{"id":"d414bf44-b1ae-4b59-bd3f-1050402134b9","entityType":"agent","slug":"clawhub-paradoxfuzzle-custom-mysql","name":"VectorClaw","canonicalUrl":"https://www.xpersona.co/agent/clawhub-paradoxfuzzle-custom-mysql","canonicalPath":"/agent/clawhub-paradoxfuzzle-custom-mysql","generatedAt":"2026-10-10T15:52:03.857Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:26:27.509Z","emptyReason":null},"description":"Provides a secure, least-privilege interface for managing user data, personas, and config snapshots in MySQL with input validation and secret redaction.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17cger457jwgfzqgbpjb2ydrh8632mt:custom-mysql","sourceUrl":"https://clawhub.ai/paradoxfuzzle/custom-mysql","homepage":"https://clawhub.ai/paradoxfuzzle/skills/custom-mysql","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/paradoxfuzzle/custom-mysql","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/paradoxfuzzle/skills/custom-mysql","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"VectorClaw technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:26:27.509Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:26:27.509Z","emptyReason":null},"stars":null,"forks":null,"downloads":1412,"packageName":null,"latestVersion":"5.0.1","tractionLabel":"1.4K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:26:27.508Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T13:26:27.509Z","lastCrawledAt":"2026-10-10T13:26:27.508Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T13:26:27.508Z","lastVerifiedAt":null,"highlights":[{"version":"5.0.1","createdAt":"2026-05-27T16:32:21.100Z","changelog":"**Summary: Privacy, consent, and security improvements based on audit.** - Added prominent PRIVACY & CONSENT NOTICE to documentation, requiring explicit user opt-in before enabling auto-extraction, and outlining administrator responsibilities. - Provided clear guidance on user notification, opt-in, deletion, data review, and retention configuration. - Added dedicated rollback script (`rollback_user.sql`) to support user-requested data deletion. - No database schema changes; update consists of new documentation and guidance (upgrade script placeholder only). - Version bump to 5.0.1.","fileCount":24,"zipByteSize":71060},{"version":"5.0.0","createdAt":"2026-05-27T14:04:22.566Z","changelog":"custom-mysql v4.0.1 changelog - Added SQL migration scripts for upgrade: `update_page.sql`, `update_page_v5.sql`, `upgrade_v4_to_v5.sql` - Added release post documentation files: `RELEASE_POST.md`, `RELEASE_POST_v5.md` - Removed legacy metadata file `_meta.json` - Prepares for transition to auto-extraction and native knowledge graph features for v5.0.0","fileCount":23,"zipByteSize":65811},{"version":"4.0.0","createdAt":"2026-05-21T23:05:43.056Z","changelog":"VectorClaw v4.0.0 — Memory Consolidation Systems VectorClaw v4.0.0 adds three structured memory systems that give your agent reasoning, reflection, and multi-dimensional recall over stored memories. Built for OpenClaw agents wanting deeper, more autonomous memory management in a self-hosted MyVector stack. New in This Release - HindSight — Post-Conversation Consolidation - After each conversation cycle, HindSight analyzes recent interactions to extract: - Sentiment trends — positive/negative/neutral ratios across recent interactions - Frequently discussed topics — what the user keeps coming back to - New topic discovery — subjects discussed but not yet stored as memories - Rolling importance adjustment — promotes frequently accessed memories, flags stale ones - Recurring theme detection to highlight meaningful behavioral patterns - HoloGraphic — Multi-Dimensional Memory Tagging Every memory is automatically tagged across multiple dimensions for richer retrieval: - Emotive — positive, negative, complex, neutral - Context — work, personal, health, tech, social, creative - Urgency — immediate, ongoing, timeless, historical - People — auto-detected names referenced in the memory This means you can query memory from any angle: \"How did [user] feel about X?\" or \"What health topics came up in the last month?\" — not just keyword search. Hancho — Knowledge Graph Reasoning Hancho reads across stored memories, identifies connections between related facts, and derives new implied knowledge across 7 reasoning rules: medication side effects, health chains, tech infrastructure, creative passions, relationship depth, interest-to-skill growth, and emotional coping patterns. Derived insights are stored as first-class memories with reasoning lineage back to source facts. memory_consolidation.py Script A standalone script runs all three systems sequentially. Supports --user, --all-users, --dry-run, and individual system flags. Scheduled every 6 hours via OpenClaw heartbeat. Upgrade docker exec -i myvector-db mysql -u mysqlclaw -p<pass> mysqlclaw < upgrade_v3_to_v4.sql No data loss — existing tables and data are preserved. Memory Architecture (v4) Your agent now operates with four interconnected memory systems: MEMORY.md (curated narrative), MyVector/VectorClaw (structured profiles + dimensional tags + reasoning), Mem0 (auto-captured conversational facts), and ChromaDB (semantic file search). The consolidation script bridges all four every 6 hours. --- Full changelog and docs in the repo.","fileCount":17,"zipByteSize":47813},{"version":"1.1.12","createdAt":"2026-05-11T21:37:55.177Z","changelog":"**Major update: MySQL backend replaced with Dockerized MyVector container (MySQL 8.4 + vector search).** - Local MySQL dependency removed; now requires MyVector running in Docker, with all DB commands routed via `docker exec`. - Requires a dedicated least-privilege MySQL user; root/admin accounts are now explicitly rejected for security. - .env parsing hardened; credentials must be present or the skill will refuse to run (“fail closed”). - Security and retention policy documentation updated; allowlist reduced to 26 approved tables. - New setup and usage instructions for MyVector container, user creation, and schema installation. - Added vector_claw.sh and vector_claw_setup.sh scripts; removed legacy custom_mysql.sh and setup_wizard.sh.","fileCount":16,"zipByteSize":44370},{"version":"1.1.11","createdAt":"2026-05-11T18:34:41.941Z","changelog":"- Added SETUP_GUIDE.md with detailed step-by-step installation and setup instructions. - SKILL.md now references SETUP_GUIDE.md for MySQL/database setup support.","fileCount":16,"zipByteSize":40026},{"version":"1.1.10","createdAt":"2026-05-11T18:04:05.929Z","changelog":"- Added SQL upgrade script: upgrade_v1_to_v2.sql. - Provides migration support from v1 schema to v2 for the skill.","fileCount":15,"zipByteSize":35158},{"version":"1.1.9","createdAt":"2026-05-11T17:19:57.322Z","changelog":"**Major 2.0.0 release with expanded memory types, analytics, and enhanced security.** - Added mem0-like memory features: temporal decay, mood tracking, synaptic memory, thought streaming, and community-wide analytics. - Expanded user modeling: mood states, engagement patterns, proactive reminders, agent learnings, trending topics, and event logging. - Increased table allowlist for writes from 12 to 28 approved tables. - Improved security: better SQL injection prevention, new enum validations, and more blocked inputs (comments, hex strings). - Updated usage with new convenience commands and data fields for advanced interactions and memory types.","fileCount":14,"zipByteSize":30993},{"version":"1.1.8","createdAt":"2026-05-10T11:05:41.369Z","changelog":"**Snapshot functionality removed and security further tightened in v1.1.7:** - Snapshot management features removed, including the agent_config_files and allowed_snapshot_paths tables and the snapshot_config command. - No longer stores or references MEMORY.md, AGENTS.md, BOOT.md, or SECURITY.md in the database. - Schema and script updates: removed agent_config_files, allowed_snapshot_paths, and related SQL logic; cleanup_snapshots.sql now empty; sanitize_snapshot.sh is now a no-op with a deprecation notice. - Documentation and installation instructions updated to reflect removals and clarified usage.","fileCount":14,"zipByteSize":21615}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17cger457jwgfzqgbpjb2ydrh8632mt:custom-mysql","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17cger457jwgfzqgbpjb2ydrh8632mt:custom-mysql` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/paradoxfuzzle/custom-mysql before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T15:52:03.852Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-paradoxfuzzle-custom-mysql/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:26:27.509Z","emptyReason":null},"readme":"Skill: VectorClaw\n\nOwner: paradoxfuzzle\n\nSummary: Provides a secure, least-privilege interface for managing user data, personas, and config snapshots in MySQL with input validation and secret redaction.\n\nTags: MySQL:1.0.8, database:1.0.8, latest:5.0.1, persistence:1.0.8, persona:1.0.8\n\nVersion history:\n\nv5.0.1 | 2026-05-27T16:32:21.100Z | user\n\n**Summary: Privacy, consent, and security improvements based on audit.**\n\n- Added prominent PRIVACY & CONSENT NOTICE to documentation, requiring explicit user opt-in before enabling auto-extraction, and outlining administrator responsibilities.\n- Provided clear guidance on user notification, opt-in, deletion, data review, and retention configuration.\n- Added dedicated rollback script (`rollback_user.sql`) to support user-requested data deletion.\n- No database schema changes; update consists of new documentation and guidance (upgrade script placeholder only).\n- Version bump to 5.0.1.\n\nv5.0.0 | 2026-05-27T14:04:22.566Z | user\n\ncustom-mysql v4.0.1 changelog\n\n- Added SQL migration scripts for upgrade: `update_page.sql`, `update_page_v5.sql`, `upgrade_v4_to_v5.sql`\n- Added release post documentation files: `RELEASE_POST.md`, `RELEASE_POST_v5.md`\n- Removed legacy metadata file `_meta.json`\n- Prepares for transition to auto-extraction and native knowledge graph features for v5.0.0\n\nv4.0.0 | 2026-05-21T23:05:43.056Z | user\n\nVectorClaw v4.0.0 — Memory Consolidation Systems\nVectorClaw v4.0.0 adds three structured memory systems that give your agent reasoning, reflection, and multi-dimensional recall over stored memories. Built for OpenClaw agents wanting deeper, more autonomous memory management in a self-hosted MyVector stack.\n\nNew in This Release\n- HindSight — Post-Conversation Consolidation\n- After each conversation cycle, HindSight analyzes recent interactions to extract:\n- Sentiment trends — positive/negative/neutral ratios across recent interactions\n- Frequently discussed topics — what the user keeps coming back to\n- New topic discovery — subjects discussed but not yet stored as memories\n- Rolling importance adjustment — promotes frequently accessed memories, flags stale ones\n- Recurring theme detection to highlight meaningful behavioral patterns\n- HoloGraphic — Multi-Dimensional Memory Tagging\n\nEvery memory is automatically tagged across multiple dimensions for richer retrieval:\n- Emotive — positive, negative, complex, neutral\n- Context — work, personal, health, tech, social, creative\n- Urgency — immediate, ongoing, timeless, historical\n- People — auto-detected names referenced in the memory\n\nThis means you can query memory from any angle: \"How did [user] feel about X?\" or \"What health topics came up in the last month?\" — not just keyword search.\n\nHancho — Knowledge Graph Reasoning\nHancho reads across stored memories, identifies connections between related facts, and derives new implied knowledge across 7 reasoning rules: medication side effects, health chains, tech infrastructure, creative passions, relationship depth, interest-to-skill growth, and emotional coping patterns. Derived insights are stored as first-class memories with reasoning lineage back to source facts.\n\nmemory_consolidation.py Script\nA standalone script runs all three systems sequentially. Supports --user, --all-users, --dry-run, and individual system flags. Scheduled every 6 hours via OpenClaw heartbeat.\n\nUpgrade\ndocker exec -i myvector-db \nmysql -u mysqlclaw -p<pass>\n mysqlclaw <\n upgrade_v3_to_v4.sql\n\nNo data loss — existing tables and data are preserved.\n\nMemory Architecture (v4)\n Your agent now operates with four interconnected memory systems: MEMORY.md (curated narrative), MyVector/VectorClaw (structured profiles + dimensional tags + reasoning), Mem0 (auto-captured conversational facts), and ChromaDB (semantic file search). The consolidation script bridges all four every 6 hours.\n\n---\n\nFull changelog and docs in the repo.\n\nv1.1.12 | 2026-05-11T21:37:55.177Z | user\n\n**Major update: MySQL backend replaced with Dockerized MyVector container (MySQL 8.4 + vector search).**\n\n- Local MySQL dependency removed; now requires MyVector running in Docker, with all DB commands routed via `docker exec`.\n- Requires a dedicated least-privilege MySQL user; root/admin accounts are now explicitly rejected for security.\n- .env parsing hardened; credentials must be present or the skill will refuse to run (“fail closed”).\n- Security and retention policy documentation updated; allowlist reduced to 26 approved tables.\n- New setup and usage instructions for MyVector container, user creation, and schema installation.\n- Added vector_claw.sh and vector_claw_setup.sh scripts; removed legacy custom_mysql.sh and setup_wizard.sh.\n\nv1.1.11 | 2026-05-11T18:34:41.941Z | user\n\n- Added SETUP_GUIDE.md with detailed step-by-step installation and setup instructions.\n- SKILL.md now references SETUP_GUIDE.md for MySQL/database setup support.\n\nv1.1.10 | 2026-05-11T18:04:05.929Z | user\n\n- Added SQL upgrade script: upgrade_v1_to_v2.sql.\n- Provides migration support from v1 schema to v2 for the skill.\n\nv1.1.9 | 2026-05-11T17:19:57.322Z | user\n\n**Major 2.0.0 release with expanded memory types, analytics, and enhanced security.**\n\n- Added mem0-like memory features: temporal decay, mood tracking, synaptic memory, thought streaming, and community-wide analytics.\n- Expanded user modeling: mood states, engagement patterns, proactive reminders, agent learnings, trending topics, and event logging.\n- Increased table allowlist for writes from 12 to 28 approved tables.\n- Improved security: better SQL injection prevention, new enum validations, and more blocked inputs (comments, hex strings).\n- Updated usage with new convenience commands and data fields for advanced interactions and memory types.\n\nv1.1.8 | 2026-05-10T11:05:41.369Z | user\n\n**Snapshot functionality removed and security further tightened in v1.1.7:**\n\n- Snapshot management features removed, including the agent_config_files and allowed_snapshot_paths tables and the snapshot_config command.\n- No longer stores or references MEMORY.md, AGENTS.md, BOOT.md, or SECURITY.md in the database.\n- Schema and script updates: removed agent_config_files, allowed_snapshot_paths, and related SQL logic; cleanup_snapshots.sql now empty; sanitize_snapshot.sh is now a no-op with a deprecation notice.\n- Documentation and installation instructions updated to reflect removals and clarified usage.\n\nv1.1.7 | 2026-05-10T08:24:29.541Z | user\n\n**Expanded security controls and validation in MySQL profile storage skill.**\n\n- Enforced single-statement execution; semicolons now rejected in statements.\n- Blocked DDL commands such as DROP, TRUNCATE, CREATE, ALTER, GRANT, and REVOKE.\n- Implemented path traversal and sensitive file pattern blocking.\n- Added explicit snapshot path allowlist validation.\n- Switched to Python-based string escaping for robust MySQL safety.\n- Set script permissions to 700 (owner execute only).\n\nv1.1.6 | 2026-05-06T05:09:33.705Z | user\n\nNo code changes detected; documentation security details and changelog improved.\n\n- Updated documentation to clarify that DML now always requires interactive confirmation with no non-interactive bypass.\n- Improved changelog entries for prior versions, ensuring accuracy about DML restrictions.\n- No changes made to source code or skill functionality.\n\nv1.1.5 | 2026-05-06T00:43:55.327Z | user\n\n**Stronger security and safer operations—DML now requires confirmation, and all writes are table-allowlisted:**\n\n- `query` command is now limited to SELECT-only queries.\n- All DML operations (INSERT/UPDATE/DELETE/REPLACE) require interactive user confirmation; the `--yes` bypass is removed.\n- Table allowlist is enforced for all write operations, further restricting updates to approved tables.\n- Clarified requirement for a dedicated, least-privilege MySQL user account.\n- Added note that data retention defaults to 30 days, and full user data deletion is supported.\n\nv1.1.4 | 2026-05-05T20:43:36.774Z | user\n\nSecurity hardening complete: Patched SQL injection, implemented SQL whitelist, and removed all hardcoded credentials and developer files.\n\nv1.1.3 | 2026-05-05T20:18:44.066Z | user\n\n- Removed the create_admin_user.sh file for a leaner setup.\n- No functional or configuration changes to other scripts or capabilities.\n- Documentation version incremented to 1.1.2.\n\nv1.1.2 | 2026-05-05T20:06:19.645Z | user\n\n- Bumped version to 1.1.1 and updated the changelog.\n- Added detailed release notes for v1.1.0 in the changelog section.\n- Clarified security improvements and added mention of user tracking tables and SQL injection fixes in the changelog for v1.1.1.\n\nv1.1.1 | 2026-05-05T19:59:59.936Z | user\n\nSecurity fix: Removed hardcoded credentials, fixed SQL injection, added user tracking tables.\n\nv1.1.0 | 2026-05-05T19:29:56.836Z | user\n\nMajor update: 5 new tables, user context/tracking, convenience commands, .env support, non-interactive DML with --yes flag\n\nv1.0.8 | 2026-05-04T21:40:19.866Z | auto\n\n- Added new executable script: custom_mysql.sh.\n- Updated documentation to reference custom_mysql.sh instead of custom_mysql for command usage.\n- No functional changes to security architecture or dependencies. \n- Files list and example commands now align with the presence of custom_mysql.sh.\n\nv1.0.7 | 2026-05-04T21:29:18.561Z | auto\n\n**Skill version 1.0.7 highlights stricter capability documentation and clarifies security design.**\n\n- Added `CAPABILITIES.md` for explicit declarations of allowed and disallowed actions, to address false \"crypto/wallet/payment\" capability scanner signals.\n- Updated `SKILL.md` with a new, greatly clarified capability scope section and references to `CAPABILITIES.md`.\n- Emphasized that the skill performs only local MySQL database operations, with no wallet, crypto, payment, or external API access.\n- Polished documentation: reorganized and condensed sections, clarified security features and expected environment.\n- No functional or code logic changes; this is a documentation and transparency release.\n\nv1.0.6 | 2026-05-04T20:19:50.163Z | auto\n\n- Added an explicit \"Capability Scope\" section clarifying that the skill does not interact with wallets, cryptocurrencies, or payment systems; redaction of such secrets is purely defensive.\n- Updated dependencies: Perl is now required for advanced regex redaction in `sanitize_snapshot.sh`.\n- Strengthened documentation of script execution (`exec_script`): all statements are run individually through the SQL safety wrapper, and only reviewed/bundled scripts should be used.\n- Enhanced documentation for clarity around installation, input validation, and security controls.\n\nv1.0.4 | 2026-05-04T20:00:19.126Z | auto\n\nMySQLClaw Skill v1.0.4 delivers security-focused MySQL management features for OpenClaw agents.\n\n- Strengthened credential handling: passwords never appear in process listings, credentials file auto-deleted on exit.\n- Enhanced SQL execution safety: rejects multi-statements, blocks DDL, requires confirmation for DML, enforces input sanitization.\n- Snapshot management: secrets automatically redacted, files tightly whitelisted, auto-purge after 30 days.\n- Strict input validation: all identifiers and database user input checked by regex.\n- Setup wizard and commands streamlined for user safety and ease of use.\n\nArchive index:\n\nArchive v5.0.1: 24 files, 71060 bytes\n\nFiles: .clawhub/origin.json (143b), CAPABILITIES.md (10598b), changelog.md (40016b), cleanup_snapshots.sql (410b), create_user_tables.sql (23845b), populate_templates.sql (938b), RELEASE_POST_v5.md (3893b), RELEASE_POST.md (4559b), rollback_user.sql (2267b), sanitize_snapshot.sh (754b), SETUP_GUIDE.md (11774b), skill-card.md (2806b), SKILL.md (19795b), sql_safe_exec.sh (7681b), update_page_v5.sql (8759b), update_page.sql (7555b), updated_SKILL.md (8350b), upgrade_v1_to_v2.sql (14739b), upgrade_v3_to_v4.sql (2741b), upgrade_v4_to_v5.sql (5045b), upgrade_v5.0.0_to_v5.0.1.sql (5397b), vector_claw_setup.sh (6093b), vector_claw.sh (17898b), _meta.json (131b)\n\nFile v5.0.1:SKILL.md\n\n# paradoxfuzzle/custom-mysql\n\n## ⚠️ PRIVACY & CONSENT NOTICE — READ BEFORE INSTALLING\n\nThis skill **automatically extracts, infers, and persistently stores sensitive personal information** from user conversations, including but not limited to:\n\n- **Emotional states and mood patterns** (stress, anxiety, sadness, joy)\n- **Relationship signals** (who users interact with, closeness, trust)\n- **Health and wellness indicators** (medication mentions, symptoms, coping patterns)\n- **Behavioral profiling** (engagement patterns, time-of-day activity, topic preferences)\n- **Inferred preferences and traits** (derived from conversation patterns, not explicitly stated)\n- **Agent reasoning logs** (internal chain-of-thought stored alongside user data)\n\n**By installing this skill, you accept responsibility for:**\n\n1. **Informing all users** that their conversation data is being profiled and persisted\n2. **Obtaining explicit opt-in consent** before enabling auto-extraction for any user\n3. **Providing a clear mechanism** for users to request full data deletion (`rollback_user.sql`)\n4. **Reviewing auto-extracted data** for accuracy and sensitivity before it affects agent behavior\n5. **Configuring retention limits** appropriate to your use case (default: 30-90 days depending on data type)\n\nThis is a **self-hosted, self-managed system**. No data leaves your infrastructure. However, the breadth of profiling it performs is significant and should not be enabled without user awareness.\n\n**Disable auto-extraction by default.** Enable per-user only after explicit opt-in.\n\n---\n\n## Overview\n\nSecurity-hardened MyVector MySQL profile storage with capability bounding for OpenClaw. Tracks interactions, relationships, context, skill usage, notes, preferences, media, food, personas, mood states, engagement patterns, proactive reminders, agent learnings, community sentiment, trending topics, and community events. Now includes HindSight (post-conversation consolidation), HoloGraphic (multi-dimensional tagging), and Hancho (knowledge graph reasoning) memory systems. v4.0.0 integrates with the `memory_consolidation.py` script for automated heartbeat-based memory maintenance. All SQL is routed through `docker exec` into the MyVector container. Requires a dedicated least-privilege MySQL user — root/admin accounts are rejected.