\": null\n}\n\n### review:auth:feedback\n{\n  \"key\": \"review:auth:feedback\",\n  \"value\": {\n    \"approved\": true,\n    \"comments\": [\n      \"Good separation of concerns\",\n      \"Add input validation\"\n    ],\n    \"reviewer\": \"code_reviewer\"\n  },\n  \"sourceAgent\": \"code_reviewer\",\n  \"timestamp\": \"2026-09-29T15:46:56.166Z\",\n  \"ttl\": null\n}\n\n### test:auth:results\n{\n  \"key\": \"test:auth:results\",\n  \"value\": {\n    \"passed\": 42,\n    \"failed\": 0,\n    \"skipped\": 2,\n    \"coverage\": 87.3,\n    \"duration\": 3200\n  },\n  \"sourceAgent\": \"test_runner\",\n  \"timestamp\": \"2026-09-29T15:46:56.167Z\",\n  \"ttl\": null\n}\n\n### infra:k8s:config\n{\n  \"key\": \"infra:k8s:config\",\n  \"value\": {\n    \"replicas\": 3\n  },\n  \"sourceAgent\": \"devops_agent\",\n  \"timestamp\": \"2026-09-29T15:46:56.169Z\",\n  \"ttl\": null\n}\n\n## Coordination Signals\n## Execution History\n\nFile v5.15.4:skill.json\n\n{\r\n  \"name\": \"SwarmOrchestrator\",\r\n  \"version\": \"5.15.4\",\r\n  \"description\": \"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Workflow delegations via the host platform's sessions_send may invoke external model APIs.\",\r\n  \"author\": \"Network-AI Community\",\r\n  \"homepage\": \"https://network-ai.org\",\r\n  \"repository\": \"https://github.com/Jovancoding/Network-AI\",  \"source\": \"https://github.com/Jovancoding/Network-AI\",  \"license\": \"MIT\",\r\n  \"tags\": [\"multi-agent\", \"swarm\", \"orchestration\", \"governance\", \"audit\", \"permissions\", \"security\", \"blackboard\", \"budget\", \"local-only\"],\r\n  \"runtime\": \"python\",\r\n  \"entrypoint\": \"scripts/swarm_guard.py\",\r\n  \"gateway\": \"local\",\r\n  \"install\": {\r\n    \"description\": \"No install step required. All Python scripts use standard library only (zero third-party packages). Simply ensure python3 is available and run scripts directly from the scripts/ directory.\",\r\n    \"python\": {\r\n      \"requirements\": \"requirements.txt\",\r\n      \"requirements_note\": \"requirements.txt contains zero required packages. All scripts use Python stdlib only.\",\r\n      \"install_command\": \"# No install needed\",\r\n      \"scripts\": [\"scripts/blackboard.py\", \"scripts/swarm_guard.py\", \"scripts/check_permission.py\", \"scripts/validate_token.py\", \"scripts/revoke_token.py\", \"scripts/context_manager.py\"],\r\n      \"note\": \"All scripts run locally only. No external network calls. No third-party dependencies.\"\r\n    }\r\n  },\r\n  \"capabilities\": {\r\n    \"delegate_task\": {\r\n      \"description\": \"Delegate a task to a specialized sub-agent within the swarm\",\r\n      \"parameters\": {\r\n        \"targetAgent\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"description\": \"The identifier of the target agent to receive the task\"\r\n        },\r\n        \"taskPayload\": {\r\n          \"type\": \"object\",\r\n          \"required\": true,\r\n          \"description\": \"The task context, instructions, and any required data\"\r\n        },\r\n        \"priority\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"low\", \"normal\", \"high\", \"critical\"],\r\n          \"default\": \"normal\",\r\n          \"description\": \"Task priority level for queue ordering\"\r\n        },\r\n        \"timeout\": {\r\n          \"type\": \"number\",\r\n          \"default\": 30000,\r\n          \"description\": \"Maximum execution time in milliseconds\"\r\n        },\r\n        \"requiresAuth\": {\r\n          \"type\": \"boolean\",\r\n          \"default\": false,\r\n          \"description\": \"Whether this task requires a permission grant (via check_permission.py)\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"taskId\": { \"type\": \"string\" },\r\n          \"status\": { \"type\": \"string\" },\r\n          \"result\": { \"type\": \"any\" },\r\n          \"agentTrace\": { \"type\": \"array\" }\r\n        }\r\n      }\r\n    },\r\n    \"query_swarm_state\": {\r\n      \"description\": \"Query the current state of the agent swarm, including active tasks, blackboard contents, and agent availability\",\r\n      \"parameters\": {\r\n        \"scope\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"all\", \"agents\", \"tasks\", \"blackboard\", \"permissions\"],\r\n          \"default\": \"all\",\r\n          \"description\": \"The scope of state information to retrieve\"\r\n        },\r\n        \"agentFilter\": {\r\n          \"type\": \"array\",\r\n          \"items\": { \"type\": \"string\" },\r\n          \"description\": \"Optional list of agent IDs to filter results\"\r\n        },\r\n        \"includeHistory\": {\r\n          \"type\": \"boolean\",\r\n          \"default\": false,\r\n          \"description\": \"Include historical task execution data\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"timestamp\": { \"type\": \"string\" },\r\n          \"activeAgents\": { \"type\": \"array\" },\r\n          \"pendingTasks\": { \"type\": \"array\" },\r\n          \"blackboardSnapshot\": { \"type\": \"object\" },\r\n          \"permissionGrants\": { \"type\": \"array\" }\r\n        }\r\n      }\r\n    },\r\n    \"spawn_parallel_agents\": {\r\n      \"description\": \"Spawn multiple sub-agents in parallel for complex task decomposition\",\r\n      \"parameters\": {\r\n        \"tasks\": {\r\n          \"type\": \"array\",\r\n          \"required\": true,\r\n          \"items\": {\r\n            \"type\": \"object\",\r\n            \"properties\": {\r\n              \"agentType\": { \"type\": \"string\" },\r\n              \"taskPayload\": { \"type\": \"object\" }\r\n            }\r\n          },\r\n          \"description\": \"Array of parallel tasks to execute\"\r\n        },\r\n        \"synthesisStrategy\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"merge\", \"vote\", \"chain\", \"first-success\"],\r\n          \"default\": \"merge\",\r\n          \"description\": \"How to combine results from parallel agents\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"synthesizedResult\": { \"type\": \"any\" },\r\n          \"individualResults\": { \"type\": \"array\" },\r\n          \"executionMetrics\": { \"type\": \"object\" }\r\n        }\r\n      }\r\n    },\r\n    \"request_permission\": {\r\n      \"description\": \"Request permission for sensitive operations via the local permission gating script\",\r\n      \"parameters\": {\r\n        \"resourceType\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"DATABASE\", \"PAYMENTS\", \"EMAIL\", \"FILE_EXPORT\"],\r\n          \"required\": true,\r\n          \"description\": \"The type of protected resource being requested\"\r\n        },\r\n        \"justification\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"description\": \"Reason for requesting access\"\r\n        },\r\n        \"scope\": {\r\n          \"type\": \"string\",\r\n          \"description\": \"Specific scope of access needed\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"granted\": { \"type\": \"boolean\" },\r\n          \"grantToken\": { \"type\": \"string\" },\r\n          \"expiresAt\": { \"type\": \"string\" },\r\n          \"restrictions\": { \"type\": \"array\" }\r\n        }\r\n      }\r\n    },\r\n    \"update_blackboard\": {\r\n      \"description\": \"Write or update entries on the shared blackboard for cross-agent coordination\",\r\n      \"parameters\": {\r\n        \"key\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"description\": \"The blackboard entry key\"\r\n        },\r\n        \"value\": {\r\n          \"type\": \"any\",\r\n          \"required\": true,\r\n          \"description\": \"The data to store\"\r\n        },\r\n        \"ttl\": {\r\n          \"type\": \"number\",\r\n          \"description\": \"Time-to-live in seconds (optional)\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"success\": { \"type\": \"boolean\" },\r\n          \"previousValue\": { \"type\": \"any\" }\r\n        }\r\n      }\r\n    },\r\n    \"inject_context\": {\r\n      \"description\": \"Read the persistent project context file and return a formatted markdown block for injection into an agent system prompt. This is Layer 3 (long-lived) memory — architecture decisions, goals, tech stack, milestones, and banned approaches that every agent in the swarm should know.\",\r\n      \"parameters\": {},\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"contextMarkdown\": { \"type\": \"string\", \"description\": \"Formatted markdown block ready to prepend to an agent system prompt\" },\r\n          \"updatedAt\": { \"type\": \"string\", \"description\": \"ISO timestamp of last context update\" }\r\n        }\r\n      }\r\n    },\r\n    \"update_context\": {\r\n      \"description\": \"Persist a decision, milestone update, stack entry, goal, or banned approach to the project context file (Layer 3 memory). Changes are appended and survive across sessions.\",\r\n      \"parameters\": {\r\n        \"section\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"enum\": [\"decisions\", \"milestones\", \"stack\", \"goals\", \"banned\", \"project\"],\r\n          \"description\": \"The context section to update\"\r\n        },\r\n        \"add\": {\r\n          \"type\": \"any\",\r\n          \"description\": \"Item to append (JSON object or plain string, depending on section)\"\r\n        },\r\n        \"set\": {\r\n          \"type\": \"object\",\r\n          \"description\": \"Key-value pairs to merge into the section (use for stack and project)\"\r\n        },\r\n        \"complete\": {\r\n          \"type\": \"string\",\r\n          \"description\": \"Milestone name to mark completed (milestones section only)\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"success\": { \"type\": \"boolean\" },\r\n          \"section\": { \"type\": \"string\" }\r\n        }\r\n      }\r\n    }\r\n  },\r\n  \"permissions\": {\r\n    \"required\": [\"local_filesystem\", \"internal_skill_calls\"],\r\n    \"optional\": [\"external_api_access\"],\r\n    \"permissionGating\": {\r\n      \"enabled\": true,\r\n      \"protectedResources\": [\"DATABASE\", \"PAYMENTS\", \"EMAIL\", \"FILE_EXPORT\"],\r\n      \"note\": \"Permission checks are implemented locally via scripts/check_permission.py using weighted scoring (justification 40%, trust 30%, risk 30%). No external auth service.\"\r\n    }\r\n  },\r\n  \"dependencies\": {},\r\n  \"config\": {\r\n    \"blackboardPath\": \"./swarm-blackboard.md\",\r\n    \"maxParallelAgents\": null,\r\n    \"maxParallelAgents_default\": \"Infinity (no hard cap since v4.0.0 — set to a positive integer to enforce a limit)\",\r\n    \"defaultTimeout\": 30000,\r\n    \"enableTracing\": true\r\n  },\r\n  \"env\": {},\r\n  \"privacy\": {\r\n    \"audit_log\": {\r\n      \"path\": \"data/audit_log.jsonl\",\r\n      \"scope\": \"local-only\",\r\n      \"description\": \"Append-only JSONL audit log recording operation metadata (agentId, action, timestamp, outcome). Stays in local data/ directory. No data is sent externally by this skill.\",\r\n      \"contains\": [\"agentId\", \"action\", \"timestamp\", \"outcome\", \"resource\", \"justification (free-text, agent-provided)\"],\r\n      \"pii_warning\": \"Justification fields are free-text and may contain user-supplied content. Do not put PII, secrets, or credentials in justification strings. Restrict file permissions on data/ and rotate logs periodically.\",\r\n      \"does_not_contain\": [\"API keys\", \"external endpoints\"]\r\n    }\r\n  }\r\n}\n\nFile v5.15.4:requirements.txt\n\n# ============================================================================\r\n# ZERO DEPENDENCIES REQUIRED\r\n# ============================================================================\r\n# This file is documentation only. Do NOT run `pip install -r requirements.txt`.\r\n#\r\n# All 6 Python scripts use the standard library only:\r\n#   blackboard.py, swarm_guard.py, check_permission.py,\r\n#   validate_token.py, revoke_token.py, context_manager.py\r\n#\r\n# Standard library modules used:\r\n#   argparse, json, os, re, sys, time, hashlib, uuid, datetime, pathlib,\r\n#   typing, contextlib, fcntl (Unix; file-lock fallback on Windows)\r\n#\r\n# ── OPTIONAL (for development only, not required to run the skill) ──────────\r\n# filelock>=3.0.0  # Cross-platform file locking (Windows production)\r\n# mypy>=1.0.0      # Static type checking\r\n# pytest>=7.0.0    # Running the test suite\n\nArchive v5.15.3: 12 files, 63166 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34745b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2125b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nFile v5.15.3:SKILL.md\n\n---\r\nname: network-ai\r\ndescription: \"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle).