{"id":"a8a84fe6-b2e3-4381-8faf-4e19fb4c05e0","entityType":"agent","slug":"clawhub-offbyonce-stigmem-node","name":"Stigmem","canonicalUrl":"https://www.xpersona.co/agent/clawhub-offbyonce-stigmem-node","canonicalPath":"/agent/clawhub-offbyonce-stigmem-node","generatedAt":"2026-10-11T17:41:49.157Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T14:01:48.729Z","emptyReason":null},"description":"Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node. Skill: Stigmem Owner: offbyonce Summary: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node. Tags: latest:1.0.9 Version history: v1.0.9 | 2026-05-24T21:46:20.279Z | user - Documentation: adds a \"Compatible Stigmem plugins\" section for OpenClaw operators, pointing to the six published Stigmem plugin packages and clarifying that plugin i","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s179kesrpw7r6vgz4egmxqja458610ra:stigmem-node","sourceUrl":"https://clawhub.ai/offbyonce/stigmem-node","homepage":"https://clawhub.ai/offbyonce/skills/stigmem-node","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/offbyonce/stigmem-node","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/offbyonce/skills/stigmem-node","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node. Skill: Stigmem Owner: off"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:01:48.729Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:01:48.729Z","emptyReason":null},"stars":null,"forks":null,"downloads":1053,"packageName":null,"latestVersion":"1.0.9","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:01:48.666Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T14:01:48.729Z","lastCrawledAt":"2026-10-11T14:01:48.666Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T14:01:48.666Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.9","createdAt":"2026-05-24T21:46:20.279Z","changelog":"- Documentation: adds a \"Compatible Stigmem plugins\" section for OpenClaw operators, pointing to the six published Stigmem plugin packages and clarifying that plugin installation and enablement happen on the Stigmem node side, not inside the OpenClaw skill environment. - Documentation: refreshes the alpha-status note for the v0.9.0a9 ClawHub artifact refresh.","fileCount":4,"zipByteSize":8855},{"version":"1.0.8","createdAt":"2026-05-10T21:47:31.012Z","changelog":"- **Source directory renamed** from `adapters/openclaw/clawhub-skill/` to `adapters/openclaw/skill/`. The `clawhub-` prefix was the root cause of two publish-time inference bugs: (a) display-name inferred as \"Clawhub Skill\" when `--name` was omitted (regressed v1.0.3 and v1.0.6), (b) slug inferred as `clawhub-skill` which trips ClawHub's protected-namespace check (\"clawhub-*\"), forcing every publish to pass `--slug stigmem-node` explicitly. Both worked around in CI via PR #82's hard-coded flags; this rename removes the inference dependency at the source. The CI flags are now belt-and-suspenders rather than required workarounds. Skill behavior unchanged; manifest content unchanged; this is a source-tree refactor only.","fileCount":3,"zipByteSize":9101},{"version":"1.0.7","createdAt":"2026-05-10T08:58:04.076Z","changelog":"Fix: corrected skill display name (was 'Clawhub Skill' on v1.0.6, now 'Stigmem'). Same regression as v1.0.3 — clawhub CLI infers display name from the directory name (clawhub-skill/) when --name is not passed. Permanent fix in this release: a CI workflow now hard-codes --name on every publish; v0.9.0a2 will additionally rename the source directory.","fileCount":3,"zipByteSize":8792},{"version":"1.0.6","createdAt":"2026-05-10T08:49:18.671Z","changelog":"Updated install.package pin to stigmem-py>=0.9.0a1,<1.0.0 to match the v0.9.0a1 reset of the stigmem package line. See retraction post: https://dev.to/offbyonce/walking-back-our-v10-announcement-resetting-to-v090a1-as-the-first-build-al0","fileCount":3,"zipByteSize":8395},{"version":"1.0.5","createdAt":"2026-05-04T09:20:14.440Z","changelog":"Fix: corrected documentation URLs to include ReadTheDocs path prefix (/en/latest/) — all links now resolve correctly.","fileCount":3,"zipByteSize":7855},{"version":"1.0.4","createdAt":"2026-05-04T09:14:55.283Z","changelog":"Fix: corrected documentation domain — all doc links now point to docs.stigmem.dev (not stigmem.dev).","fileCount":3,"zipByteSize":7811},{"version":"1.0.3","createdAt":"2026-05-04T08:55:31.738Z","changelog":"Fix: corrected skill display name (was showing 'Clawhub Skill' due to folder name, now correctly shows 'Stigmem').","fileCount":3,"zipByteSize":7768},{"version":"1.0.2","createdAt":"2026-05-04T08:43:00.264Z","changelog":"Fixed homepage and documentation URLs (now point to the OpenClaw connector guide). Expanded security section covering five risk areas with concrete mitigations: prompt injection, stale/poisoned facts, identity scope, dependency pinning, and federation scope.","fileCount":3,"zipByteSize":7727}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s179kesrpw7r6vgz4egmxqja458610ra:stigmem-node","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T17:41:49.153Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-offbyonce-stigmem-node/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T14:01:48.729Z","emptyReason":null},"readme":"Skill: Stigmem\n\nOwner: offbyonce\n\nSummary: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\n\nTags: latest:1.0.9\n\nVersion history:\n\nv1.0.9 | 2026-05-24T21:46:20.279Z | user\n\n- Documentation: adds a \"Compatible Stigmem plugins\" section for OpenClaw\n  operators, pointing to the six published Stigmem plugin packages and\n  clarifying that plugin installation and enablement happen on the Stigmem node\n  side, not inside the OpenClaw skill environment.\n- Documentation: refreshes the alpha-status note for the v0.9.0a9 ClawHub\n  artifact refresh.\n\nv1.0.8 | 2026-05-10T21:47:31.012Z | user\n\n- **Source directory renamed** from `adapters/openclaw/clawhub-skill/` to `adapters/openclaw/skill/`. The `clawhub-` prefix was the root cause of two publish-time inference bugs: (a) display-name inferred as \"Clawhub Skill\" when `--name` was omitted (regressed v1.0.3 and v1.0.6), (b) slug inferred as `clawhub-skill` which trips ClawHub's protected-namespace check (\"clawhub-*\"), forcing every publish to pass `--slug stigmem-node` explicitly. Both worked around in CI via PR #82's hard-coded flags; this rename removes the inference dependency at the source. The CI flags are now belt-and-suspenders rather than required workarounds. Skill behavior unchanged; manifest content unchanged; this is a source-tree refactor only.\n\nv1.0.7 | 2026-05-10T08:58:04.076Z | user\n\nFix: corrected skill display name (was 'Clawhub Skill' on v1.0.6, now 'Stigmem'). Same regression as v1.0.3 — clawhub CLI infers display name from the directory name (clawhub-skill/) when --name is not passed. Permanent fix in this release: a CI workflow now hard-codes --name on every publish; v0.9.0a2 will additionally rename the source directory.\n\nv1.0.6 | 2026-05-10T08:49:18.671Z | user\n\nUpdated install.package pin to stigmem-py>=0.9.0a1,<1.0.0 to match the v0.9.0a1 reset of the stigmem package line. See retraction post: https://dev.to/offbyonce/walking-back-our-v10-announcement-resetting-to-v090a1-as-the-first-build-al0\n\nv1.0.5 | 2026-05-04T09:20:14.440Z | user\n\nFix: corrected documentation URLs to include ReadTheDocs path prefix (/en/latest/) — all links now resolve correctly.\n\nv1.0.4 | 2026-05-04T09:14:55.283Z | user\n\nFix: corrected documentation domain — all doc links now point to docs.stigmem.dev (not stigmem.dev).