\n\n## Version\n\n5.0.1 – 2026-05-27 (security audit response)\n\n## Memory Systems\n\nVectorClaw v5.0.0 makes MyVector self-sufficient. It includes three memory enhancement systems (v4) plus auto-extraction and native knowledge graph reasoning (v5):\n\n### HindSight — Post-Conversation Consolidation\n- Analyzes recent interactions (sentiment trends, topic frequency)\n- Identifies new topics not yet stored as memories\n- Detects recurring themes worth tracking\n- Stores findings in `user_context` (categories: discovery, behavioral, emotional)\n\n### HoloGraphic — Multi-Dimensional Tagging\n- Tags memories with: emotion, context, urgency, people\n- **Emotion**: positive, negative, complex, neutral\n- **Context**: work, personal, health, tech, social, creative\n- **Urgency**: immediate, ongoing, timeless, historical\n- **People**: auto-detected names (NoodlyPanda, Ev, Cyle, Jerith, etc.)\n- Enables retrieval from any angle (\"how did Ev feel about X\", \"health topics in May\")\n- Stores tags in `user_context` (category: metadata)\n\n### Hancho — Knowledge Graph Reasoning\n- Connects related facts to derive new insights via 7 reasoning rules:\n  1. **medication_side_effects**: medication keywords + side effect keywords\n  2. **health_chain**: condition keywords + treatment keywords\n  3. **tech_infrastructure**: infra keywords + AI/model keywords\n  4. **creative_passion**: interest keywords + creation keywords\n  5. **relationship_depth**: emotional keywords + interaction keywords\n  6. **interest_to_skill**: learning keywords + skill keywords\n  7. **emotional_pattern**: stress keywords + coping keywords\n- Inter-user reasoning finds shared topics between users\n- Stores derived insights in `user_context` (categories: reasoning, social_graph)\n\n### Memory Types\n\n| Type | Table | Description |\n|------|-------|-------------|\n| **Episodic** | `user_context` | Specific events/experiences with timestamps |\n| **Semantic** | `user_context` | General facts and knowledge |\n| **Procedural** | `user_context` | How-to knowledge and habits |\n| **Emotional** | `user_mood` | Emotional states with triggers and intensity |\n| **Preference** | `user_preferences` | Explicit preferences with confidence |\n| **Synaptic** | `synaptic_memory` | Key-value memory with priority and decay |\n| **HoloGraphic** | `user_context` (metadata) | Multi-dimensional tags (emotion, context, urgency, people) |\n| **HindSight** | `user_context` (discovery) | Post-conversation consolidation findings |\n| **Auto-Extracted** | `memories` (v5.0.0) | LLM-extracted facts with source='auto', deduped on insert |\n| **Graph-Derived** | `memory_relations` (v5.0.0) | Knowledge graph edges: mentions, implies, contradicts, same_entity, related_to |\n| **Extraction Log** | `extraction_log` (v5.0.0) | Quality metrics for empirical prompt tuning |\n\n### Memory Sources (v5.0.0)\n\nAll memories in the `memories` table now track their provenance:\n\n| Source | Description | Initial Confidence |\n|--------|-------------|-------------------|\n| `manual` | Written explicitly by agent | 0.9 |\n| `auto` | Extracted by local LLM hook | 0.6-0.7 |\n| `consolidation` | Derived from consolidation pass | 0.7 |\n| `import` | Imported from external system | 0.5 |\n\nAuto-extracted memories can be promoted via `verified_by_human = TRUE` when grounding confirms accuracy.\n\n### Auto-Extraction Hook (v5.0.0) — Replaces Mem0\n\nThe auto-extraction hook uses a local LLM to extract atomic facts from conversation text and insert them directly into MyVector. This replaces Mem0's zero-effort capture with full ownership.\n\n**Script:** `scripts/auto-extract.py`\n\n```bash\n# Extract from text\npython3 scripts/auto-extract.py \"conversation text here\" --user <discord_id>\n\n# Extract from file\npython3 scripts/auto-extract.py --file /path/to/conversation.txt --user <discord_id>\n\n# Dry run (preview without inserting)\npython3 scripts/auto-extract.py \"text\" --user <id> --dry-run\n\n# Output as JSON\npython3 scripts/auto-extract.py \"text\" --user <id> --dry-run --json\n```\n\n**Pipeline:**\n1. Local qwen3.5:4b extracts structured JSON (core_fact, confidence, entities, linked_to, tags, memory_type, importance)\n2. Key mapping normalizes LLM output (\"fact\" → \"core_fact\", invalid types → \"semantic\")\n3. Dedup: Jaccard similarity check against existing memories, merges if >50% overlap\n4. Insert with `source='auto'` for quality tracking\n5. Auto-discover relations: finds existing memories sharing entities\n6. Logs extraction metrics to `extraction_log`\n\n**Prompt design:** Uses string concatenation (not f-strings) to avoid curly brace issues with JSON examples. Strict key name requirements in prompt.\n\n**Fallback:** Regex-based extraction when LLM is unavailable.\n\n### Memory Relations + Knowledge Graph (v5.0.0) — Replaces Hancho\n\nNative MySQL knowledge graph that replaces Hancho's external reasoning.\n\n**Table:** `memory_relations`\n- `fact_id`, `related_fact_id` → FK to memories.id\n- `relation_type`: mentions, implies, contradicts, same_entity, related_to\n- `confidence`: 0.0-1.0\n- `source`: auto, manual, consolidation\n- Unique constraint on (fact_id, related_fact_id, relation_type)\n\n**Consolidation script:** `scripts/hancho-consolidate.py`\n\n```bash\n# Consolidate recent memories (default: last 6 hours)\npython3 scripts/hancho-consolidate.py --user <discord_id>\n\n# Lookback window\npython3 scripts/hancho-consolidate.py --user <id> --hours 24\n\n# Dry run\npython3 scripts/hancho-consolidate.py --user <id> --dry-run\n```\n\n**Pipeline:**\n1. Scan recent memories for shared entities/terms (Jaccard > 0.15)\n2. Contradiction detection: same-topic facts with opposite polarity\n3. Insert edges into `memory_relations`\n4. Derive hub insights (facts with 3+ connections)\n\n**Graph traversal:** Pre-computed view `memory_graph_1hop` for fast retrieval.\n\n### Extraction Quality Logging (v5.0.0)\n\nTracks auto-extraction quality for empirical tuning:\n\n**Table:** `extraction_log`\n- facts extracted, merged, inserted, relations discovered per run\n- input length, extraction time (ms), model used, fallback usage\n- Per-user and time-based indexes\n\n### Consolidation Script\n\n- **`memory_consolidation.py`** at `~/.openclaw/workspace/scripts/memory_consolidation.py`\n- Runs HindSight + HoloGraphic + Hancho in sequence\n- Scheduled every 6 hours via heartbeat and cron\n- Commands:\n  ```bash\n  python3 memory_consolidation.py --user <discord_id>\n  python3 memory_consolidation.py --all-users\n  python3 memory_consolidation.py --user <id> --dry-run\n  python3 memory_consolidation.py --user <id> --hindisght-only\n  python3 memory_consolidation.py --user <id> --holohraphic-only\n  python3 memory_consolidation.py --user <id> --hancho-only\n  ```\n\n## Capabilities\n\n- MyVector MySQL read/write operations only (no external APIs, crypto, or wallets)\n- All SQL routed through MyVector Docker container via `docker exec`\n- Uses `.env` files for credentials (parsed as KEY=VALUE, never shell-sourced)\n- All SQL routed through `sql_safe_exec.sh` for safety\n- `query` command is SELECT-only\n- DML requires interactive confirmation (no non-interactive bypass)\n- Table allowlist enforced for all write operations (26 approved tables)\n- Single-statement execution only (semicolons rejected)\n- **DDL blocked at the runtime layer** (`sql_safe_exec.sh` rejects DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE from agent-facing commands)\n- **Schema migrations are an exception**: Version upgrade scripts (`upgrade_vX_to_vY.sql`) use DDL (ALTER TABLE, CREATE TABLE IF NOT EXISTS) and must be run by a human administrator using `docker exec` directly — NOT through the agent-facing `sql_safe_exec.sh` wrapper. This is intentional: schema evolution requires DDL, but day-to-day agent operations do not.\n- Comment injection blocked (`/* */`, `--`, `#`)\n- Hex-encoded string detection blocked\n- Path traversal and sensitive file patterns blocked\n- Proper MySQL string escaping via Python (handles all edge cases)\n- Enum validation on all convenience command parameters\n- **FAIL CLOSED**: refuses to connect if MYSQL_USER or MYSQL_PASSWORD is missing\n- **REJECTS root/admin users**: requires dedicated least-privilege account\n- **Verifies MyVector container is running** before attempting connection\n- **Credentials loaded from environment variables** — never hardcoded in any Python script\n- **Memory consolidation**: HindSight + HoloGraphic + Hancho reasoning via heartbeat\n- **Auto-extraction**: Local LLM-powered fact extraction replacing Mem0 (v5.0.0)\n- **Knowledge graph**: Native MySQL `memory_relations` table replacing Hancho (v5.0.0)\n- **Graph traversal**: `memory_graph_1hop` view for retrieval-time graph expansion\n- **Extraction quality tracking**: `extraction_log` table for empirical prompt tuning\n\n### Deprecated Features (v5.0.0)\n\n- **Mem0**: Auto-extraction replaced by `scripts/auto-extract.py`. Run in parallel for 7-10 days to validate quality, then retire.\n- **Hancho**: Knowledge graph reasoning replaced by `memory_relations` table + `scripts/hancho-consolidate.py`. Native MySQL graph is tighter and fully owned.\n\n## Configuration\n\n| Option          | Default       | Notes                                  |\n|-----------------|---------------|----------------------------------------|\n| `MYSQL_USER`    | *required*    | Dedicated least-privilege account (NOT root) |\n| `MYSQL_PASSWORD`| *required*    | Store in `.env` (chmod 600)            |\n| `MYSQL_PORT`    | `3310`        | MyVector Docker port mapping           |\n| `DATABASE`      | `mysqlclaw`   | Target database                        |\n\n**MyVector Docker container must be running:**\n```bash\ndocker run -d --name myvector-db -p 3310:3306 \\\n  -e MYSQL_ROOT_PASSWORD=<root_pw> \\\n  -e MYSQL_DATABASE=mysqlclaw \\\n  ghcr.io/askdba/myvector:mysql8.4\n```\n\n## Installation\n\n**⚠️ Before installation**: Review the PRIVACY & CONSENT NOTICE above. Obtain explicit opt-in from all users before enabling auto-extraction or memory profiling.\n\n```bash\n# 1. Start MyVector container (if not running)\ndocker run -d --name myvector-db -p 3310:3306 \\\n  -e MYSQL_ROOT_PASSWORD=<root_pw> \\\n  -e MYSQL_DATABASE=mysqlclaw \\\n  ghcr.io/askdba/myvector:mysql8.4\n\n# 2. Create a dedicated least-privilege user inside MyVector\ndocker exec -it myvector-db mysql -u root -p<root_pw> -e \"\n  CREATE USER IF NOT EXISTS 'mysqlclaw'@'%' IDENTIFIED BY '<strong_password>';\n  GRANT SELECT, INSERT, UPDATE, DELETE ON mysqlclaw.* TO 'mysqlclaw'@'%';\n  FLUSH PRIVILEGES;\n\"\n\n# 3. Create .env file with the dedicated user's credentials\ncat > .env <<'EOF'\nMYSQL_USER=mysqlclaw\nMYSQL_PASSWORD=<strong_password>\nMYSQL_PORT=3310\nDATABASE=mysqlclaw\nEOF\nchmod 600 .env\n\n# 4. Apply schema with setup wizard\ncd ~/.openclaw/workspace/skills/custom-mysql\n./setup_wizard.sh\n\n# 5. Run initial consolidation (DRY RUN first, then live)\ncd ~/.openclaw/workspace\npython3 scripts/memory_consolidation.py --user <your_discord_id> --dry-run\npython3 scripts/memory_consolidation.py --user <your_discord_id>\n```\n\n**Auto-extraction is DISABLED by default.** To enable per-user after explicit opt-in:\n```bash\nexport MYSQL_USER=mysqlclaw\nexport MYSQL_PASSWORD=<your_password>\npython3 scripts/auto-extract.py --file /path/to/conversation.txt --user <discord_id> --dry-run\n# Review output, then run without --dry-run\n```\n\n## Usage\n\n```bash\n# Query (SELECT-only)\ncustom_mysql.sh query \"SELECT * FROM users LIMIT 5\"\n\n# Execute script (DML requires interactive confirmation)\ncustom_mysql.sh exec --file /path/to/scripts.sql\n\n# Convenience commands:\ncustom_mysql.sh insert_interaction <uid> <dir> <topic> <summary> [sentiment] [is_important]\ncustom_mysql.sh insert_note <uid> <note> [category] [is_pinned]\ncustom_mysql.sh insert_context <uid> <key> <value> [type] [importance] [expires_at]\ncustom_mysql.sh insert_skill_usage <uid> <skill_name> [action] [status] [duration_ms] [error_type]\ncustom_mysql.sh insert_relationship <uid> <related_uid> <type> [strength] [trust] [notes]\ncustom_mysql.sh insert_mood <uid> <mood> [intensity] [trigger_topic] [confidence]\ncustom_mysql.sh insert_reminder <uid> <trigger_type> <condition> <text> [priority]\ncustom_mysql.sh insert_thought <uid> <thought> [type] [channel_id]\ncustom_mysql.sh insert_learning <type> <title> <description> [priority] [user] [skill]\ncustom_mysql.sh insert_event <type> <title> [description] [channel_id]\n\n# Memory consolidation (v4.0.0):\npython3 ~/.openclaw/workspace/scripts/memory_consolidation.py --user <uid>\npython3 ~/.openclaw/workspace/scripts/memory_consolidation.py --all-users\n```\n\n## Data Retention & Deletion\n\n### Retention Policies (configurable via `data_retention_policy` table, v5.0.1)\nAll retention defaults are configurable. Run `SELECT * FROM data_retention_policy;` to review.\n\n| Data Type | Default Retention | Table |\n|-----------|-------------------|-------|\n| User interactions | 30 days | `user_interactions` |\n| Mood states | 90 days | `user_mood` |\n| HoloGraphic metadata | 30 days | `user_context` |\n| Consolidation-derived | 90 days | `user_context` |\n| **Agent reasoning (thought_stream)** | **7 days** | `thought_stream` |\n| Synaptic memory | 365 days (with decay) | `synaptic_memory` |\n| Community sentiment/trends | 90 days | `community_sentiment`, `trending_topics` |\n| Activity heatmap | 90 days | `user_activity_heatmap` |\n| Auto-extracted memories | 30 days | `memories` where source='auto' |\n| Manual memories | 365 days | `memories` where source='manual' |\n| Extraction quality logs | 30 days | `extraction_log` |\n| Audit logs | 365 days | `audit_log` |\n| Notes, relationships, preferences | Until explicitly deleted | `user_notes`, `user_relationships`, etc. |\n| Reminders | Auto-deactivate after `max_triggers` | `proactive_reminders` |\n\n**⚠️ Agent reasoning logs (`thought_stream`) default to 7-day retention.** Chain-of-thought data is sensitive and should not be retained long-term. Configure in `data_retention_policy`.\n\n### Deletion\n- Full user data deletion via `rollback_user.sql` covers all user-data tables\n- Rollback procedure wipes all user-specific data while preserves schema\n- **All deletions are logged to `audit_log`** (v5.0.1)\n\n### Consent & Provenance (v5.0.1)\n- **Auto-extraction is opt-in only** — disabled by default per-user (`extraction_config` table)\n- Users must explicitly consent before auto-extraction is enabled\n- Consent timestamp and method are recorded\n- Inferred data is stored with lower confidence scores (≤ 0.7)\n- Emotional/mood data requires confidence ≥ 0.7\n- `agent_learnings` affecting behavior must be reviewed before activation\n- Users can request full data deletion at any time\n\n## Security (v5.0.1)\n\n- **MyVector Docker container**: All SQL runs inside the container via `docker exec`\n- **Dedicated least-privilege user required**: root/admin accounts explicitly rejected\n- **Credentials via environment variables**: Python scripts load from `os.environ`. Shell scripts (`.sh`) load from `.env` file.\n- **Password never on command line**: Uses temporary `--defaults-extra-file` with `chmod 600` for shell commands.\n- **`.env` parsed safely**: KEY=VALUE line parsing only — never evaluated as shell code.\n- `query` command is SELECT-only (no DML through query).\n- DML requires interactive user confirmation (for agent-facing commands).\n- Single-statement execution only (semicolons rejected).\n- **DDL blocked at runtime**: `sql_safe_exec.sh` prevents DDL (DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE) for agent-facing commands.\n- **Schema migrations are a human admin task**: Upgrade scripts (`upgrade_vX.sql`) must be run directly via `docker exec` by an administrator with root privileges, not through the agent-facing wrappers.\n- Table allowlist enforced (26 approved tables).\n- Path traversal and sensitive file patterns blocked.\n- Comment injection blocked.\n- Hex-encoded string detection blocked.\n- Proper MySQL string escaping via Python.\n- Foreign key constraints prevent orphaned data.\n- Script permissions: 700 (owner execute only).\n- Config directory permissions: 700.\n- **`audit_log` table**: Tracks all data access and modification for accountability (v5.0.1).\n- **`extraction_config` table**: Enforces per-user opt-in for auto-extraction (v5.0.1).\n- **`data_retention_policy` table**: Configurable retention limits for all data types (v5.0.1).\n\n## Sentiment Scoring\n\n- **Per interaction**: `user_interactions.sentiment` (enum) + `sentiment_score` (float, -1 to 1)\n- **Per user trend**: Rolling average from recent interactions\n- **Community-wide**: `community_sentiment` aggregated by time period\n- **Mood impact**: Each interaction can shift user's mood (`mood_impact` field)\n- **HindSight analysis**: Automated sentiment trend analysis during consolidation\n\n## Engagement Patterns\n\n- **Time of day**: When user is most active\n- **Day of week**: Weekly activity cycles\n- **Topic triggers**: What topics engage this user most\n- **Channel preference**: Which channels they use\n- **Response style**: How they prefer to interact\n- **Session length**: Typical interaction duration\n- **Activity bursts**: Periods of high activity\n\n## Removed Features\n\n- **Snapshot functionality removed (v1.1.7)`**: The `agent_config_files` table and related commands removed\n- **Local MySQL dependency removed (v3.0.0)`**: Replaced with MyVector Docker container\n\n## Change Log\n\nSee [changelog.md](changelog.md) for full version history.\n\n## Setup Guide\n\nFor step-by-step instructions, see [SETUP_GUIDE.md](SETUP_GUIDE.md).\n\nVisit <https://clawhub.ai/paradoxfuzzle/custom-mysql> for live updates.\n\nFile v5.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7efbevah63xw54q5r7f0x07x80483q\",\n  \"slug\": \"custom-mysql\",\n  \"version\": \"5.0.1\",\n  \"publishedAt\": 1779899541100\n}\n\nFile v5.0.1:CAPABILITIES.md\n\n# VectorClaw — Capability Declarations\n\nThis document explicitly declares what VectorClaw **can** and **cannot** do.\nIt is intended to resolve automated security scanner false positives.\n\n**Version: 5.0.0**\n\n---\n\n## What VectorClaw DOES\n\n| Capability | Status | Notes |\n|---|---|---|\n| MyVector MySQL database operations | ✅ YES | SELECT, INSERT, UPDATE, DELETE on `mysqlclaw` schema via Docker container |\n| User profile storage | ✅ YES | Food prefs, media prefs, communication preferences |\n| Interaction tracking | ✅ YES | Messages, reactions, session grouping |\n| Relationship mapping | ✅ YES | Social graph with trust levels and interaction frequency |\n| Mood tracking | ✅ YES | Emotional states with triggers and intensity |\n| Context storage | ✅ YES | 14 context types: episodic, semantic, procedural, emotional, preference, fact, custom, hindisght, holohraphic, hancho, discovery, behavioral, metadata, reasoning, social_graph, auto_extracted, graph_derived, extraction_quality |\n| Synaptic memory | ✅ YES | Key-value with priority and automatic decay |\n| Thought stream | ✅ YES | Agent reasoning log (reasoning, observation, decision, reflection, planning) |\n| Proactive reminders | ✅ YES | Time-based, event-based, pattern-based follow-up triggers |\n| Agent learnings | ✅ YES | Self-improvement tracking (correction, preference, pattern, error, success, insight, rule) |\n| **HindSight memory consolidation** | ✅ YES | Post-conversation analysis: sentiment trends, topic discovery, importance scoring |\n| **HoloGraphic multi-dimensional tagging** | ✅ YES | Tags memories with emotion, context, urgency, people |\n| **Memory refresh / decay** | ✅ YES | synaptic_memory auto-decay, consolidation log, retention policies |\n| Engagement pattern analysis | ✅ YES | Time of day, day of week, topic triggers, channel preference |\n| Community sentiment | ✅ YES | Aggregated community mood tracking |\n| Trending topics | ✅ YES | Per-period trend identification |\n| Skill usage tracking | ✅ YES | Per-skill usage with error categorization |\n| Community events | ✅ YES | Milestone/incident logging |\n| Multi-dimensional search | ✅ YES | Query by emotion, context, urgency, people, time period |\n| Secure credential handling | ✅ YES | .env parsing, temp files, trap cleanup |\n| Input validation | ✅ YES | Enum validation, numeric validation, SQL escaping |\n| **Auto-extraction (v5.0.0)** | ✅ YES | Local LLM (qwen3.5:4b) extracts atomic facts from conversation text, replaces Mem0 |\n| **Memory relations graph (v5.0.0)** | ✅ YES | Native MySQL knowledge graph via `memory_relations` table, replaces Hancho |\n| **Graph traversal (v5.0.0)** | ✅ YES | `memory_graph_1hop` view for retrieval-time 1-hop graph expansion |\n| **Extraction quality logging (v5.0.0)** | ✅ YES | `extraction_log` table tracks facts extracted/merged/inserted, timing, model used |\n| **Source tracking (v5.0.0)** | ✅ YES | All memories track source: manual, auto, consolidation, import |\n| **Human verification (v5.0.0)** | ✅ YES | `verified_by_human` flag for promoting auto-extracted facts |\n| **Contradiction detection (v5.0.0)** | ✅ YES | Consolidation pass detects same-topic facts with opposite polarity |\n| **Hub insight derivation (v5.0.0)** | ✅ YES | Identifies high-degree facts (3+ connections) as important |\n\n---\n\n## What VectorClaw DOES NOT do\n\n| Capability | Status | Notes |\n|---|---|---|\n| External API calls | ❌ NO | No HTTP requests to third-party services |\n| Cryptocurrency / wallet operations | ❌ NO | No wallet, crypto, or blockchain code |\n| Financial transactions | ❌ NO | No purchase or payment processing |\n| File system access beyond DB | ❌ NO | No reading/writing arbitrary files |\n| Email sending | ❌ NO | No SMTP or email API |\n| Shell command execution | ❌ NO | No exec, system, or shell_exec outside Docker MySQL |\n| Local MySQL server | ❌ NO | MyVector Docker container only — no host MySQL required |\n| Root/admin MySQL access | ❌ NO | Explicitly rejected — dedicated least-privilege account required |\n| DDL operations (agent-facing) | ❌ NO | DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE blocked from agent-facing commands via `sql_safe_exec.sh`. Schema migration scripts run separately by human administrators. |\n| Multi-statement SQL | ❌ NO | Single-statement only — semicolons rejected |\n| Write without confirmation | ❌ NO | DML requires interactive user confirmation |\n| Access other users' private data | ❌ NO | Only processes data for the authenticated user |\n| Store operational config files | ❌ NO | No snapshots of MEMORY.md, AGENTS.md, etc. |\n| Arbitrary