\"\r\nmetadata:\r\n  openclaw:\r\n    emoji: \"\\U0001F41D\"\r\n    homepage: https://network-ai.org\r\n    capabilities:\r\n      filesystem: \"read/write — project root `swarm-blackboard.md` (blackboard state), `data/pending_changes/<id>.json` (WAL entries), `data/audit_log.jsonl`, `data/active_grants.json`, `data/.signing_key`, `data/project-context.json`, `data/task_tracking.json`, `data/agent_health.json`, `data/budget_tracking.json`. All paths are local; no data leaves the local filesystem. When NETWORK_AI_ENV is set, data paths are rooted at `data/<env>/` instead of `data/`. The `--path` argument in blackboard.py is validated against the project root at runtime — paths outside the project directory are rejected (CWE-22).\"\r\n      env_vars: \"read — NETWORK_AI_ENV (environment routing), NETWORK_AI_MCP_SECRET (MCP bearer auth), NETWORK_AI_MINIMAL (minimal-mode flag). No env vars are written.\"\r\n      shell_exec: \"optional — AgentRuntime (lib/agent-runtime.ts) with SandboxPolicy and ApprovalGate; disabled by default. Never auto-enabled by this skill. auto_approve must NOT be set in production (see auto_approve_warning below).\"\r\n      tcp_port: \"optional — MCP SSE server (bin/mcp-server.ts) binds 127.0.0.1 only when explicitly started by the operator. Requires a non-empty bearer-token secret. Never auto-started by this skill or any bundled Python script.\"\r\n    bundle_scope:\r\n      clawhub_python_scripts: \"Python stdlib only — scripts/*.py (blackboard.py, check_permission.py, context_manager.py, swarm_guard.py, validate_token.py, revoke_token.py). Zero network calls, zero subprocesses, zero third-party packages. This is the scope scanned by SkillSpector.\"\r\n      npm_full_package: \"The npm package (npm install network-ai) adds: TypeScript library modules, CLI (bin/cli.ts), and optional MCP SSE server (bin/mcp-server.ts). The MCP SSE server exposes a TCP port and is NOT activated by installing or importing the package — it must be explicitly started by the operator.\"\r\n    network_calls:\r\n      python_scripts: none\r\n      typescript_library: \"none — BYOC (bring your own client); zero outbound calls from library code; all LLM/API clients are injected by the caller\"\r\n      mcp_sse_server: \"optional — binds 127.0.0.1:<port> when explicitly started by the operator; all connections require a bearer-token secret (NETWORK_AI_MCP_SECRET); never auto-started\"\r\n    inter_agent_comms: \"none — this skill does not implement, invoke, or control inter-agent messaging or sessions_send. All coordination is via local file-based blackboard only.\"\r\n    sessions_send: \"NOT implemented or invoked by this skill. sessions_send is a host-platform built-in entirely outside this skill's control. See data-flow notice below.\"\r\n    sessions_ops: \"platform-provided — outside this skill's control\"\r\n    requires:\r\n      bins:\r\n        - python3\r\n      optional_bins: []\r\n    env: {}\r\n    privacy:\r\n      audit_log:\r\n        path: data/audit_log.jsonl\r\n        scope: local-only\r\n        description: \"Local append-only JSONL file recording operation metadata. No data leaves the machine.\"\r\n        pii_warning: \"Justification strings are truncated to 200 characters before being written to the audit log. Audit summary output (--audit-summary --json) omits justification text from returned entries. Do not include PII, credentials, or secrets in justification fields — the truncated text still persists on disk. Grant tokens are masked to a short prefix in all listing outputs; full tokens appear only at issuance time.\"\r\n      data_directory:\r\n        path: data/\r\n        scope: local-only\r\n        files: [\"audit_log.jsonl\", \"active_grants.json\", \".signing_key\", \"project-context.json\", \"task_tracking.json\", \"agent_health.json\", \"budget_tracking.json\", \"pending_changes/<id>.json\"]\r\n        description: \"All persistent state is local-only. No data leaves the local filesystem.\"\r\n      blackboard_file:\r\n        path: swarm-blackboard.md\r\n        scope: local-only\r\n        description: \"Shared coordination state written by scripts/blackboard.py (project root). Contains task results, grant tokens, status flags, and TTL-scoped cache entries. Access should be restricted to the local user running the swarm.\"\r\n      auto_approve_warning: \"ApprovalGate.auto_approve (lib/agent-runtime.ts) must NOT be enabled in production or untrusted environments. It is only appropriate in explicitly isolated CI/dev sandboxes where all commands executed by the runtime are known and trusted in advance.\"\r\n---\r\n\r\n# Swarm Orchestrator Skill\r\n\r\n> **Scope:** The bundled Python scripts (`scripts/*.py`) make **no network calls**, use only the Python standard library, and have **zero third-party dependencies**. Tokens are UUID-based (`grant_{uuid4().hex}`) stored in `data/active_grants.json`. Audit logging is plain JSONL (`data/audit_log.jsonl`).\r\n\r\n> **Advisory tokens notice:** Grant tokens issued by `check_permission.py` are **advisory scoring outputs only** — the caller-supplied `--agent` identity is not cryptographically verified. Downstream systems must not treat these tokens as authenticated credentials without adding a separate identity-verification step or human approval gate, especially for PAYMENTS, DATABASE, and FILE_EXPORT resources.\r\n\r\n> **Data-flow notice (host platform — not this skill):** This skill does NOT implement, invoke, or control `sessions_send` or any inter-agent messaging. All bundled Python scripts are local-only tools (budget guard, blackboard, permission scorer, context manager). If your platform has a `sessions_send` built-in, whether and how it is used is entirely the **host platform’s** responsibility and is outside this skill’s scope. If you need to prevent external network calls, disable or reroute delegation in your **platform settings** before installing this skill.\r\n\r\n> **Context file integrity:** The `context_manager.py inject` command now validates `data/project-context.json` for injection patterns and oversized fields before printing the context block. Review any warnings printed to stderr before passing the output to an agent system prompt.\r\n\r\n> **PII / sensitive-data warning:** The `justification` field in permission requests and the audit log (`data/audit_log.jsonl`) store free-text strings provided by agents. **Do not include PII, secrets, or credentials in justification text.** Consider restricting file permissions on `data/` or running this skill in an isolated workspace.\r\n\r\n## Setup\r\n\r\n**No pip install required.** All 6 scripts use Python standard library only — zero third-party packages.\r\n\r\n> **Note on `requirements.txt`:** The file exists for documentation purposes only — it lists the stdlib modules used and has **no required packages**. All listed deps are commented out as optional. You do not need to run `pip install -r requirements.txt`.\r\n\r\n```bash\r\n# Prerequisite: python3 (any version ≥ 3.8)\r\npython3 --version\r\n\r\n# That's it. Run any script directly:\r\npython3 scripts/blackboard.py list\r\npython3 scripts/swarm_guard.py budget-init --task-id \"task_001\" --budget 10000\r\n\r\n# Optional: for cross-platform file locking on Windows production hosts\r\npip install filelock  # only needed if you see locking issues on Windows\r\n```\r\n\r\nThe `data/` directory is created automatically on first run. No configuration files, environment variables, or credentials are required.\r\n\r\n> **Multi-environment support (v5.4.0):** All five Python scripts now read the `NETWORK_AI_ENV` environment variable at startup and accept a `--env <name>` CLI argument. When set, all data paths are routed to `data/<env>/` instead of the root `data/` directory. Use this to isolate dev, staging, and production state.\r\n>\r\n> ```bash\r\n> # Run against the dev environment\r\n> NETWORK_AI_ENV=dev python3 scripts/blackboard.py list\r\n> python3 scripts/check_permission.py --active-grants --env dev\r\n> ```\r\n\r\nMulti-agent coordination system for complex workflows requiring task delegation, parallel execution, and permission-controlled access to sensitive APIs.\r\n\r\n## 🎯 Orchestrator System Instructions\r\n\r\n**You are the Orchestrator Agent** responsible for decomposing complex tasks, delegating to specialized agents, and synthesizing results. Follow this protocol:\r\n\r\n### Core Responsibilities\r\n\r\n1. **DECOMPOSE** complex prompts into 3 specialized sub-tasks\r\n2. **DELEGATE** using the budget-aware handoff protocol\r\n3. **VERIFY** results on the blackboard before committing\r\n4. **SYNTHESIZE** final output only after all validations pass\r\n\r\n### Task Decomposition Protocol\r\n\r\nWhen you receive a complex request, decompose it into exactly **3 sub-tasks**:\r\n\r\n```\r\n┌─────────────────────────────────────────────────────────────────┐\r\n│                     COMPLEX USER REQUEST                        │\r\n└─────────────────────────────────────────────────────────────────┘\r\n                              │\r\n                              ▼\r\n        ┌─────────────────────┼─────────────────────┐\r\n        │                     │                     │\r\n        ▼                     ▼                     ▼\r\n┌───────────────┐   ┌───────────────┐   ┌───────────────┐\r\n│  SUB-TASK 1   │   │  SUB-TASK 2   │   │  SUB-TASK 3   │\r\n│ data_analyst  │   │ risk_assessor │   │strategy_advisor│\r\n│    (DATA)     │   │   (VERIFY)    │   │  (RECOMMEND)  │\r\n└───────────────┘   └───────────────┘   └───────────────┘\r\n        │                     │                     │\r\n        └─────────────────────┼─────────────────────┘\r\n                              ▼\r\n                    ┌───────────────┐\r\n                    │  SYNTHESIZE   │\r\n                    │ orchestrator  │\r\n                    └───────────────┘\r\n```\r\n\r\n**Decomposition Template:**\r\n```\r\nTASK DECOMPOSITION for: \"{user_request}\"\r\n\r\nSub-Task 1 (DATA): [data_analyst]\r\n  - Objective: Extract/process raw data\r\n  - Output: Structured JSON with metrics\r\n\r\nSub-Task 2 (VERIFY): [risk_assessor]  \r\n  - Objective: Validate data quality & compliance\r\n  - Output: Validation report with confidence score\r\n\r\nSub-Task 3 (RECOMMEND): [strategy_advisor]\r\n  - Objective: Generate actionable insights\r\n  - Output: Recommendations with rationale\r\n```\r\n\r\n### Budget Check Protocol\r\n\r\n**Run the budget interceptor before any task delegation:**\r\n\r\n```bash\r\n# Run this before delegating to any sub-agent\r\npython {baseDir}/scripts/swarm_guard.py intercept-handoff \\\r\n  --task-id \"task_001\" \\\r\n  --from orchestrator \\\r\n  --to data_analyst \\\r\n  --message \"Analyze Q4 revenue data\"\r\n```\r\n\r\n**Decision Logic:**\r\n```\r\nIF result.allowed == true:\r\n    → Budget check passed — proceed with the delegated task\r\n    → Note tokens_spent and remaining_budget\r\nELSE:\r\n    → STOP — budget exceeded or handoff limit reached\r\n    → Report blocked reason to user\r\n    → Consider: reduce scope or abort task\r\n```\r\n\r\n### Pre-Commit Verification Workflow\r\n\r\nBefore returning final results to the user:\r\n\r\n```bash\r\n# Step 1: Check all sub-task results on blackboard\r\npython {baseDir}/scripts/blackboard.py read \"task:001:data_analyst\"\r\npython {baseDir}/scripts/blackboard.py read \"task:001:risk_assessor\"\r\npython {baseDir}/scripts/blackboard.py read \"task:001:strategy_advisor\"\r\n\r\n# Step 2: Validate each result\r\npython {baseDir}/scripts/swarm_guard.py validate-result \\\r\n  --task-id \"task_001\" \\\r\n  --agent data_analyst \\\r\n  --result '{\"status\":\"success\",\"output\":{...},\"confidence\":0.85}'\r\n\r\n# Step 3: Supervisor review (checks all issues)\r\npython {baseDir}/scripts/swarm_guard.py supervisor-review --task-id \"task_001\"\r\n\r\n# Step 4: Only if APPROVED, commit final state\r\npython {baseDir}/scripts/blackboard.py write \"task:001:final\" \\\r\n  '{\"status\":\"SUCCESS\",\"output\":{...}}'\r\n```\r\n\r\n**Verdict Handling:**\r\n| Verdict | Action |\r\n|---------|--------|\r\n| `APPROVED` | Commit and return results to user |\r\n| `WARNING` | Review issues, fix if possible, then commit |\r\n| `BLOCKED` | Do NOT return results. Report failure. |\r\n\r\n---\r\n\r\n## The 3-Layer Memory Model\r\n\r\nEvery agent in the swarm operates with three memory layers, each with a different scope and lifetime:\r\n\r\n| Layer | Name | Lifetime | Managed by |\r\n|-------|------|----------|------------|\r\n| **1** | Agent context | Ephemeral — current task only | Platform (per-session) |\r\n| **2** | Blackboard | TTL-scoped — shared across agents | `scripts/blackboard.py` |\r\n| **3** | Project context | Persistent — survives all sessions | `scripts/context_manager.py` |\r\n\r\n### Layer 1 — Agent Context\r\nEach agent's own context window: the current task instructions, conversation history, and immediate working memory. Managed automatically by the OpenClaw/LLM platform. Nothing to configure.