\n\nv1.0.3 | 2026-05-04T08:55:31.738Z | user\n\nFix: corrected skill display name (was showing 'Clawhub Skill' due to folder name, now correctly shows 'Stigmem').\n\nv1.0.2 | 2026-05-04T08:43:00.264Z | user\n\nFixed homepage and documentation URLs (now point to the OpenClaw connector guide). Expanded security section covering five risk areas with concrete mitigations: prompt injection, stale/poisoned facts, identity scope, dependency pinning, and federation scope.\n\nv1.0.1 | 2026-05-03T21:32:32.471Z | user\n\nSecurity: pin dep to >=1.0.0,<2.0.0; remove caller-supplied source from emit_decision; sanitize fact values before prompt injection; add security notes to docs.\n\nv1.0.0 | 2026-05-03T21:23:18.244Z | user\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces for OpenClaw agents\n\nArchive index:\n\nArchive v1.0.9: 4 files, 8855 bytes\n\nFiles: adapter.py (427b), skill-card.md (2615b), SKILL.md (16843b), _meta.json (131b)\n\nFile v1.0.9:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.9\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n        - STIGMEM_API_KEY\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: true\n        description: \"Least-privilege API key for the Stigmem node. Required by from_env(); rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n      - name: STIGMEM_OPENCLAW_ALLOWED_HANDOFF_TARGETS\n        required: false\n        description: \"Comma-separated agent: entity URI allowlist for handoff and escalation targets. The source entity is always allowed.\"\n    install:\n      - kind: uv\n        package: \"stigmem-openclaw>=0.9.0a9,<1.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n> **Alpha status.** This source copy is prepared for the v0.9.0a9 ClawHub\n> artifact refresh, which adds plugin-awareness pointers. The OpenClaw skill\n> remains available for v0.9.0aN evaluation only, not as a recommended\n> production integration. The adapter separates retrieved\n> content from\n> instruction-channel recall output and exports a required system prompt\n> directive, but the broader ADR-003 hardening line still needs MCP parity,\n> operator docs, and feedback-loop controls before high-stakes production use. See\n> [LIMITATIONS.md §9](https://github.com/eidetic-labs/stigmem/blob/main/LIMITATIONS.md#9-running-the-openclaw-bundled-adapter-as-is).\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable append-only `roadmap:decision` facts for significant architectural choices; dedupe externally before calling if your workflow needs at-most-once semantics.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Set `STIGMEM_API_KEY` to a least-privilege key for the node.\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n4. Set `STIGMEM_OPENCLAW_ALLOWED_HANDOFF_TARGETS` to any additional `agent:`\n   entity URIs this deployment may hand off or escalate to.\n\n## Usage\n\n`adapter.py` is bundled with this skill as a compatibility shim. Import it directly from the skill directory; the install spec above supplies the packaged `stigmem-openclaw` adapter and its `stigmem-py` dependency.\n\n```python\nfrom adapter import OpenClawStigmemAdapter, SYSTEM_PROMPT_DIRECTIVE\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\n    \"\\n\\n\" + SYSTEM_PROMPT_DIRECTIVE + \"\\n\\n\" + ctx.summary if ctx else \"\"\n)\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for the pre-reset design work load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n    idempotency_key=\"session-2026-05-02-abc\",\n)\n```\n\n## Compatible Stigmem plugins\n\nYour Stigmem node can be extended with opt-in plugins that change what this\nOpenClaw skill sees when it calls boot, handoff, decision, and escalation.\nThe plugins are installed and enabled on the Stigmem node, not on the OpenClaw\nagent side, but their effects are visible to this skill's recall and fact-write\nsurfaces.\n\n| Plugin | Effect on this skill |\n|---|---|\n| [`stigmem-plugin-multi-tenant`](https://pypi.org/project/stigmem-plugin-multi-tenant/) | Boot context, handoff, decision, and escalation become tenant-scoped on the node side |\n| [`stigmem-plugin-source-attestation`](https://pypi.org/project/stigmem-plugin-source-attestation/) | Recalled facts include source trust scores; low-trust sources can be filtered or quarantined by the node |\n| [`stigmem-plugin-memory-garden-acl`](https://pypi.org/project/stigmem-plugin-memory-garden-acl/) | Memory-garden membership controls which gardens the boot handshake reads from |\n| [`stigmem-plugin-tombstones`](https://pypi.org/project/stigmem-plugin-tombstones/) | Tombstoned facts are filtered from recall results and boot context |\n| [`stigmem-plugin-time-travel`](https://pypi.org/project/stigmem-plugin-time-travel/) | Historical handoff and decision queries become available against the node |\n| [`stigmem-plugin-lazy-instruction-discovery`](https://pypi.org/project/stigmem-plugin-lazy-instruction-discovery/) | Boot context becomes lazier: instructions are resolved on demand from the node |\n\nThese plugins do not require changes to this OpenClaw skill or your agent code.\nWhether any are active depends on how your Stigmem node is configured. Ask your\nStigmem node operator whether plugins are enabled, or inspect `stigmem doctor`\noutput on the node side.\n\nSee [docs.stigmem.dev/en/latest/docs/plugins](https://docs.stigmem.dev/en/latest/docs/plugins)\nfor the full plugin catalog, per-plugin enablement, and security carve-outs.\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and formats them as untrusted content for the agent's system prompt. A compromised or misconfigured node can craft fact values that attempt to redirect agent goals.\n\n**Current mitigations:**\n- `ctx.summary` is wrapped in explicit `UNTRUSTED STIGMEM CONTENT` delimiters.\n- `SYSTEM_PROMPT_DIRECTIVE` tells the model that retrieved context is data, not instructions.\n- `recall_context()` consumes channel-separated recall output and keeps instruction-channel facts out of the content summary.\n\nThese mitigations do **not** make retrieved memory safe to treat as instructions.\nThey define the adapter contract for content-channel recall; broader ADR-003\nhardening continues in the future hardened-core line.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for evaluation. Do not point\n  high-stakes agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope\n  namespace, not your primary operational node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The adapter records decisions append-only; dedupe externally before calling if repeated writes are a risk in your workflow.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g.,\n  `agent:openclaw-eval-alice`). The generic default `agent:openclaw` should not\n  be shared across deployments because facts from different deployments become\n  indistinguishable in the fact graph.\n- Set `STIGMEM_OPENCLAW_ALLOWED_HANDOFF_TARGETS` to the exact downstream agents\n  this deployment may contact. Unknown, malformed, or non-`agent:` targets are\n  rejected before any handoff or escalation writes occur.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-openclaw>=0.9.0a9,<1.0.0`) so compatible alpha-line updates are picked up automatically. A future alpha or beta release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for any\n  repeatable evaluation environment rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\n`:latest` is fine for trying things out; for repeatable evaluation swap to a\npinned version tag (`:0.9.0a9`) or a `@sha256:<digest>` pin — the install guide\non docs.stigmem.dev has the full tag-selection table.