file reads | ❌ NO | Path traversal blocked |\n| Modify its own security rules | ❌ NO | Table allowlist and security controls are static |\n| **External memory services** | ❌ NO (v5.0.0) | Mem0 and Hancho deprecated — all functionality native in MyVector |\n\n---\n\n## Memory Architecture (v5.0.0)\n\n```\n┌─────────────────────────────────────────────────────────────────┐\n│                    OpenClaw Agent (Jerith)                        │\n├─────────────────────────────────────────────────────────────────┤\n│                                                                   │\n│  ┌──────────┐  ┌──────────┐  ┌──────────────────────────────┐  │\n│  │ MEMORY.md │  │ ChromaDB │  │     MyVector MySQL           │  │\n│  │ (narrative│  │ (semantic│  │     (Docker container)        │  │\n│  │  context) │  │  search) │  │                              │  │\n│  └──────────┘  └──────────┘  │  memories (with source,      │  │\n│                               │    verified_by_human)        │  │\n│                               │  memory_relations (graph)    │  │\n│                               │  extraction_log (quality)    │  │\n│                               │  user_context (14 types)     │  │\n│                               │  user_mood, user_prefs, etc. │  │\n│                               │  + 26 more tables            │  │\n│                               └──────────────────────────────┘  │\n│                                              │                    │\n│              ┌───────────────────────────────┤                    │\n│              ▼                               ▼                    │\n│  ┌─────────────────────┐      ┌─────────────────────────┐       │\n│  │ auto-extract.py     │      │ hancho-consolidate.py   │       │\n│  │ (local LLM extract) │      │ (graph reasoning)       │       │\n│  │ Replaces Mem0       │      │ Replaces Hancho         │       │\n│  └─────────────────────┘      └─────────────────────────┘       │\n│              │                               │                    │\n│              └───────────────┬───────────────┘                    │\n│                              ▼                                    │\n│                   ┌────────────────────┐                         │\n│                   │ Retrieval Gate v3  │                         │\n│                   │ (triggered pull    │                         │\n│                   │  + graph expansion)│                         │\n│                   └────────────────────┘                         │\n└─────────────────────────────────────────────────────────────────┘\n```\n\n## Dimensional Tag Reference (HoloGraphic)\n\n| Dimension | Values | Example |\n|-----------|--------|---------|\n| Emotion | positive, negative, complex, neutral | \"Ev's medication worries\" → negative |\n| Context | work, personal, health, tech, social, creative | \"Server setup\" → tech |\n| Urgency | immediate, ongoing, timeless, historical | \"Current medication\" → ongoing |\n| People | auto-detected names | \"Ev and Cyle\" → Ev,Cyle |\n\n## Memory Relations Reference (v5.0.0)\n\n| Relation Type | Description | Discovery Method |\n|---------------|-------------|-----------------|\n| `mentions` | Fact A mentions entities from Fact B | Term overlap (Jaccard > 0.15) |\n| `implies` | Fact A logically implies Fact B | LLM reasoning during consolidation |\n| `contradicts` | Fact A contradicts Fact B (same topic, opposite polarity) | Polarity detection |\n| `same_entity` | Both facts reference the same entity | Entity matching |\n| `related_to` | General relatedness | Category or topic overlap |\n\n## Memory Source Tracking (v5.0.0)\n\n| Source | Description | Initial Confidence | Verification |\n|--------|-------------|-------------------|--------------|\n| `manual` | Written explicitly by agent | 0.9 | N/A (trusted) |\n| `auto` | Extracted by local LLM hook | 0.6-0.7 | `verified_by_human` flag |\n| `consolidation` | Derived from consolidation pass | 0.7 | Review on next cycle |\n| `import` | Imported from external system | 0.5 | Manual review required |\n\n## Trust Rules\n\n- All data storage requires explicit user consent or direct interaction\n- Inferred data is stored with lower confidence scores (≤ 0.7)\n- Emotional/mood data with confidence < 0.7 is not stored\n- `agent_learnings` affecting behavior must be reviewed before activation\n- Users can request full data deletion at any time via rollback_user.sql\n- Consolidation only processes data the agent already has access to — no new data sources\n- Auto-extracted facts start at lower confidence and require human verification to promote\n- Contradictions between high-confidence facts are flagged for review, not auto-resolved\n\nFile v5.0.1:changelog.md\n\n# CHANGELOG\n\nAll notable changes to the **VectorClaw** skill for OpenClaw are documented in this file.\n\nThe format follows the [Keep a Changelog](https://keepachangelog.com/en/1.0.0/) specification and respects [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [5.0.0] – 2026-05-27\n\n### Added — MyVector Self-Sufficiency: Auto-Extraction + Knowledge Graph\n\nThis release makes MyVector self-sufficient by absorbing Mem0's auto-extraction and Hancho's knowledge graph reasoning into native MySQL systems.\n\n**Auto-Extraction Hook (`scripts/auto-extract.py`):**\n- Uses local qwen3.5:4b model with structured JSON prompt to extract atomic facts from conversation text\n- Extracts: core_fact, confidence (0-1), entities[], linked_to[], tags[], memory_type, importance\n- Key mapping normalizes LLM output (handles \"fact\" → \"core_fact\", invalid memory_types → \"semantic\")\n- Auto-dedup on insert: Jaccard similarity check against existing memories, merges if >50% overlap\n- Auto-discovers relations: finds existing memories sharing entities, creates edges in `memory_relations` table\n- Source tracking: marks auto-extracted memories with `source='auto'` for quality monitoring\n- Fallback to regex-based extraction when LLM is unavailable\n- Validates memory_type against DB enum before insert\n\n**Memory Relations Table (`memory_relations`):**\n- Native MySQL knowledge graph replacing Hancho's external reasoning\n- Schema: fact_id, related_fact_id, relation_type, confidence, source, discovered_at\n- Relation types: mentions, implies, contradicts, same_entity, related_to\n- Source tracking: auto (from extraction), manual, consolidation\n- Unique constraint prevents duplicate edges\n- Indexes for fast graph traversal during retrieval\n\n**Hancho Consolidation Pass (`scripts/hancho-consolidate.py`):**\n- Scans recent memories for shared entities/terms (Jaccard > 0.15)\n- Contradiction detection: finds same-topic facts with opposite polarity\n- Inserts edges into `memory_relations`\n- Derives hub insights (facts with 3+ connections = important)\n- Runs as heartbeat job (every 1-4 hours recommended)\n\n**Extraction Quality Logging (`extraction_log`):**\n- Tracks: facts extracted, merged, inserted, relations discovered per run\n- Records: input length, extraction time, model used, fallback usage\n- Enables empirical tuning of extraction prompt over time\n\n**Graph Traversal View (`memory_graph_1hop`):**\n- Pre-computed MySQL view for fast 1-hop graph traversal during retrieval\n- Joins memory_relations with memories for complete edge+node data\n- Filtered to confidence >= 0.5 for quality\n\n### Changed — Database Schema\n\n- **`memories` table**: Added `source` (enum: manual/auto/consolidation/import), `verified_by_human` (boolean), `extraction_prompt` (text) columns\n- **`memories` table**: Added `idx_mem_source` index for source-based queries\n- **`user_context` table**: Extended `context_type` enum with `auto_extracted`, `graph_derived`, `extraction_quality`\n- **New table**: `memory_relations` — knowledge graph edges\n- **New table**: `extraction_log` — extraction quality metrics\n- **New view**: `memory_graph_1hop` — fast graph traversal\n\n### Changed — SKILL.md Updated\n\n- **Version bumped to 5.0.0**\n- **Added Auto-Extraction section** documenting the auto-extract hook, prompt design, key mapping, and dedup logic\n- **Added Memory Relations section** documenting the knowledge graph schema, relation types, and consolidation pass\n- **Added Extraction Logging section** documenting quality tracking\n- **Added deprecation notes** for Mem0 (auto-extraction replaced) and Hancho (knowledge graph replaced)\n- **Updated Memory Types table** with new source tracking and graph-derived types\n- **Updated data retention policies** for auto-extracted memories (7-day parallel run, then 30-day review cycle)\n\n### Deprecated — External Memory Tools\n\n- **Mem0**: Auto-extraction replaced by `auto-extract.py` with local qwen3.5:4b. Run in parallel for 7-10 days for quality comparison, then retire.\n- **Hancho**: Knowledge graph reasoning replaced by `memory_relations` table + `hancho-consolidate.py`. Native MySQL graph traversal is tighter and fully owned.\n\n### Migration Notes — IMPORTANT\n\n**⚠️ Backup first!** Always back up your database before running any migration:\n```bash\ndocker exec myvector-db mysqldump -u root -p<pass> mysqlclaw > backup_pre_v5.sql\n```\n\n- Run `upgrade_v4_to_v5.sql` to apply schema changes. **This script uses DDL** (ALTER TABLE, CREATE TABLE IF NOT EXISTS). Run directly via `docker exec`, NOT through `sql_safe_exec.sh`.\n- Existing memories default to `source='manual'` — no data migration needed\n- **Auto-extraction is disabled by default.** Enable per-user only after explicit opt-in.\n- Run `hancho-consolidate.py --dry-run` first to preview graph edges before committing\n- **Review auto-extracted data** for accuracy and sensitivity before it affects agent behavior\n\n### Security Audit Response (v5.0.1)\n\nThis release addresses findings from the ClawHub security audit (37 findings, 2026-05-27):\n\n- **Credential handling**: All Python scripts now load credentials from environment variables. No hardcoded passwords in any script.\n- **DDL documentation**: Clarified that schema migrations require DDL and must be run by human administrators directly, not through the agent-facing wrapper.\n- **Privacy notice**: Added prominent consent/privacy warning at the top of SKILL.md.\n- **Auto-extraction opt-in**: Auto-extraction is now disabled by default. Must be explicitly enabled per-user.\n- **Backup warnings**: Migration instructions now include explicit backup-first warnings.\n- **Consolidation scope**: Added `--dry-run` and user-scoping to all consolidation commands.\n- **thought_stream isolation**: Agent reasoning logs are now stored with optional user linkage (user_id can be NULL) to avoid co-locating chain-of-thought with identifiable user data.\n\n---\n\n## [4.0.0] – 2026-05-21\n\n### Added — HindSight + HoloGraphic + Hancho Memory Systems\n\nThis release adds three memory enhancement systems that run during heartbeat consolidation cycles:\n\n**HindSight** — Post-conversation analysis:\n- Analyzes recent interactions for sentiment trends (positive/negative/neutral ratios)\n- Identifies frequently discussed topics and new topics not yet stored as memories\n- Detects recurring themes worth tracking\n- Stores findings as derived memories in `user_context` (category: discovery/behavioral/emotional)\n\n**HoloGraphic** — Multi-dimensional memory tagging:\n- Tags every memory with: emotion (positive/negative/complex/neutral), context (work/personal/health/tech/social/creative), urgency (immediate/ongoing/timeless/historical), people involved\n- Enables retrieval from any angle (e.g., \"how did Ev feel about X\" or \"what health topics came up in May\")\n- Stores tags as structured memories in `user_context` (category: metadata)\n\n**Hancho** — Knowledge graph reasoning:\n- Connects related facts across memories to derive new insights\n- 7 reasoning rules: medication side effects, health chains, tech infrastructure, creative passions, relationship depth, interest-to-skill, emotional coping patterns\n- Inter-user reasoning finds shared topics between users\n- Stores derived insights as new memories in `user_context` (category: reasoning)\n\n### Added — memory_consolidation.py Script\n\n- **`memory_consolidation.py`** — Standalone consolidation script that runs HindSight + HoloGraphic + Hancho in sequence.\n- Supports `--user <id>`, `--all-users`, `--hindisght-only`, `--holohraphic-only`, `--hancho-only`, `--dry-run` flags.\n- Integrates with `community-memory.py` via subprocess calls.\n- Scheduled to run every 6 hours via OpenClaw heartbeat and cron.\n- Already processed: NP (4 derived insights, 10 tagged memories) and Ev (10 tagged memories).\n\n### Changed — SKILL.md Updated\n\n- **Version bumped to 4.0.0**\n- **Added Memory Consolidation section** documenting HindSight, HoloGraphic, and Hancho systems.\n- **Added Memory Types table** with 6 types: Episodic, Semantic, Procedural, Emotional, Preference, Synaptic, HoloGraphic (multi-dimensional tags), and Hancho (derived reasoning).\n- **Added dimensional tag reference**: emotion, context, urgency, people fields for HoloGraphic tagging.\n- **Added reasoning rule reference**: 7 Hancho reasoning patterns with examples.\n- **Updated data retention policies** for new memory types (HoloGraphic tags: 30-day refresh; Hancho derived: 90-day review).\n- **Updated Memory Architecture section** in README to reference all 3 systems and when to use each.\n\n### Changed — Database Schema Enhancements\n\n- **`user_context` table**: Enhanced `context_type` enum to include new consolidation types: `hindisght`, `holohraphic`, `hancho`, `discovery`, `behavioral`, `metadata`, `reasoning`, `social_graph`.\n- **`memory_consolidation_log` table**: Now actively used. Each consolidation run logs: consolidation type, source count, result count, affected users, timestamp.\n- **New indexes on `user_context`**: Added composite index on `(user_id, context_type, importance)` for faster consolidation queries.\n- **New index on `user_interactions`**: Added composite index on `(user_id, created_at, sentiment)` for HindSight trend analysis.\n\n### Added — New SQL Migration Script\n\n- **`upgrade_v3_to_v4.sql`** — Migration script for upgrading v3.x installations to v4.0.0:\n  - Adds new enum values to `user_context.context_type`\n  - Adds new indexes for consolidation queries\n  - Safe to run on production (uses `IF NOT EXISTS` and `ALTER TABLE ... ADD COLUMN IF NOT EXISTS`)\n\n### Updated — Documentation\n\n- **CAPABILITIES.md** — Added HindSight, HoloGraphic, and Hancho to capability declarations. Added memory_consolidation.py as a required script.\n- **SETUP_GUIDE.md** — Added section on memory consolidation setup and scheduling.\n- **SKILL.md** — Updated memory type table, added consolidation commands, updated architecture diagram.\n\n### Security\n\n- Consolidation performs both reads and writes: analysis is SELECT-only, but derived memories, tags, and graph edges are written to the database.\n- Write operations use direct database connections (not through `sql_safe_exec.sh`) since consolidation is an automated background process, not an interactive agent command.\n- Consolidation only processes data the agent already has access to.\n- **Recommended**: Run with `--dry-run` first to review what will be written.\n\n### Migration Notes (v3.x → v4.0.0)\n\n1. Back up your `mysqlclaw` database before upgrading.\n2. Run `upgrade_v3_to_v4.sql` against your existing database:\n   ```bash\n   docker exec -i myvector-db mysql -u mysqlclaw -p<pass> mysqlclaw < upgrade_v3_to_v4.sql\n   ```\n3. Copy `memory_consolidation.py` to `~/.openclaw/workspace/scripts/`.\n4. Add the 6-hour consolidation heartbeat task to `HEARTBEAT.md`.\n5. Run initial consolidation: `python3 memory_consolidation.py --user <id>`.\n6. Existing data is preserved — new tables/columns use `IF NOT EXISTS`.\n\n---\n\n## [3.1.0] – 2026-05-11\n\n### Changed — Renamed from MySQLClaw to VectorClaw\n\n- **Skill renamed from MySQLClaw to VectorClaw.** The skill name, slug, and all internal references updated to reflect the new name. The old name `MySQLClaw` implied a MySQL-specific dependency; `VectorClaw` better reflects the MyVector (MySQL 8.4 + vector search) foundation.\n- **Directory renamed from `mysqlclaw` to `vectorclaw`.** The active skill directory is now `skills/vectorclaw/`. The dev-only `custom-mysql` directory retains its name for reference.\n- **Script files renamed.** `custom_mysql.sh` → `vector_claw.sh`, `setup_wizard.sh` → `vector_claw_setup.sh`.\n- **`_meta.json` slug updated** from `custom-mysql` to `vector-claw`.\n- **All documentation updated.** `SKILL.md`, `CAPABILITIES.md`, `updated_SKILL.md`, `SETUP_GUIDE.md`, `changelog.md` — all references to MySQLClaw replaced with VectorClaw.\n\n---\n\n## [3.0.0] – 2026-05-11\n\n### Changed — Replaced MySQL with MyVector Docker Container\n\n- **Replaced local MySQL dependency with MyVector Docker container.** The skill no longer requires a local MySQL server or client. All SQL is routed through `docker exec` into the MyVector container (`ghcr.io/askdba/myvector:mysql8.4`), which provides MySQL 8.4 compatibility with vector search extensions. This eliminates the host MySQL 8.4 client's missing `mysql_native_password` auth plugin issue.\n\n- **`sql_safe_exec.sh` completely rewritten for Docker exec.** The `MYSQL_CMD` now uses `docker exec -i myvector-db mysql --defaults-extra-file=...` instead of the host `mysql` binary. Credentials are copied into the container via `docker cp` before each query. The container is verified to be running before any connection attempt.\n\n- **All references to local MySQL replaced with MyVector.** `SKILL.md`, `CAPABILITIES.md`, `updated_SKILL.md`, `SETUP_GUIDE.md`, and `_meta.json` updated to reflect MyVector Docker container as the database backend.\n\n### Security Fixes (ClawScan audit response)\n\n- **Fail-closed authentication.** Previously, `sql_safe_exec.sh` silently fell back to `root` when `MYSQL_USER` was not set in `.env`. Now the skill explicitly refuses to connect if `MYSQL_USER` or `MYSQL_PASSWORD` is missing, printing an error message explaining the requirement for a dedicated least-privilege account.\n\n- **Root/admin user rejection.** The skill now explicitly rejects `root`, `admin`, and `mysql` usernames. If a user attempts to use these accounts, the skill prints an error and exits. This addresses the ClawScan finding that the skill could silently fall back to database-administrator privileges.\n\n- **Container verification.** Before attempting any SQL connection, the skill now verifies that the MyVector Docker container exists and is running. If the container is missing or stopped, the skill prints a helpful error message with the `docker run` command to start it.\n\n- **Removed wallet/crypto/purchase capability flags from `_meta.json`.** The previous metadata incorrectly declared `crypto`, `requires-wallet`, `can-make-purchases`, and `requires-sensitive-credentials` capability signals. These have been removed. The skill has never contained wallet, cryptocurrency, or purchase code.\n\n- **`_meta.json` updated with accurate declarations.** Added `docker` to `requiredBinaries` (replacing `mysql`). Updated `credentialEnvVars` to match actual usage. Updated description to mention MyVector and least-privilege requirement.\n\n- **`setup_wizard.sh` rewritten for MyVector.** The wizard now: (1) checks Docker is running, (2) creates/starts the MyVector container, (3) creates a dedicated least-privilege MySQL user inside the container, (4) applies the schema, (5) verifies the connection. No longer shows the root password as a default value — prompts securely with `-s` flag.\n\n- **`updated_SKILL.md` — added opt-in, provenance, and review rules.** Added explicit consent requirements: opt-in for each data source, provenance tracking (source, confidence, timestamp), review requirement for `agent_learnings` before they affect behavior, and retention/deletion enforcement.\n\n- **`updated_SKILL.md` — added source path restrictions.** Explicitly lists approved sources (Discord messages, reactions, user statements, observed patterns, agent reasoning) and prohibited sources (operational config files, secrets/credentials, other users' private data, arbitrary file reads).\n\n- **`CAPABILITIES.md` — removed wallet/crypto/purchase declarations.** Added `Fail-closed auth`, `Rejects root/admin`, and `Container verification` to the \"What VectorClaw DOES\" section. Added `Local MySQL server` and `Root/admin MySQL access` to the \"What VectorClaw DOES NOT do\" section.\n\n- **`SKILL.md` — version bumped to 3.0.0.** Updated all documentation to reference MyVector Docker container instead of local MySQL. Added Removed Features entry for local MySQL dependency.\n\n- **`.env` file removed from `custom-mysql` directory.** The development-only skill directory no longer contains any credentials. Only the `mysqlclaw` skill directory (the installed, active skill) has a `.env` file.\n\n- **`custom-mysql` confirmed as dev-only.** This skill is never installed or used in production. All production use goes through the `mysqlclaw` skill directory.\n\n### Security Audit Results (v3.0.0)\n\n1. ✅ **File permissions** — All shell scripts set to 700 (owner execute only). All data files set to 644.\n2. ✅ **No hardcoded credentials** — No passwords in any file. The setup wizard prompts interactively.\n3. ✅ **No eval usage** — Zero `eval` statements across all scripts.\n4. ✅ **No shell-sourced .env** — `.env` is parsed as KEY=VALUE lines only, never evaluated as shell code.\n5. ✅ **No password on command line** — Uses temporary `--defaults-extra-file` with `chmod 600`.\n6. ✅ **No root/admin fallback** — Root is explicitly rejected, not defaulted.\n7. ✅ **Fail-closed on missing creds** — Refuses to connect without MYSQL_USER and MYSQL_PASSWORD.\n8. ✅ **Container verification** — Verifies MyVector container is running before connecting.\n9. ✅ **DDL blocking** — DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE blocked.\n10. ✅ **Table allowlist** — 26 approved tables enforced for all write operations.\n11. ✅ **DML confirmation** — Interactive confirmation required for all write operations.\n12. ✅ **Single-statement enforcement** — Semicolons rejected to prevent stacked queries.\n13. ✅ **Path traversal prevention** — Sensitive paths and file operations blocked.\n14. ✅ **Comment injection prevention** — `/* */`, `--`, `#` style comments blocked.\n15. ✅ **Hex-encoding prevention** — `0x...` patterns blocked.\n16. ✅ **Temp file safety** — `mktemp` with `chmod 600` and trap-based cleanup.\n17. ✅ **Foreign key constraints** — All user-data tables have ON DELETE CASCADE.\n18. ✅ **Rollback completeness** — `rollback_user.sql` covers all 26 user-data tables.\n19. ✅ **No wallet/crypto/purchase code** — Confirmed zero wallet, crypto, or purchase functionality.\n20. ✅ **Accurate metadata** — `_meta.json` capability flags match actual behavior.