\r\n\r\n### Layer 2 — Blackboard (Shared Coordination State)\r\nA shared markdown file (`swarm-blackboard.md`) for real-time cross-agent coordination: task results, grant tokens, status flags, and TTL-scoped cache entries. Agents read and write via `scripts/blackboard.py`. Entries expire automatically.\r\n\r\n### Layer 3 — Project Context (Persistent Long-Term Memory)\r\nA JSON file (`data/project-context.json`) that holds information every agent should know, regardless of what session or task is running:\r\n- **Goals** — long-term objectives of the project\r\n- **Tech stack** — languages, frameworks, infrastructure\r\n- **Milestones** — completed, in-progress, and planned work\r\n- **Architecture decisions** — design choices and their rationales\r\n- **Banned approaches** — approaches that have been ruled out\r\n\r\n#### Initialising Project Context\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py init \\\r\n  --name \"MyProject\" \\\r\n  --description \"Multi-agent workflow automation\" \\\r\n  --version \"1.0.0\"\r\n```\r\n\r\n#### Injecting Context into an Agent System Prompt\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py inject\r\n```\r\n\r\nCopy the output block to the top of your agent's system prompt. Every agent that receives this block shares the same long-term project awareness.\r\n\r\n#### Recording a Decision\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section decisions \\\r\n  --add '{\"decision\": \"Use atomic blackboard commits\", \"rationale\": \"Prevent race conditions in parallel agents\"}'\r\n```\r\n\r\n#### Updating Milestones\r\n\r\n```bash\r\n# Mark a milestone complete\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section milestones --complete \"Ship v2.0\"\r\n\r\n# Add a planned milestone\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section milestones --add '{\"planned\": \"Integrate vector memory\"}'\r\n```\r\n\r\n#### Setting the Tech Stack\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section stack \\\r\n  --set '{\"language\": \"Python\", \"runtime\": \"Python 3.11\", \"framework\": \"SwarmOrchestrator\"}'\r\n```\r\n\r\n#### Banning an Approach\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section banned \\\r\n  --add \"Direct database writes from agent scripts (use permission gating)\"\r\n```\r\n\r\n---\r\n\r\n## When to Use This Skill\r\n\r\nUse this skill when the task requires **local, file-based** multi-agent coordination within a single trusted workspace. All 6 bundled Python scripts run locally with zero network calls, zero subprocesses, and zero third-party packages.\r\n\r\n### Use for\r\n- **Task Delegation** — decompose complex work into sub-tasks routed to named in-session agents (`data_analyst`, `strategy_advisor`, `risk_assessor`)\r\n- **Parallel Execution** — run multiple local agents simultaneously and synthesize results via the shared blackboard\r\n- **Permission Wall** — score and gate access to abstract resource labels (`DATABASE`, `PAYMENTS`, `EMAIL`, `FILE_EXPORT`) before performing sensitive local operations\r\n- **Shared Blackboard** — coordinate ephemeral task state across in-session agents via a persistent markdown file\r\n\r\n### Do NOT use for\r\n- External API or network service calls — the bundled Python scripts make **zero outbound network calls**\r\n- Production identity or authorization — grant tokens are **advisory scoring outputs only**, not authenticated credentials; do not use as real access control\r\n- Shell command execution or agent spawning — those capabilities require the TypeScript library (`npm install network-ai`) with operator-level `AgentRuntime` + `SandboxPolicy` configuration; they are **never activated by this skill**\r\n- Starting an MCP or HTTP server — the optional MCP server (`bin/mcp-server.ts`) is an npm-package feature that must be explicitly started by the operator; it is **not part of this skill bundle**\r\n- Any task solvable with a single direct tool call — this skill adds coordination overhead and is only appropriate when multiple agents must share state\r\n\r\n## Quick Start\r\n\r\n### 1. Initialize Budget (FIRST!)\r\n\r\n**Always initialize a budget before any multi-agent task:**\r\n\r\n```bash\r\npython {baseDir}/scripts/swarm_guard.py budget-init \\\r\n  --task-id \"task_001\" \\\r\n  --budget 10000 \\\r\n  --description \"Q4 Financial Analysis\"\r\n```\r\n\r\n### 2. Check Budget Before Task Delegation\r\n\r\n\r\nAlways run the budget guard before delegating any task:\r\n\r\n```bash\r\n# 1. Check budget (this skill's Python script)\r\npython {baseDir}/scripts/swarm_guard.py intercept-handoff \\\r\n  --task-id \"task_001\" --from orchestrator --to data_analyst \\\r\n  --message \"Analyze Q4 revenue data\"\r\n\r\n# 2. If result.allowed == true, proceed with delegation via your platform's built-in tools.\r\n# If result.allowed == false, stop — budget exceeded or handoff limit reached.\r\n```\r\n\r\n### 3. Check Permission Before API Access\r\n\r\nBefore accessing SAP or Financial APIs, evaluate the request:\r\n\r\n```bash\r\n# Run the permission checker script\r\npython {baseDir}/scripts/check_permission.py \\\r\n  --agent \"data_analyst\" \\\r\n  --resource \"DATABASE\" \\\r\n  --justification \"Need Q4 invoice data for quarterly report\" \\\r\n  --scope \"read:invoices\"\r\n```\r\n\r\nThe script will output a grant token if approved, or denial reason if rejected.\r\n\r\n### 4. Use the Shared Blackboard\r\n\r\nRead/write coordination state:\r\n\r\n```bash\r\n# Write to blackboard\r\npython {baseDir}/scripts/blackboard.py write \"task:q4_analysis\" '{\"status\": \"in_progress\", \"agent\": \"data_analyst\"}'\r\n\r\n# Read from blackboard  \r\npython {baseDir}/scripts/blackboard.py read \"task:q4_analysis\"\r\n\r\n# List all entries\r\npython {baseDir}/scripts/blackboard.py list\r\n```\r\n\r\n## Agent-to-Agent Handoff Protocol\r\n\r\nWhen delegating tasks between agents, always run the budget guard first.\r\n\r\n### Step 1: Initialize Budget & Check Capacity\r\n```bash\r\n# Initialize budget (if not already done)\r\npython {baseDir}/scripts/swarm_guard.py budget-init --task-id \"task_001\" --budget 10000\r\n\r\n# Check current status\r\npython {baseDir}/scripts/swarm_guard.py budget-check --task-id \"task_001\"\r\n```\r\n\r\n### Step 2: Identify Target Agent\r\n\r\nCommon agent types:\r\n| Agent | Specialty |\r\n|-------|-----------|\r\n| `data_analyst` | Data processing, SQL, analytics |\r\n| `strategy_advisor` | Business strategy, recommendations |\r\n| `risk_assessor` | Risk analysis, compliance checks |\r\n| `orchestrator` | Coordination, task decomposition |\r\n\r\n### Step 3: Run Budget Guard Before Delegation\r\n\r\n```bash\r\n# Check budget AND handoff limits before delegating\r\npython {baseDir}/scripts/swarm_guard.py intercept-handoff \\\r\n  --task-id \"task_001\" \\\r\n  --from orchestrator \\\r\n  --to data_analyst \\\r\n  --message \"Analyze Q4 data\" \\\r\n  --artifact  # Include if expecting output\r\n```\r\n\r\n**If ALLOWED:** Proceed with delegation via your platform's own tools\r\n**If BLOCKED:** Stop — budget exceeded or handoff limit reached; do not delegate\r\n\r\n### Step 4: Construct Handoff Message\r\n\r\nInclude these fields in your delegation:\r\n- **instruction**: Clear task description\r\n- **context**: Relevant background information\r\n- **constraints**: Any limitations or requirements\r\n- **expectedOutput**: What format/content you need back\r\n\r\n### Step 5: Check Results\r\n\r\nAfter delegation completes, read results from the blackboard:\r\n\r\n```bash\r\npython {baseDir}/scripts/blackboard.py read \"task:001:data_analyst\"\r\n```\r\n\r\n## Permission Scoring\r\n\r\n> **Tokens are audit scoring outputs only.** Grant tokens from `check_permission.py` are NOT authenticated credentials and must NOT be used as real access control. They are advisory hints based on a local scoring model. Require a separate authenticated identity and explicit human approval before accessing PAYMENTS, DATABASE, or FILE_EXPORT resources.\r\n\r\n**Always score permission before accessing:**\r\n- `DATABASE` — Internal database / data store (abstract label — no external credentials)\r\n- `PAYMENTS` — Financial/payment data services (abstract label — requires `--confirm-high-risk`)\r\n- `EMAIL` — Email sending capability (abstract label)\r\n- `FILE_EXPORT` — Exporting data to local files (abstract label — requires `--confirm-high-risk`)\r\n\r\n> **Note**: These are abstract local resource type names used by `check_permission.py`. No external API credentials are required or used — all evaluation runs locally.\r\n\r\n### Permission Evaluation Criteria\r\n\r\n| Factor | Weight | Criteria |\r\n|--------|--------|----------|\r\n| Justification | 40% | Must explain specific task need |\r\n| Trust Level | 30% | Agent's established trust score |\r\n| Risk Assessment | 30% | Resource sensitivity + scope breadth |\r\n\r\n### Using the Permission Script\r\n\r\n```bash\r\n# Request permission\r\npython {baseDir}/scripts/check_permission.py \\\r\n  --agent \"your_agent_id\" \\\r\n  --resource \"PAYMENTS\" \\\r\n  --justification \"Generating quarterly financial summary for board presentation\" \\\r\n  --scope \"read:revenue,read:expenses\"\r\n\r\n# Output if approved:\r\n# ✅ GRANTED\r\n# Token: grant_a1b2c3d4e5f6\r\n# Expires: 2026-02-04T15:30:00Z\r\n# Restrictions: read_only, no_pii_fields, audit_required\r\n\r\n# Output if denied:\r\n# ❌ DENIED\r\n# Reason: Justification is insufficient. Please provide specific task context.\r\n```\r\n\r\n### Restriction Types\r\n\r\n| Resource | Default Restrictions |\r\n|----------|---------------------|\r\n| DATABASE | `read_only`, `max_records:100` |\r\n| PAYMENTS | `read_only`, `no_pii_fields`, `audit_required` |\r\n| EMAIL | `rate_limit:10_per_minute` |\r\n| FILE_EXPORT | `anonymize_pii`, `local_only` |\r\n\r\n## Shared Blackboard Pattern\r\n\r\nThe blackboard (`swarm-blackboard.md`) is a markdown file for agent coordination:\r\n\r\n```markdown\r\n# Swarm Blackboard\r\nLast Updated: 2026-02-04T10:30:00Z\r\n\r\n## Knowledge Cache\r\n### task:q4_analysis\r\n{\"status\": \"completed\", \"result\": {...}, \"agent\": \"data_analyst\"}\r\n\r\n### cache:revenue_summary  \r\n{\"q4_total\": 1250000, \"growth\": 0.15}\r\n```\r\n\r\n### Blackboard Operations\r\n\r\n```bash\r\n# Write with TTL (expires after 1 hour)\r\npython {baseDir}/scripts/blackboard.py write \"cache:temp_data\" '{\"value\": 123}' --ttl 3600\r\n\r\n# Read (returns null if expired)\r\npython {baseDir}/scripts/blackboard.py read \"cache:temp_data\"\r\n\r\n# Delete\r\npython {baseDir}/scripts/blackboard.py delete \"cache:temp_data\"\r\n\r\n# Get full snapshot\r\npython {baseDir}/scripts/blackboard.py snapshot\r\n```\r\n\r\n## Parallel Execution\r\n\r\nFor tasks requiring multiple agent perspectives:\r\n\r\n### Strategy 1: Merge (Default)\r\nCombine all agent outputs into unified result.\r\n```\r\nAsk data_analyst AND strategy_advisor to both analyze the dataset.\r\nMerge their insights into a comprehensive report.\r\n```\r\n\r\n### Strategy 2: Vote\r\nUse when you need consensus - pick the result with highest confidence.\r\n\r\n### Strategy 3: First-Success\r\nUse for redundancy - take first successful result.\r\n\r\n### Strategy 4: Chain\r\nSequential processing - output of one feeds into next.\r\n\r\n> **TypeScript engine (v4.15.0):** These strategies map directly to the `FanOutFanIn` module (`lib/fan-out.ts`) which provides `merge`, `vote`, `firstSuccess`, and `consensus` fan-in strategies with concurrency control. For multi-phase workflows with approval gates, see `PhasePipeline` (`lib/phase-pipeline.ts`). For result scoring and threshold filtering, see `ConfidenceFilter` (`lib/confidence-filter.ts`). Matcher-based hooks (`lib/adapter-hooks.ts`) can target specific agents or tools via glob patterns. For sandboxed agent execution, see `AgentRuntime` (`lib/agent-runtime.ts`). For large-scale agent coordination, see `StrategyAgent` (`lib/strategy-agent.ts`).\r\n\r\n### Example Parallel Workflow\r\n\r\n```\r\n# For each delegation below, first run the budget guard:\r\n#   python {baseDir}/scripts/swarm_guard.py intercept-handoff --task-id \"task_001\" --from orchestrator --to <agent> --message \"<task>\"\r\n# If result.allowed == true, delegate via your platform's own tools.\r\n1. Delegate to data_analyst: \"Extract key metrics from Q4 data\"\r\n2. Delegate to risk_assessor: \"Identify compliance risks in Q4 data\"\r\n3. Delegate to strategy_advisor: \"Recommend actions based on Q4 trends\"\r\n4. Wait for all results and read them from the blackboard\r\n5. Synthesize: Combine metrics + risks + recommendations into executive summary\r\n```\r\n\r\n## Security Considerations\r\n\r\n1. **Never bypass the permission wall** for gated resources\r\n2. **Always include justification** explaining the business need\r\n3. **Use minimal scope** - request only what you need\r\n4. **Check token expiry** - tokens are valid for 5 minutes\r\n5. **Validate tokens** - use `python {baseDir}/scripts/validate_token.py TOKEN` to verify grant tokens before use\r\n6. **Audit trail** - all permission requests are logged\r\n\r\n## 📝 Audit Trail Requirements (MANDATORY)\r\n\r\n**Every sensitive action MUST be logged to `data/audit_log.jsonl`** to maintain compliance and enable forensic analysis.