\n\nFull setup guide and federation docs: [docs.stigmem.dev/en/latest/docs/guides/federation](https://docs.stigmem.dev/en/latest/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://docs.stigmem.dev/en/latest/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n> **Note on versioning.** This ClawHub skill is independently versioned along its own semver line. The skill's `version:` (currently 1.0.x) tracks the skill's ClawHub release history; the dependency on stigmem is expressed via the `install.package` pin (currently `stigmem-openclaw>=0.9.0a9,<1.0.0`). The bare-stigmem version line was reset to v0.9.0a1 in May 2026 — see [the retraction post](https://dev.to/offbyonce/walking-back-our-v10-announcement-resetting-to-v090a1-as-the-first-build-al0) — but ClawHub registry rules require monotonically increasing skill versions, so the skill stays on its 1.0.x line. The two version surfaces are intentionally decoupled.\n\n### v1.0.9\n\n- Documentation: adds a \"Compatible Stigmem plugins\" section for OpenClaw\n  operators, pointing to the six published Stigmem plugin packages and\n  clarifying that plugin installation and enablement happen on the Stigmem node\n  side, not inside the OpenClaw skill environment.\n- Documentation: refreshes the alpha-status note for the v0.9.0a9 ClawHub\n  artifact refresh.\n\n### v1.0.8\n\n- **Source directory renamed** from `adapters/openclaw/clawhub-skill/` to `adapters/openclaw/skill/`. The `clawhub-` prefix was the root cause of two publish-time inference bugs: (a) display-name inferred as \"Clawhub Skill\" when `--name` was omitted (regressed v1.0.3 and v1.0.6), (b) slug inferred as `clawhub-skill` which trips ClawHub's protected-namespace check (\"clawhub-*\"), forcing every publish to pass `--slug stigmem-node` explicitly. Both worked around in CI via PR #82's hard-coded flags; this rename removes the inference dependency at the source. The CI flags are now belt-and-suspenders rather than required workarounds. Skill behavior unchanged; manifest content unchanged; this is a source-tree refactor only.\n\n### v0.9.0a9 ClawHub artifact refresh\n\n- Documentation: explicitly frames the OpenClaw skill as alpha/evaluation-only.\n  This is the source state prepared for the a3 ClawHub publish.\n- Documentation: corrects the dependency-pinning section to the alpha line\n  (`stigmem-openclaw>=0.9.0a9,<1.0.0`) and avoids claiming presentation-layer\n  sanitization is a complete prompt-injection defense.\n\n### v1.0.7\n\n- Fix: corrected skill display name (was 'Clawhub Skill' on v1.0.6, now 'Stigmem'). Same regression as v1.0.3 — the publish CLI infers the display name from the directory name (which was `adapters/openclaw/clawhub-skill/` at the time; renamed in v1.0.8) when `--name` is not explicitly passed. The v1.0.6 publish was driven by a manual CLI invocation that omitted the flag. Permanent fix: a new `.github/workflows/clawhub-publish.yml` automates the publish on every push to main that touches the skill directory, with `--name \"Stigmem\"` and `--slug stigmem-node` hard-coded so neither can drift again. v1.0.8 additionally renamed the source directory to drop the inference dependency entirely.\n\n### v1.0.6\n\n- Updated `install.package` pin from `stigmem-py>=1.0.0,<2.0.0` to `stigmem-py>=0.9.0a1,<1.0.0` to match the v0.9.0a1 reset of the stigmem package line. This is the contract that ties the skill to a specific stigmem release line. Adopters who installed earlier ClawHub skill versions (1.0.0–1.0.5) had a `stigmem-py>=1.0.0rc1` dependency that was end-to-end uninstallable (see retraction post, \"What the audit found\"); v1.0.6 is the first installable skill release in this respect.\n- Documentation: added the retraction-post reference and the independent-versioning note above.\n- **Note (added 2026-05-10):** v1.0.6 shipped with an incorrect display name (\"Clawhub Skill\" instead of \"Stigmem\") because the publish-time CLI invocation omitted the `--name` flag. Adopters who installed v1.0.6 see the wrong display name in `clawhub list` etc. Upgrade to v1.0.7 for the corrected display name; the underlying skill behavior is unchanged.\n\n### v1.0.5\n\n- Fix: corrected documentation URLs to include ReadTheDocs path prefix (`/en/latest/`); all links now resolve correctly.\n\n### v1.0.4\n\n- Fix: corrected documentation domain to `docs.stigmem.dev`.\n\n### v1.0.3\n\n- Fix: corrected skill display name (was \"Clawhub Skill\", now \"Stigmem\").\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/eidetic-labs/stigmem](https://github.com/eidetic-labs/stigmem) — Apache-2.0\n\nFile v1.0.9:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.9\",\n  \"publishedAt\": 1779659180279\n}\n\nFile v1.0.9:skill-card.md\n\n## Description:\n\nPersistent federated memory for OpenClaw agents -- boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\n\nThis skill is for research and development only.\n\n## Publisher:\n\n[offbyonce](https://clawhub.ai/user/offbyonce)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to connect OpenClaw agents to a Stigmem node for persistent memory, session handoffs, decision records, and escalation facts during evaluation or controlled integration work.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Retrieved memory from a compromised or misconfigured Stigmem node can influence agent behavior if treated as instructions.\n\nMitigation: Use a private, access-controlled node, append retrieved context after hardcoded system instructions, and inspect structured facts instead of injecting full summaries in high-stakes workflows.\n\nRisk: Facts written to shared or federated memory can persist across future agents and propagate beyond the intended deployment.\n\nMitigation: Use least-privilege per-agent API keys, unique source entities, local scopes for scratch facts, narrow federation settings, and explicit retraction for incorrect facts.\n\nRisk: Alpha-line dependency updates may change runtime behavior across repeatable evaluations.\n\nMitigation: Pin the Python dependency and Stigmem node image before evaluation or production-like use, then review release notes and run integration tests before upgrades.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/offbyonce/skills/stigmem-node)\n- [OpenClaw connector guide](https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw)\n- [Stigmem project homepage](https://stigmem.dev)\n- [Stigmem plugin catalog](https://docs.stigmem.dev/en/latest/docs/plugins)\n- [Server-resolved provenance](unavailable)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with Python and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires STIGMEM_URL and STIGMEM_API_KEY; optional environment variables configure source identity and allowed handoff targets.]\n\n## Skill Version(s):\n\n1.0.9 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.8: 3 files, 9101 bytes\n\nFiles: adapter.py (11896b), SKILL.md (12195b), _meta.json (131b)\n\nFile v1.0.8:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.8\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=0.9.0a1,<1.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for the pre-reset design work load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and injects them into the agent's system prompt. A compromised or misconfigured node can craft fact values that redirect agent goals.