\n\n---\n\n## [2.1.0] – 2026-05-11\n\n### Security Fixes (ClawScan audit response)\n\n- **Fixed `.env` file parsing — no longer shell-sourced.** Previously, `custom_mysql.sh` and `sql_safe_exec.sh` used `source \"$SCRIPT_DIR/.env\"` which evaluates the file as shell code. A malicious `.env` file could execute arbitrary commands. Changed to strict KEY=VALUE line parsing with regex validation (`^[A-Za-z_][A-Za-z0-9_]*$` for keys, only recognized MYSQL_* keys accepted). The `.env` file is never evaluated as code.\n\n- **Fixed password exposure on command line.** `sql_safe_exec.sh` was building a `MYSQL_CMD` string that included `--password=${MYSQL_PASSWORD}` directly on the command line, exposing credentials to local process inspection (`ps`, `/proc`). Replaced with temporary `--defaults-extra-file` approach: credentials are written to a `mktemp` file with `chmod 600`, used via `--defaults-extra-file`, and cleaned up via `trap cleanup_creds EXIT` on any exit (normal, error, or signal). Password never appears on the command line.\n\n- **Added source path restrictions and consent rules.** Replaced the broad \"Data Ingestion as Source of Truth\" section in `updated_SKILL.md` with explicit source restrictions: approved sources (Discord messages, reactions, user statements, observed patterns, agent reasoning) and prohibited sources (operational config files, secrets/credentials, other users' private data, arbitrary file reads). Added consent & sensitivity rules: explicit over inferred, emotional data confidence threshold (≥ 0.7), retention policies, and deletion procedures.\n\n- **Updated `_meta.json` with required binaries and credential env vars.** Declared `requiredBinaries: [\"mysql\", \"openssl\", \"python3\"]` and `credentialEnvVars: [\"MYSQL_USER\", \"MYSQL_PASSWORD\", \"MYSQL_HOST\", \"MYSQL_PORT\", \"DATABASE\"]` so users have a complete pre-install picture of requirements.\n\n- **Removed `.env` from `custom-mysql` directory.** The development-only `custom-mysql` skill directory no longer contains any credentials. The `.env` file with MySQL credentials exists only in the `mysqlclaw` skill directory (the installed, active skill).\n\n- **Synced all v2.1.0 fixes to `mysqlclaw` directory.** Both `custom-mysql` (dev) and `mysqlclaw` (installed) directories now contain identical code, with the exception that only `mysqlclaw` has a `.env` file.\n\n### Changed\n\n- `sql_safe_exec.sh` version bumped to v2.1.0.\n- `custom_mysql.sh` version bumped to v2.1.0.\n- `setup_wizard.sh` version bumped to v2.1.0.\n- `_meta.json` version bumped to 2.1.0.\n\n---\n\n## [2.0.0] – 2026-05-11\n\n### Added — New Tables (16 new tables)\n\n- **`user_mood`** — Emotional state tracking per user. Stores mood state (happy/excited/calm/neutral/tired/stressed/frustrated/sad/angry/anxious), intensity (0-1), trigger topic/context, source reference, and confidence score. Supports mem0-like emotional memory. Indexed by user+time and mood state.\n\n- **`user_engagement_patterns`** — Behavioral pattern analysis per user. Tracks 7 pattern types: time_of_day, day_of_week, topic_trigger, channel_preference, response_style, session_length, activity_burst. Each pattern has a key, value, frequency count, and confidence score. Enables the agent to learn *how* and *when* each user prefers to interact.\n\n- **`conversation_sessions`** — Groups related interactions into meaningful conversation sessions. Tracks start/end time, topic, summary, message count, average sentiment, mood at start/end, and key points. Enables higher-level reasoning about conversation arcs rather than individual messages.\n\n- **`session_interactions`** — Many-to-many linking table between conversation_sessions and user_interactions. Allows flexible grouping of interactions into sessions without modifying the interaction records.\n\n- **`proactive_reminders`** — Follow-up trigger system. Supports 4 trigger types: time_based (specific date), event_based (when something happens), pattern_based (when a pattern matches), followup (after interaction). Configurable priority (low/medium/high), max trigger count, and active status. Enables the agent to remember to follow up with users.\n\n- **`synaptic_memory`** — Key-value memory store with priority scoring and automatic decay. Each entry has a priority (1-10), decay_rate (auto-reduces priority over time), access_count, and last_accessed timestamp. High-priority memories persist; low-priority ones fade naturally. Directly inspired by synaptic memory models.\n\n- **`thought_stream`** — Agent reasoning log. Records agent thoughts with 5 types: reasoning, observation, decision, reflection, planning. Linked to users and channels. Enables the agent to review its own reasoning process and learn from past decisions.\n\n- **`topic_keywords`** — Searchable topic index. Tracks keywords with weight scores, categories, mention counts, and first/last seen timestamps. Enables fast topic-based search across all user interactions without full-text scanning.\n\n- **`community_sentiment`** — Community-wide sentiment aggregation. Stores sentiment (positive/neutral/negative/mixed), score, sample_size, topic, channel, and time period. Enables tracking of overall community mood over time.\n\n- **`trending_topics`** — Trend tracking per time period. Stores mention count, unique users, average sentiment, related keywords, and date range. Enables identification of what the community is talking about.\n\n- **`community_events`** — Milestone/incident log. 5 event types: milestone, achievement, incident, trend, custom. Tracks title, description, involved users, channel, and timestamp. Enables recording important community moments.\n\n- **`agent_learnings`** — Self-improvement tracking. 7 learning types: correction, preference, pattern, error, success, insight, rule. Includes priority, active status, applied count, and links to related users/skills. Enables the agent to record and apply lessons from interactions.\n\n- **`user_activity_heatmap`** — Hour × day-of-week activity matrix per user. Tracks activity_count, message_count, interaction_count, and average_sentiment per cell. Enables data-driven engagement pattern analysis.\n\n- **`memory_consolidation_log`** — Tracks memory maintenance operations. 5 consolidation types: summarize, merge, prune, archive, reindex. Records source/result counts, affected users, and details. Enables auditing of memory lifecycle operations.\n\n### Enhanced — Existing Tables (8 tables enhanced)\n\n- **`users`** — Added: `timezone` (VARCHAR), `roles` (JSON), `total_messages` (INT), `total_reactions` (INT), `total_sessions` (INT), `last_seen` (TIMESTAMP), status expanded to include `new`/`away`/`dnd`. Added indexes on status, last_seen, last_interaction.\n\n- **`user_interactions`** — Added: `sentiment_score` (FLOAT, -1 to 1 for fine-grained sentiment), `mood_impact` (FLOAT, how much this interaction shifted the user's mood), `channel_id` (VARCHAR), `message_id` (VARCHAR), `is_important` (BOOLEAN), `requires_followup` (BOOLEAN), `followup_topic` (VARCHAR), `followup_due` (TIMESTAMP), `metadata` (JSON). Added indexes on sentiment, followup, channel+time, important.\n\n- **`user_context`** — Added: `context_type` (ENUM: episodic/semantic/procedural/emotional/preference/fact/custom), `importance` (FLOAT, 0-1 for priority), `source` (ENUM: conversation/observation/explicit/inferred/system), `channel_id`, `message_id`, `is_active` (BOOLEAN), `metadata` (JSON). Added indexes on context_type, is_active, importance. Now supports mem0-like memory type classification.\n\n- **`user_attributes`** — Added: `confidence` (FLOAT), `source` (ENUM: stated/inferred/observed), `metadata` (JSON). Expanded `attribute_type` to include: skill, trait, goal, custom (beyond like/dislike/hobby/interest). Added indexes on attribute_type and category.\n\n- **`user_media`** — Expanded `media_type` from 3 to 10 values: tv_show, movie, book, game, music, podcast, anime, comic, youtube, other. Added: `status` (ENUM: completed/in_progress/planned/dropped/on_hold), `progress` (VARCHAR), `review` (TEXT), `source` (ENUM: stated/observed/inferred). Added indexes on rating and status.\n\n- **`user_food_preferences`** — Expanded `preference` from 2 to 6 values: loves, likes, neutral, dislikes, allergic, hates. Added: `context` (VARCHAR), `source` (ENUM: stated/observed/inferred), `metadata` (JSON). Added index on preference.\n\n- **`user_relationships`** — Added: `trust_level` (TINYINT 1-10), `interaction_frequency` (ENUM: daily/weekly/monthly/rarely/never), `shared_interactions` (JSON), `notes` (TEXT), `first_interaction` (TIMESTAMP). Expanded `relationship_type` to include: close_friend, mentor, mentee, rival. Added index on relationship_type.\n\n- **`skill_usage`** — Added: `error_type` (VARCHAR) for categorized error tracking. Added index on error_type.\n\n- **`user_notes`** — Added: `tags` (JSON for flexible tagging), `is_pinned` (BOOLEAN), `is_private` (BOOLEAN), `source_message_id` (VARCHAR). Added indexes on is_pinned and is_private.\n\n### Added — New Convenience Commands (custom_mysql.sh)\n\n- **`insert_mood <uid> <mood> [intensity] [trigger] [confidence]`** — Track user mood with validation against 10 mood states and numeric validation for intensity/confidence.\n\n- **`insert_reminder <uid> <type> <condition> <text> [priority]`** — Set proactive reminders with enum validation for trigger type and priority.\n\n- **`insert_thought <uid> <thought> [type] [channel_id]`** — Log agent reasoning with validation against 5 thought types.\n\n- **`insert_learning <type> <title> <desc> [priority] [user] [skill]`** — Record agent learnings with enum validation.\n\n- **`insert_event <type> <title> [description] [channel_id]`** — Log community events with enum validation.\n\n- **`insert_interaction`** — Added `is_important` parameter.\n\n- **`insert_note`** — Added `is_pinned` parameter.\n\n- **`insert_context`** — Added `context_type`, `importance` (with numeric validation), `expires_at` parameters.\n\n- **`insert_skill_usage`** — Added `error_type` parameter.\n\n- **`insert_relationship`** — Added `trust_level` (with numeric validation) and `notes` parameters.\n\n### Added — New Security Controls\n\n- **Comment injection blocking.** `sql_safe_exec.sh` now rejects SQL containing `/*`, `*/`, `--` followed by whitespace, or `#` followed by whitespace. This prevents attackers from using comments to truncate SQL and bypass security checks.\n\n- **Hex-encoded string detection.** `sql_safe_exec.sh` now rejects SQL containing `0x` followed by hex digits, `UNHEX(`, or `HEX(`. This prevents encoding-based bypasses of the escaping system.\n\n- **Enum validation helper.** `custom_mysql.sh` includes a `validate_enum()` function that validates parameter values against allowed lists. All enum parameters on convenience commands (mood states, trigger types, relationship types, context types, priorities, statuses, etc.) are validated before being used in SQL.\n\n- **Numeric validation for float parameters.** `insert_mood` validates `intensity` and `confidence` as numeric. `insert_context` validates `importance` as numeric. Prevents SQL injection through these parameters.\n\n- **Table allowlist expanded from 12 to 28.** Added all 16 new tables plus `session_interactions` and `user_activity_heatmap` to the approved write table list in `sql_safe_exec.sh`.\n\n### Changed — Existing Security\n\n- **sql_safe_exec.sh version bumped to v2.0.0.** Added comment injection and hex-encoding detection security controls. Added 16 new tables to the write allowlist.\n\n- **custom_mysql.sh version bumped to v2.0.0.** Added 5 new convenience commands (insert_mood, insert_reminder, insert_thought, insert_learning, insert_event). Enhanced 5 existing commands with new parameters. Added `validate_enum()` helper function. All parameters properly escaped and validated.\n\n- **setup_wizard.sh version bumped to v2.0.0.** Added `python3` to dependency checks. Added verification of new tables after schema application. Lists each new table with ✓/✗ status. Now also runs `populate_templates.sql` during setup.\n\n- **`rollback_user.sql` updated.** Now covers all 26 user-data tables in proper deletion order for foreign key constraints. Added: session_interactions, conversation_sessions, user_mood, user_engagement_patterns, user_activity_heatmap, proactive_reminders, synaptic_memory, thought_stream, user_notes (already existed but order corrected). Added deletion of user's topic_keywords and agent_learnings references.\n\n- **`create_user_tables.sql` rewritten.** Now creates 28 total tables (up from 12). All existing tables preserved with ALTER-style enhancements (new columns). 16 new tables added. Proper indexing throughout. Foreign key constraints with ON DELETE CASCADE on all user-data tables.\n\n### Updated — Documentation\n\n- **`SKILL.md`** — Completely rewritten for v2.0.0. Added memory type reference table (mem0-like types). Added sentiment scoring explanation. Added engagement patterns description. Updated data retention policies for new table types. Updated security section with new controls.\n\n- **`CAPABILITIES.md`** — Expanded capability declarations. Added all new tables and capabilities. Updated approved write table list to 28 tables. Added enum validation, comment injection prevention, and hex-encoding prevention as declared capabilities. Updated trust rules to include inferred data and mood data aging.\n\n- **`updated_SKILL.md`** — Added comprehensive v2.0.0 section documenting all new features, enhanced tables, new security controls, and new commands.\n\n- **`changelog.md`** — This comprehensive changelog entry for v2.0.0.\n\n### Security Audit\n\nA comprehensive security audit was performed on all files in this release. Results:\n\n1. ✅ **File permissions** — All shell scripts set to 700 (owner execute only). All data files set to 644.\n2. ✅ **No hardcoded credentials** — No passwords, tokens, or API keys in any file. All credentials loaded from env/.\n3. ✅ **No eval usage** — Zero `eval` statements across all scripts.\n4. ✅ **SQL injection prevention** — All user input escaped via Python `mysql_escape()`. Numeric parameters validated with regex. Enum parameters validated against allowlists.\n5. ✅ **Comment injection prevention** — `/* */`, `--`, `#` style comments blocked in SQL.\n6. ✅ **Hex-encoding prevention** — `0x...` patterns blocked in SQL.\n7. ✅ **DDL blocking** — DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE, RENAME blocked.\n8. ✅ **Table allowlist** — 28 approved tables enforced for all write operations.\n9. ✅ **DML confirmation** — Interactive confirmation required for all write operations.\n10. ✅ **Single-statement enforcement** — Semicolons rejected to prevent stacked queries.\n11. ✅ **Path traversal prevention** — Sensitive paths and file operations blocked.\n12. ✅ **Temp file safety** — `mktemp` with 600 permissions and trap-based cleanup.\n13. ✅ **Foreign key constraints** — All user-data tables have ON DELETE CASCADE.\n14. ✅ **Rollback completeness** — `rollback_user.sql` covers all 26 user-data tables.\n\n### Bug Fixes (post-initial v2.0.0 release)\n\n- **Fixed convenience command SQL semicolon mismatch.** The convenience commands in `custom_mysql.sh` were generating SQL with trailing semicolons (e.g., `INSERT ... VALUES (...);`), but `sql_safe_exec.sh` rejects semicolons as a security measure (single-statement enforcement). Stripped all trailing semicolons from convenience command SQL templates. The `sql_safe_exec.sh` already handles single-statement execution — semicolons are neither needed nor allowed.\n\n- **Fixed `sql_safe_exec.sh` credential loading.** The `sql_safe_exec.sh` was invoking `mysql -D mysqlclaw -e \"$SQL\"` directly without loading credentials from the `.env` file. Updated to build a `MYSQL_CMD` string from env vars (`MYSQL_USER`, `MYSQL_PASSWORD`, `MYSQL_HOST`, `MYSQL_PORT`, `DATABASE`) so the `.env` file is properly used for authentication.\n\n- **Added `upgrade_v1_to_v2.sql` migration script.** Created a standalone upgrade script for existing v1.x installations to apply the v2.0.0 schema changes (new tables, column additions, enum migrations, index additions) without data loss. Safe to run on production databases.\n\n- **Synced skill files to `mysqlclaw` directory.** The `mysqlclaw` skill directory (installed from ClawHub as `custom-mysql` v1.1.6) was updated with all v2.0.0 files: `create_user_tables.sql`, `custom_mysql.sh`, `sql_safe_exec.sh`, `rollback_user.sql`, `setup_wizard.sh`, `SKILL.md`, `CAPABILITIES.md`, `changelog.md`, `updated_SKILL.md`, and supporting files.\n\n- **Created `.env` file for mysqlclaw skill.** Added `.env` with MySQL credentials (`root` / `29361775`, host `localhost`, port `3306`, database `mysqlclaw`) to the `mysqlclaw` skill directory.\n\n### Migration Notes (v1.x → v2.0.0)\n\nFor existing installations upgrading from v1.x:\n\n1. Back up your `mysqlclaw` database before upgrading.\n2. The existing 12 tables are preserved — new columns are added with ALTER TABLE.\n3. New tables are created with `IF NOT EXISTS` — safe to re-run.\n4. Existing data is not modified or removed.\n5. Run `./setup_wizard.sh` against your existing database to apply additions.\n6. Update `sql_safe_exec.sh` to get the expanded table allowlist.\n7. Update `custom_mysql.sh` to get the new convenience commands.\n8. The `rollback_user.sql` has been updated — use the new version for full data deletion.\n\n---\n\n## [1.1.7] – 2026-05-10\n\n### Security\n\n- **Removed snapshot functionality to prevent storage of sensitive operational files.** The `agent_config_files` table, `allowed_snapshot_paths` table, `snapshot_config` command, `cleanup_snapshots.sql`, and `sanitize_snapshot.sh` have been removed or disabled. This addresses a security concern about storing the contents of MEMORY.md, AGENTS.md, BOOT.md, and SECURITY.md in the database, which could expose sensitive operational data.\n- **Removed MEMORY.md, AGENTS.md, BOOT.md, SECURITY.md from all path allowlists.** These files are no longer referenced anywhere in the skill.\n- **Removed `agent_config_files` from the write table allowlist** in `sql_safe_exec.sh`.\n- **Reduced approved write table count from 14 to 12** (removed `agent_config_files` and `allowed_snapshot_paths`).\n- **`sanitize_snapshot.sh` converted to a no-op** with deprecation notice for backward compatibility.\n- **`cleanup_snapshots.sql` emptied** and replaced with explanatory comments.\n- **Updated `create_user_tables.sql`** to remove `agent_config_files` and `allowed_snapshot_paths` table definitions and all related indexes.\n- **Updated `rollback_user.sql`** to remove `agent_config_files` reference.\n- **Updated `CAPABILITIES.md`** to reflect removed snapshot capability and updated allowlist.\n- **Updated `SKILL.md`** with removed features section and updated security documentation.\n- **Version bumped to v1.1.7.**\n\n## [1.1.6] – 2026-05-10\n\n### Security\n\n- **SQL Injection fix: replaced broken `sed` escaping with Python `mysql_escape()`.** All `insert_*` commands now use a Python 3 helper that properly escapes single quotes, backslashes, newlines, carriage returns, and NUL bytes.\n- **Implemented table allowlist in `sql_safe_exec.sh`.** Added a strict allowlist of 14 approved `mysqlclaw` tables.\n- **Implemented DDL blocking in `sql_safe_exec.sh`.** DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE blocked.\n- **Implemented path traversal blocking in `sql_safe_exec.sh`.**\n- **Implemented single-statement enforcement in `sql_safe_exec.sh`.**\n- **Implemented `--readonly` flag in `sql_safe_exec.sh`.**\n- **Fixed `rollback_user.sql`: added missing tables.**\n- **Tightened path traversal regex.**\n- **Set restrictive file permissions (700 for scripts).**\n- **Version bumped to v1.1.6.**\n\n## [1.0.0] - 2026-05-04\n\n### Added\n\n- Complete user-profile schema (users, user_preferences, user_attributes, user_media, user_food_preferences)\n- Persona management (user_personas table)\n- Configuration snapshot system (agent_config_files table — later removed in v1.1.7)\n- Setup wizard (setup_wizard.sh)\n- Convenient high-level commands\n- Error handling & transactions\n- Documentation\n\n### Changed\n\n- Replaced hard-coded MySQL credentials with placeholder variables\n- Added SQL `INSERT … ON DUPLICATE KEY UPDATE` logic for idempotent inserts\n\n## 1.0.1 – 2026-05-04\n\n- Security hardening: removed unsafe `eval` usage in `setup_wizard.sh`.\n- Added input validation and safe variable quoting.\n- Introduced `sql_safe_exec.sh` wrapper.\n\n## 1.0.2 – 2026-05-04\n\n- Added Secret Redaction policy, Destructive Action confirmation guidelines.\n\n## 1.0.3 – 2026-05-04\n\n- Added credential security (--defaults-extra-file), DML confirmation, path traversal prevention.\n\n## 1.0.4 – 2026-05-04\n\n- Multi-statement SQL rejection, trap-based credential cleanup.\n\n## 1.0.5 – 2026-05-04\n\n- Fixed sanitize_snapshot.sh, documented exec_script routing.\n\n## 1.0.6 – 2026-05-04\n\n- Added Capability Scope section to SKILL.md.\n\n## 1.0.7 – 2026-05-04\n\n- Added `custom_mysql` executable and `CAPABILITIES.md`.\n\n## 1.1.0 – 2026-05-05\n\n- Added 5 new tracking tables (user_interactions, user_relationships, user_context, skill_usage, user_notes).\n- Enriched users table with display name/avatar/status fields.\n- Added .env file support.\n\n## 1.1.1 – 2026-05-05\n\n- Fixed credential exposure by removing `create_admin_user.sh`.\n\n## 1.1.2 – 2026-05-05\n\n- Removed environment-specific Discord ID references from CAPABILITIES.md.\n\n## 1.1.3 – 2026-05-05\n\n- SQL Injection fix: Refactored insert commands with proper escaping.\n- Added strict command whitelist in sql_safe_exec.sh.\n\n## 1.1.4 – 2026-05-05\n\n- Versioning fix for ClawHub registration.\n\n## 1.1.5 – 2026-05-05\n\n- Removed `--yes` bypass from all DML paths.\n- query command is now SELECT-only.\n- Added table allowlist and --readonly flag.\n- Added Data Retention, Consent & Deletion policy.\n\nFile v5.0.1:RELEASE_POST_v5.md\n\n# VectorClaw v5.0.0 — MyVector Self-Sufficiency\n\n**VectorClaw v5.0.0 makes MyVector the single source of truth for all agent memory.** Auto-extraction and knowledge graph reasoning are now native MySQL systems, eliminating dependency on external tools (Mem0, Hancho).