\r\n\r\n> **Privacy note:** Audit log entries contain agent-provided free-text fields (justifications, descriptions). These are stored locally in `data/audit_log.jsonl` and kept on this machine only by this skill — no audit data leaves the local filesystem. However, **do not put PII, passwords, or API keys in justification strings** — they persist on disk. Consider periodic log rotation and restricting OS file permissions on the `data/` directory.\r\n\r\n### What Gets Logged Automatically\r\n\r\nThe scripts automatically log these events:\r\n- `permission_granted` - When access is approved\r\n- `permission_denied` - When access is rejected\r\n- `permission_revoked` - When a token is manually revoked\r\n- `ttl_cleanup` - When expired tokens are purged\r\n- `result_validated` / `result_rejected` - Swarm Guard validations\r\n\r\n### Log Entry Format\r\n\r\n```json\r\n{\r\n  \"timestamp\": \"2026-02-04T10:30:00+00:00\",\r\n  \"action\": \"permission_granted\",\r\n  \"details\": {\r\n    \"agent_id\": \"data_analyst\",\r\n    \"resource_type\": \"DATABASE\",\r\n    \"justification\": \"Q4 revenue analysis\",\r\n    \"token\": \"grant_abc123...\",\r\n    \"restrictions\": [\"read_only\", \"max_records:100\"]\r\n  }\r\n}\r\n```\r\n\r\n### Reading the Audit Log\r\n\r\n```bash\r\n# View recent entries (last 10)\r\ntail -10 {baseDir}/data/audit_log.jsonl\r\n\r\n# Search for specific agent\r\ngrep \"data_analyst\" {baseDir}/data/audit_log.jsonl\r\n\r\n# Count actions by type\r\ncat {baseDir}/data/audit_log.jsonl | jq -r '.action' | sort | uniq -c\r\n```\r\n\r\n### Custom Audit Entries\r\n\r\nIf you perform a sensitive action manually, log it:\r\n\r\n```python\r\nimport json\r\nfrom datetime import datetime, timezone\r\nfrom pathlib import Path\r\n\r\naudit_file = Path(\"{baseDir}/data/audit_log.jsonl\")\r\nentry = {\r\n    \"timestamp\": datetime.now(timezone.utc).isoformat(),\r\n    \"action\": \"manual_data_access\",\r\n    \"details\": {\r\n        \"agent\": \"orchestrator\",\r\n        \"description\": \"Direct database query for debugging\",\r\n        \"justification\": \"Investigating data sync issue #1234\"\r\n    }\r\n}\r\nwith open(audit_file, \"a\") as f:\r\n    f.write(json.dumps(entry) + \"\\n\")\r\n```\r\n\r\n## 🧹 TTL Enforcement (Token Lifecycle)\r\n\r\nExpired permission tokens are automatically tracked. Run periodic cleanup:\r\n\r\n```bash\r\n# Validate a grant token\r\npython {baseDir}/scripts/validate_token.py grant_a1b2c3d4e5f6\r\n\r\n# List expired tokens (without removing)\r\npython {baseDir}/scripts/revoke_token.py --list-expired\r\n\r\n# Remove all expired tokens\r\npython {baseDir}/scripts/revoke_token.py --cleanup\r\n\r\n# Output:\r\n# 🧹 TTL Cleanup Complete\r\n#    Removed: 3 expired token(s)\r\n#    Remaining active grants: 2\r\n```\r\n\r\n**Best Practice**: Run `--cleanup` at the start of each multi-agent task to ensure a clean permission state.\r\n\r\n## ⚠️ Swarm Guard: Preventing Common Failures\r\n\r\nTwo critical issues can derail multi-agent swarms:\r\n\r\n### 1. The Handoff Tax 💸\r\n\r\n**Problem**: Agents waste tokens \"talking about\" work instead of doing it.\r\n\r\n**Prevention**:\r\n```bash\r\n# Before each handoff, check your budget:\r\npython {baseDir}/scripts/swarm_guard.py check-handoff --task-id \"task_001\"\r\n\r\n# Output:\r\n# 🟢 Task: task_001\r\n#    Handoffs: 1/3\r\n#    Remaining: 2\r\n#    Action Ratio: 100%\r\n```\r\n\r\n**Rules enforced**:\r\n- **Max 3 handoffs per task** - After 3, produce output or abort\r\n- **Max 500 chars per message** - Be concise: instruction + constraints + expected output\r\n- **60% action ratio** - At least 60% of handoffs must produce artifacts\r\n- **2-minute planning limit** - No output after 2min = timeout\r\n\r\n```bash\r\n# Record a handoff (with tax checking):\r\npython {baseDir}/scripts/swarm_guard.py record-handoff \\\r\n  --task-id \"task_001\" \\\r\n  --from orchestrator \\\r\n  --to data_analyst \\\r\n  --message \"Analyze sales data, output JSON summary\" \\\r\n  --artifact  # Include if this handoff produces output\r\n```\r\n\r\n### 2. Silent Failure Detection 👻\r\n\r\n**Problem**: One agent fails silently, others keep working on bad data.\r\n\r\n**Prevention - Heartbeats**:\r\n```bash\r\n# Agents must send heartbeats while working:\r\npython {baseDir}/scripts/swarm_guard.py heartbeat --agent data_analyst --task-id \"task_001\"\r\n\r\n# Check if an agent is healthy:\r\npython {baseDir}/scripts/swarm_guard.py health-check --agent data_analyst\r\n\r\n# Output if healthy:\r\n# 💚 Agent 'data_analyst' is HEALTHY\r\n#    Last seen: 15s ago\r\n\r\n# Output if failed:\r\n# 💔 Agent 'data_analyst' is UNHEALTHY\r\n#    Reason: STALE_HEARTBEAT\r\n#    → Do NOT use any pending results from this agent.\r\n```\r\n\r\n**Prevention - Result Validation**:\r\n```bash\r\n# Before using another agent's result, validate it:\r\npython {baseDir}/scripts/swarm_guard.py validate-result \\\r\n  --task-id \"task_001\" \\\r\n  --agent data_analyst \\\r\n  --result '{\"status\": \"success\", \"output\": {\"revenue\": 125000}, \"confidence\": 0.85}'\r\n\r\n# Output:\r\n# ✅ RESULT VALID\r\n#    → APPROVED - Result can be used by other agents\r\n```\r\n\r\n**Required result fields**: `status`, `output`, `confidence`\r\n\r\n### Supervisor Review\r\n\r\nBefore finalizing any task, run supervisor review:\r\n```bash\r\npython {baseDir}/scripts/swarm_guard.py supervisor-review --task-id \"task_001\"\r\n\r\n# Output:\r\n# ✅ SUPERVISOR VERDICT: APPROVED\r\n#    Task: task_001\r\n#    Age: 1.5 minutes\r\n#    Handoffs: 2\r\n#    Artifacts: 2\r\n```\r\n\r\n**Verdicts**:\r\n- `APPROVED` - Task healthy, results usable\r\n- `WARNING` - Issues detected, review recommended\r\n- `BLOCKED` - Critical failures, do NOT use results\r\n\r\n## Troubleshooting\r\n\r\n### Permission Denied\r\n- Provide more specific justification (mention task, purpose, expected outcome)\r\n- Narrow the requested scope\r\n- Check agent trust level\r\n\r\n### Blackboard Read Returns Null\r\n- Entry may have expired (check TTL)\r\n- Key may be misspelled\r\n- Entry was never written\r\n\r\n### Session Not Found\r\n- Run `sessions_list` (OpenClaw platform built-in) to see available sessions\r\n- Session may need to be started first\r\n\r\n## Security Framework Assessment (MAESTRO / OWASP AST)\r\n\r\nThe following findings are drawn from the **MAESTRO Agent Security Threat** framework (OWASP LLM / ASVS mapping). They are addressed by existing architectural controls in Network-AI — not open vulnerabilities.\r\n\r\n> **Engine-level OWASP Agentic AI Top 10 (2026):** the TypeScript orchestration engine maps all 10 OWASP Agentic risk categories (ASI-01 … ASI-10) to deterministic controls, verifiable programmatically via `verifyOwaspCoverage()` (`lib/owasp-compliance.ts`, exported from `network-ai`). See the coverage table in the README. The MAESTRO/AST findings below scope the bundled Python skill scripts.\r\n\r\n### AST03 — Over-Privileged Skills · Severity: High\r\n\r\n> *Skills are granted broader permissions than their stated function requires, creating excessive blast radius if prompt-injected.*\r\n\r\n| Control | How Network-AI addresses it |\r\n|---|---|\r\n| **Permission manifest** | `metadata.openclaw` in SKILL.md frontmatter explicitly declares `bundle_scope` (Python scripts: local-only; full npm package: includes optional MCP SSE server), `network_calls` (Python scripts: none; MCP SSE server: TCP, operator-started, bearer-token required), `requires.bins: [python3]` — no API credentials, no external services in core |\r\n| **Least-privilege resource gating** | `check_permission.py` uses a weighted scoring model (justification 40 %, trust 30 %, risk 30 %); PAYMENTS and FILE_EXPORT require `--confirm-high-risk` acknowledgment before any token is issued; `--scope` limits every grant to minimum required access |\r\n| **Abstract resource labels only** | PAYMENTS, DATABASE, EMAIL, FILE_EXPORT are local scoring labels — no external credentials exist in the skill; there is nothing to leak to an external service |\r\n| **HMAC-signed grant tokens** | Since v5.5.2, every grant record carries `_sig` (HMAC-SHA256 over canonical fields); `validate_token.py` rejects tampered records — privilege escalation via forged grants is detected at validation time |\r\n| **SandboxPolicy + FileAccessor** | AgentRuntime's `SandboxPolicy` enforces command allowlists/blocklists; `FileAccessor` restricts all file I/O to `data/<env>/`; out-of-scope access throws `SourceProtectionError` and returns `{success: false}` without leaking path details |\r\n| **Advisory-only tokens** | All grant tokens are explicitly marked `advisory: true`; downstream systems must add a separate authenticated identity check and human approval before any real sensitive action — documented in frontmatter and throughout SKILL.md |\r\n\r\n### AST06 — Weak Isolation · Severity: High\r\n\r\n> *Skills execute in the host agent's security context with full filesystem, shell, and network access.*\r\n\r\n| Control | How Network-AI addresses it |\r\n|---|---|\r\n| **Zero network calls (Python scripts)** | All bundled Python scripts use Python stdlib only, spawn no subprocesses, and make no network calls — declared in `metadata.openclaw.network_calls` and `bundle_scope`. The optional TypeScript MCP server (`bin/mcp-server.ts`) is not part of the ClawHub bundle; it must be explicitly started by the operator via `npx network-ai-server` and requires a non-empty bearer-token secret. |\r\n| **AgentRuntime sandbox** | `ShellExecutor` enforces per-command timeout and output-size limits; `SandboxPolicy` allowlist/blocklist prevents unapproved shell commands from running at all |\r\n| **ClaimVerifier (Tier 1 agent honesty)** | `AgentRuntime` issues HMAC-signed outcome-bound receipts (`ExecutionReceipt`) on every `exec()` and `writeFile()`; `ClaimVerifier` (`lib/claim-verifier.ts`) reconciles agent-declared manifests against the audit log — `UNSUPPORTED_CLAIM` and `UNDISCLOSED_ACTION` violations surface through `ComplianceMonitor`; repeated fabrication decays `AuthGuardian` trust and forces `ApprovalGate` supervision |\r\n| **Source protection** | `SandboxPolicy.sourceProtection` constrains `FileAccessor.read/write/list` to `data/<env>/` only; any attempt to read outside that boundary throws `SourceProtectionError` — the agent receives `{success: false}`, no path details leak |\r\n| **Environment isolation** | `NETWORK_AI_ENV` / `--env` routes all state to `data/<env>/`; dev, staging, and production state are fully separated; live state (`audit_log.jsonl`, `active_grants.json`) never promotes across environments |\r\n| **ApprovalGate** | High-risk shell or file operations require explicit human or callback approval before execution; auto-approve only in explicitly trusted environments |\r\n| **No hot-reload surface** | Bundled scripts do not implement or respond to a SkillsWatcher; skill updates require explicit `clawhub install` or `npm install` — no mid-session reload is possible |\r\n\r\n### AST07 — Update Drift · Severity: Medium\r\n\r\n> *Installed skills drift out of sync — either unpatched (leaving known CVEs open) or blindly auto-updated (potentially receiving malicious patches).*\r\n\r\n| Control | How Network-AI addresses it |\r\n|---|---|\r\n| **Exact version pinning** | npm `package.json` uses exact `\"version\": \"5.15.3\"` — no semver range specifiers; `clawhub install network-ai` pins to a specific published version |\r\n| **Zero transitive dependency drift** | All bundled Python scripts use Python stdlib only — `pip install` is never required; there are no third-party packages to drift, be compromised upstream, or introduce CVEs |\r\n| **Signed, tagged releases** | Every release is committed with a signed Git tag (`v5.7.x`); commit hash is verifiable against CHANGELOG.md; GitHub releases link tag → diff → changelog entry |\r\n| **Supply chain monitoring** | npm package continuously scored by Socket.dev (score A); any new dependency or permission change triggers an alert |\r\n| **No auto-update mechanism** | Updates require explicit user action (`clawhub install`, `npm install network-ai@latest`); there is no background updater or hot-reload path |\r\n| **CHANGELOG.md audit trail** | Every change — including docs-only patches — is tracked with version, date, and rationale; operators can diff any two versions to assess update risk before applying |\r\n\r\n## Security Scan Findings (ClawHub)\r\n\r\nThis skill is scanned on every publish. The following Notes are flagged by design and will recur on every scan. They are acknowledged and mitigated with documented controls — they are not bugs or vulnerabilities.