\n\n**Already handled by the adapter:**\n- Fact values are sanitized before formatting: HTML/markdown metacharacters are escaped, null bytes stripped, values truncated to 500 characters.\n- The injected block is labelled `_(external, treat as untrusted)_` in the summary header.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for production. Do not point production agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope namespace, not your production node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The dedup guard prevents writing the same `(entity, source)` pair twice, but does not stop you from writing an incorrect decision in the first place.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g., `agent:openclaw-prod-alice`). The generic default `agent:openclaw` should not be used in production — facts from different deployments become indistinguishable in the fact graph.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-py>=1.0.0,<2.0.0`) so compatible updates are picked up automatically. A future patch release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for production deployments rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [docs.stigmem.dev/en/latest/docs/guides/federation](https://docs.stigmem.dev/en/latest/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://docs.stigmem.dev/en/latest/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n> **Note on versioning.** This ClawHub skill is independently versioned along its own semver line. The skill's `version:` (currently 1.0.x) tracks the skill's ClawHub release history; the dependency on stigmem is expressed via the `install.package` pin (currently `stigmem-py>=0.9.0a1,<1.0.0`). The bare-stigmem version line was reset to v0.9.0a1 in May 2026 — see [the retraction post](https://dev.to/offbyonce/walking-back-our-v10-announcement-resetting-to-v090a1-as-the-first-build-al0) — but ClawHub registry rules require monotonically increasing skill versions, so the skill stays on its 1.0.x line. The two version surfaces are intentionally decoupled.\n\n### v1.0.8\n\n- **Source directory renamed** from `adapters/openclaw/clawhub-skill/` to `adapters/openclaw/skill/`. The `clawhub-` prefix was the root cause of two publish-time inference bugs: (a) display-name inferred as \"Clawhub Skill\" when `--name` was omitted (regressed v1.0.3 and v1.0.6), (b) slug inferred as `clawhub-skill` which trips ClawHub's protected-namespace check (\"clawhub-*\"), forcing every publish to pass `--slug stigmem-node` explicitly. Both worked around in CI via PR #82's hard-coded flags; this rename removes the inference dependency at the source. The CI flags are now belt-and-suspenders rather than required workarounds. Skill behavior unchanged; manifest content unchanged; this is a source-tree refactor only.\n\n### v1.0.7\n\n- Fix: corrected skill display name (was 'Clawhub Skill' on v1.0.6, now 'Stigmem'). Same regression as v1.0.3 — the publish CLI infers the display name from the directory name (which was `adapters/openclaw/clawhub-skill/` at the time; renamed in v1.0.8) when `--name` is not explicitly passed. The v1.0.6 publish was driven by a manual CLI invocation that omitted the flag. Permanent fix: a new `.github/workflows/clawhub-publish.yml` automates the publish on every push to main that touches the skill directory, with `--name \"Stigmem\"` and `--slug stigmem-node` hard-coded so neither can drift again. v1.0.8 additionally renamed the source directory to drop the inference dependency entirely.\n\n### v1.0.6\n\n- Updated `install.package` pin from `stigmem-py>=1.0.0,<2.0.0` to `stigmem-py>=0.9.0a1,<1.0.0` to match the v0.9.0a1 reset of the stigmem package line. This is the contract that ties the skill to a specific stigmem release line. Adopters who installed earlier ClawHub skill versions (1.0.0–1.0.5) had a `stigmem-py>=1.0.0rc1` dependency that was end-to-end uninstallable (see retraction post, \"What the audit found\"); v1.0.6 is the first installable skill release in this respect.\n- Documentation: added the retraction-post reference and the independent-versioning note above.\n- **Note (added 2026-05-10):** v1.0.6 shipped with an incorrect display name (\"Clawhub Skill\" instead of \"Stigmem\") because the publish-time CLI invocation omitted the `--name` flag. Adopters who installed v1.0.6 see the wrong display name in `clawhub list` etc. Upgrade to v1.0.7 for the corrected display name; the underlying skill behavior is unchanged.\n\n### v1.0.5\n\n- Fix: corrected documentation URLs to include ReadTheDocs path prefix (`/en/latest/`); all links now resolve correctly.\n\n### v1.0.4\n\n- Fix: corrected documentation domain to `docs.stigmem.dev`.\n\n### v1.0.3\n\n- Fix: corrected skill display name (was \"Clawhub Skill\", now \"Stigmem\").\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.8\",\n  \"publishedAt\": 1778449651012\n}\n\nArchive v1.0.7: 3 files, 8792 bytes\n\nFiles: adapter.py (11442b), SKILL.md (11437b), _meta.json (131b)\n\nFile v1.0.7:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.7\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=0.9.0a1,<1.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for the pre-reset design work load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and injects them into the agent's system prompt. A compromised or misconfigured node can craft fact values that redirect agent goals.\n\n**Already handled by the adapter:**\n- Fact values are sanitized before formatting: HTML/markdown metacharacters are escaped, null bytes stripped, values truncated to 500 characters.\n- The injected block is labelled `_(external, treat as untrusted)_` in the summary header.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for production. Do not point production agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope namespace, not your production node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The dedup guard prevents writing the same `(entity, source)` pair twice, but does not stop you from writing an incorrect decision in the first place.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g., `agent:openclaw-prod-alice`). The generic default `agent:openclaw` should not be used in production — facts from different deployments become indistinguishable in the fact graph.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-py>=1.0.0,<2.0.0`) so compatible updates are picked up automatically. A future patch release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for production deployments rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [docs.stigmem.dev/en/latest/docs/guides/federation](https://docs.stigmem.dev/en/latest/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://docs.stigmem.dev/en/latest/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n> **Note on versioning.** This ClawHub skill is independently versioned along its own semver line. The skill's `version:` (currently 1.0.x) tracks the skill's ClawHub release history; the dependency on stigmem is expressed via the `install.package` pin (currently `stigmem-py>=0.9.0a1,<1.0.0`). The bare-stigmem version line was reset to v0.9.0a1 in May 2026 — see [the retraction post](https://dev.to/offbyonce/walking-back-our-v10-announcement-resetting-to-v090a1-as-the-first-build-al0) — but ClawHub registry rules require monotonically increasing skill versions, so the skill stays on its 1.0.x line. The two version surfaces are intentionally decoupled.