\n\n## New in This Release\n\n### Auto-Extraction Hook — Replaces Mem0\n\nThe auto-extraction hook uses a local LLM (qwen3.5:4b) to extract atomic facts from conversation text and insert them directly into MyVector:\n\n- **Structured extraction:** core_fact, confidence, entities, linked_to, tags, memory_type, importance\n- **Key mapping:** Normalizes LLM output (\"fact\" → \"core_fact\", invalid types → \"semantic\")\n- **Auto-dedup:** Jaccard similarity check on insert — merges if >50% overlap\n- **Source tracking:** All auto-extracted memories marked with `source='auto'`\n- **Human verification:** `verified_by_human` flag for promoting accurate auto-facts\n- **Fallback:** Regex-based extraction when LLM is unavailable\n- **Quality logging:** Every extraction run logged to `extraction_log` for empirical tuning\n\n```bash\npython3 scripts/auto-extract.py \"conversation text\" --user <discord_id>\npython3 scripts/auto-extract.py --file /path/to/text.txt --user <id> --dry-run\n```\n\n### Memory Relations + Knowledge Graph — Replaces Hancho\n\nNative MySQL knowledge graph that replaces Hancho's external reasoning:\n\n- **`memory_relations` table:** fact_id, related_fact_id, relation_type, confidence, source\n- **Relation types:** mentions, implies, contradicts, same_entity, related_to\n- **Auto-discovery:** Finds existing memories sharing entities during extraction\n- **Consolidation pass:** Periodic scanning for contradictions and new edges\n- **Hub insight derivation:** Identifies high-degree facts (3+ connections) as important\n- **`memory_graph_1hop` view:** Pre-computed 1-hop graph traversal for retrieval\n\n```bash\npython3 scripts/hancho-consolidate.py --user <discord_id>\npython3 scripts/hancho-consolidate.py --user <id> --hours 24 --dry-run\n```\n\n### Database Schema Changes\n\n- **`memories` table:** Added `source`, `verified_by_human`, `extraction_prompt` columns\n- **New table:** `memory_relations` — knowledge graph edges\n- **New table:** `extraction_log` — extraction quality metrics\n- **New view:** `memory_graph_1hop` — fast graph traversal\n- **`user_context` enum:** Added `auto_extracted`, `graph_derived`, `extraction_quality`\n\n### Extraction Quality Logging\n\nTracks auto-extraction quality for empirical prompt tuning:\n- Facts extracted, merged, inserted, relations discovered per run\n- Input length, extraction time (ms), model used, fallback usage\n- Per-user and time-based indexes\n\n## Upgrade\n\n```bash\n# 1. Back up your database\ndocker exec myvector-db mysqldump -u root -p<pass> jerith > backup_pre_v5.sql\n\n# 2. Apply schema migration\ndocker exec -i myvector-db mysql -u root -p<pass> jerith < upgrade_v4_to_v5.sql\n\n# 3. Run initial consolidation to build graph edges\npython3 scripts/hancho-consolidate.py --all-users --dry-run\n\n# 4. If dry run looks good, run for real\npython3 scripts/hancho-consolidate.py --all-users\n\n# 5. Test auto-extraction\npython3 scripts/auto-extract.py \"Test conversation text\" --user <your_id> --dry-run\n```\n\n## Deprecation Plan\n\n- **Mem0:** Run auto-extract in parallel for 7-10 days. Compare quality. Retire Mem0 when auto-extract matches or exceeds.\n- **Hancho:** Memory relations table + consolidation pass already active. Retire Hancho after 7-10 day validation.\n\n## Why Consolidate?\n\n- **Unified pruning:** One system for importance decay, access tracking, and cleanup\n- **Confidence propagation:** Facts and relations share the same confidence model\n- **No sync issues:** No more stale data between separate systems\n- **Full ownership:** Every byte of memory is queryable, auditable, and tunable\n- **Simpler bootstrap:** Fewer external dependencies in context window\n\nFile v5.0.1:RELEASE_POST.md\n\n# VectorClaw v5.0.0 — MyVector Self-Sufficiency\n\n> **Security update (v5.0.1):** This release addresses 37 findings from the ClawHub security audit. All Python scripts now use environment variable credentials (no hardcoded passwords), auto-extraction is opt-in only, migration scripts include explicit backup warnings, and privacy/consent documentation has been added.\n\nVectorClaw v5.0.0 makes MyVector fully self-sufficient by absorbing Mem0's auto-extraction and Hancho's knowledge graph reasoning into native MySQL systems. No more external memory services — everything runs in your Docker container with local LLM support.\n\n> **⚠️ Privacy notice:** This system automatically extracts and persists sensitive personal data (emotional states, relationship signals, health indicators, behavioral profiles) from user conversations. Obtain explicit opt-in consent before enabling auto-extraction. See the PRIVACY & CONSENT NOTICE in SKILL.md.\n\n## New in This Release\n\n### Auto-Extraction Hook (`scripts/auto-extract.py`)\nReplaces Mem0 with a local LLM-powered extraction pipeline:\n- Uses qwen3.5:4b via Ollama to extract atomic facts from conversation text\n- Structured JSON output: core_fact, confidence, entities, linked_to, tags, memory_type, importance\n- Auto-dedup on insert: Jaccard similarity check, merges if >50% overlap\n- Auto-discovers relations: finds existing memories sharing entities, creates graph edges\n- Source tracking: marks facts with `source='auto'` for quality monitoring\n- Fallback to regex-based extraction when LLM is unavailable\n- Validates all output against DB enums before insert\n\n### Memory Relations Table (`memory_relations`)\nNative MySQL knowledge graph replacing Hancho:\n- Schema: fact_id, related_fact_id, relation_type, confidence, source, discovered_at\n- Relation types: mentions, implies, contradicts, same_entity, related_to\n- Unique constraint prevents duplicate edges\n- Indexed for fast graph traversal during retrieval\n\n### Hancho Consolidation Pass (`scripts/hancho-consolidate.py`)\nGraph reasoning that runs as a scheduled heartbeat job:\n- Scans recent memories for shared entities/terms (Jaccard > 0.15)\n- Contradiction detection: same-topic facts with opposite polarity\n- Inserts edges into `memory_relations`\n- Derives hub insights (facts with 3+ connections flagged as important)\n\n### Extraction Quality Logging (`extraction_log`)\nTracks quality metrics for empirical tuning:\n- Facts extracted, merged, inserted, relations discovered per run\n- Input length, extraction time, model used, fallback usage\n\n### Graph Traversal View (`memory_graph_1hop`)\nPre-computed MySQL view for fast 1-hop graph expansion during retrieval.\n\n### Schema Changes (v4 → v5)\n\n- `memories` table: added `source`, `verified_by_human`, `extraction_prompt` columns\n- `user_context` context_type enum: added `auto_extracted`, `graph_derived`, `extraction_quality`\n- New tables: `memory_relations`, `extraction_log`\n- New view: `memory_graph_1hop`\n\n## Upgrade\n\n**⚠️ Always back up first:**\n```bash\ndocker exec myvector-db mysqldump -u root -p<pass> mysqlclaw > backup_pre_v5.sql\n```\n\n```bash\n# 1. Apply schema migration (requires admin/root — this is DDL)\ndocker exec -i myvector-db mysql -u root -p<pass> mysqlclaw < upgrade_v4_to_v5.sql\n\n# 2. Set environment variables for credentials\nexport MYSQL_USER=mysqlclaw\nexport MYSQL_PASSWORD=<your_least_priv_password>\n\n# 3. Test auto-extraction (DRY RUN first — always)\ncd ~/.openclaw/workspace\npython3 scripts/auto-extract.py \"Test fact: user likes Python\" --user <id> --dry-run --json\n\n# 4. Test consolidation (DRY RUN first — always)\npython3 scripts/hancho-consolidate.py --user <id> --hours 24 --dry-run\n```\n\n**Auto-extraction is disabled by default.** Only enable per-user after explicit opt-in and dry-run review.\n\n## Memory Architecture (v5)\n\nYour agent now operates with four interconnected memory systems:\n\n1. **MEMORY.md** — Always-in-context curated narrative (relationships, emotions, key lessons)\n2. **MyVector (VectorClaw v5)** — Structured profiles, interactions, mood, preferences, dimensional tags, reasoning insights, auto-extraction, knowledge graph\n3. **ChromaDB** — Semantic search across workspace files (skills, projects, session logs)\n4. **Mem0** — Deprecated (rate-limited); auto-extract replaces it. Retire after 7-10 day parallel validation.\n\nThe `auto-extract.py` hook and `hancho-consolidate.py` run as heartbeat jobs, continuously improving recall quality without manual intervention.\n\n---\n\nFull changelog: [changelog.md](changelog.md)\n\nFile v5.0.1:SETUP_GUIDE.md\n\n# MySQL & MyVector Setup Guide for Agents\n\nThis document provides step-by-step instructions for agents to install MySQL, configure the `mysqlclaw` database with proper security, and set up MyVector for vector search.\n\n---\n\n## Part 1: Install MySQL Server\n\n```bash\n# Install MySQL server\nsudo apt update && sudo apt install -y mysql-server\n\n# Run secure installation (set root password, remove anonymous users, etc.)\nsudo mysql_secure_installation\n\n# Start and enable MySQL\nsudo systemctl start mysql\nsudo systemctl enable mysql\n```\n\nVerify installation:\n```bash\nmysql --version\nsudo systemctl status mysql\n```\n\n---\n\n## Part 2: Create the `mysqlclaw` Database and Users\n\nLog in as root and run:\n\n```sql\n-- Create the database with proper character set\nCREATE DATABASE IF NOT EXISTS mysqlclaw\n  CHARACTER SET utf8mb4\n  COLLATE utf8mb4_unicode_ci;\n\n-- Admin user (full control, only for initial setup and maintenance)\nCREATE USER IF NOT EXISTS 'mysqlclaw_admin'@'localhost'\n  IDENTIFIED BY 'YourStrongAdminPasswordHere123!';\n\nGRANT ALL PRIVILEGES ON mysqlclaw.* TO 'mysqlclaw_admin'@'localhost';\n\n-- Least-privileged user (for daily use by VectorClaw skill)\n-- Only has SELECT, INSERT, UPDATE, DELETE — no DDL, no DROP, no GRANT\nCREATE USER IF NOT EXISTS 'mysqlclaw'@'localhost'\n  IDENTIFIED BY 'YourStrongLeastPrivPasswordHere456!';\n\nGRANT SELECT, INSERT, UPDATE, DELETE ON mysqlclaw.* TO 'mysqlclaw'@'localhost';\n\nFLUSH PRIVILEGES;\n```\n\n**Important security notes:**\n- Replace the example passwords with strong random passwords (32+ chars)\n- The `mysqlclaw` user should NEVER have DDL privileges (CREATE, ALTER, DROP, GRANT)\n- Store passwords in the skill's `.env` file with `chmod 600` permissions\n- The admin user should only be used for schema migrations and maintenance\n\nVerify the users:\n```sql\nSELECT user, host, plugin FROM mysql.user WHERE user LIKE 'mysqlclaw%';\nSHOW GRANTS FOR 'mysqlclaw'@'localhost';\n```\n\n---\n\n## Part 3: Set Up MyVector (Vector Search Plugin)\n\nMyVector adds vector similarity search capabilities to MySQL. The easiest way is using the official Docker container.\n\n### Option A: Docker (Recommended)\n\n```bash\n# Pull and run MyVector container\ndocker run -d \\\n  --name myvector-db \\\n  -p 3310:3306 \\\n  -e MYSQL_ROOT_PASSWORD=myvector \\\n  -e MYSQL_DATABASE=mysqlclaw \\\n  -v myvector-data:/var/lib/mysql \\\n  ghcr.io/askdba/myvector:mysql8.4\n```\n\n**Notes:**\n- Port `3310` is used to avoid conflicts with any existing MySQL on `3306`\n- The `mysqlclaw` database is created automatically\n- Data persists in the `myvector-data` Docker volume\n\nVerify MyVector is running:\n```bash\ndocker ps | grep myvector\ndocker exec -it myvector-db mysql -u root -pmyvector -e \"SELECT VERSION();\"\n```\n\n### Option B: Install MyVector Plugin on Existing MySQL\n\nIf you already have MySQL running and want to add MyVector directly:\n\n```bash\n# Download the MyVector plugin (check GitHub for latest release)\n# https://github.com/askdba/myvector\n\n# Install the plugin\nmysql -u root -p -e \"\n  INSTALL PLUGIN myvector SONAME 'myvector.so';\n\";\n```\n\n---\n\n## Part 4: Apply the VectorClaw Schema\n\nAfter MySQL and MyVector are running, apply the skill's database schema:\n\n```bash\ncd ~/.openclaw/workspace/skills/mysqlclaw\n\n# Set up .env with your credentials\ncat > .env << 'EOF'\nMYSQL_USER=mysqlclaw\nMYSQL_PASSWORD=YourStrongLeastPrivPasswordHere456!\nMYSQL_HOST=localhost\nMYSQL_PORT=3310\nDATABASE=mysqlclaw\nEOF\nchmod 600 .env\n\n# Run the setup wizard\n./setup_wizard.sh\n```\n\nOr apply the schema directly:\n```bash\nmysql -u mysqlclaw -p -h 127.0.0.1 -P 3310 mysqlclaw < create_user_tables.sql\nmysql -u mysqlclaw -p -h 127.0.0.1 -P 3310 mysqlclaw < populate_templates.sql\n```\n\n---\n\n## Part 5: Verify Everything Works\n\n```bash\ncd ~/.openclaw/workspace/skills/mysqlclaw\n\n# Test query\n./custom_mysql.sh query \"SELECT COUNT(*) FROM users;\"\n\n# Test insert\necho \"yes\" | ./custom_mysql.sh insert_interaction \\\n  \"agent_test\" inbound \"setup verification\" \"Testing VectorClaw after install\" positive\n\n# Verify\n./custom_mysql.sh query \"SELECT * FROM user_interactions ORDER BY created_at DESC LIMIT 1;\"\n```\n\n---\n\n## Architecture Overview\n\n```\n┌─────────────────────────────────────────────┐\n│                  Agent                       │\n│          (custom_mysql.sh commands)          │\n└──────────────────┬──────────────────────────┘\n                   │\n                   ▼\n┌─────────────────────────────────────────────┐\n│           sql_safe_exec.sh                   │\n│  • Single-statement enforcement              │\n│  • DDL blocking                              │\n│  • Table allowlist (28 tables)               │\n│  • Comment injection blocking                │\n│  • Hex-encoding detection                    │\n│  • DML interactive confirmation              │\n│  • Credentials via --defaults-extra-file     │\n└──────────────────┬──────────────────────────┘\n                   │\n                   ▼\n┌─────────────────────────────────────────────┐\n│     MyVector DB (MySQL 8.4 + vectors)       │\n│     Port 3310 / Database: mysqlclaw          │\n│                                              │\n│  28 tables:                                  │\n│  • users, user_preferences, user_attributes  │\n│  • user_media, user_food_preferences         │\n│  • user_personas, persona_templates          │\n│  • user_interactions, conversation_sessions  │\n│  • session_interactions, user_relationships  │\n│  • user_context, skill_usage, user_notes     │\n│  • user_mood, user_engagement_patterns       │\n│  • user_activity_heatmap, proactive_reminders│\n│  • synaptic_memory, thought_stream           │\n│  • topic_keywords, community_sentiment       │\n│  • trending_topics, community_events         │\n│  • agent_learnings, memory_consolidation_log │\n└─────────────────────────────────────────────┘\n```\n\n---\n\n## Troubleshooting\n\n| Issue | Solution |\n|-------|----------|\n| `Access denied for user 'mysqlclaw'` | Check `.env` credentials match the MySQL user |\n| `Can't connect to MySQL server` | Verify MySQL is running: `sudo systemctl status mysql` |\n| `Plugin 'myvector' not found` | Use the Docker image which includes MyVector pre-installed |\n| `Table doesn't exist` | Run `create_user_tables.sql` to apply the schema |\n| `ERROR: Multi-statement SQL not allowed` | Remove semicolons from SQL — `sql_safe_exec.sh` handles single statements |\n| Port 3306 conflict | MyVector Docker uses port 3310 by default |\n\n---\n\n## Part 7: v5.0.0 — MyVector Self-Sufficiency Setup\n\nv5.0.0 adds auto-extraction and knowledge graph capabilities that replace Mem0 and Hancho.\n\n### Apply v5 Schema Migration\n\n```bash\n# Back up first\ndocker exec myvector-db mysqldump -u root -p<pass> jerith > backup_pre_v5.sql\n\n# Apply migration\ndocker exec -i myvector-db mysql -u root -p<pass> jerith < upgrade_v4_to_v5.sql\n```\n\n### Set Up Auto-Extraction Hook\n\n```bash\n# Test with dry run\npython3 scripts/auto-extract.py \\\n  \"Test: user likes Python for backend development\" \\\n  --user <discord_id> --dry-run --json\n\n# Run for real\npython3 scripts/auto-extract.py \\\n  \"User mentioned they prefer concise responses with warmth\" \\\n  --user <discord_id>\n```\n\n### Set Up Hancho Consolidation\n\n```bash\n# Preview graph edges\npython3 scripts/hancho-consolidate.py --all-users --hours 24 --dry-run\n\n# Build the graph\npython3 scripts/hancho-consolidate.py --all-users --hours 24\n```\n\n### Schedule Heartbeat Jobs\n\nAdd to `~/.openclaw/workspace/HEARTBEAT.md`:\n```markdown\n# MyVector v5 maintenance\n- Every 1 hour: Run `python3 scripts/auto-extract.py` on recent conversations\n- Every 4 hours: Run `python3 scripts/hancho-consolidate.py --all-users --hours 4`\n- Every 6 hours: Run `python3 scripts/memory_consolidation.py --all-users`\n- Daily: Review `extraction_log` for quality metrics\n- Weekly: Review `memory_relations` for contradiction flags\n```\n\n### Parallel Run with Mem0/Hancho (7-10 days)\n\nDuring validation period:\n1. Keep Mem0 and Hancho running\n2. Run auto-extract and hancho-consolidate in parallel\n3. Compare quality: check `extraction_log` for facts extracted, merge rate, relation density\n4. When auto-extract quality matches or exceeds Mem0, retire Mem0\n5. When graph edges are comprehensive, retire Hancho\n\n### New Tables Reference\n\n| Table | Purpose | Since |\n|-------|---------|-------|\n| `memory_relations` | Knowledge graph edges between facts | v5.0.0 |\n| `extraction_log` | Auto-extraction quality metrics | v5.0.0 |\n| `memories.source` | Track fact provenance (manual/auto/consolidation/import) | v5.0.0 |\n| `memories.verified_by_human` | Promotion flag for auto-extracted facts | v5.0.0 |\n\n### New Views Reference\n\n| View | Purpose | Since |\n|------|---------|-------|\n| `memory_graph_1hop` | Fast 1-hop graph traversal for retrieval | v5.0.0 |\n\n---\n\n## Part 8: v5.0.1 — Security Hardening Setup\n\n### Apply v5.0.1 Security Migration\n\n```bash\n# ⚠️ Back up FIRST\ndocker exec myvector-db mysqldump -u root -p<pass> mysqlclaw > backup_pre_v5.0.1.sql\n\n# Apply migration (requires root/admin — this is DDL)\ndocker exec -i myvector-db mysql -u root -p<pass> mysqlclaw < upgrade_v5.0.0_to_v5.0.1.sql\n```\n\n### Configure Credentials for Python Scripts\n\nPython scripts (auto-extract, hancho-consolidate, retrieval-gate) load credentials from environment variables. **They no longer contain hardcoded passwords.**\n\nSet up your environment:\n```bash\n# Add to your .bashrc or .env file\nexport MYSQL_USER=mysqlclaw\nexport MYSQL_PASSWORD=<your_least_priv_password>\nexport MYSQL_HOST=127.0.0.1\nexport MYSQL_PORT=3310\nexport DATABASE=mysqlclaw\n```\n\n**Note**: The `.env` file is used by the shell scripts (`vector_claw.sh`, `sql_safe_exec.sh`). The Python scripts read from `os.environ`. Export the same variables or `source` the `.env` file before running Python scripts.\n\n### Set Up Per-User Extraction Opt-In\n\nAuto-extraction is **disabled by default**. For each user:\n```bash\n# 1. Insert extraction config (disabled)\ndocker exec -i myvector-db mysql -u root -p<pass> mysqlclaw -e \\\n  \"INSERT INTO extraction_config (user_id) VALUES ('<discord_id>');\"\n\n# 2. After explicit user opt-in, enable:\ndocker exec -i myvector-db mysql -u root -p<pass> mysqlclaw -e \\\n  \"UPDATE extraction_config SET auto_extract_enabled=TRUE, consent_given_at=NOW(), consent_method='explicit' WHERE user_id='<discord_id>';\"\n```\n\n### Configure Data Retention\n\nDefault retention policies are inserted by the migration. To customize:\n```bash\n# Example: extend mood retention to 180 days\ndocker exec -i myvector-db mysql -u root -p<pass> mysqlclaw -e \\\n  \"UPDATE data_retention_policy SET retention_days=180 WHERE table_name='user_mood';\"\n```\n\n### New Tables in v5.0.1\n\n| Table | Purpose | Since |\n|-------|---------|-------|\n| `extraction_config` | Per-user auto-extraction opt-in and settings | v5.0.1 |\n| `data_retention_policy` | Configurable retention limits per data type | v5.0.1 |\n| `audit_log` | Data access/modification audit trail | v5.0.1 |\n\n### Updated Schema\n\n| Change | Reason | Since |\n|--------|--------|-------|\n| `thought_stream.user_id` → NULL allowed | Decouple agent reasoning from user-identifiable data | v5.0.1 |\n\nFile v5.0.1:skill-card.md\n\n## Description:\n\nProvides a secure, least-privilege interface for managing user data, personas, memory, and configuration snapshots in a self-hosted MyVector MySQL database.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[paradoxfuzzle](https://clawhub.ai/user/paradoxfuzzle)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use VectorClaw to give an OpenClaw-style agent controlled MySQL-backed memory, profile, relationship, mood, reminder, and usage-tracking operations in a self-hosted MyVector container. Administrators should review consent, retention, and deletion controls before enabling auto-extraction or profiling.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Persistent profiling of sensitive personal data and agent reasoning logs can create privacy and consent risk.\n\nMitigation: Disable auto-extraction, mood tracking, engagement tracking, and heartbeat jobs until each user has recorded opt-in consent; use extraction_config, data_retention_policy, audit_log, and rollback_user.sql for consent, retention, audit, and deletion workflows.\n\nRisk: Setup and migration require credentials, Docker MyVector, and administrator schema changes.\n\nMitigation: Use a dedicated least-privilege MySQL user, avoid root/admin for agent-facing commands, keep .env chmod 600, back up before migrations, and run DDL upgrade scripts manually through docker exec rather than through sql_safe_exec.sh.\n\nRisk: Unpinned container images and unresolved SQL validation concerns could weaken the intended safety controls.\n\nMitigation: Pin and verify the MyVector container image, route agent SQL through sql_safe_exec.sh, keep SELECT-only queries separate from confirmed DML, and complete the security review guidance before deployment.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/paradoxfuzzle/skills/custom-mysql)\n- [SKILL.md](artifact/SKILL.md)\n- [SETUP_GUIDE.md](artifact/SETUP_GUIDE.md)\n- [CAPABILITIES.md](artifact/CAPABILITIES.md)\n- [changelog.md](artifact/changelog.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell commands and SQL scripts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Self-hosted MyVector/MySQL operations through reviewed scripts; DML requires interactive confirmation.]\n\n## Skill Version(s):\n\n5.0.1 (source: server release metadata and artifact/SKILL.md, released 2026-05-27)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v5.0.1:updated_SKILL.md\n\n# Custom MySQL Skill v3.0.0\n\nThis skill allows interaction with a MyVector MySQL database for deep community memory storage. It is security-hardened with a 26-table write allowlist, enum validation, comment injection prevention, hex-encoding detection, fail-closed auth, and root/admin rejection. v3.0.0 replaces the local MySQL dependency with MyVector (MySQL 8.4 + vector search) running in a Docker container.