\r\n\r\n| Finding | Severity | Why it recurs | Documented control |\r\n|---------|----------|---------------|--------------------|  \r\n| **ASI01** Agent Goal Hijack | High | Orchestrator skill performs multi-step decomposition and delegation by design | Use this skill only when multi-agent orchestration is desired; for simple requests the scope guard responds directly without decomposing |\r\n| **ASI03** Identity and Privilege Abuse (advisory tokens) | Medium | Grant tokens are advisory scoring outputs only — caller-supplied `--agent` identity is not cryptographically verified; skill explicitly warns tokens must not be used as real authorization for PAYMENTS, DATABASE, or FILE_EXPORT | Tokens are explicitly marked advisory in SKILL.md and source; require separate platform auth and human approval before any real database, payment, email, or export action |\r\n| **ASI03** Identity and Privilege Abuse (local grant state) | Low | The permission system creates persistent local state (`active_grants.json`, `audit_log.jsonl`, `.signing_key`) — security-relevant files that are purpose-aligned but accessible to anyone with `data/` access | Keep the skill directory private; back up or delete local grant state when no longer needed; do not share `data/` casually; restrict OS-level permissions on `data/` on shared machines |\r\n| **ASI03** Identity and Privilege Abuse (token integrity) | ~~High~~ Resolved | Token payload had no integrity protection — active_grants.json could be edited to forge elevated grants | Fixed in v5.5.2 — `check_permission.py` HMAC-SHA256 signs each grant (`_sig` field, stdlib `hmac`+`hashlib`, key at `data/.signing_key`); `validate_token.py` verifies before accepting; tampered tokens rejected with `\"Token signature invalid\"` |\r\n| **ASI03** Identity and Privilege Abuse (env-scoped paths) | ~~High~~ Resolved | `revoke_token.py` resolved `GRANTS_FILE`/`AUDIT_LOG` at module load from root `data/`, ignoring `NETWORK_AI_ENV` — revoking tokens in one env could silently miss env-specific grant files | Fixed in v5.5.1 — `_resolve_data_dir()` added, `--env` CLI argument introduced, paths re-resolved in `main()` before file I/O; consistent with `check_permission.py` and `validate_token.py` |\r\n| **ASI06** Memory and Context Poisoning (project context) | Medium | Persistent `data/project-context.json` is injected into every agent session by design — inaccurate or malicious context could steer future agent behavior | `_validate_context()` runs injection-pattern detection before every inject; do not store secrets/credentials; review `data/project-context.json` before use; clear `data/` between projects |\r\n| **ASI06** Memory and Context Poisoning (audit log free text) | Low | `justification` field in permission requests and `data/audit_log.jsonl` store agent-provided free-text strings locally — PII or secrets placed there will persist on disk | Do not include PII, secrets, or credentials in justification text; restrict access to `data/` on shared machines; rotate/delete `audit_log.jsonl` when no longer needed |\r\n| **ASI07** Insecure Inter-Agent Communication | High | Blackboard is local file-based; origin/identity depends on local file access, not authenticated messaging | Run in a trusted workspace; restrict file permissions on `data/`; review blackboard changes before relying on them for important decisions |\r\n| **ASI08** Cascading Failures | ~~High~~ Resolved | `os` was referenced before import in `swarm_guard.py` — fixed in v5.4.4; `import os` now present | Fixed — `swarm_guard.py` now imports `os` at module level; budget/health guard starts correctly |\r\n| **SkillSpector** Description-Behavior Mismatch (`McpStreamableServer` network exposure) | ~~Medium~~ Resolved | The trigger was `comment.txt` — an in-progress draft GitHub-issue note describing the optional `McpStreamableServer` HTTP/MCP server (a native server binding a TCP port) — being bundled into the published ClawHub skill. Its prose contradicted the bundle's 'zero network calls' / local-only positioning. | Fixed in v5.12.7 — `comment.txt` added to `.clawhubignore` (the ignore file ClawHub actually honours; the earlier `.clawignore` entry was never read by the CLI). New `scripts/clawhub-check.js` guard (`npm run clawhub:check`) fails the release if any non-allowlisted file would be bundled, so draft notes can no longer leak. The Python skill bundle itself still makes zero network calls; `McpStreamableServer` is in the optional npm package only and is never auto-started. |\r\n| **SkillSpector** Context-Inappropriate Capability (MCP control surface breadth) | ~~Medium~~ Resolved | Same root cause — `comment.txt` enumerated the HTTP MCP server's 22 privileged tools (blackboard write, token ops, agent_spawn, fsm_transition, audit_query), which the scanner read as a broad remote-control surface inside a local skill. | Fixed in v5.12.7 — `comment.txt` excluded from the bundle (see row above) and enforced by the `clawhub:check` guard. The HTTP MCP server itself remains opt-in: it requires a non-empty bearer secret before `listen()` binds (fail-closed), runs only via `NETWORK_AI_MCP_SECRET=<secret> npx network-ai-server`, binds `127.0.0.1` by default, and is documented in `SUPPLY_CHAIN.md §5a`. |\r\n| **SkillSpector** Context-Inappropriate Capability (`_load_signing_key()` token minting) | Medium, 92% | `scripts/check_permission.py` mints, HMAC-signs, persists, and lists grant tokens — a de facto local authorization artifact that downstream components may be tempted to treat as real credentials. | Token advisory-only warnings appear in source, SKILL.md, and SECURITY.md. Every grant response includes the advisory notice. Tokens are labeled `grant_{uuid4().hex}`; the HMAC signature only proves local origin, not external identity. Platform-level authentication is required before any destructive action (PAYMENTS, DATABASE, FILE_EXPORT). See ASI03 rows above. |\r\n| **SkillSpector** Intent-Code Divergence (`FILE_EXPORT` missing from `HIGH_RISK_RESOURCES`) | ~~Low~~ Resolved | Comment stated `FILE_EXPORT` requires `--confirm-high-risk` but `HIGH_RISK_RESOURCES` only contained `PAYMENTS` and `DATABASE`; file export requests could receive advisory grants without the extra acknowledgment | Fixed in v5.11.0 — `FILE_EXPORT` added to `HIGH_RISK_RESOURCES` in `check_permission.py`; now requires `--confirm-high-risk` consistent with the documented policy |\r\n| **SkillSpector** YARA `agent_skill_mcp_tool_poisoning_metadata` (MCP/tool metadata poisoning indicators) | ~~High~~ Resolved | SKILL.md frontmatter `description:` retained an older phrasing that referenced the optional TypeScript network server alongside \"zero network calls\" — a combination the YARA rule flags. A privacy-note sentence also used wording adjacent to file/data references that the exfiltration sub-rule flagged. | Fixed in v5.13.1 — frontmatter `description:` confirmed clean (server reference removed; TypeScript engine noted as parent repository only). Privacy note reworded to remove the flagged phrase. VirusTotal 64/64 clean throughout. |\r\n| **SkillSpector** Description-Behavior Mismatch (`ensure_data_dir()` ignoring env scope) | ~~Medium~~ Resolved | `ensure_data_dir()` always created the fixed top-level `data/` directory instead of the active env-specific path, breaking environment isolation when `NETWORK_AI_ENV` is set | Fixed in v5.11.0 — `ensure_data_dir()` now delegates to `_resolve_data_dir()` so audit log and grant files are always written to the correct env-scoped directory |\r\n\r\n## References\r\n\r\nThis skill is part of the larger [Network-AI](https://github.com/Jovancoding/Network-AI) project. See the repository for full documentation on the permission system, blackboard schema, and trust-level calculations.\n\nFile v5.15.3:_meta.json\n\n{\n  \"ownerId\": \"kn75j1xcebk74re38bv714kh1h81804p\",\n  \"slug\": \"network-ai\",\n  \"version\": \"5.15.3\",\n  \"publishedAt\": 1790546059456\n}\n\nFile v5.15.3:skill-card.md\n\n## Description:\n\nCoordinates local multi-agent workflows through a shared blackboard, budget checks, advisory permission grants, and persistent project context.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jovancoding](https://clawhub.ai/user/jovancoding)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and teams use this skill to coordinate agents in a trusted local workspace, track task budgets, share results, and carry project context between sessions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Persistent project context may carry misleading instructions into later agent sessions.\n\nMitigation: Use a trusted local workspace and review project context before injecting it into agent prompts.\n\nRisk: Locally stored grant tokens could be mistaken for authenticated authorization.\n\nMitigation: Treat grants as advisory; require separate identity checks and approval for sensitive actions.\n\nRisk: Justifications and stored context may retain personal data or secrets on disk.\n\nMitigation: Avoid putting secrets or personal data in these fields and restrict access to the local data directory.\n\nRisk: The optional server command may install an unverified package version.\n\nMitigation: Do not run it unless the package version is pinned and independently verified.\n\n## Reference(s):\n\n- [Network-AI ClawHub release](https://clawhub.ai/jovancoding/skills/network-ai)\n- [Network-AI homepage](https://network-ai.org)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Shell commands, Files]\n\n**Output Format:** [Markdown guidance and local command-line output]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Local blackboard and project-context files can persist between sessions.]\n\n## Skill Version(s):\n\n5.15.3 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v5.15.3:swarm-blackboard.md\n\n# Swarm Blackboard\nLast Updated: 2026-09-27T21:35:52.726Z\n\n## Active Tasks\n| TaskID | Agent | Status | Started | Description |\n|--------|-------|--------|---------|-------------|\n\n## Knowledge Cache\n### code:auth:implementation\n{\n  \"key\": \"code:auth:implementation\",\n  \"value\": {\n    \"files\": [\n      \"src/auth/login.ts\",\n      \"src/auth/middleware.ts\"\n    ],\n    \"linesChanged\": 245,\n    \"status\": \"complete\"\n  },\n  \"sourceAgent\": \"code_writer\",\n  \"timestamp\": \"2026-09-27T21:35:52.717Z\",\n  \"ttl\": null\n}\n\n### review:auth:feedback\n{\n  \"key\": \"review:auth:feedback\",\n  \"value\": {\n    \"approved\": true,\n    \"comments\": [\n      \"Good separation of concerns\",\n      \"Add input validation\"\n    ],\n    \"reviewer\": \"code_reviewer\"\n  },\n  \"sourceAgent\": \"code_reviewer\",\n  \"timestamp\": \"2026-09-27T21:35:52.721Z\",\n  \"ttl\": null\n}\n\n### test:auth:results\n{\n  \"key\": \"test:auth:results\",\n  \"value\": {\n    \"passed\": 42,\n    \"failed\": 0,\n    \"skipped\": 2,\n    \"coverage\": 87.3,\n    \"duration\": 3200\n  },\n  \"sourceAgent\": \"test_runner\",\n  \"timestamp\": \"2026-09-27T21:35:52.722Z\",\n  \"ttl\": null\n}\n\n### infra:k8s:config\n{\n  \"key\": \"infra:k8s:config\",\n  \"value\": {\n    \"replicas\": 3\n  },\n  \"sourceAgent\": \"devops_agent\",\n  \"timestamp\": \"2026-09-27T21:35:52.726Z\",\n  \"ttl\": null\n}\n\n## Coordination Signals\n## Execution History\n\nFile v5.15.3:skill.json\n\n{\r\n  \"name\": \"SwarmOrchestrator\",\r\n  \"version\": \"5.15.3\",\r\n  \"description\": \"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Workflow delegations via the host platform's sessions_send may invoke external model APIs.\",\r\n  \"author\": \"Network-AI Community\",\r\n  \"homepage\": \"https://network-ai.org\",\r\n  \"repository\": \"https://github.com/Jovancoding/Network-AI\",  \"source\": \"https://github.com/Jovancoding/Network-AI\",  \"license\": \"MIT\",\r\n  \"tags\": [\"multi-agent\", \"swarm\", \"orchestration\", \"governance\", \"audit\", \"permissions\", \"security\", \"blackboard\", \"budget\", \"local-only\"],\r\n  \"runtime\": \"python\",\r\n  \"entrypoint\": \"scripts/swarm_guard.py\",\r\n  \"gateway\": \"local\",\r\n  \"install\": {\r\n    \"description\": \"No install step required. All Python scripts use standard library only (zero third-party packages). Simply ensure python3 is available and run scripts directly from the scripts/ directory.\",\r\n    \"python\": {\r\n      \"requirements\": \"requirements.txt\",\r\n      \"requirements_note\": \"requirements.txt contains zero required packages. All scripts use Python stdlib only.\",\r\n      \"install_command\": \"# No install needed\",\r\n      \"scripts\": [\"scripts/blackboard.py\", \"scripts/swarm_guard.py\", \"scripts/check_permission.py\", \"scripts/validate_token.py\", \"scripts/revoke_token.py\", \"scripts/context_manager.py\"],\r\n      \"note\": \"All scripts run locally only. No external network calls. No third-party dependencies.