\n\n### v1.0.7\n\n- Fix: corrected skill display name (was 'Clawhub Skill' on v1.0.6, now 'Stigmem'). Same regression as v1.0.3 — the publish CLI infers the display name from the directory name (`adapters/openclaw/clawhub-skill/`) when `--name` is not explicitly passed. The v1.0.6 publish was driven by a manual CLI invocation that omitted the flag. Permanent fix: a new `.github/workflows/clawhub-publish.yml` automates the publish on every push to main that touches `adapters/openclaw/clawhub-skill/**`, with `--name \"Stigmem\"` and `--slug stigmem-node` hard-coded so neither can drift again. v0.9.0a2 will additionally rename the source directory to drop the inference dependency entirely.\n\n### v1.0.6\n\n- Updated `install.package` pin from `stigmem-py>=1.0.0,<2.0.0` to `stigmem-py>=0.9.0a1,<1.0.0` to match the v0.9.0a1 reset of the stigmem package line. This is the contract that ties the skill to a specific stigmem release line. Adopters who installed earlier ClawHub skill versions (1.0.0–1.0.5) had a `stigmem-py>=1.0.0rc1` dependency that was end-to-end uninstallable (see retraction post, \"What the audit found\"); v1.0.6 is the first installable skill release in this respect.\n- Documentation: added the retraction-post reference and the independent-versioning note above.\n- **Note (added 2026-05-10):** v1.0.6 shipped with an incorrect display name (\"Clawhub Skill\" instead of \"Stigmem\") because the publish-time CLI invocation omitted the `--name` flag. Adopters who installed v1.0.6 see the wrong display name in `clawhub list` etc. Upgrade to v1.0.7 for the corrected display name; the underlying skill behavior is unchanged.\n\n### v1.0.5\n\n- Fix: corrected documentation URLs to include ReadTheDocs path prefix (`/en/latest/`); all links now resolve correctly.\n\n### v1.0.4\n\n- Fix: corrected documentation domain to `docs.stigmem.dev`.\n\n### v1.0.3\n\n- Fix: corrected skill display name (was \"Clawhub Skill\", now \"Stigmem\").\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.7\",\n  \"publishedAt\": 1778403484076\n}\n\nArchive v1.0.6: 3 files, 8395 bytes\n\nFiles: adapter.py (11442b), SKILL.md (10389b), _meta.json (131b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.6\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=0.9.0a1,<1.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for the pre-reset design work load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and injects them into the agent's system prompt. A compromised or misconfigured node can craft fact values that redirect agent goals.\n\n**Already handled by the adapter:**\n- Fact values are sanitized before formatting: HTML/markdown metacharacters are escaped, null bytes stripped, values truncated to 500 characters.\n- The injected block is labelled `_(external, treat as untrusted)_` in the summary header.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for production. Do not point production agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope namespace, not your production node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The dedup guard prevents writing the same `(entity, source)` pair twice, but does not stop you from writing an incorrect decision in the first place.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g., `agent:openclaw-prod-alice`). The generic default `agent:openclaw` should not be used in production — facts from different deployments become indistinguishable in the fact graph.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-py>=1.0.0,<2.0.0`) so compatible updates are picked up automatically. A future patch release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for production deployments rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [docs.stigmem.dev/en/latest/docs/guides/federation](https://docs.stigmem.dev/en/latest/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://docs.stigmem.dev/en/latest/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n> **Note on versioning.** This ClawHub skill is independently versioned along its own semver line. The skill's `version:` (currently 1.0.x) tracks the skill's ClawHub release history; the dependency on stigmem is expressed via the `install.package` pin (currently `stigmem-py>=0.9.0a1,<1.0.0`). The bare-stigmem version line was reset to v0.9.0a1 in May 2026 — see [the retraction post](https://dev.to/offbyonce/walking-back-our-v10-announcement-resetting-to-v090a1-as-the-first-build-al0) — but ClawHub registry rules require monotonically increasing skill versions, so the skill stays on its 1.0.x line. The two version surfaces are intentionally decoupled.\n\n### v1.0.6\n\n- Updated `install.package` pin from `stigmem-py>=1.0.0,<2.0.0` to `stigmem-py>=0.9.0a1,<1.0.0` to match the v0.9.0a1 reset of the stigmem package line. This is the contract that ties the skill to a specific stigmem release line. Adopters who installed earlier ClawHub skill versions (1.0.0–1.0.5) had a `stigmem-py>=1.0.0rc1` dependency that was end-to-end uninstallable (see retraction post, \"What the audit found\"); v1.0.6 is the first installable skill release in this respect.\n- Documentation: added the retraction-post reference and the independent-versioning note above.\n\n### v1.0.5\n\n- Fix: corrected documentation URLs to include ReadTheDocs path prefix (`/en/latest/`); all links now resolve correctly.\n\n### v1.0.4\n\n- Fix: corrected documentation domain to `docs.stigmem.dev`.\n\n### v1.0.3\n\n- Fix: corrected skill display name (was \"Clawhub Skill\", now \"Stigmem\").\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1778402958671\n}\n\nArchive v1.0.5: 3 files, 7855 bytes\n\nFiles: adapter.py (11442b), SKILL.md (9114b), _meta.json (131b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.5\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=1.0.0,<2.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for Phase 2 load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and injects them into the agent's system prompt. A compromised or misconfigured node can craft fact values that redirect agent goals.\n\n**Already handled by the adapter:**\n- Fact values are sanitized before formatting: HTML/markdown metacharacters are escaped, null bytes stripped, values truncated to 500 characters.\n- The injected block is labelled `_(external, treat as untrusted)_` in the summary header.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for production. Do not point production agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope namespace, not your production node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The dedup guard prevents writing the same `(entity, source)` pair twice, but does not stop you from writing an incorrect decision in the first place.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g., `agent:openclaw-prod-alice`). The generic default `agent:openclaw` should not be used in production — facts from different deployments become indistinguishable in the fact graph.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-py>=1.0.0,<2.0.0`) so compatible updates are picked up automatically. A future patch release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for production deployments rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [docs.stigmem.dev/en/latest/docs/guides/federation](https://docs.stigmem.dev/en/latest/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://docs.stigmem.dev/en/latest/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n### v1.0.5\n\n- Fix: corrected documentation URLs to include ReadTheDocs path prefix (`/en/latest/`) — all links now resolve correctly.