\n\n## What's New in v3.0.0\n\n### MyVector Docker Container\n- **Replaces local MySQL entirely**: No local MySQL server or client required\n- All SQL is routed through `docker exec` into the MyVector container\n- MyVector provides MySQL 8.4 compatibility with vector search extensions\n- Container must be running before the skill can connect\n- Credentials are passed via temporary `--defaults-extra-file` (never on command line)\n\n### Security: Fail-Closed Auth\n- **Refuses to connect** if `MYSQL_USER` or `MYSQL_PASSWORD` is missing from `.env`\n- **Explicitly rejects** root, admin, and mysql usernames\n- Requires a dedicated least-privilege MySQL account\n- Verifies MyVector Docker container is running before attempting connection\n\n### Security: Safe .env Parsing\n- `.env` file is parsed as KEY=VALUE lines only — never evaluated as shell code\n- Only recognized MYSQL_* keys are accepted\n- Keys validated against `^[A-Za-z_][A-Za-z0-9_]*$` regex\n\n### Updated Existing Tables\n- **`users`**: Added timezone, roles, activity stats (messages, reactions, sessions), last_seen\n- **`user_interactions`**: Added sentiment_score, mood_impact, followup flags, channel_id, message_id, is_important\n- **`user_context`**: Added context_type (episodic/semantic/procedural/emotional), importance, source, is_active\n- **`user_attributes`**: Added confidence, source (stated/inferred/observed), expanded types (skill, trait, goal, custom)\n- **`user_media`**: Expanded to 10 media types (game, music, podcast, anime, comic, youtube, other), added status/progress\n- **`user_food_preferences`**: Expanded preference scale (loves/likes/neutral/dislikes/allergic/hates)\n- **`user_relationships`**: Added trust_level, interaction_frequency, shared_interests, expanded types (close_friend, mentor, mentee, rival)\n- **`skill_usage`**: Added error_type column\n- **`user_notes`**: Added tags, is_pinned, is_private, source_message_id\n\n## Commands\n\n### Execute SQL Query\n```bash\ncustom_mysql query \"YOUR_SQL_QUERY_HERE\"\n```\n\n### Execute Script\n```bash\ncustom_mysql execute_script --file /path/to/your/script.sql\n```\n\n### Insert Interaction\n```bash\ncustom_mysql insert_interaction <user_id> <direction> <topic> <summary> [sentiment] [is_important]\n```\n\n### Insert Note\n```bash\ncustom_mysql insert_note <user_id> <note> [category] [is_pinned]\n```\n\n### Insert Context (mem0-like)\n```bash\ncustom_mysql insert_context <user_id> <key> <value> [type] [importance] [expires_at]\n```\nTypes: `episodic`, `semantic`, `procedural`, `emotional`, `preference`, `fact`, `custom`\n\n### Insert Skill Usage\n```bash\ncustom_mysql insert_skill_usage <user_id> <skill_name> [action] [status] [duration_ms] [error_type]\n```\n\n### Insert Relationship\n```bash\ncustom_mysql insert_relationship <user_id> <related_user_id> <type> [strength] [trust] [notes]\n```\n\n### Insert Mood\n```bash\ncustom_mysql insert_mood <user_id> <mood> [intensity] [trigger_topic] [confidence]\n```\nMoods: `happy`, `excited`, `calm`, `neutral`, `tired`, `stressed`, `frustrated`, `sad`, `angry`, `anxious`\n\n### Insert Reminder\n```bash\ncustom_mysql insert_reminder <user_id> <trigger_type> <condition> <text> [priority]\n```\nTrigger types: `time_based`, `event_based`, `pattern_based`, `followup`\n\n### Insert Thought\n```bash\ncustom_mysql insert_thought <user_id> <thought> [type] [channel_id]\n```\nThought types: `reasoning`, `observation`, `decision`, `reflection`, `planning`\n\n### Insert Learning\n```bash\ncustom_mysql insert_learning <type> <title> <description> [priority] [user] [skill]\n```\nLearning types: `correction`, `preference`, `pattern`, `error`, `success`, `insight`, `rule`\n\n### Insert Community Event\n```bash\ncustom_mysql insert_event <type> <title> [description] [channel_id]\n```\nEvent types: `milestone`, `achievement`, `incident`, `trend`, `custom`\n\n## Configuration\n\nBefore using this skill, set the following environment variables:\n\n- `MYSQL_USER`: Dedicated least-privilege MySQL username (NOT root)\n- `MYSQL_PASSWORD`: The user's password\n- `MYSQL_PORT`: MyVector Docker port (default: 3310)\n- `DATABASE`: The MySQL database name (default: mysqlclaw)\n\n**Example setup:**\n```bash\nexport MYSQL_USER=\"mysqlclaw\"\nexport MYSQL_PASSWORD=\"your_secure_password\"\nexport MYSQL_PORT=\"3310\"\nexport DATABASE=\"mysqlclaw\"\n```\n\nOr create a `.env` file in the skill directory (chmod 600).\n\n**Prerequisites:**\n- Docker must be installed and running\n- MyVector container must be running: `docker run -d --name myvector-db -p 3310:3306 -e MYSQL_ROOT_PASSWORD=<pw> -e MYSQL_DATABASE=mysqlclaw ghcr.io/askdba/myvector:mysql8.4`\n- A dedicated least-privilege MySQL user must be created inside the container\n\n## Installation for New Users\n\n1. **Start MyVector container:**\n   ```bash\n   docker run -d --name myvector-db -p 3310:3306 \\\n     -e MYSQL_ROOT_PASSWORD=<root_pw> \\\n     -e MYSQL_DATABASE=mysqlclaw \\\n     ghcr.io/askdba/myvector:mysql8.4\n   ```\n\n2. **Create dedicated least-privilege user:**\n   ```bash\n   docker exec -it myvector-db mysql -u root -p<root_pw> -e \"\n     CREATE USER IF NOT EXISTS 'mysqlclaw'@'%' IDENTIFIED BY '<strong_password>';\n     GRANT SELECT, INSERT, UPDATE, DELETE ON mysqlclaw.* TO 'mysqlclaw'@'%';\n     FLUSH PRIVILEGES;\n   \"\n   ```\n\n3. **Copy the Skill:** Copy the entire `custom_mysql` directory to `~/.openclaw/workspace/skills/`\n\n4. **Set Environment Variables:** Set required env vars or create `.env` file\n\n5. **Initialize Database Schema:**\n   ```bash\n   cd ~/.openclaw/workspace/skills/custom-mysql\n   ./setup_wizard.sh\n   ```\n\n6. **Run Commands:** Use `custom_mysql query`, `custom_mysql insert_*`, etc.\n\n---\n\n## Data Ingestion — Source Restrictions & Consent Rules\n\nThis skill is designed to be the central hub for community user data. When ingesting data:\n\n### ✅ Approved Sources:\n- **Direct Discord messages** — messages sent by users in Discord channels/DMs\n- **Discord reactions** — emoji reactions made by users\n- **User-provided statements** — explicit preferences, facts, or corrections stated by users\n- **Observed interaction patterns** — engagement times, topic preferences, channel usage\n- **Agent reasoning** — thoughts, decisions, reflections logged by the agent\n\n### ❌ Prohibited Sources:\n- **Operational config files** — never store contents of MEMORY.md, AGENTS.md, USER.md, IDENTITY.md, SOUL.md, BOOT.md, SECURITY.md, TOOLS.md, CODE.md, or any other workspace configuration files\n- **Secrets/credentials** — API keys, tokens, passwords, private keys\n- **Other users' private data** — data about user A shared by user B without user A's consent\n- **Arbitrary file reads** — no reading of local filesystem files not explicitly listed above\n\n### Consent & Sensitivity Rules:\n- **Explicit over inferred** — mark inferred data with `source: 'inferred'` and lower confidence\n- **Emotional data** — mood tracking should be based on clear expression, not speculation (confidence ≥ 0.7)\n- **Sensitive memories** — flag with appropriate importance; respect user requests for deletion\n- **Opt-in required** — explicit user consent required before storing sensitive personal data\n- **Provenance tracking** — all records should include source, confidence, and timestamp\n- **Review before acting** — `agent_learnings` and rule-like memories must be reviewed before affecting future behavior\n\n### Retention & Deletion:\n- Interaction logs: 30-day rolling window\n- Mood data: 90-day rolling window\n- Thought stream: 30-day rolling window\n- Synaptic memory: auto-decay via `decay_rate`\n- Full user data deletion via `rollback_user.sql` covers all 26 user-data tables\n\n### Storage Best Practices:\n- Use `custom_mysql insert_*` commands (not raw SQL) for all writes\n- Validate enum parameters against allowed values\n- Escape all user input via the built-in Python `mysql_escape()`\n- Never construct SQL by concatenating raw user input\n- Use `query` command for all reads (SELECT-only)\n- Use `exec --file` with reviewed scripts for batch operations\n\nFile v5.0.1:.clawhub/origin.json\n\n{\n  \"version\": 1,\n  \"registry\": \"https://clawhub.ai\",\n  \"slug\": \"vector-claw\",\n  \"installedVersion\": \"1.1.6\",\n  \"installedAt\": 1778270961199\n}\n\nArchive v5.0.0: 23 files, 65811 bytes\n\nFiles: .clawhub/origin.json (143b), CAPABILITIES.md (10467b), changelog.md (38386b), cleanup_snapshots.sql (410b), create_user_tables.sql (23845b), populate_templates.sql (938b), RELEASE_POST_v5.md (3893b), RELEASE_POST.md (4590b), rollback_user.sql (2267b), sanitize_snapshot.sh (754b), SETUP_GUIDE.md (9417b), skill-card.md (3177b), SKILL.md (15574b), sql_safe_exec.sh (7570b), update_page_v5.sql (8759b), update_page.sql (7555b), updated_SKILL.md (8350b), upgrade_v1_to_v2.sql (14739b), upgrade_v3_to_v4.sql (2741b), upgrade_v4_to_v5.sql (5045b), vector_claw_setup.sh (6093b), vector_claw.sh (17898b), _meta.json (131b)\n\nFile v5.0.0:SKILL.md\n\n# paradoxfuzzle/custom-mysql\n\n## Overview\n\nSecurity-hardened MyVector MySQL profile storage with capability bounding for OpenClaw. Tracks interactions, relationships, context, skill usage, notes, preferences, media, food, personas, mood states, engagement patterns, proactive reminders, agent learnings, community sentiment, trending topics, and community events. Now includes HindSight (post-conversation consolidation), HoloGraphic (multi-dimensional tagging), and Hancho (knowledge graph reasoning) memory systems. v4.0.0 integrates with the `memory_consolidation.py` script for automated heartbeat-based memory maintenance. All SQL is routed through `docker exec` into the MyVector container. Requires a dedicated least-privilege MySQL user — root/admin accounts are rejected.\n\n## Version\n\n5.0.0 – 2026-05-27\n\n## Memory Systems\n\nVectorClaw v5.0.0 makes MyVector self-sufficient. It includes three memory enhancement systems (v4) plus auto-extraction and native knowledge graph reasoning (v5):\n\n### HindSight — Post-Conversation Consolidation\n- Analyzes recent interactions (sentiment trends, topic frequency)\n- Identifies new topics not yet stored as memories\n- Detects recurring themes worth tracking\n- Stores findings in `user_context` (categories: discovery, behavioral, emotional)\n\n### HoloGraphic — Multi-Dimensional Tagging\n- Tags memories with: emotion, context, urgency, people\n- **Emotion**: positive, negative, complex, neutral\n- **Context**: work, personal, health, tech, social, creative\n- **Urgency**: immediate, ongoing, timeless, historical\n- **People**: auto-detected names (NoodlyPanda, Ev, Cyle, Jerith, etc.)\n- Enables retrieval from any angle (\"how did Ev feel about X\", \"health topics in May\")\n- Stores tags in `user_context` (category: metadata)\n\n### Hancho — Knowledge Graph Reasoning\n- Connects related facts to derive new insights via 7 reasoning rules:\n  1. **medication_side_effects**: medication keywords + side effect keywords\n  2. **health_chain**: condition keywords + treatment keywords\n  3. **tech_infrastructure**: infra keywords + AI/model keywords\n  4. **creative_passion**: interest keywords + creation keywords\n  5. **relationship_depth**: emotional keywords + interaction keywords\n  6. **interest_to_skill**: learning keywords + skill keywords\n  7. **emotional_pattern**: stress keywords + coping keywords\n- Inter-user reasoning finds shared topics between users\n- Stores derived insights in `user_context` (categories: reasoning, social_graph)\n\n### Memory Types\n\n| Type | Table | Description |\n|------|-------|-------------|\n| **Episodic** | `user_context` | Specific events/experiences with timestamps |\n| **Semantic** | `user_context` | General facts and knowledge |\n| **Procedural** | `user_context` | How-to knowledge and habits |\n| **Emotional** | `user_mood` | Emotional states with triggers and intensity |\n| **Preference** | `user_preferences` | Explicit preferences with confidence |\n| **Synaptic** | `synaptic_memory` | Key-value memory with priority and decay |\n| **HoloGraphic** | `user_context` (metadata) | Multi-dimensional tags (emotion, context, urgency, people) |\n| **HindSight** | `user_context` (discovery) | Post-conversation consolidation findings |\n| **Auto-Extracted** | `memories` (v5.0.0) | LLM-extracted facts with source='auto', deduped on insert |\n| **Graph-Derived** | `memory_relations` (v5.0.0) | Knowledge graph edges: mentions, implies, contradicts, same_entity, related_to |\n| **Extraction Log** | `extraction_log` (v5.0.0) | Quality metrics for empirical prompt tuning |\n\n### Memory Sources (v5.0.0)\n\nAll memories in the `memories` table now track their provenance:\n\n| Source | Description | Initial Confidence |\n|--------|-------------|-------------------|\n| `manual` | Written explicitly by agent | 0.9 |\n| `auto` | Extracted by local LLM hook | 0.6-0.7 |\n| `consolidation` | Derived from consolidation pass | 0.7 |\n| `import` | Imported from external system | 0.5 |\n\nAuto-extracted memories can be promoted via `verified_by_human = TRUE` when grounding confirms accuracy.\n\n### Auto-Extraction Hook (v5.0.0) — Replaces Mem0\n\nThe auto-extraction hook uses a local LLM to extract atomic facts from conversation text and insert them directly into MyVector. This replaces Mem0's zero-effort capture with full ownership.\n\n**Script:** `scripts/auto-extract.py`\n\n```bash\n# Extract from text\npython3 scripts/auto-extract.py \"conversation text here\" --user <discord_id>\n\n# Extract from file\npython3 scripts/auto-extract.py --file /path/to/conversation.txt --user <discord_id>\n\n# Dry run (preview without inserting)\npython3 scripts/auto-extract.py \"text\" --user <id> --dry-run\n\n# Output as JSON\npython3 scripts/auto-extract.py \"text\" --user <id> --dry-run --json\n```\n\n**Pipeline:**\n1. Local qwen3.5:4b extracts structured JSON (core_fact, confidence, entities, linked_to, tags, memory_type, importance)\n2. Key mapping normalizes LLM output (\"fact\" → \"core_fact\", invalid types → \"semantic\")\n3. Dedup: Jaccard similarity check against existing memories, merges if >50% overlap\n4. Insert with `source='auto'` for quality tracking\n5. Auto-discover relations: finds existing memories sharing entities\n6. Logs extraction metrics to `extraction_log`\n\n**Prompt design:** Uses string concatenation (not f-strings) to avoid curly brace issues with JSON examples. Strict key name requirements in prompt.\n\n**Fallback:** Regex-based extraction when LLM is unavailable.\n\n### Memory Relations + Knowledge Graph (v5.0.0) — Replaces Hancho\n\nNative MySQL knowledge graph that replaces Hancho's external reasoning.\n\n**Table:** `memory_relations`\n- `fact_id`, `related_fact_id` → FK to memories.id\n- `relation_type`: mentions, implies, contradicts, same_entity, related_to\n- `confidence`: 0.0-1.0\n- `source`: auto, manual, consolidation\n- Unique constraint on (fact_id, related_fact_id, relation_type)\n\n**Consolidation script:** `scripts/hancho-consolidate.py`\n\n```bash\n# Consolidate recent memories (default: last 6 hours)\npython3 scripts/hancho-consolidate.py --user <discord_id>\n\n# Lookback window\npython3 scripts/hancho-consolidate.py --user <id> --hours 24\n\n# Dry run\npython3 scripts/hancho-consolidate.py --user <id> --dry-run\n```\n\n**Pipeline:**\n1. Scan recent memories for shared entities/terms (Jaccard > 0.15)\n2. Contradiction detection: same-topic facts with opposite polarity\n3. Insert edges into `memory_relations`\n4. Derive hub insights (facts with 3+ connections)\n\n**Graph traversal:** Pre-computed view `memory_graph_1hop` for fast retrieval.\n\n### Extraction Quality Logging (v5.0.0)\n\nTracks auto-extraction quality for empirical tuning:\n\n**Table:** `extraction_log`\n- facts extracted, merged, inserted, relations discovered per run\n- input length, extraction time (ms), model used, fallback usage\n- Per-user and time-based indexes\n\n### Consolidation Script\n\n- **`memory_consolidation.py`** at `~/.openclaw/workspace/scripts/memory_consolidation.py`\n- Runs HindSight + HoloGraphic + Hancho in sequence\n- Scheduled every 6 hours via heartbeat and cron\n- Commands:\n  ```bash\n  python3 memory_consolidation.py --user <discord_id>\n  python3 memory_consolidation.py --all-users\n  python3 memory_consolidation.py --user <id> --dry-run\n  python3 memory_consolidation.py --user <id> --hindisght-only\n  python3 memory_consolidation.py --user <id> --holohraphic-only\n  python3 memory_consolidation.py --user <id> --hancho-only\n  ```\n\n## Capabilities\n\n- MyVector MySQL read/write operations only (no external APIs, crypto, or wallets)\n- All SQL routed through MyVector Docker container via `docker exec`\n- Uses `.env` files for credentials (parsed as KEY=VALUE, never shell-sourced)\n- All SQL routed through `sql_safe_exec.sh` for safety\n- `query` command is SELECT-only\n- DML requires interactive confirmation (no non-interactive bypass)\n- Table allowlist enforced for all write operations (26 approved tables)\n- Single-statement execution only (semicolons rejected)\n- DDL blocked (DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE)\n- Comment injection blocked (`/* */`, `--`, `#`)\n- Hex-encoded string detection blocked\n- Path traversal and sensitive file patterns blocked\n- Proper MySQL string escaping via Python (handles all edge cases)\n- Enum validation on all convenience command parameters\n- **FAIL CLOSED**: refuses to connect if MYSQL_USER or MYSQL_PASSWORD is missing\n- **REJECTS root/admin users**: requires dedicated least-privilege account\n- **Verifies MyVector container is running** before attempting connection\n- **Memory consolidation**: HindSight + HoloGraphic + Hancho reasoning via heartbeat\n- **Auto-extraction**: Local LLM-powered fact extraction replacing Mem0 (v5.0.0)\n- **Knowledge graph**: Native MySQL `memory_relations` table replacing Hancho (v5.0.0)\n- **Graph traversal**: `memory_graph_1hop` view for retrieval-time graph expansion\n- **Extraction quality tracking**: `extraction_log` table for empirical prompt tuning\n\n### Deprecated Features (v5.0.0)\n\n- **Mem0**: Auto-extraction replaced by `scripts/auto-extract.py`. Run in parallel for 7-10 days to validate quality, then retire.\n- **Hancho**: Knowledge graph reasoning replaced by `memory_relations` table + `scripts/hancho-consolidate.py`. Native MySQL graph is tighter and fully owned.\n\n## Configuration\n\n| Option          | Default       | Notes                                  |\n|-----------------|---------------|----------------------------------------|\n| `MYSQL_USER`    | *required*    | Dedicated least-privilege account (NOT root) |\n| `MYSQL_PASSWORD`| *required*    | Store in `.env` (chmod 600)            |\n| `MYSQL_PORT`    | `3310`        | MyVector Docker port mapping           |\n| `DATABASE`      | `mysqlclaw`   | Target database                        |\n\n**MyVector Docker container must be running:**\n```bash\ndocker run -d --name myvector-db -p 3310:3306 \\\n  -e MYSQL_ROOT_PASSWORD=<root_pw> \\\n  -e MYSQL_DATABASE=mysqlclaw \\\n  ghcr.io/askdba/myvector:mysql8.4\n```\n\n## Installation\n\n```bash\n# 1. Start MyVector container (if not running)\ndocker run -d --name myvector-db -p 3310:3306 \\\n  -e MYSQL_ROOT_PASSWORD=<root_pw> \\\n  -e MYSQL_DATABASE=mysqlclaw \\\n  ghcr.io/askdba/myvector:mysql8.4\n\n# 2. Create a dedicated least-privilege user inside MyVector\ndocker exec -it myvector-db mysql -u root -p<root_pw> -e \"\n  CREATE USER IF NOT EXISTS 'mysqlclaw'@'%' IDENTIFIED BY '<strong_password>';\n  GRANT SELECT, INSERT, UPDATE, DELETE ON mysqlclaw.* TO 'mysqlclaw'@'%';\n  FLUSH PRIVILEGES;\n\"\n\n# 3. Create .env file with the dedicated user's credentials\ncat > .env <<'EOF'\nMYSQL_USER=mysqlclaw\nMYSQL_PASSWORD=<strong_password>\nMYSQL_PORT=3310\nDATABASE=mysqlclaw\nEOF\nchmod 600 .env\n\n# 4. Apply schema with setup wizard\ncd ~/.openclaw/workspace/skills/custom-mysql\n./setup_wizard.sh\n\n# 5. Run initial consolidation\ncd ~/.openclaw/workspace\npython3 scripts/memory_consolidation.py --user <your_discord_id>\n```\n\n## Usage\n\n```bash\n# Query (SELECT-only)\ncustom_mysql.sh query \"SELECT * FROM users LIMIT 5\"\n\n# Execute script (DML requires interactive confirmation)\ncustom_mysql.sh exec --file /path/to/scripts.sql\n\n# Convenience commands:\ncustom_mysql.sh insert_interaction <uid> <dir> <topic> <summary> [sentiment] [is_important]\ncustom_mysql.sh insert_note <uid> <note> [category] [is_pinned]\ncustom_mysql.sh insert_context <uid> <key> <value> [type] [importance] [expires_at]\ncustom_mysql.sh insert_skill_usage <uid> <skill_name> [action] [status] [duration_ms] [error_type]\ncustom_mysql.sh insert_relationship <uid> <related_uid> <type> [strength] [trust] [notes]\ncustom_mysql.sh insert_mood <uid> <mood> [intensity] [trigger_topic] [confidence]\ncustom_mysql.sh insert_reminder <uid> <trigger_type> <condition> <text> [priority]\ncustom_mysql.sh insert_thought <uid> <thought> [type] [channel_id]\ncustom_mysql.sh insert_learning <type> <title> <description> [priority] [user] [skill]\ncustom_mysql.sh insert_event <type> <title> [description] [channel_id]\n\n# Memory consolidation (v4.0.0):\npython3 ~/.openclaw/workspace/scripts/memory_consolidation.py --user <uid>\npython3 ~/.openclaw/workspace/scripts/memory_consolidation.py --all-users\n```\n\n## Data Retention & Deletion\n\n### Retention Policies\n- `user_interactions`: 30-day rolling window\n- `user_mood`: 90-day rolling window\n- `user_context` (HoloGraphic metadata): 30-day refresh cycle\n- `user_context` (Hancho reasoning): 90-day review cycle\n- `user_context` (HindSight discoveries): 90-day review cycle\n- `thought_stream`: 30-day rolling window\n- `synaptic_memory`: auto-decay via `decay_rate` column\n- `community_sentiment`, `trending_topics`: 90-day rolling window\n- `user_activity_heatmap`: rolling 90-day windows\n- `user_notes`, `user_relationships`, `skill_usage`, `user_context`: retained until explicitly deleted\n- `proactive_reminders`: auto-deactivate after `max_triggers` reached\n- `memory_consolidation_log`: retained for auditing (no auto-delete)\n\n### Deletion\n- Full user data deletion via `rollback_user.sql` covers all 26 user-data tables\n- Rollback procedure wipes all user-specific data while preserving schema\n\n### Consent & Provenance\n- All profile data is stored only for the user who provided it\n- Inferred data must be marked with `source: 'inferred'` and lower confidence\n- Emotional/mood data requires confidence ≥ 0.7\n- `agent_learnings` and rule-like memories must be reviewed before affecting future behavior\n- Explicit opt-in required for each data source\n\n## Security\n\n- **MyVector Docker container**: All SQL runs inside the container via `docker exec`\n- **Dedicated least-privilege user required**: root/admin accounts explicitly rejected\n- **Password never on command line**: Uses temporary `--defaults-extra-file` with `chmod 600`\n- **`.env` parsed safely**: KEY=VALUE line parsing only — never evaluated as shell code\n- `query` command is SELECT-only (no DML through query)\n- DML requires interactive user confirmation\n- Single-statement execution only (semicolons rejected)\n- DDL blocked (DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE)\n- Table allowlist enforced (26 approved tables)\n- Path traversal and sensitive file patterns blocked\n- Comment injection blocked\n- Hex-encoded string detection blocked\n- Proper MySQL string escaping via Python\n- Foreign key constraints prevent orphaned data\n- Script permissions: 700 (owner execute only)\n- Config directory permissions: 700\n\n## Sentiment Scoring\n\n- **Per interaction**: `user_interactions.sentiment` (enum) + `sentiment_score` (float, -1 to 1)\n- **Per user trend**: Rolling average from recent interactions\n- **Community-wide**: `community_sentiment` aggregated by time period\n- **Mood impact**: Each interaction can shift user's mood (`mood_impact` field)\n- **HindSight analysis**: Automated sentiment trend analysis during consolidation\n\n## Engagement Patterns\n\n- **Time of day**: When user is most active\n- **Day of week**: Weekly activity cycles\n- **Topic triggers**: What topics engage this user most\n- **Channel preference**: Which channels they use\n- **Response style**: How they prefer to interact\n- **Session length**: Typical interaction duration\n- **Activity bursts**: Periods of high activity\n\n## Removed Features\n\n- **Snapshot functionality removed (v1.1.7)`**: The `agent_config_files` table and related commands removed\n- **Local MySQL dependency removed (v3.0.0)`**: Replaced with MyVector Docker container\n\n## Change Log\n\nSee [changelog.md](changelog.md) for full version history.