\"\r\n    }\r\n  },\r\n  \"capabilities\": {\r\n    \"delegate_task\": {\r\n      \"description\": \"Delegate a task to a specialized sub-agent within the swarm\",\r\n      \"parameters\": {\r\n        \"targetAgent\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"description\": \"The identifier of the target agent to receive the task\"\r\n        },\r\n        \"taskPayload\": {\r\n          \"type\": \"object\",\r\n          \"required\": true,\r\n          \"description\": \"The task context, instructions, and any required data\"\r\n        },\r\n        \"priority\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"low\", \"normal\", \"high\", \"critical\"],\r\n          \"default\": \"normal\",\r\n          \"description\": \"Task priority level for queue ordering\"\r\n        },\r\n        \"timeout\": {\r\n          \"type\": \"number\",\r\n          \"default\": 30000,\r\n          \"description\": \"Maximum execution time in milliseconds\"\r\n        },\r\n        \"requiresAuth\": {\r\n          \"type\": \"boolean\",\r\n          \"default\": false,\r\n          \"description\": \"Whether this task requires a permission grant (via check_permission.py)\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"taskId\": { \"type\": \"string\" },\r\n          \"status\": { \"type\": \"string\" },\r\n          \"result\": { \"type\": \"any\" },\r\n          \"agentTrace\": { \"type\": \"array\" }\r\n        }\r\n      }\r\n    },\r\n    \"query_swarm_state\": {\r\n      \"description\": \"Query the current state of the agent swarm, including active tasks, blackboard contents, and agent availability\",\r\n      \"parameters\": {\r\n        \"scope\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"all\", \"agents\", \"tasks\", \"blackboard\", \"permissions\"],\r\n          \"default\": \"all\",\r\n          \"description\": \"The scope of state information to retrieve\"\r\n        },\r\n        \"agentFilter\": {\r\n          \"type\": \"array\",\r\n          \"items\": { \"type\": \"string\" },\r\n          \"description\": \"Optional list of agent IDs to filter results\"\r\n        },\r\n        \"includeHistory\": {\r\n          \"type\": \"boolean\",\r\n          \"default\": false,\r\n          \"description\": \"Include historical task execution data\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"timestamp\": { \"type\": \"string\" },\r\n          \"activeAgents\": { \"type\": \"array\" },\r\n          \"pendingTasks\": { \"type\": \"array\" },\r\n          \"blackboardSnapshot\": { \"type\": \"object\" },\r\n          \"permissionGrants\": { \"type\": \"array\" }\r\n        }\r\n      }\r\n    },\r\n    \"spawn_parallel_agents\": {\r\n      \"description\": \"Spawn multiple sub-agents in parallel for complex task decomposition\",\r\n      \"parameters\": {\r\n        \"tasks\": {\r\n          \"type\": \"array\",\r\n          \"required\": true,\r\n          \"items\": {\r\n            \"type\": \"object\",\r\n            \"properties\": {\r\n              \"agentType\": { \"type\": \"string\" },\r\n              \"taskPayload\": { \"type\": \"object\" }\r\n            }\r\n          },\r\n          \"description\": \"Array of parallel tasks to execute\"\r\n        },\r\n        \"synthesisStrategy\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"merge\", \"vote\", \"chain\", \"first-success\"],\r\n          \"default\": \"merge\",\r\n          \"description\": \"How to combine results from parallel agents\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"synthesizedResult\": { \"type\": \"any\" },\r\n          \"individualResults\": { \"type\": \"array\" },\r\n          \"executionMetrics\": { \"type\": \"object\" }\r\n        }\r\n      }\r\n    },\r\n    \"request_permission\": {\r\n      \"description\": \"Request permission for sensitive operations via the local permission gating script\",\r\n      \"parameters\": {\r\n        \"resourceType\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"DATABASE\", \"PAYMENTS\", \"EMAIL\", \"FILE_EXPORT\"],\r\n          \"required\": true,\r\n          \"description\": \"The type of protected resource being requested\"\r\n        },\r\n        \"justification\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"description\": \"Reason for requesting access\"\r\n        },\r\n        \"scope\": {\r\n          \"type\": \"string\",\r\n          \"description\": \"Specific scope of access needed\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"granted\": { \"type\": \"boolean\" },\r\n          \"grantToken\": { \"type\": \"string\" },\r\n          \"expiresAt\": { \"type\": \"string\" },\r\n          \"restrictions\": { \"type\": \"array\" }\r\n        }\r\n      }\r\n    },\r\n    \"update_blackboard\": {\r\n      \"description\": \"Write or update entries on the shared blackboard for cross-agent coordination\",\r\n      \"parameters\": {\r\n        \"key\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"description\": \"The blackboard entry key\"\r\n        },\r\n        \"value\": {\r\n          \"type\": \"any\",\r\n          \"required\": true,\r\n          \"description\": \"The data to store\"\r\n        },\r\n        \"ttl\": {\r\n          \"type\": \"number\",\r\n          \"description\": \"Time-to-live in seconds (optional)\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"success\": { \"type\": \"boolean\" },\r\n          \"previousValue\": { \"type\": \"any\" }\r\n        }\r\n      }\r\n    },\r\n    \"inject_context\": {\r\n      \"description\": \"Read the persistent project context file and return a formatted markdown block for injection into an agent system prompt. This is Layer 3 (long-lived) memory — architecture decisions, goals, tech stack, milestones, and banned approaches that every agent in the swarm should know.\",\r\n      \"parameters\": {},\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"contextMarkdown\": { \"type\": \"string\", \"description\": \"Formatted markdown block ready to prepend to an agent system prompt\" },\r\n          \"updatedAt\": { \"type\": \"string\", \"description\": \"ISO timestamp of last context update\" }\r\n        }\r\n      }\r\n    },\r\n    \"update_context\": {\r\n      \"description\": \"Persist a decision, milestone update, stack entry, goal, or banned approach to the project context file (Layer 3 memory). Changes are appended and survive across sessions.\",\r\n      \"parameters\": {\r\n        \"section\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"enum\": [\"decisions\", \"milestones\", \"stack\", \"goals\", \"banned\", \"project\"],\r\n          \"description\": \"The context section to update\"\r\n        },\r\n        \"add\": {\r\n          \"type\": \"any\",\r\n          \"description\": \"Item to append (JSON object or plain string, depending on section)\"\r\n        },\r\n        \"set\": {\r\n          \"type\": \"object\",\r\n          \"description\": \"Key-value pairs to merge into the section (use for stack and project)\"\r\n        },\r\n        \"complete\": {\r\n          \"type\": \"string\",\r\n          \"description\": \"Milestone name to mark completed (milestones section only)\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"success\": { \"type\": \"boolean\" },\r\n          \"section\": { \"type\": \"string\" }\r\n        }\r\n      }\r\n    }\r\n  },\r\n  \"permissions\": {\r\n    \"required\": [\"local_filesystem\", \"internal_skill_calls\"],\r\n    \"optional\": [\"external_api_access\"],\r\n    \"permissionGating\": {\r\n      \"enabled\": true,\r\n      \"protectedResources\": [\"DATABASE\", \"PAYMENTS\", \"EMAIL\", \"FILE_EXPORT\"],\r\n      \"note\": \"Permission checks are implemented locally via scripts/check_permission.py using weighted scoring (justification 40%, trust 30%, risk 30%). No external auth service.\"\r\n    }\r\n  },\r\n  \"dependencies\": {},\r\n  \"config\": {\r\n    \"blackboardPath\": \"./swarm-blackboard.md\",\r\n    \"maxParallelAgents\": null,\r\n    \"maxParallelAgents_default\": \"Infinity (no hard cap since v4.0.0 — set to a positive integer to enforce a limit)\",\r\n    \"defaultTimeout\": 30000,\r\n    \"enableTracing\": true\r\n  },\r\n  \"env\": {},\r\n  \"privacy\": {\r\n    \"audit_log\": {\r\n      \"path\": \"data/audit_log.jsonl\",\r\n      \"scope\": \"local-only\",\r\n      \"description\": \"Append-only JSONL audit log recording operation metadata (agentId, action, timestamp, outcome). Stays in local data/ directory. No data is sent externally by this skill.\",\r\n      \"contains\": [\"agentId\", \"action\", \"timestamp\", \"outcome\", \"resource\", \"justification (free-text, agent-provided)\"],\r\n      \"pii_warning\": \"Justification fields are free-text and may contain user-supplied content. Do not put PII, secrets, or credentials in justification strings. Restrict file permissions on data/ and rotate logs periodically.\",\r\n      \"does_not_contain\": [\"API keys\", \"external endpoints\"]\r\n    }\r\n  }\r\n}\n\nFile v5.15.3:requirements.txt\n\n# ============================================================================\r\n# ZERO DEPENDENCIES REQUIRED\r\n# ============================================================================\r\n# This file is documentation only. Do NOT run `pip install -r requirements.txt`.\r\n#\r\n# All 6 Python scripts use the standard library only:\r\n#   blackboard.py, swarm_guard.py, check_permission.py,\r\n#   validate_token.py, revoke_token.py, context_manager.py\r\n#\r\n# Standard library modules used:\r\n#   argparse, json, os, re, sys, time, hashlib, uuid, datetime, pathlib,\r\n#   typing, contextlib, fcntl (Unix; file-lock fallback on Windows)\r\n#\r\n# ── OPTIONAL (for development only, not required to run the skill) ──────────\r\n# filelock>=3.0.0  # Cross-platform file locking (Windows production)\r\n# mypy>=1.0.0      # Static type checking\r\n# pytest>=7.0.0    # Running the test suite\n\nArchive v5.15.2: 12 files, 63146 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34745b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2025b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nFile v5.15.2:SKILL.md\n\n---\r\nname: network-ai\r\ndescription: \"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle).\"\r\nmetadata:\r\n  openclaw:\r\n    emoji: \"\\U0001F41D\"\r\n    homepage: https://network-ai.org\r\n    capabilities:\r\n      filesystem: \"read/write — project root `swarm-blackboard.md` (blackboard state), `data/pending_changes/<id>.json` (WAL entries), `data/audit_log.jsonl`, `data/active_grants.json`, `data/.signing_key`, `data/project-context.json`, `data/task_tracking.json`, `data/agent_health.json`, `data/budget_tracking.json`. All paths are local; no data leaves the local filesystem. When NETWORK_AI_ENV is set, data paths are rooted at `data/<env>/` instead of `data/`. The `--path` argument in blackboard.py is validated against the project root at runtime — paths outside the project directory are rejected (CWE-22).\"\r\n      env_vars: \"read — NETWORK_AI_ENV (environment routing), NETWORK_AI_MCP_SECRET (MCP bearer auth), NETWORK_AI_MINIMAL (minimal-mode flag). No env vars are written.\"\r\n      shell_exec: \"optional — AgentRuntime (lib/agent-runtime.ts) with SandboxPolicy and ApprovalGate; disabled by default. Never auto-enabled by this skill. auto_approve must NOT be set in production (see auto_approve_warning below).\"\r\n      tcp_port: \"optional — MCP SSE server (bin/mcp-server.ts) binds 127.0.0.1 only when explicitly started by the operator. Requires a non-empty bearer-token secret. Never auto-started by this skill or any bundled Python script.\"\r\n    bundle_scope:\r\n      clawhub_python_scripts: \"Python stdlib only — scripts/*.py (blackboard.py, check_permission.py, context_manager.py, swarm_guard.py, validate_token.py, revoke_token.py). Zero network calls, zero subprocesses, zero third-party packages. This is the scope scanned by SkillSpector.\"\r\n      npm_full_package: \"The npm package (npm install network-ai) adds: TypeScript library modules, CLI (bin/cli.ts), and optional MCP SSE server (bin/mcp-server.ts). The MCP SSE server exposes a TCP port and is NOT activated by installing or importing the package — it must be explicitly started by the operator.\"\r\n    network_calls:\r\n      python_scripts: none\r\n      typescript_library: \"none — BYOC (bring your own client); zero outbound calls from library code; all LLM/API clients are injected by the caller\"\r\n      mcp_sse_server: \"optional — binds 127.0.0.1:<port> when explicitly started by the operator; all connections require a bearer-token secret (NETWORK_AI_MCP_SECRET); never auto-started\"\r\n    inter_agent_comms: \"none — this skill does not implement, invoke, or control inter-agent messaging or sessions_send. All coordination is via local file-based blackboard only.