\n\n### v1.0.4\n\n- Fix: corrected documentation domain to `docs.stigmem.dev`.\n\n### v1.0.3\n\n- Fix: corrected skill display name (was \"Clawhub Skill\", now \"Stigmem\").\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1777886414440\n}\n\nArchive v1.0.4: 3 files, 7811 bytes\n\nFiles: adapter.py (11442b), SKILL.md (8975b), _meta.json (131b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.4\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://docs.stigmem.dev/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=1.0.0,<2.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for Phase 2 load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and injects them into the agent's system prompt. A compromised or misconfigured node can craft fact values that redirect agent goals.\n\n**Already handled by the adapter:**\n- Fact values are sanitized before formatting: HTML/markdown metacharacters are escaped, null bytes stripped, values truncated to 500 characters.\n- The injected block is labelled `_(external, treat as untrusted)_` in the summary header.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for production. Do not point production agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope namespace, not your production node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The dedup guard prevents writing the same `(entity, source)` pair twice, but does not stop you from writing an incorrect decision in the first place.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g., `agent:openclaw-prod-alice`). The generic default `agent:openclaw` should not be used in production — facts from different deployments become indistinguishable in the fact graph.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-py>=1.0.0,<2.0.0`) so compatible updates are picked up automatically. A future patch release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for production deployments rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [docs.stigmem.dev/docs/guides/federation](https://docs.stigmem.dev/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://docs.stigmem.dev/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n### v1.0.4\n\n- Fix: corrected documentation domain — all doc links now point to `docs.stigmem.dev` (not `stigmem.dev`).\n\n### v1.0.3\n\n- Fix: corrected skill display name (was \"Clawhub Skill\", now \"Stigmem\").\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://docs.stigmem.dev/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1777886095283\n}\n\nArchive v1.0.3: 3 files, 7768 bytes\n\nFiles: adapter.py (11442b), SKILL.md (8828b), _meta.json (131b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.3\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://stigmem.dev/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=1.0.0,<2.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for Phase 2 load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and injects them into the agent's system prompt. A compromised or misconfigured node can craft fact values that redirect agent goals.\n\n**Already handled by the adapter:**\n- Fact values are sanitized before formatting: HTML/markdown metacharacters are escaped, null bytes stripped, values truncated to 500 characters.\n- The injected block is labelled `_(external, treat as untrusted)_` in the summary header.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for production. Do not point production agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope namespace, not your production node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The dedup guard prevents writing the same `(entity, source)` pair twice, but does not stop you from writing an incorrect decision in the first place.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g., `agent:openclaw-prod-alice`). The generic default `agent:openclaw` should not be used in production — facts from different deployments become indistinguishable in the fact graph.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-py>=1.0.0,<2.0.0`) so compatible updates are picked up automatically. A future patch release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for production deployments rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [stigmem.dev/docs/guides/federation](https://stigmem.dev/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://stigmem.dev/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n### v1.0.3\n\n- Fix: corrected skill display name (was \"Clawhub Skill\", now \"Stigmem\").\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://stigmem.dev/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1777884931738\n}\n\nArchive v1.0.2: 3 files, 7727 bytes\n\nFiles: adapter.py (11442b), SKILL.md (8741b), _meta.json (131b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.2\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://stigmem.dev/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=1.0.0,<2.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for Phase 2 load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security\n\n### Prompt injection via retrieved context\n\n`boot()` retrieves facts from an external Stigmem node and injects them into the agent's system prompt. A compromised or misconfigured node can craft fact values that redirect agent goals.\n\n**Already handled by the adapter:**\n- Fact values are sanitized before formatting: HTML/markdown metacharacters are escaped, null bytes stripped, values truncated to 500 characters.\n- The injected block is labelled `_(external, treat as untrusted)_` in the summary header.\n\n**What you should do:**\n- **Append** the Stigmem context after your hardcoded system prompt — never prepend it — so your instructions take precedence over retrieved memory.\n- In high-stakes or irreversible workflows, skip `boot()` or use `ctx.facts` for programmatic inspection instead of injecting the full summary.\n- Use a private, access-controlled Stigmem node for production. Do not point production agents at a shared or publicly writable node.\n\n### Stale and poisoned facts\n\nFacts written by this adapter persist durably and propagate to every agent on the same node. An incorrect decision or handoff influences all future sessions until explicitly retracted.\n\n**What you should do:**\n- Use `scope=\"local\"` for agent scratch facts that should not leave the local node.\n- Use `scope=\"company\"` only for facts that should legitimately be shared across agents.\n- Run experimental workloads against a separate Stigmem node or a dedicated scope namespace, not your production node.\n- Retract incorrect facts explicitly (`DELETE /v1/facts/{id}`) rather than waiting for expiry. The 24-hour expiry on escalations is a safety net, not a correction mechanism.\n- Treat `emit_decision()` as a write to a shared audit log: only call it for confirmed, significant choices. The dedup guard prevents writing the same `(entity, source)` pair twice, but does not stop you from writing an incorrect decision in the first place.\n\n### API key and agent identity scope\n\nOver-privileged API keys grant unnecessary read/write access across your node. The default `STIGMEM_SOURCE_ENTITY` value (`agent:openclaw`) is a generic shared identifier that conflates facts from different deployments.\n\n**What you should do:**\n- Issue a dedicated API key per agent deployment. Never share a key across agents or environments.\n- Rotate keys regularly; revoke via the node admin API (`DELETE /v1/auth/keys/{id}`) if a key is compromised.