\n\n## Setup Guide\n\nFor step-by-step instructions, see [SETUP_GUIDE.md](SETUP_GUIDE.md).\n\nVisit <https://clawhub.ai/paradoxfuzzle/custom-mysql> for live updates.\n\nFile v5.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7efbevah63xw54q5r7f0x07x80483q\",\n  \"slug\": \"custom-mysql\",\n  \"version\": \"5.0.0\",\n  \"publishedAt\": 1779890662566\n}\n\nFile v5.0.0:CAPABILITIES.md\n\n# VectorClaw — Capability Declarations\n\nThis document explicitly declares what VectorClaw **can** and **cannot** do.\nIt is intended to resolve automated security scanner false positives.\n\n**Version: 5.0.0**\n\n---\n\n## What VectorClaw DOES\n\n| Capability | Status | Notes |\n|---|---|---|\n| MyVector MySQL database operations | ✅ YES | SELECT, INSERT, UPDATE, DELETE on `mysqlclaw` schema via Docker container |\n| User profile storage | ✅ YES | Food prefs, media prefs, communication preferences |\n| Interaction tracking | ✅ YES | Messages, reactions, session grouping |\n| Relationship mapping | ✅ YES | Social graph with trust levels and interaction frequency |\n| Mood tracking | ✅ YES | Emotional states with triggers and intensity |\n| Context storage | ✅ YES | 14 context types: episodic, semantic, procedural, emotional, preference, fact, custom, hindisght, holohraphic, hancho, discovery, behavioral, metadata, reasoning, social_graph, auto_extracted, graph_derived, extraction_quality |\n| Synaptic memory | ✅ YES | Key-value with priority and automatic decay |\n| Thought stream | ✅ YES | Agent reasoning log (reasoning, observation, decision, reflection, planning) |\n| Proactive reminders | ✅ YES | Time-based, event-based, pattern-based follow-up triggers |\n| Agent learnings | ✅ YES | Self-improvement tracking (correction, preference, pattern, error, success, insight, rule) |\n| **HindSight memory consolidation** | ✅ YES | Post-conversation analysis: sentiment trends, topic discovery, importance scoring |\n| **HoloGraphic multi-dimensional tagging** | ✅ YES | Tags memories with emotion, context, urgency, people |\n| **Memory refresh / decay** | ✅ YES | synaptic_memory auto-decay, consolidation log, retention policies |\n| Engagement pattern analysis | ✅ YES | Time of day, day of week, topic triggers, channel preference |\n| Community sentiment | ✅ YES | Aggregated community mood tracking |\n| Trending topics | ✅ YES | Per-period trend identification |\n| Skill usage tracking | ✅ YES | Per-skill usage with error categorization |\n| Community events | ✅ YES | Milestone/incident logging |\n| Multi-dimensional search | ✅ YES | Query by emotion, context, urgency, people, time period |\n| Secure credential handling | ✅ YES | .env parsing, temp files, trap cleanup |\n| Input validation | ✅ YES | Enum validation, numeric validation, SQL escaping |\n| **Auto-extraction (v5.0.0)** | ✅ YES | Local LLM (qwen3.5:4b) extracts atomic facts from conversation text, replaces Mem0 |\n| **Memory relations graph (v5.0.0)** | ✅ YES | Native MySQL knowledge graph via `memory_relations` table, replaces Hancho |\n| **Graph traversal (v5.0.0)** | ✅ YES | `memory_graph_1hop` view for retrieval-time 1-hop graph expansion |\n| **Extraction quality logging (v5.0.0)** | ✅ YES | `extraction_log` table tracks facts extracted/merged/inserted, timing, model used |\n| **Source tracking (v5.0.0)** | ✅ YES | All memories track source: manual, auto, consolidation, import |\n| **Human verification (v5.0.0)** | ✅ YES | `verified_by_human` flag for promoting auto-extracted facts |\n| **Contradiction detection (v5.0.0)** | ✅ YES | Consolidation pass detects same-topic facts with opposite polarity |\n| **Hub insight derivation (v5.0.0)** | ✅ YES | Identifies high-degree facts (3+ connections) as important |\n\n---\n\n## What VectorClaw DOES NOT do\n\n| Capability | Status | Notes |\n|---|---|---|\n| External API calls | ❌ NO | No HTTP requests to third-party services |\n| Cryptocurrency / wallet operations | ❌ NO | No wallet, crypto, or blockchain code |\n| Financial transactions | ❌ NO | No purchase or payment processing |\n| File system access beyond DB | ❌ NO | No reading/writing arbitrary files |\n| Email sending | ❌ NO | No SMTP or email API |\n| Shell command execution | ❌ NO | No exec, system, or shell_exec outside Docker MySQL |\n| Local MySQL server | ❌ NO | MyVector Docker container only — no host MySQL required |\n| Root/admin MySQL access | ❌ NO | Explicitly rejected — dedicated least-privilege account required |\n| DDL operations | ❌ NO | DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE blocked |\n| Multi-statement SQL | ❌ NO | Single-statement only — semicolons rejected |\n| Write without confirmation | ❌ NO | DML requires interactive user confirmation |\n| Access other users' private data | ❌ NO | Only processes data for the authenticated user |\n| Store operational config files | ❌ NO | No snapshots of MEMORY.md, AGENTS.md, etc. |\n| Arbitrary file reads | ❌ NO | Path traversal blocked |\n| Modify its own security rules | ❌ NO | Table allowlist and security controls are static |\n| **External memory services** | ❌ NO (v5.0.0) | Mem0 and Hancho deprecated — all functionality native in MyVector |\n\n---\n\n## Memory Architecture (v5.0.0)\n\n```\n┌─────────────────────────────────────────────────────────────────┐\n│                    OpenClaw Agent (Jerith)                        │\n├─────────────────────────────────────────────────────────────────┤\n│                                                                   │\n│  ┌──────────┐  ┌──────────┐  ┌──────────────────────────────┐  │\n│  │ MEMORY.md │  │ ChromaDB │  │     MyVector MySQL           │  │\n│  │ (narrative│  │ (semantic│  │     (Docker container)        │  │\n│  │  context) │  │  search) │  │                              │  │\n│  └──────────┘  └──────────┘  │  memories (with source,      │  │\n│                               │    verified_by_human)        │  │\n│                               │  memory_relations (graph)    │  │\n│                               │  extraction_log (quality)    │  │\n│                               │  user_context (14 types)     │  │\n│                               │  user_mood, user_prefs, etc. │  │\n│                               │  + 26 more tables            │  │\n│                               └──────────────────────────────┘  │\n│                                              │                    │\n│              ┌───────────────────────────────┤                    │\n│              ▼                               ▼                    │\n│  ┌─────────────────────┐      ┌─────────────────────────┐       │\n│  │ auto-extract.py     │      │ hancho-consolidate.py   │       │\n│  │ (local LLM extract) │      │ (graph reasoning)       │       │\n│  │ Replaces Mem0       │      │ Replaces Hancho         │       │\n│  └─────────────────────┘      └─────────────────────────┘       │\n│              │                               │                    │\n│              └───────────────┬───────────────┘                    │\n│                              ▼                                    │\n│                   ┌────────────────────┐                         │\n│                   │ Retrieval Gate v3  │                         │\n│                   │ (triggered pull    │                         │\n│                   │  + graph expansion)│                         │\n│                   └────────────────────┘                         │\n└─────────────────────────────────────────────────────────────────┘\n```\n\n## Dimensional Tag Reference (HoloGraphic)\n\n| Dimension | Values | Example |\n|-----------|--------|---------|\n| Emotion | positive, negative, complex, neutral | \"Ev's medication worries\" → negative |\n| Context | work, personal, health, tech, social, creative | \"Server setup\" → tech |\n| Urgency | immediate, ongoing, timeless, historical | \"Current medication\" → ongoing |\n| People | auto-detected names | \"Ev and Cyle\" → Ev,Cyle |\n\n## Memory Relations Reference (v5.0.0)\n\n| Relation Type | Description | Discovery Method |\n|---------------|-------------|-----------------|\n| `mentions` | Fact A mentions entities from Fact B | Term overlap (Jaccard > 0.15) |\n| `implies` | Fact A logically implies Fact B | LLM reasoning during consolidation |\n| `contradicts` | Fact A contradicts Fact B (same topic, opposite polarity) | Polarity detection |\n| `same_entity` | Both facts reference the same entity | Entity matching |\n| `related_to` | General relatedness | Category or topic overlap |\n\n## Memory Source Tracking (v5.0.0)\n\n| Source | Description | Initial Confidence | Verification |\n|--------|-------------|-------------------|--------------|\n| `manual` | Written explicitly by agent | 0.9 | N/A (trusted) |\n| `auto` | Extracted by local LLM hook | 0.6-0.7 | `verified_by_human` flag |\n| `consolidation` | Derived from consolidation pass | 0.7 | Review on next cycle |\n| `import` | Imported from external system | 0.5 | Manual review required |\n\n## Trust Rules\n\n- All data storage requires explicit user consent or direct interaction\n- Inferred data is stored with lower confidence scores (≤ 0.7)\n- Emotional/mood data with confidence < 0.7 is not stored\n- `agent_learnings` affecting behavior must be reviewed before activation\n- Users can request full data deletion at any time via rollback_user.sql\n- Consolidation only processes data the agent already has access to — no new data sources\n- Auto-extracted facts start at lower confidence and require human verification to promote\n- Contradictions between high-confidence facts are flagged for review, not auto-resolved\n\nFile v5.0.0:changelog.md\n\n# CHANGELOG\n\nAll notable changes to the **VectorClaw** skill for OpenClaw are documented in this file.\n\nThe format follows the [Keep a Changelog](https://keepachangelog.com/en/1.0.0/) specification and respects [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [5.0.0] – 2026-05-27\n\n### Added — MyVector Self-Sufficiency: Auto-Extraction + Knowledge Graph\n\nThis release makes MyVector self-sufficient by absorbing Mem0's auto-extraction and Hancho's knowledge graph reasoning into native MySQL systems.\n\n**Auto-Extraction Hook (`scripts/auto-extract.py`):**\n- Uses local qwen3.5:4b model with structured JSON prompt to extract atomic facts from conversation text\n- Extracts: core_fact, confidence (0-1), entities[], linked_to[], tags[], memory_type, importance\n- Key mapping normalizes LLM output (handles \"fact\" → \"core_fact\", invalid memory_types → \"semantic\")\n- Auto-dedup on insert: Jaccard similarity check against existing memories, merges if >50% overlap\n- Auto-discovers relations: finds existing memories sharing entities, creates edges in `memory_relations` table\n- Source tracking: marks auto-extracted memories with `source='auto'` for quality monitoring\n- Fallback to regex-based extraction when LLM is unavailable\n- Validates memory_type against DB enum before insert\n\n**Memory Relations Table (`memory_relations`):**\n- Native MySQL knowledge graph replacing Hancho's external reasoning\n- Schema: fact_id, related_fact_id, relation_type, confidence, source, discovered_at\n- Relation types: mentions, implies, contradicts, same_entity, related_to\n- Source tracking: auto (from extraction), manual, consolidation\n- Unique constraint prevents duplicate edges\n- Indexes for fast graph traversal during retrieval\n\n**Hancho Consolidation Pass (`scripts/hancho-consolidate.py`):**\n- Scans recent memories for shared entities/terms (Jaccard > 0.15)\n- Contradiction detection: finds same-topic facts with opposite polarity\n- Inserts edges into `memory_relations`\n- Derives hub insights (facts with 3+ connections = important)\n- Runs as heartbeat job (every 1-4 hours recommended)\n\n**Extraction Quality Logging (`extraction_log`):**\n- Tracks: facts extracted, merged, inserted, relations discovered per run\n- Records: input length, extraction time, model used, fallback usage\n- Enables empirical tuning of extraction prompt over time\n\n**Graph Traversal View (`memory_graph_1hop`):**\n- Pre-computed MySQL view for fast 1-hop graph traversal during retrieval\n- Joins memory_relations with memories for complete edge+node data\n- Filtered to confidence >= 0.5 for quality\n\n### Changed — Database Schema\n\n- **`memories` table**: Added `source` (enum: manual/auto/consolidation/import), `verified_by_human` (boolean), `extraction_prompt` (text) columns\n- **`memories` table**: Added `idx_mem_source` index for source-based queries\n- **`user_context` table**: Extended `context_type` enum with `auto_extracted`, `graph_derived`, `extraction_quality`\n- **New table**: `memory_relations` — knowledge graph edges\n- **New table**: `extraction_log` — extraction quality metrics\n- **New view**: `memory_graph_1hop` — fast graph traversal\n\n### Changed — SKILL.md Updated\n\n- **Version bumped to 5.0.0**\n- **Added Auto-Extraction section** documenting the auto-extract hook, prompt design, key mapping, and dedup logic\n- **Added Memory Relations section** documenting the knowledge graph schema, relation types, and consolidation pass\n- **Added Extraction Logging section** documenting quality tracking\n- **Added deprecation notes** for Mem0 (auto-extraction replaced) and Hancho (knowledge graph replaced)\n- **Updated Memory Types table** with new source tracking and graph-derived types\n- **Updated data retention policies** for auto-extracted memories (7-day parallel run, then 30-day review cycle)\n\n### Deprecated — External Memory Tools\n\n- **Mem0**: Auto-extraction replaced by `auto-extract.py` with local qwen3.5:4b. Run in parallel for 7-10 days for quality comparison, then retire.\n- **Hancho**: Knowledge graph reasoning replaced by `memory_relations` table + `hancho-consolidate.py`. Native MySQL graph traversal is tighter and fully owned.\n\n### Migration Notes\n\n- Run `upgrade_v4_to_v5.sql` to apply schema changes\n- Existing memories default to `source='manual'` — no data migration needed\n- Auto-extraction starts populating `source='auto'` memories immediately\n- Run `hancho-consolidate.py --dry-run` first to preview graph edges before committing\n\n---\n\n## [4.0.0] – 2026-05-21\n\n### Added — HindSight + HoloGraphic + Hancho Memory Systems\n\nThis release adds three memory enhancement systems that run during heartbeat consolidation cycles:\n\n**HindSight** — Post-conversation analysis:\n- Analyzes recent interactions for sentiment trends (positive/negative/neutral ratios)\n- Identifies frequently discussed topics and new topics not yet stored as memories\n- Detects recurring themes worth tracking\n- Stores findings as derived memories in `user_context` (category: discovery/behavioral/emotional)\n\n**HoloGraphic** — Multi-dimensional memory tagging:\n- Tags every memory with: emotion (positive/negative/complex/neutral), context (work/personal/health/tech/social/creative), urgency (immediate/ongoing/timeless/historical), people involved\n- Enables retrieval from any angle (e.g., \"how did Ev feel about X\" or \"what health topics came up in May\")\n- Stores tags as structured memories in `user_context` (category: metadata)\n\n**Hancho** — Knowledge graph reasoning:\n- Connects related facts across memories to derive new insights\n- 7 reasoning rules: medication side effects, health chains, tech infrastructure, creative passions, relationship depth, interest-to-skill, emotional coping patterns\n- Inter-user reasoning finds shared topics between users\n- Stores derived insights as new memories in `user_context` (category: reasoning)\n\n### Added — memory_consolidation.py Script\n\n- **`memory_consolidation.py`** — Standalone consolidation script that runs HindSight + HoloGraphic + Hancho in sequence.\n- Supports `--user <id>`, `--all-users`, `--hindisght-only`, `--holohraphic-only`, `--hancho-only`, `--dry-run` flags.\n- Integrates with `community-memory.py` via subprocess calls.\n- Scheduled to run every 6 hours via OpenClaw heartbeat and cron.\n- Already processed: NP (4 derived insights, 10 tagged memories) and Ev (10 tagged memories).\n\n### Changed — SKILL.md Updated\n\n- **Version bumped to 4.0.0**\n- **Added Memory Consolidation section** documenting HindSight, HoloGraphic, and Hancho systems.\n- **Added Memory Types table** with 6 types: Episodic, Semantic, Procedural, Emotional, Preference, Synaptic, HoloGraphic (multi-dimensional tags), and Hancho (derived reasoning).\n- **Added dimensional tag reference**: emotion, context, urgency, people fields for HoloGraphic tagging.\n- **Added reasoning rule reference**: 7 Hancho reasoning patterns with examples.\n- **Updated data retention policies** for new memory types (HoloGraphic tags: 30-day refresh; Hancho derived: 90-day review).\n- **Updated Memory Architecture section** in README to reference all 3 systems and when to use each.\n\n### Changed — Database Schema Enhancements\n\n- **`user_context` table**: Enhanced `context_type` enum to include new consolidation types: `hindisght`, `holohraphic`, `hancho`, `discovery`, `behavioral`, `metadata`, `reasoning`, `social_graph`.\n- **`memory_consolidation_log` table**: Now actively used. Each consolidation run logs: consolidation type, source count, result count, affected users, timestamp.\n- **New indexes on `user_context`**: Added composite index on `(user_id, context_type, importance)` for faster consolidation queries.\n- **New index on `user_interactions`**: Added composite index on `(user_id, created_at, sentiment)` for HindSight trend analysis.\n\n### Added — New SQL Migration Script\n\n- **`upgrade_v3_to_v4.sql`** — Migration script for upgrading v3.x installations to v4.0.0:\n  - Adds new enum values to `user_context.context_type`\n  - Adds new indexes for consolidation queries\n  - Safe to run on production (uses `IF NOT EXISTS` and `ALTER TABLE ... ADD COLUMN IF NOT EXISTS`)\n\n### Updated — Documentation\n\n- **CAPABILITIES.md** — Added HindSight, HoloGraphic, and Hancho to capability declarations. Added memory_consolidation.py as a required script.\n- **SETUP_GUIDE.md** — Added section on memory consolidation setup and scheduling.\n- **SKILL.md** — Updated memory type table, added consolidation commands, updated architecture diagram.\n\n### Security\n\n- All consolidation operations follow existing security model: SELECT-only for analysis, write operations go through `sql_safe_exec.sh` with confirmation.\n- No new attack surface introduced.\n- Consolidation only processes data the agent already has access to.\n\n### Migration Notes (v3.x → v4.0.0)\n\n1. Back up your `mysqlclaw` database before upgrading.\n2. Run `upgrade_v3_to_v4.sql` against your existing database:\n   ```bash\n   docker exec -i myvector-db mysql -u mysqlclaw -p<pass> mysqlclaw < upgrade_v3_to_v4.sql\n   ```\n3. Copy `memory_consolidation.py` to `~/.openclaw/workspace/scripts/`.\n4. Add the 6-hour consolidation heartbeat task to `HEARTBEAT.md`.\n5. Run initial consolidation: `python3 memory_consolidation.py --user <id>`.\n6. Existing data is preserved — new tables/columns use `IF NOT EXISTS`.\n\n---\n\n## [3.1.0] – 2026-05-11\n\n### Changed — Renamed from MySQLClaw to VectorClaw\n\n- **Skill renamed from MySQLClaw to VectorClaw.** The skill name, slug, and all internal references updated to reflect the new name. The old name `MySQLClaw` implied a MySQL-specific dependency; `VectorClaw` better reflects the MyVector (MySQL 8.4 + vector search) foundation.\n- **Directory renamed from `mysqlclaw` to `vectorclaw`.** The active skill directory is now `skills/vectorclaw/`. The dev-only `custom-mysql` directory retains its name for reference.\n- **Script files renamed.** `custom_mysql.sh` → `vector_claw.sh`, `setup_wizard.sh` → `vector_claw_setup.sh`.\n- **`_meta.json` slug updated** from `custom-mysql` to `vector-claw`.\n- **All documentation updated.** `SKILL.md`, `CAPABILITIES.md`, `updated_SKILL.md`, `SETUP_GUIDE.md`, `changelog.md` — all references to MySQLClaw replaced with VectorClaw.\n\n---\n\n## [3.0.0] – 2026-05-11\n\n### Changed — Replaced MySQL with MyVector Docker Container\n\n- **Replaced local MySQL dependency with MyVector Docker container.** The skill no longer requires a local MySQL server or client. All SQL is routed through `docker exec` into the MyVector container (`ghcr.io/askdba/myvector:mysql8.4`), which provides MySQL 8.4 compatibility with vector search extensions. This eliminates the host MySQL 8.4 client's missing `mysql_native_password` auth plugin issue.\n\n- **`sql_safe_exec.sh` completely rewritten for Docker exec.** The `MYSQL_CMD` now uses `docker exec -i myvector-db mysql --defaults-extra-file=...` instead of the host `mysql` binary. Credentials are copied into the container via `docker cp` before each query. The container is verified to be running before any connection attempt.\n\n- **All references to local MySQL replaced with MyVector.** `SKILL.md`, `CAPABILITIES.md`, `updated_SKILL.md`, `SETUP_GUIDE.md`, and `_meta.json` updated to reflect MyVector Docker container as the database backend.\n\n### Security Fixes (ClawScan audit response)\n\n- **Fail-closed authentication.** Previously, `sql_safe_exec.sh` silently fell back to `root` when `MYSQL_USER` was not set in `.env`. Now the skill explicitly refuses to connect if `MYSQL_USER` or `MYSQL_PASSWORD` is missing, printing an error message explaining the requirement for a dedicated least-privilege account.\n\n- **Root/admin user rejection.** The skill now explicitly rejects `root`, `admin`, and `mysql` usernames. If a user attempts to use these accounts, the skill prints an error and exits. This addresses the ClawScan finding that the skill could silently fall back to database-administrator privileges.\n\n- **Container verification.** Before attempting any SQL connection, the skill now verifies that the MyVector Docker container exists and is running. If the container is missing or stopped, the skill prints a helpful error message with the `docker run` command to start it.\n\n- **Removed wallet/crypto/purchase capability flags from `_meta.json`.