\"\r\n    sessions_send: \"NOT implemented or invoked by this skill. sessions_send is a host-platform built-in entirely outside this skill's control. See data-flow notice below.\"\r\n    sessions_ops: \"platform-provided — outside this skill's control\"\r\n    requires:\r\n      bins:\r\n        - python3\r\n      optional_bins: []\r\n    env: {}\r\n    privacy:\r\n      audit_log:\r\n        path: data/audit_log.jsonl\r\n        scope: local-only\r\n        description: \"Local append-only JSONL file recording operation metadata. No data leaves the machine.\"\r\n        pii_warning: \"Justification strings are truncated to 200 characters before being written to the audit log. Audit summary output (--audit-summary --json) omits justification text from returned entries. Do not include PII, credentials, or secrets in justification fields — the truncated text still persists on disk. Grant tokens are masked to a short prefix in all listing outputs; full tokens appear only at issuance time.\"\r\n      data_directory:\r\n        path: data/\r\n        scope: local-only\r\n        files: [\"audit_log.jsonl\", \"active_grants.json\", \".signing_key\", \"project-context.json\", \"task_tracking.json\", \"agent_health.json\", \"budget_tracking.json\", \"pending_changes/<id>.json\"]\r\n        description: \"All persistent state is local-only. No data leaves the local filesystem.\"\r\n      blackboard_file:\r\n        path: swarm-blackboard.md\r\n        scope: local-only\r\n        description: \"Shared coordination state written by scripts/blackboard.py (project root). Contains task results, grant tokens, status flags, and TTL-scoped cache entries. Access should be restricted to the local user running the swarm.\"\r\n      auto_approve_warning: \"ApprovalGate.auto_approve (lib/agent-runtime.ts) must NOT be enabled in production or untrusted environments. It is only appropriate in explicitly isolated CI/dev sandboxes where all commands executed by the runtime are known and trusted in advance.\"\r\n---\r\n\r\n# Swarm Orchestrator Skill\r\n\r\n> **Scope:** The bundled Python scripts (`scripts/*.py`) make **no network calls**, use only the Python standard library, and have **zero third-party dependencies**. Tokens are UUID-based (`grant_{uuid4().hex}`) stored in `data/active_grants.json`. Audit logging is plain JSONL (`data/audit_log.jsonl`).\r\n\r\n> **Advisory tokens notice:** Grant tokens issued by `check_permission.py` are **advisory scoring outputs only** — the caller-supplied `--agent` identity is not cryptographically verified. Downstream systems must not treat these tokens as authenticated credentials without adding a separate identity-verification step or human approval gate, especially for PAYMENTS, DATABASE, and FILE_EXPORT resources.\r\n\r\n> **Data-flow notice (host platform — not this skill):** This skill does NOT implement, invoke, or control `sessions_send` or any inter-agent messaging. All bundled Python scripts are local-only tools (budget guard, blackboard, permission scorer, context manager). If your platform has a `sessions_send` built-in, whether and how it is used is entirely the **host platform’s** responsibility and is outside this skill’s scope. If you need to prevent external network calls, disable or reroute delegation in your **platform settings** before installing this skill.\r\n\r\n> **Context file integrity:** The `context_manager.py inject` command now validates `data/project-context.json` for injection patterns and oversized fields before printing the context block. Review any warnings printed to stderr before passing the output to an agent system prompt.\r\n\r\n> **PII / sensitive-data warning:** The `justification` field in permission requests and the audit log (`data/audit_log.jsonl`) store free-text strings provided by agents. **Do not include PII, secrets, or credentials in justification text.** Consider restricting file permissions on `data/` or running this skill in an isolated workspace.\r\n\r\n## Setup\r\n\r\n**No pip install required.** All 6 scripts use Python standard library only — zero third-party packages.\r\n\r\n> **Note on `requirements.txt`:** The file exists for documentation purposes only — it lists the stdlib modules used and has **no required packages**. All listed deps are commented out as optional. You do not need to run `pip install -r requirements.txt`.\r\n\r\n```bash\r\n# Prerequisite: python3 (any version ≥ 3.8)\r\npython3 --version\r\n\r\n# That's it. Run any script directly:\r\npython3 scripts/blackboard.py list\r\npython3 scripts/swarm_guard.py budget-init --task-id \"task_001\" --budget 10000\r\n\r\n# Optional: for cross-platform file locking on Windows production hosts\r\npip install filelock  # only needed if you see locking issues on Windows\r\n```\r\n\r\nThe `data/` directory is created automatically on first run. No configuration files, environment variables, or credentials are required.\r\n\r\n> **Multi-environment support (v5.4.0):** All five Python scripts now read the `NETWORK_AI_ENV` environment variable at startup and accept a `--env <name>` CLI argument. When set, all data paths are routed to `data/<env>/` instead of the root `data/` directory. Use this to isolate dev, staging, and production state.\r\n>\r\n> ```bash\r\n> # Run against the dev environment\r\n> NETWORK_AI_ENV=dev python3 scripts/blackboard.py list\r\n> python3 scripts/check_permission.py --active-grants --env dev\r\n> ```\r\n\r\nMulti-agent coordination system for complex workflows requiring task delegation, parallel execution, and permission-controlled access to sensitive APIs.\r\n\r\n## 🎯 Orchestrator System Instructions\r\n\r\n**You are the Orchestrator Agent** responsible for decomposing complex tasks, delegating to specialized agents, and synthesizing results. Follow this protocol:\r\n\r\n### Core Responsibilities\r\n\r\n1. **DECOMPOSE** complex prompts into 3 specialized sub-tasks\r\n2. **DELEGATE** using the budget-aware handoff protocol\r\n3. **VERIFY** results on the blackboard before committing\r\n4. **SYNTHESIZE** final output only after all validations pass\r\n\r\n### Task Decomposition Protocol\r\n\r\nWhen you receive a complex request, decompose it into exactly **3 sub-tasks**:\r\n\r\n```\r\n┌─────────────────────────────────────────────────────────────────┐\r\n│                     COMPLEX USER REQUEST                        │\r\n└─────────────────────────────────────────────────────────────────┘\r\n                              │\r\n                              ▼\r\n        ┌─────────────────────┼─────────────────────┐\r\n        │                     │                     │\r\n        ▼                     ▼                     ▼\r\n┌───────────────┐   ┌───────────────┐   ┌───────────────┐\r\n│  SUB-TASK 1   │   │  SUB-TASK 2   │   │  SUB-TASK 3   │\r\n│ data_analyst  │   │ risk_assessor │   │strategy_advisor│\r\n│    (DATA)     │   │   (VERIFY)    │   │  (RECOMMEND)  │\r\n└───────────────┘   └───────────────┘   └───────────────┘\r\n        │                     │                     │\r\n        └─────────────────────┼─────────────────────┘\r\n                              ▼\r\n                    ┌───────────────┐\r\n                    │  SYNTHESIZE   │\r\n                    │ orchestrator  │\r\n                    └───────────────┘\r\n```\r\n\r\n**Decomposition Template:**\r\n```\r\nTASK DECOMPOSITION for: \"{user_request}\"\r\n\r\nSub-Task 1 (DATA): [data_analyst]\r\n  - Objective: Extract/process raw data\r\n  - Output: Structured JSON with metrics\r\n\r\nSub-Task 2 (VERIFY): [risk_assessor]  \r\n  - Objective: Validate data quality & compliance\r\n  - Output: Validation report with confidence score\r\n\r\nSub-Task 3 (RECOMMEND): [strategy_advisor]\r\n  - Objective: Generate actionable insights\r\n  - Output: Recommendations with rationale\r\n```\r\n\r\n### Budget Check Protocol\r\n\r\n**Run the budget interceptor before any task delegation:**\r\n\r\n```bash\r\n# Run this before delegating to any sub-agent\r\npython {baseDir}/scripts/swarm_guard.py intercept-handoff \\\r\n  --task-id \"task_001\" \\\r\n  --from orchestrator \\\r\n  --to data_analyst \\\r\n  --message \"Analyze Q4 revenue data\"\r\n```\r\n\r\n**Decision Logic:**\r\n```\r\nIF result.allowed == true:\r\n    → Budget check passed — proceed with the delegated task\r\n    → Note tokens_spent and remaining_budget\r\nELSE:\r\n    → STOP — budget exceeded or handoff limit reached\r\n    → Report blocked reason to user\r\n    → Consider: reduce scope or abort task\r\n```\r\n\r\n### Pre-Commit Verification Workflow\r\n\r\nBefore returning final results to the user:\r\n\r\n```bash\r\n# Step 1: Check all sub-task results on blackboard\r\npython {baseDir}/scripts/blackboard.py read \"task:001:data_analyst\"\r\npython {baseDir}/scripts/blackboard.py read \"task:001:risk_assessor\"\r\npython {baseDir}/scripts/blackboard.py read \"task:001:strategy_advisor\"\r\n\r\n# Step 2: Validate each result\r\npython {baseDir}/scripts/swarm_guard.py validate-result \\\r\n  --task-id \"task_001\" \\\r\n  --agent data_analyst \\\r\n  --result '{\"status\":\"success\",\"output\":{...},\"confidence\":0.85}'\r\n\r\n# Step 3: Supervisor review (checks all issues)\r\npython {baseDir}/scripts/swarm_guard.py supervisor-review --task-id \"task_001\"\r\n\r\n# Step 4: Only if APPROVED, commit final state\r\npython {baseDir}/scripts/blackboard.py write \"task:001:final\" \\\r\n  '{\"status\":\"SUCCESS\",\"output\":{...}}'\r\n```\r\n\r\n**Verdict Handling:**\r\n| Verdict | Action |\r\n|---------|--------|\r\n| `APPROVED` | Commit and return results to user |\r\n| `WARNING` | Review issues, fix if possible, then commit |\r\n| `BLOCKED` | Do NOT return results. Report failure. |\r\n\r\n---\r\n\r\n## The 3-Layer Memory Model\r\n\r\nEvery agent in the swarm operates with three memory layers, each with a different scope and lifetime:\r\n\r\n| Layer | Name | Lifetime | Managed by |\r\n|-------|------|----------|------------|\r\n| **1** | Agent context | Ephemeral — current task only | Platform (per-session) |\r\n| **2** | Blackboard | TTL-scoped — shared across agents | `scripts/blackboard.py` |\r\n| **3** | Project context | Persistent — survives all sessions | `scripts/context_manager.py` |\r\n\r\n### Layer 1 — Agent Context\r\nEach agent's own context window: the current task instructions, conversation history, and immediate working memory. Managed automatically by the OpenClaw/LLM platform. Nothing to configure.\r\n\r\n### Layer 2 — Blackboard (Shared Coordination State)\r\nA shared markdown file (`swarm-blackboard.md`) for real-time cross-agent coordination: task results, grant tokens, status flags, and TTL-scoped cache entries. Agents read and write via `scripts/blackboard.py`. Entries expire automatically.\r\n\r\n### Layer 3 — Project Context (Persistent Long-Term Memory)\r\nA JSON file (`data/project-context.json`) that holds information every agent should know, regardless of what session or task is running:\r\n- **Goals** — long-term objectives of the project\r\n- **Tech stack** — languages, frameworks, infrastructure\r\n- **Milestones** — completed, in-progress, and planned work\r\n- **Architecture decisions** — design choices and their rationales\r\n- **Banned approaches** — approaches that have been ruled out\r\n\r\n#### Initialising Project Context\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py init \\\r\n  --name \"MyProject\" \\\r\n  --description \"Multi-agent workflow automation\" \\\r\n  --version \"1.0.0\"\r\n```\r\n\r\n#### Injecting Context into an Agent System Prompt\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py inject\r\n```\r\n\r\nCopy the output block to the top of your agent's system prompt. Every agent that receives this block shares the same long-term project awareness.\r\n\r\n#### Recording a Decision\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section decisions \\\r\n  --add '{\"decision\": \"Use atomic blackboard commits\", \"rationale\": \"Prevent race conditions in parallel agents\"}'\r\n```\r\n\r\n#### Updating Milestones\r\n\r\n```bash\r\n# Mark a milestone complete\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section milestones --complete \"Ship v2.0\"\r\n\r\n# Add a planned milestone\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section milestones --add '{\"planned\": \"Integrate vector memory\"}'\r\n```\r\n\r\n#### Setting the Tech Stack\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section stack \\\r\n  --set '{\"language\": \"Python\", \"runtime\": \"Python 3.11\", \"framework\": \"SwarmOrchestrator\"}'\r\n```\r\n\r\n#### Banning an Approach\r\n\r\n```bash\r\npython {baseDir}/scripts/context_manager.py update \\\r\n  --section banned \\\r\n  --add \"Direct database writes from agent scripts (use permission gating)\"\r\n```\r\n\r\n---\r\n\r\n## When to Use This Skill\r\n\r\nUse this skill when the task requires **local, file-based** multi-agent coordination within a single trusted workspace. All 6 bundled Python scripts run locally with zero network calls, zero subprocesses, and zero third-party packages.