\n- Set `STIGMEM_SOURCE_ENTITY` to a unique per-deployment URI (e.g., `agent:openclaw-prod-alice`). The generic default `agent:openclaw` should not be used in production — facts from different deployments become indistinguishable in the fact graph.\n\n### Dependency pinning\n\nThe install spec uses a version range (`stigmem-py>=1.0.0,<2.0.0`) so compatible updates are picked up automatically. A future patch release could change runtime behaviour.\n\n**What you should do:**\n- Pin the exact version in a lockfile (`uv.lock` or `requirements.txt`) for production deployments rather than relying on the range alone.\n- Review `stigmem-py` release notes before upgrading and run your integration tests against the new version before rollout.\n\n### Federation scope\n\nIf your Stigmem node federates with partner nodes, facts stored with `scope=\"public\"` or `scope=\"company\"` are replicated to those peers. Agent working memory stored at too broad a scope can leak to unintended recipients.\n\n**What you should do:**\n- Use `scope=\"local\"` for session-internal or scratch facts that should stay on the originating node.\n- Audit the `allowed_scopes` in your federation peer registrations. Start with `[\"public\"]` and add `\"company\"` only when cross-org sharing is explicitly intended.\n- Disable federation entirely (`STIGMEM_FEDERATION_ENABLED=false`) if your deployment does not require multi-node replication.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [stigmem.dev/docs/guides/federation](https://stigmem.dev/docs/guides/federation)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://stigmem.dev/docs/guides/federation#external-onboarding).\n\n## Changelog\n\n### v1.0.2\n\n- Fixed incorrect `homepage` and `Documentation` URLs — now point to the\n  [OpenClaw connector guide](https://stigmem.dev/docs/guides/connectors/openclaw)\n  instead of the federation page.\n- Expanded security section to cover all five ClawHub security findings with\n  concrete mitigations: prompt injection, stale/poisoned facts, identity scope,\n  dependency pinning, and federation scope.\n\n### v1.0.1\n\n- Security: `source_entity` bound at construction time; cannot be overridden per-call.\n- Security: fact values sanitized (HTML/markdown escaping, null-byte stripping,\n  500-character truncation) before system-prompt injection.\n- Bundled `adapter.py` in the skill directory for self-contained installs.\n\n### v1.0.0\n\nInitial release — boot handshake, handoff, decision, and escalation surfaces.\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1777884180264\n}\n\nArchive v1.0.1: 3 files, 6196 bytes\n\nFiles: adapter.py (11442b), SKILL.md (4920b), _meta.json (131b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.1\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://stigmem.dev/docs/guides/federation#external-onboarding\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled. Use a least-privilege key scoped to the intended node only; rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: \"stigmem-py>=1.0.0,<2.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for Phase 2 load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Security notes\n\n**Memory isolation** — Facts written via this skill persist across sessions and agents. An incorrect decision, handoff, or escalation propagates to future agent runs. Use separate Stigmem nodes (or separate scope namespaces) for experimental and production workloads. Retract stale facts explicitly rather than relying on expiry.\n\n**Retrieved facts are untrusted** — `boot()` returns facts from an external node. The adapter sanitizes values before formatting them into a summary, but you should still review the injected context before acting on it in high-stakes workflows.\n\n**API key scope** — Set `STIGMEM_API_KEY` to a key scoped only to the nodes this agent needs to read from and write to. Rotate keys regularly. Never share a key across multiple unrelated agent deployments.\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [stigmem.dev/docs/guides/federation](https://stigmem.dev/docs/guides/federation#external-onboarding)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://stigmem.dev/docs/guides/federation#external-onboarding).\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1777843952471\n}\n\nArchive v1.0.0: 3 files, 5390 bytes\n\nFiles: adapter.py (10652b), SKILL.md (3955b), _meta.json (131b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.0\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://stigmem.dev/docs/guides/federation#external-onboarding\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: false\n        description: \"API key for the Stigmem node. Omit if the node runs with auth disabled.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n    install:\n      - kind: uv\n        package: stigmem-py>=1.0.0rc1\n---\n\n# stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable `roadmap:decision` facts for significant architectural choices; built-in dedup guard prevents repeated writes.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Optionally set `STIGMEM_API_KEY` (required if the node has auth enabled).\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent instance (default: `agent:openclaw`).\n\n## Usage\n\n`adapter.py` is bundled with this skill. Import it directly from the skill directory — no separate package install needed beyond `stigmem-py` (declared in the install spec above).\n\n```python\nfrom adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for Phase 2 load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)\n```\n\n## Running your own Stigmem node\n\nStigmem nodes are self-hosted. The quickest way to spin one up:\n\n```bash\ndocker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest\n```\n\nFull setup guide and federation docs: [stigmem.dev/docs/guides/federation](https://stigmem.dev/docs/guides/federation#external-onboarding)\n\n## Federation\n\nStigmem nodes can federate with each other to share public-scoped facts across organizations. To connect your node to a partner network, see the [external integrator onboarding guide](https://stigmem.dev/docs/guides/federation#external-onboarding).\n\n## Source\n\n[github.com/Eidetic-Labs/stigmem](https://github.com/Eidetic-Labs/stigmem) — Apache-2.0\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1777843398244\n}","readmeExcerpt":"Skill: Stigmem Owner: offbyonce Summary: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node. Tags: latest:1.0.9 Version history: v1.0.9 | 2026-05-24T21:46:20.279Z | user - Documentation: adds a \"Compatible Stigmem plugins\" section for OpenClaw operators, pointing to the six published Stigmem plugin packages and clarifying that plugin i","codeSnippets":[],"executableExamples":[{"language":"python","snippet":"from adapter import OpenClawStigmemAdapter, SYSTEM_PROMPT_DIRECTIVE\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\n    \"\\n\\n\" + SYSTEM_PROMPT_DIRECTIVE + \"\\n\\n\" + ctx.summary if ctx else \"\"\n)\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for the pre-reset design work load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n    idempotency_key=\"session-2026-05-02-abc\",\n)"},{"language":"bash","snippet":"docker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest"},{"language":"python","snippet":"from adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for the pre-reset design work load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)"},{"language":"bash","snippet":"docker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest"},{"language":"python","snippet":"from adapter import OpenClawStigmemAdapter\n\nadapter = OpenClawStigmemAdapter.from_env()\n\n# At session start — inject ctx.summary into the system prompt\nctx = adapter.boot(\n    user_entity=\"user:alice\",\n    project_entities=[\"project:my-roadmap\"],\n)\nsystem_prompt = base_prompt + (\"\\n\\n\" + ctx.summary if ctx else \"\")\n\n# Record a significant decision\nadapter.emit_decision(\n    entity=\"decision:auth-provider\",\n    summary=\"Chose Clerk over Auth0: simpler Next.js integration, lower per-seat cost.