** The previous metadata incorrectly declared `crypto`, `requires-wallet`, `can-make-purchases`, and `requires-sensitive-credentials` capability signals. These have been removed. The skill has never contained wallet, cryptocurrency, or purchase code.\n\n- **`_meta.json` updated with accurate declarations.** Added `docker` to `requiredBinaries` (replacing `mysql`). Updated `credentialEnvVars` to match actual usage. Updated description to mention MyVector and least-privilege requirement.\n\n- **`setup_wizard.sh` rewritten for MyVector.** The wizard now: (1) checks Docker is running, (2) creates/starts the MyVector container, (3) creates a dedicated least-privilege MySQL user inside the container, (4) applies the schema, (5) verifies the connection. No longer shows the root password as a default value — prompts securely with `-s` flag.\n\n- **`updated_SKILL.md` — added opt-in, provenance, and review rules.** Added explicit consent requirements: opt-in for each data source, provenance tracking (source, confidence, timestamp), review requirement for `agent_learnings` before they affect behavior, and retention/deletion enforcement.\n\n- **`updated_SKILL.md` — added source path restrictions.** Explicitly lists approved sources (Discord messages, reactions, user statements, observed patterns, agent reasoning) and prohibited sources (operational config files, secrets/credentials, other users' private data, arbitrary file reads).\n\n- **`CAPABILITIES.md` — removed wallet/crypto/purchase declarations.** Added `Fail-closed auth`, `Rejects root/admin`, and `Container verification` to the \"What VectorClaw DOES\" section. Added `Local MySQL server` and `Root/admin MySQL access` to the \"What VectorClaw DOES NOT do\" section.\n\n- **`SKILL.md` — version bumped to 3.0.0.** Updated all documentation to reference MyVector Docker container instead of local MySQL. Added Removed Features entry for local MySQL dependency.\n\n- **`.env` file removed from `custom-mysql` directory.** The development-only skill directory no longer contains any credentials. Only the `mysqlclaw` skill directory (the installed, active skill) has a `.env` file.\n\n- **`custom-mysql` confirmed as dev-only.** This skill is never installed or used in production. All production use goes through the `mysqlclaw` skill directory.\n\n### Security Audit Results (v3.0.0)\n\n1. ✅ **File permissions** — All shell scripts set to 700 (owner execute only). All data files set to 644.\n2. ✅ **No hardcoded credentials** — No passwords in any file. The setup wizard prompts interactively.\n3. ✅ **No eval usage** — Zero `eval` statements across all scripts.\n4. ✅ **No shell-sourced .env** — `.env` is parsed as KEY=VALUE lines only, never evaluated as shell code.\n5. ✅ **No password on command line** — Uses temporary `--defaults-extra-file` with `chmod 600`.\n6. ✅ **No root/admin fallback** — Root is explicitly rejected, not defaulted.\n7. ✅ **Fail-closed on missing creds** — Refuses to connect without MYSQL_USER and MYSQL_PASSWORD.\n8. ✅ **Container verification** — Verifies MyVector container is running before connecting.\n9. ✅ **DDL blocking** — DROP, TRUNCATE, CREATE, ALTER, GRANT, REVOKE blocked.\n10. ✅ **Table allowlist** — 26 approved tables enforced for all write operations.\n11. ✅ **DML confirmation** — Interactive confirmation required for all write operations.\n12. ✅ **Single-statement enforcement** — Semicolons rejected to prevent stacked queries.\n13. ✅ **Path traversal prevention** — Sensitive paths and file operations blocked.\n14. ✅ **Comment injection prevention** — `/* */\n\nArchive v4.0.0: 17 files, 47813 bytes\n\nFiles: _meta.json (131b), .clawhub/origin.json (143b), CAPABILITIES.md (9051b), changelog.md (34165b), cleanup_snapshots.sql (410b), create_user_tables.sql (23845b), populate_templates.sql (938b), rollback_user.sql (2267b), sanitize_snapshot.sh (754b), SETUP_GUIDE.md (7094b), SKILL.md (11299b), sql_safe_exec.sh (7570b), updated_SKILL.md (8350b), upgrade_v1_to_v2.sql (14739b), upgrade_v3_to_v4.sql (2741b), vector_claw_setup.sh (6093b), vector_claw.sh (17898b)\n\nArchive v1.1.12: 16 files, 44370 bytes\n\nFiles: _meta.json (132b), .clawhub/origin.json (143b), CAPABILITIES.md (8308b), changelog.md (29265b), cleanup_snapshots.sql (410b), create_user_tables.sql (23845b), populate_templates.sql (938b), rollback_user.sql (2267b), sanitize_snapshot.sh (754b), SETUP_GUIDE.md (7094b), SKILL.md (9068b), sql_safe_exec.sh (7570b), updated_SKILL.md (8350b), upgrade_v1_to_v2.sql (14739b), vector_claw_setup.sh (6093b), vector_claw.sh (17898b)\n\nArchive v1.1.11: 16 files, 40026 bytes\n\nFiles: _meta.json (132b), .clawhub/origin.json (144b), CAPABILITIES.md (7241b), changelog.md (22126b), cleanup_snapshots.sql (410b), create_user_tables.sql (23845b), custom_mysql.sh (17996b), populate_templates.sql (938b), rollback_user.sql (2267b), sanitize_snapshot.sh (754b), SETUP_GUIDE.md (7091b), setup_wizard.sh (4583b), SKILL.md (7115b), sql_safe_exec.sh (5646b), updated_SKILL.md (7374b), upgrade_v1_to_v2.sql (14739b)\n\nArchive v1.1.10: 15 files, 35158 bytes\n\nFiles: _meta.json (132b), .clawhub/origin.json (144b), CAPABILITIES.md (7241b), changelog.md (19585b), cleanup_snapshots.sql (410b), create_user_tables.sql (23845b), custom_mysql.sh (17670b), populate_templates.sql (938b), rollback_user.sql (2267b), sanitize_snapshot.sh (754b), setup_wizard.sh (4583b), SKILL.md (6919b), sql_safe_exec.sh (4892b), updated_SKILL.md (6350b), upgrade_v1_to_v2.sql (14739b)\n\nArchive v1.1.9: 14 files, 30993 bytes\n\nFiles: _meta.json (131b), .clawhub/origin.json (144b), CAPABILITIES.md (7241b), changelog.md (17879b), cleanup_snapshots.sql (410b), create_user_tables.sql (23845b), custom_mysql.sh (17684b), populate_templates.sql (938b), rollback_user.sql (2267b), sanitize_snapshot.sh (754b), setup_wizard.sh (4583b), SKILL.md (6919b), sql_safe_exec.sh (4466b), updated_SKILL.md (6350b)\n\nArchive v1.1.8: 14 files, 21615 bytes\n\nFiles: _meta.json (131b), .clawhub/origin.json (144b), CAPABILITIES.md (4778b), changelog.md (13902b), cleanup_snapshots.sql (410b), create_user_tables.sql (6681b), custom_mysql.sh (8936b), populate_templates.sql (938b), rollback_user.sql (945b), sanitize_snapshot.sh (754b), setup_wizard.sh (3806b), SKILL.md (4570b), sql_safe_exec.sh (3375b), updated_SKILL.md (3770b)\n\nArchive v1.1.7: 14 files, 22619 bytes\n\nFiles: _meta.json (131b), .clawhub/origin.json (144b), CAPABILITIES.md (5056b), changelog.md (12461b), cleanup_snapshots.sql (1854b), create_user_tables.sql (7596b), custom_mysql.sh (10739b), populate_templates.sql (938b), rollback_user.sql (986b), sanitize_snapshot.sh (1503b), setup_wizard.sh (4020b), SKILL.md (3284b), sql_safe_exec.sh (3429b), updated_SKILL.md (3770b)\n\nArchive v1.1.6: 13 files, 19461 bytes\n\nFiles: CAPABILITIES.md (5056b), changelog.md (9438b), cleanup_snapshots.sql (1854b), create_user_tables.sql (7596b), custom_mysql.sh (9418b), populate_templates.sql (938b), rollback_user.sql (628b), sanitize_snapshot.sh (1503b), setup_wizard.sh (4020b), SKILL.md (2973b), sql_safe_exec.sh (632b), updated_SKILL.md (3770b), _meta.json (131b)","readmeExcerpt":"Skill: VectorClaw Owner: paradoxfuzzle Summary: Provides a secure, least-privilege interface for managing user data, personas, and config snapshots in MySQL with input validation and secret redaction. Tags: MySQL:1.0.8, database:1.0.8, latest:5.0.1, persistence:1.0.8, persona:1.0.8 Version history: v5.0.1 | 2026-05-27T16:32:21.100Z | user **Summary: Privacy, consent, and security improvements based on audit.** - Adde","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# Extract from text\npython3 scripts/auto-extract.py \"conversation text here\" --user <discord_id>\n\n# Extract from file\npython3 scripts/auto-extract.py --file /path/to/conversation.txt --user <discord_id>\n\n# Dry run (preview without inserting)\npython3 scripts/auto-extract.py \"text\" --user <id> --dry-run\n\n# Output as JSON\npython3 scripts/auto-extract.py \"text\" --user <id> --dry-run --json"},{"language":"bash","snippet":"# Consolidate recent memories (default: last 6 hours)\npython3 scripts/hancho-consolidate.py --user <discord_id>\n\n# Lookback window\npython3 scripts/hancho-consolidate.py --user <id> --hours 24\n\n# Dry run\npython3 scripts/hancho-consolidate.py --user <id> --dry-run"},{"language":"bash","snippet":"python3 memory_consolidation.py --user <discord_id>\n  python3 memory_consolidation.py --all-users\n  python3 memory_consolidation.py --user <id> --dry-run\n  python3 memory_consolidation.py --user <id> --hindisght-only\n  python3 memory_consolidation.py --user <id> --holohraphic-only\n  python3 memory_consolidation.py --user <id> --hancho-only"},{"language":"bash","snippet":"docker run -d --name myvector-db -p 3310:3306 \\\n  -e MYSQL_ROOT_PASSWORD=<root_pw> \\\n  -e MYSQL_DATABASE=mysqlclaw \\\n  ghcr.io/askdba/myvector:mysql8.4"},{"language":"bash","snippet":"# 1. Start MyVector container (if not running)\ndocker run -d --name myvector-db -p 3310:3306 \\\n  -e MYSQL_ROOT_PASSWORD=<root_pw> \\\n  -e MYSQL_DATABASE=mysqlclaw \\\n  ghcr.io/askdba/myvector:mysql8.4\n\n# 2. Create a dedicated least-privilege user inside MyVector\ndocker exec -it myvector-db mysql -u root -p<root_pw> -e \"\n  CREATE USER IF NOT EXISTS 'mysqlclaw'@'%' IDENTIFIED BY '<strong_password>';\n  GRANT SELECT, INSERT, UPDATE, DELETE ON mysqlclaw.* TO 'mysqlclaw'@'%';\n  FLUSH PRIVILEGES;\n\"\n\n# 3. Create .env file with the dedicated user's credentials\ncat > .env <<'EOF'\nMYSQL_USER=mysqlclaw\nMYSQL_PASSWORD=<strong_password>\nMYSQL_PORT=3310\nDATABASE=mysqlclaw\nEOF\nchmod 600 .env\n\n# 4. Apply schema with setup wizard\ncd ~/.openclaw/workspace/skills/custom-mysql\n./setup_wizard.sh\n\n# 5. Run initial consolidation (DRY RUN first, then live)\ncd ~/.openclaw/workspace\npython3 scripts/memory_consolidation.py --user <your_discord_id> --dry-run\npython3 scripts/memory_consolidation.py --user <your_discord_id>"},{"language":"bash","snippet":"export MYSQL_USER=mysqlclaw\nexport MYSQL_PASSWORD=<your_password>\npython3 scripts/auto-extract.py --file /path/to/conversation.txt --user <discord_id> --dry-run\n# Review output, then run without --dry-run"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"# paradoxfuzzle/custom-mysql\n\n## ⚠️ PRIVACY & CONSENT NOTICE — READ BEFORE INSTALLING\n\nThis skill **automatically extracts, infers, and persistently stores sensitive personal information** from user conversations, including but not limited to:\n\n- **Emotional states and mood patterns** (stress, anxiety, sadness, joy)\n- **Relationship signals** (who users interact with, closeness, trust)\n- **Health and wellness indicators** (medication mentions, symptoms, coping patterns)\n- **Behavioral profiling** (engagement patterns, time-of-day activity, topic preferences)\n- **Inferred preferences and traits** (derived from conversation patterns, not explicitly stated)\n- **Agent reasoning logs** (internal chain-of-thought stored alongside user data)\n\n**By installing this skill, you accept responsibility for:**\n\n1. **Informing all users** that their conversation data is being profiled and persisted\n2. **Obtaining explicit opt-in consent** before enabling auto-extraction for any user\n3. **Providing a clear mechanism** for users to request full data deletion (`rollback_user.sql`)\n4. **Reviewing auto-extracted data** for accuracy and sensitivity before it affects agent behavior\n5. **Configuring retention limits** appropriate to your use case (default: 30-90 days depending on data type)\n\nThis is a **self-hosted, self-managed system**. No data leaves your infrastructure. However, the breadth of profiling it performs is significant and should not be enabled without user awareness.\n\n**Disable auto-extraction by default.** Enable per-user only after explicit opt-in.\n\n---\n\n## Overview\n\nSecurity-hardened MyVector MySQL profile storage with capability bounding for OpenClaw. Tracks interactions, relationships, context, skill usage, notes, preferences, media, food, personas, mood states, engagement patterns, proactive reminders, agent learnings, community sentiment, trending topics, and community events. Now includes HindSight (post-conversation consolidation), HoloGraphic (multi-dimensional tagging), and Hancho (knowledge graph reasoning) memory systems. v4.0.0 integrates with the `memory_consolidation.py` script for automated heartbeat-based memory maintenance. All SQL is routed through `docker exec` into the MyVector container. Requires a dedicated least-privilege MySQL user — root/admin accounts are rejected.\n\n## Version\n\n5.0.1 – 2026-05-27 (security audit response)\n\n## Memory Systems\n\nVectorClaw v5.0.0 makes MyVector self-sufficient. It includes three memory enhancement systems (v4) plus auto-extraction and native knowledge graph reasoning (v5):\n\n### HindSight — Post-Conversation Consolidation\n- Analyzes recent interactions (sentiment trends, topic frequency)\n- Identifies new topics not yet stored as memories\n- Detects recurring themes worth tracking\n- Stores findings in `user_context` (categories: discovery, behavioral, emotional)\n\n### HoloGraphic — Multi-Dimensional Tagging\n- Tags memories with: emotion, context, urgency, people\n- **Emotion**: positive, negative, comp"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7efbevah63xw54q5r7f0x07x80483q\",\n  \"slug\": \"custom-mysql\",\n  \"version\": \"5.0.1\",\n  \"publishedAt\": 1779899541100\n}"},{"path":"CAPABILITIES.md","content":"# VectorClaw — Capability Declarations\n\nThis document explicitly declares what VectorClaw **can** and **cannot** do.\nIt is intended to resolve automated security scanner false positives.\n\n**Version: 5.0.0**\n\n---\n\n## What VectorClaw DOES\n\n| Capability | Status | Notes |\n|---|---|---|\n| MyVector MySQL database operations | ✅ YES | SELECT, INSERT, UPDATE, DELETE on `mysqlclaw` schema via Docker container |\n| User profile storage | ✅ YES | Food prefs, media prefs, communication preferences |\n| Interaction tracking | ✅ YES | Messages, reactions, session grouping |\n| Relationship mapping | ✅ YES | Social graph with trust levels and interaction frequency |\n| Mood tracking | ✅ YES | Emotional states with triggers and intensity |\n| Context storage | ✅ YES | 14 context types: episodic, semantic, procedural, emotional, preference, fact, custom, hindisght, holohraphic, hancho, discovery, behavioral, metadata, reasoning, social_graph, auto_extracted, graph_derived, extraction_quality |\n| Synaptic memory | ✅ YES | Key-value with priority and automatic decay |\n| Thought stream | ✅ YES | Agent reasoning log (reasoning, observation, decision, reflection, planning) |\n| Proactive reminders | ✅ YES | Time-based, event-based, pattern-based follow-up triggers |\n| Agent learnings | ✅ YES | Self-improvement tracking (correction, preference, pattern, error, success, insight, rule) |\n| **HindSight memory consolidation** | ✅ YES | Post-conversation analysis: sentiment trends, topic discovery, importance scoring |\n| **HoloGraphic multi-dimensional tagging** | ✅ YES | Tags memories with emotion, context, urgency, people |\n| **Memory refresh / decay** | ✅ YES | synaptic_memory auto-decay, consolidation log, retention policies |\n| Engagement pattern analysis | ✅ YES | Time of day, day of week, topic triggers, channel preference |\n| Community sentiment | ✅ YES | Aggregated community mood tracking |\n| Trending topics | ✅ YES | Per-period trend identification |\n| Skill usage tracking | ✅ YES | Per-skill usage with error categorization |\n| Community events | ✅ YES | Milestone/incident logging |\n| Multi-dimensional search | ✅ YES | Query by emotion, context, urgency, people, time period |\n| Secure credential handling | ✅ YES | .env parsing, temp files, trap cleanup |\n| Input validation | ✅ YES | Enum validation, numeric validation, SQL escaping |\n| **Auto-extraction (v5.0.0)** | ✅ YES | Local LLM (qwen3.5:4b) extracts atomic facts from conversation text, replaces Mem0 |\n| **Memory relations graph (v5.0.0)** | ✅ YES | Native MySQL knowledge graph via `memory_relations` table, replaces Hancho |\n| **Graph traversal (v5.0.0)** | ✅ YES | `memory_graph_1hop` view for retrieval-time 1-hop graph expansion |\n| **Extraction quality logging (v5.0.0)** | ✅ YES | `extraction_log` table tracks facts extracted/merged/inserted, timing, model used |\n| **Source tracking (v5.0.0)** | ✅ YES | All memories track source: manual, auto, consolidation, import |\n| **Human verification (v5.0.0)** | ✅ YES | `"},{"path":"changelog.md","content":"# CHANGELOG\n\nAll notable changes to the **VectorClaw** skill for OpenClaw are documented in this file.\n\nThe format follows the [Keep a Changelog](https://keepachangelog.com/en/1.0.0/) specification and respects [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [5.0.0] – 2026-05-27\n\n### Added — MyVector Self-Sufficiency: Auto-Extraction + Knowledge Graph\n\nThis release makes MyVector self-sufficient by absorbing Mem0's auto-extraction and Hancho's knowledge graph reasoning into native MySQL systems.\n\n**Auto-Extraction Hook (`scripts/auto-extract.py`):**\n- Uses local qwen3.5:4b model with structured JSON prompt to extract atomic facts from conversation text\n- Extracts: core_fact, confidence (0-1), entities[], linked_to[], tags[], memory_type, importance\n- Key mapping normalizes LLM output (handles \"fact\" → \"core_fact\", invalid memory_types → \"semantic\")\n- Auto-dedup on insert: Jaccard similarity check against existing memories, merges if >50% overlap\n- Auto-discovers relations: finds existing memories sharing entities, creates edges in `memory_relations` table\n- Source tracking: marks auto-extracted memories with `source='auto'` for quality monitoring\n- Fallback to regex-based extraction when LLM is unavailable\n- Validates memory_type against DB enum before insert\n\n**Memory Relations Table (`memory_relations`):**\n- Native MySQL knowledge graph replacing Hancho's external reasoning\n- Schema: fact_id, related_fact_id, relation_type, confidence, source, discovered_at\n- Relation types: mentions, implies, contradicts, same_entity, related_to\n- Source tracking: auto (from extraction), manual, consolidation\n- Unique constraint prevents duplicate edges\n- Indexes for fast graph traversal during retrieval\n\n**Hancho Consolidation Pass (`scripts/hancho-consolidate.py`):**\n- Scans recent memories for shared entities/terms (Jaccard > 0.15)\n- Contradiction detection: finds same-topic facts with opposite polarity\n- Inserts edges into `memory_relations`\n- Derives hub insights (facts with 3+ connections = important)\n- Runs as heartbeat job (every 1-4 hours recommended)\n\n**Extraction Quality Logging (`extraction_log`):**\n- Tracks: facts extracted, merged, inserted, relations discovered per run\n- Records: input length, extraction time, model used, fallback usage\n- Enables empirical tuning of extraction prompt over time\n\n**Graph Traversal View (`memory_graph_1hop`):**\n- Pre-computed MySQL view for fast 1-hop graph traversal during retrieval\n- Joins memory_relations with memories for complete edge+node data\n- Filtered to confidence >= 0.5 for quality\n\n### Changed — Database Schema\n\n- **`memories` table**: Added `source` (enum: manual/auto/consolidation/import), `verified_by_human` (boolean), `extraction_prompt` (text) columns\n- **`memories` table**: Added `idx_mem_source` index for source-based queries\n- **`user_context` table**: Extended `context_type` enum with `auto_extracted`, `graph_derived`, `extraction_quality`\n- **New table**: `memory_relations` — k"},{"path":"RELEASE_POST_v5.md","content":"# VectorClaw v5.0.0 — MyVector Self-Sufficiency\n\n**VectorClaw v5.0.0 makes MyVector the single source of truth for all agent memory.** Auto-extraction and knowledge graph reasoning are now native MySQL systems, eliminating dependency on external tools (Mem0, Hancho).\n\n## New in This Release\n\n### Auto-Extraction Hook — Replaces Mem0\n\nThe auto-extraction hook uses a local LLM (qwen3.5:4b) to extract atomic facts from conversation text and insert them directly into MyVector:\n\n- **Structured extraction:** core_fact, confidence, entities, linked_to, tags, memory_type, importance\n- **Key mapping:** Normalizes LLM output (\"fact\" → \"core_fact\", invalid types → \"semantic\")\n- **Auto-dedup:** Jaccard similarity check on insert — merges if >50% overlap\n- **Source tracking:** All auto-extracted memories marked with `source='auto'`\n- **Human verification:** `verified_by_human` flag for promoting accurate auto-facts\n- **Fallback:** Regex-based extraction when LLM is unavailable\n- **Quality logging:** Every extraction run logged to `extraction_log` for empirical tuning\n\n```bash\npython3 scripts/auto-extract.py \"conversation text\" --user <discord_id>\npython3 scripts/auto-extract.py --file /path/to/text.txt --user <id> --dry-run\n```\n\n### Memory Relations + Knowledge Graph — Replaces Hancho\n\nNative MySQL knowledge graph that replaces Hancho's external reasoning:\n\n- **`memory_relations` table:** fact_id, related_fact_id, relation_type, confidence, source\n- **Relation types:** mentions, implies, contradicts, same_entity, related_to\n- **Auto-discovery:** Finds existing memories sharing entities during extraction\n- **Consolidation pass:** Periodic scanning for contradictions and new edges\n- **Hub insight derivation:** Identifies high-degree facts (3+ connections) as important\n- **`memory_graph_1hop` view:** Pre-computed 1-hop graph traversal for retrieval\n\n```bash\npython3 scripts/hancho-consolidate.py --user <discord_id>\npython3 scripts/hancho-consolidate.py --user <id> --hours 24 --dry-run\n```\n\n### Database Schema Changes\n\n- **`memories` table:** Added `source`, `verified_by_human`, `extraction_prompt` columns\n- **New table:** `memory_relations` — knowledge graph edges\n- **New table:** `extraction_log` — extraction quality metrics\n- **New view:** `memory_graph_1hop` — fast graph traversal\n- **`user_context` enum:** Added `auto_extracted`, `graph_derived`, `extraction_quality`\n\n### Extraction Quality Logging\n\nTracks auto-extraction quality for empirical prompt tuning:\n- Facts extracted, merged, inserted, relations discovered per run\n- Input length, extraction time (ms), model used, fallback usage\n- Per-user and time-based indexes\n\n## Upgrade\n\n```bash\n# 1. Back up your database\ndocker exec myvector-db mysqldump -u root -p<pass> jerith > backup_pre_v5.sql\n\n# 2. Apply schema migration\ndocker exec -i myvector-db mysql -u root -p<pass> jerith < upgrade_v4_to_v5.sql\n\n# 3. Run initial consolidation to build graph edges\npython3 scripts/hancho-consolidate.py --all-users --dry-ru"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2595,"uniquenessScore":39,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T13:26:27.509Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T13:26:27.509Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T15:52:03.857Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}