\r\n\r\n### Use for\r\n- **Task Delegation** — decompose complex work into sub-tasks routed to named in-session agents (`data_analyst`, `strategy_advisor`, `risk_assessor`)\r\n- **Parallel Execution** — run multiple local agents simultaneously and synthesize results via the shared blackboard\r\n- **Permission Wall** — score and gate access to abstract resource labels (`DATABASE`, `PAYMENTS`, `EMAIL`, `FILE_EXPORT`) before performing sensitive local operations\r\n- **Shared Blackboard** — coordinate ephemeral task state across in-session agents via a persistent markdown file\r\n\r\n### Do NOT use for\r\n- External API or network service calls — the bundled Python scripts make **zero outbound network calls**\r\n- Production identity or authorization — grant tokens are **advisory scoring outputs only**, not authenticated credentials; do not use as real access control\r\n- Shell command execution or agent spawning — those capabilities require t\n\nArchive v5.15.1: 12 files, 63236 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34745b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2272b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nArchive v5.15.0: 12 files, 63282 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34745b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2447b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nArchive v5.14.0: 12 files, 63295 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34745b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2486b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nArchive v5.13.4: 12 files, 63294 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34745b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2439b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nArchive v5.13.3: 12 files, 63270 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34303b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2768b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nArchive v5.13.2: 12 files, 63150 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34303b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill-card.md (2501b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)\n\nArchive v5.13.1: 11 files, 61881 bytes\n\nFiles: requirements.txt (893b), scripts/blackboard.py (34303b), scripts/check_permission.py (35080b), scripts/context_manager.py (17825b), scripts/revoke_token.py (9004b), scripts/swarm_guard.py (48270b), scripts/validate_token.py (5733b), skill.json (10289b), SKILL.md (46540b), swarm-blackboard.md (1309b), _meta.json (130b)","readmeExcerpt":"Skill: Network-AI Owner: jovancoding Summary: Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Tags: audit:4.0.4, autogen:4.0.4, b","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\r\nname: network-ai\r\ndescription: \"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle).\"\r\nallowed-tools: Read Bash(python3 scripts/blackboard.py:*) Bash(python3 scripts/check_permission.py:*) Bash(python3 scripts/context_manager.py:*) Bash(python3 scripts/swarm_guard.py:*) Bash(python3 scripts/validate_token.py:*) Bash(python3 scripts/revoke_token.py:*)\r\nmetadata:\r\n  openclaw:\r\n    emoji: \"\\U0001F41D\"\r\n    homepage: https://network-ai.org\r\n    capabilities:\r\n      filesystem: \"read/write — project root `swarm-blackboard.md` (blackboard state), `data/pending_changes/<id>.json` (WAL entries), `data/audit_log.jsonl`, `data/active_grants.json`, `data/.signing_key`, `data/project-context.json`, `data/task_tracking.json`, `data/agent_health.json`, `data/budget_tracking.json`, `data/swarm_budgets.json`, `data/heartbeats.json`, `data/.blackboard.lock`. All paths are local; no data leaves the local filesystem. When NETWORK_AI_ENV is set, data paths are rooted at `data/<env>/` instead of `data/`. The `--path` argument in blackboard.py is validated against the project root at runtime — paths outside the project directory are rejected (CWE-22).\"\r\n      env_vars: \"read — NETWORK_AI_ENV only (environment routing for data paths). No other env vars are read and none are written.\"\r\n      tools: \"Only the six bundled scripts, run via python3 (see allowed-tools), plus reading local state files. No other commands, binaries, or tools are required or invoked.\"\r\n      shell_exec: \"none — the bundled scripts spawn no subprocesses and execute no shell commands.\"\r\n      tcp_port: \"none — the bundled scripts open no sockets and bind no ports.\"\r\n      autonomous_actions: \"none — every script is a single invocation by the calling agent or operator; nothing is scheduled, auto-approved, or run in the background. Permission grants are advisory scores the caller must enforce.\"\r\n    bundle_scope:\r\n      clawhub_python_scripts: \"Python stdlib only — scripts/*.py (blackboard.py, check_permission.py, context_manager.py, swarm_guard.py, validate_token.py, revoke_token.py). Zero network calls, zero subprocesses, zero third-party packages. This is the scope scanned by SkillSpector.\"\r\n      not_in_bundle: \"The separate npm package (network-ai: TypeScript library, CLI, optional MCP server) is not part of this skill. This skill never installs, imports, or starts it.\"\r\n    network_calls:\r\n      python_scripts: none\r\n    inter_agent_comms: \"none — this skill does not implement, invoke, or control inter-agent messaging or sessions_send. All coordination is via local file-based blackboard only.\"\r\n    sessions_send: \"NOT implemented or invoked by this skill. sessions_send is a host-platform built-in entirely ou"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn75j1xcebk74re38bv714kh1h81804p\",\n  \"slug\": \"network-ai\",\n  \"version\": \"5.15.4\",\n  \"publishedAt\": 1790698911387\n}"},{"path":"skill-card.md","content":"## Description:\n\nHelps agents coordinate multi-agent work through a local shared blackboard, permission checks, budget guards, and persistent project context.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jovancoding](https://clawhub.ai/user/jovancoding)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to coordinate tasks in a shared workspace, manage advisory permission grants and token budgets, and retain local project context.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Local coordination and audit files may expose task data or grant tokens to other workspace users.\n\nMitigation: Restrict access to the skill's data directory and shared blackboard to trusted users.\n\nRisk: Permission justifications and project context can persist sensitive information locally.\n\nMitigation: Do not include secrets or personal information in justifications or project context.\n\nRisk: Advisory grant tokens do not authenticate access to sensitive external services.\n\nMitigation: Use independent authentication and authorization for databases, payments, email, and exports.\n\n## Reference(s):\n\n- [Network-AI homepage](https://network-ai.org)\n- [Network-AI on ClawHub](https://clawhub.ai/jovancoding/skills/network-ai)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, JSON, Shell commands, Guidance]\n\n**Output Format:** [Text and Markdown guidance with Python command examples and structured local state]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Maintains local coordination, grant, audit, and project-context files.]\n\n## Skill Version(s):\n\n5.15.4 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"swarm-blackboard.md","content":"# Swarm Blackboard\nLast Updated: 2026-09-29T15:46:56.169Z\n\n## Active Tasks\n| TaskID | Agent | Status | Started | Description |\n|--------|-------|--------|---------|-------------|\n\n## Knowledge Cache\n### code:auth:implementation\n{\n  \"key\": \"code:auth:implementation\",\n  \"value\": {\n    \"files\": [\n      \"src/auth/login.ts\",\n      \"src/auth/middleware.ts\"\n    ],\n    \"linesChanged\": 245,\n    \"status\": \"complete\"\n  },\n  \"sourceAgent\": \"code_writer\",\n  \"timestamp\": \"2026-09-29T15:46:56.162Z\",\n  \"ttl\": null\n}\n\n### review:auth:feedback\n{\n  \"key\": \"review:auth:feedback\",\n  \"value\": {\n    \"approved\": true,\n    \"comments\": [\n      \"Good separation of concerns\",\n      \"Add input validation\"\n    ],\n    \"reviewer\": \"code_reviewer\"\n  },\n  \"sourceAgent\": \"code_reviewer\",\n  \"timestamp\": \"2026-09-29T15:46:56.166Z\",\n  \"ttl\": null\n}\n\n### test:auth:results\n{\n  \"key\": \"test:auth:results\",\n  \"value\": {\n    \"passed\": 42,\n    \"failed\": 0,\n    \"skipped\": 2,\n    \"coverage\": 87.3,\n    \"duration\": 3200\n  },\n  \"sourceAgent\": \"test_runner\",\n  \"timestamp\": \"2026-09-29T15:46:56.167Z\",\n  \"ttl\": null\n}\n\n### infra:k8s:config\n{\n  \"key\": \"infra:k8s:config\",\n  \"value\": {\n    \"replicas\": 3\n  },\n  \"sourceAgent\": \"devops_agent\",\n  \"timestamp\": \"2026-09-29T15:46:56.169Z\",\n  \"ttl\": null\n}\n\n## Coordination Signals\n## Execution History"},{"path":"skill.json","content":"{\r\n  \"name\": \"SwarmOrchestrator\",\r\n  \"version\": \"5.15.4\",\r\n  \"description\": \"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Workflow delegations via the host platform's sessions_send may invoke external model APIs.\",\r\n  \"author\": \"Network-AI Community\",\r\n  \"homepage\": \"https://network-ai.org\",\r\n  \"repository\": \"https://github.com/Jovancoding/Network-AI\",  \"source\": \"https://github.com/Jovancoding/Network-AI\",  \"license\": \"MIT\",\r\n  \"tags\": [\"multi-agent\", \"swarm\", \"orchestration\", \"governance\", \"audit\", \"permissions\", \"security\", \"blackboard\", \"budget\", \"local-only\"],\r\n  \"runtime\": \"python\",\r\n  \"entrypoint\": \"scripts/swarm_guard.py\",\r\n  \"gateway\": \"local\",\r\n  \"install\": {\r\n    \"description\": \"No install step required. All Python scripts use standard library only (zero third-party packages). Simply ensure python3 is available and run scripts directly from the scripts/ directory.\",\r\n    \"python\": {\r\n      \"requirements\": \"requirements.txt\",\r\n      \"requirements_note\": \"requirements.txt contains zero required packages. All scripts use Python stdlib only.\",\r\n      \"install_command\": \"# No install needed\",\r\n      \"scripts\": [\"scripts/blackboard.py\", \"scripts/swarm_guard.py\", \"scripts/check_permission.py\", \"scripts/validate_token.py\", \"scripts/revoke_token.py\", \"scripts/context_manager.py\"],\r\n      \"note\": \"All scripts run locally only. No external network calls. No third-party dependencies.\"\r\n    }\r\n  },\r\n  \"capabilities\": {\r\n    \"delegate_task\": {\r\n      \"description\": \"Delegate a task to a specialized sub-agent within the swarm\",\r\n      \"parameters\": {\r\n        \"targetAgent\": {\r\n          \"type\": \"string\",\r\n          \"required\": true,\r\n          \"description\": \"The identifier of the target agent to receive the task\"\r\n        },\r\n        \"taskPayload\": {\r\n          \"type\": \"object\",\r\n          \"required\": true,\r\n          \"description\": \"The task context, instructions, and any required data\"\r\n        },\r\n        \"priority\": {\r\n          \"type\": \"string\",\r\n          \"enum\": [\"low\", \"normal\", \"high\", \"critical\"],\r\n          \"default\": \"normal\",\r\n          \"description\": \"Task priority level for queue ordering\"\r\n        },\r\n        \"timeout\": {\r\n          \"type\": \"number\",\r\n          \"default\": 30000,\r\n          \"description\": \"Maximum execution time in milliseconds\"\r\n        },\r\n        \"requiresAuth\": {\r\n          \"type\": \"boolean\",\r\n          \"default\": false,\r\n          \"description\": \"Whether this task requires a permission grant (via check_permission.py)\"\r\n        }\r\n      },\r\n      \"returns\": {\r\n        \"type\": \"object\",\r\n        \"properties\": {\r\n          \"taskId\": { \"type\": \"string\" },\r\n          \"status\": { \"type\": \"string\" },\r\n          \"result\": { \"type\": "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Skill: Network-AI Owner: jovancoding Summary: Local Python orchestration skill: multi-agent workflows via shared blackboard file, permission gating, token budget scripts, and persistent project context. The bundled Python scripts make no network calls and have zero third-party dependencies. The parent repository also contains a TypeScript engine (not included in this skill bundle). Tags: audit:4.0.4, autogen:4.0.4, b","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1758,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:06:51.147Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T03:06:51.147Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T18:06:10.976Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}