\",\n)\n\n# Escalate to another agent\nadapter.emit_escalation(\n    to_entity=\"agent:cto\",\n    goal=\"Approve increased Stripe webhook rate limit for the pre-reset design work load.\",\n    priority=\"high\",\n)\n\n# Emit a handoff when the session ends\nadapter.emit_handoff(\n    from_entity=\"agent:openclaw\",\n    to_entity=\"agent:assistant\",\n    summary=\"Auth provider chosen; Stripe limit escalation pending.\",\n    fact_refs=[\"fact-auth-decision\", \"fact-esc-stripe\"],\n    continuation=\"Resume from the Stripe rate-limit discussion.\",\n)"},{"language":"bash","snippet":"docker run --rm -p 8765:8765 \\\n  -e STIGMEM_NODE_URL=http://localhost:8765 \\\n  ghcr.io/eidetic-labs/stigmem-node:latest"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: stigmem-node\ntitle: Stigmem\ndescription: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\nversion: 1.0.9\nmetadata:\n  openclaw:\n    emoji: \"🧠\"\n    homepage: https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw\n    clawhub: https://clawhub.ai/skills/stigmem-node\n    primaryEnv: STIGMEM_URL\n    requires:\n      env:\n        - STIGMEM_URL\n        - STIGMEM_API_KEY\n    envVars:\n      - name: STIGMEM_URL\n        required: true\n        description: \"Base URL of your Stigmem node (e.g. https://stigmem.example.com).\"\n      - name: STIGMEM_API_KEY\n        required: true\n        description: \"Least-privilege API key for the Stigmem node. Required by from_env(); rotate regularly.\"\n      - name: STIGMEM_SOURCE_ENTITY\n        required: false\n        description: \"Entity URI that identifies this agent in the fact graph (default: agent:openclaw).\"\n      - name: STIGMEM_OPENCLAW_ALLOWED_HANDOFF_TARGETS\n        required: false\n        description: \"Comma-separated agent: entity URI allowlist for handoff and escalation targets. The source entity is always allowed.\"\n    install:\n      - kind: uv\n        package: \"stigmem-openclaw>=0.9.0a9,<1.0.0\"\n---\n\n# Stigmem\n\nGives your OpenClaw agent persistent, federated memory via [Stigmem](https://stigmem.dev) — an open-source knowledge fabric that stores facts as immutable, signed assertions and replicates them across nodes.\n\n> **Alpha status.** This source copy is prepared for the v0.9.0a9 ClawHub\n> artifact refresh, which adds plugin-awareness pointers. The OpenClaw skill\n> remains available for v0.9.0aN evaluation only, not as a recommended\n> production integration. The adapter separates retrieved\n> content from\n> instruction-channel recall output and exports a required system prompt\n> directive, but the broader ADR-003 hardening line still needs MCP parity,\n> operator docs, and feedback-loop controls before high-stakes production use. See\n> [LIMITATIONS.md §9](https://github.com/eidetic-labs/stigmem/blob/main/LIMITATIONS.md#9-running-the-openclaw-bundled-adapter-as-is).\n\n## What this skill provides\n\n- **Boot handshake** — on agent start, pull user preferences, project constraints, and pending handoffs from the Stigmem node and inject them into your system prompt.\n- **Handoff** — when a session ends or delegates, record a typed handoff cluster so the next agent or channel resumes with full context.\n- **Decision** — emit durable append-only `roadmap:decision` facts for significant architectural choices; dedupe externally before calling if your workflow needs at-most-once semantics.\n- **Escalation** — write `intent:escalation` facts with priority and a 24-hour expiry so stale escalations don't accumulate.\n\n## Setup\n\n1. Set `STIGMEM_URL` to your Stigmem node URL.\n2. Set `STIGMEM_API_KEY` to a least-privilege key for the node.\n3. Optionally set `STIGMEM_SOURCE_ENTITY` to the entity URI that represents this agent insta"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76hytctjgjphsz9es7nd8pwn8615tx\",\n  \"slug\": \"stigmem-node\",\n  \"version\": \"1.0.9\",\n  \"publishedAt\": 1779659180279\n}"},{"path":"skill-card.md","content":"## Description:\n\nPersistent federated memory for OpenClaw agents -- boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node.\n\nThis skill is for research and development only.\n\n## Publisher:\n\n[offbyonce](https://clawhub.ai/user/offbyonce)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to connect OpenClaw agents to a Stigmem node for persistent memory, session handoffs, decision records, and escalation facts during evaluation or controlled integration work.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Retrieved memory from a compromised or misconfigured Stigmem node can influence agent behavior if treated as instructions.\n\nMitigation: Use a private, access-controlled node, append retrieved context after hardcoded system instructions, and inspect structured facts instead of injecting full summaries in high-stakes workflows.\n\nRisk: Facts written to shared or federated memory can persist across future agents and propagate beyond the intended deployment.\n\nMitigation: Use least-privilege per-agent API keys, unique source entities, local scopes for scratch facts, narrow federation settings, and explicit retraction for incorrect facts.\n\nRisk: Alpha-line dependency updates may change runtime behavior across repeatable evaluations.\n\nMitigation: Pin the Python dependency and Stigmem node image before evaluation or production-like use, then review release notes and run integration tests before upgrades.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/offbyonce/skills/stigmem-node)\n- [OpenClaw connector guide](https://docs.stigmem.dev/en/latest/docs/guides/connectors/openclaw)\n- [Stigmem project homepage](https://stigmem.dev)\n- [Stigmem plugin catalog](https://docs.stigmem.dev/en/latest/docs/plugins)\n- [Server-resolved provenance](unavailable)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with Python and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires STIGMEM_URL and STIGMEM_API_KEY; optional environment variables configure source identity and allowed handoff targets.]\n\n## Skill Version(s):\n\n1.0.9 (source: frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node. Skill: Stigmem Owner: offbyonce Summary: Persistent federated memory for OpenClaw agents — boot handshake, handoff, decision, and escalation surfaces backed by a Stigmem node. Tags: latest:1.0.9 Version history: v1.0.9 | 2026-05-24T21:46:20.279Z | user - Documentation: adds a \"Compatible Stigmem plugins\" section for OpenClaw operators, pointing to the six published Stigmem plugin packages and clarifying that plugin i","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1382,"uniquenessScore":51,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T14:01:48.729Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T14:01:48.729Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:41:49.157Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}