{"id":"4e45ec78-4813-4ba5-a5de-47643926b118","entityType":"agent","slug":"clawhub-zw008-endpoint-aiops","name":"endpoint-aiops","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zw008-endpoint-aiops","canonicalPath":"/agent/clawhub-zw008-endpoint-aiops","generatedAt":"2026-10-10T14:46:12.411Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:40:15.748Z","emptyReason":null},"description":"Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint). Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet. Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only). Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:endpoint-aiops","sourceUrl":"https://clawhub.ai/zw008/endpoint-aiops","homepage":"https://clawhub.ai/zw008/skills/endpoint-aiops","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/zw008/endpoint-aiops","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/zw008/skills/endpoint-aiops","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"endpoint-aiops technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:40:15.748Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:40:15.748Z","emptyReason":null},"stars":null,"forks":null,"downloads":1458,"packageName":null,"latestVersion":"0.10.3","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:40:15.748Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T11:40:15.748Z","lastCrawledAt":"2026-10-10T11:40:15.748Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T11:40:15.748Z","lastVerifiedAt":null,"highlights":[{"version":"0.10.3","createdAt":"2026-09-15T05:54:58.702Z","changelog":"- Removed the skill-card.md file from the project. - No changes to skill features, code, or user experience. - Documentation updated by removing a sample file.","fileCount":7,"zipByteSize":16351},{"version":"0.10.2","createdAt":"2026-09-12T14:09:47.642Z","changelog":"- Removed redundant skill metadata file (skill-card.md) for a cleaner package. - Updated installation instructions: OpenClaw plugin install now uses the @zw008 scope for endpoint-aiops. - No functional or toolset changes; documentation only.","fileCount":7,"zipByteSize":16395},{"version":"0.10.1","createdAt":"2026-09-12T10:02:30.835Z","changelog":"## endpoint-aiops v0.10.1 - Added OpenClaw plugin install instructions and usage details to documentation. - Clarified that `uvx` is required on PATH when using as an OpenClaw plugin. - Removed the redundant `skill-card.md` file. - Minor updates for installation information and OpenClaw compatibility.","fileCount":7,"zipByteSize":16397},{"version":"0.10.0","createdAt":"2026-09-12T00:51:06.996Z","changelog":"- skill-card.md file removed - SKILL.md updated: metadata now uses anyBins and uvx, with simplified/updated environment and binary requirements - No changes to user-facing features or tool behavior - Internal compatibility and setup documentation refined","fileCount":7,"zipByteSize":16204},{"version":"0.9.0","createdAt":"2026-08-10T06:50:30.666Z","changelog":"# endpoint-aiops 0.9.0 Changelog - Removed the file: `skill-card.md` - No changes to core functionality or features - Documentation and skill metadata remain as before","fileCount":7,"zipByteSize":16245},{"version":"0.8.0","createdAt":"2026-08-03T05:52:23.691Z","changelog":"# endpoint-aiops 0.8.0 Changelog - Removed the documentation file `skill-card.md`. - No functional changes to the skill itself; only documentation cleanup.","fileCount":7,"zipByteSize":16304},{"version":"0.7.0","createdAt":"2026-08-02T09:38:43.056Z","changelog":"# endpoint-aiops 0.7.0 - Removed the `skill-card.md` file. - No functional or feature changes were made to the skill itself.","fileCount":7,"zipByteSize":16311},{"version":"0.6.0","createdAt":"2026-07-21T09:40:40.771Z","changelog":"Version 0.6.0 - Added support for authentication to igel-ums dialects, including HTTP Basic login and session cookies. - Updated credential handling: credentials now use the scheme required by each target dialect (Bearer or Basic), not just static Bearer tokens. - Improved documentation for credential storage, management, and dialect-specific login requirements. - Removed skill-card.md file. - General doc refinements and bugfixes.","fileCount":7,"zipByteSize":16244}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:endpoint-aiops","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:endpoint-aiops` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/endpoint-aiops before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T14:46:12.408Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-endpoint-aiops/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:40:15.748Z","emptyReason":null},"readme":"Skill: endpoint-aiops\n\nOwner: zw008\n\nSummary: Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint). Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet. Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only). Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).\n\nTags: latest:0.10.3\n\nVersion history:\n\nv0.10.3 | 2026-09-15T05:54:58.702Z | auto\n\n- Removed the skill-card.md file from the project.\n- No changes to skill features, code, or user experience.\n- Documentation updated by removing a sample file.\n\nv0.10.2 | 2026-09-12T14:09:47.642Z | auto\n\n- Removed redundant skill metadata file (skill-card.md) for a cleaner package.\n- Updated installation instructions: OpenClaw plugin install now uses the @zw008 scope for endpoint-aiops.\n- No functional or toolset changes; documentation only.\n\nv0.10.1 | 2026-09-12T10:02:30.835Z | auto\n\n## endpoint-aiops v0.10.1\n\n- Added OpenClaw plugin install instructions and usage details to documentation.\n- Clarified that `uvx` is required on PATH when using as an OpenClaw plugin.\n- Removed the redundant `skill-card.md` file.\n- Minor updates for installation information and OpenClaw compatibility.\n\nv0.10.0 | 2026-09-12T00:51:06.996Z | auto\n\n- skill-card.md file removed\n- SKILL.md updated: metadata now uses anyBins and uvx, with simplified/updated environment and binary requirements\n- No changes to user-facing features or tool behavior\n- Internal compatibility and setup documentation refined\n\nv0.9.0 | 2026-08-10T06:50:30.666Z | auto\n\n# endpoint-aiops 0.9.0 Changelog\n\n- Removed the file: `skill-card.md`\n- No changes to core functionality or features\n- Documentation and skill metadata remain as before\n\nv0.8.0 | 2026-08-03T05:52:23.691Z | auto\n\n# endpoint-aiops 0.8.0 Changelog\n\n- Removed the documentation file `skill-card.md`.\n- No functional changes to the skill itself; only documentation cleanup.\n\nv0.7.0 | 2026-08-02T09:38:43.056Z | auto\n\n# endpoint-aiops 0.7.0\n\n- Removed the `skill-card.md` file.\n- No functional or feature changes were made to the skill itself.\n\nv0.6.0 | 2026-07-21T09:40:40.771Z | auto\n\nVersion 0.6.0\n\n- Added support for authentication to igel-ums dialects, including HTTP Basic login and session cookies.\n- Updated credential handling: credentials now use the scheme required by each target dialect (Bearer or Basic), not just static Bearer tokens.\n- Improved documentation for credential storage, management, and dialect-specific login requirements.\n- Removed skill-card.md file.\n- General doc refinements and bugfixes.\n\nv0.5.0 | 2026-07-20T11:14:50.699Z | auto\n\n- Major documentation update: the \"skill-card.md\" file has been removed.\n- The \"setup-guide.md\" reference file has been updated.\n- No changes to code or functionality; this release is focused on documentation cleanup and streamlining reference materials.\n\nv0.4.0 | 2026-07-19T03:50:56.340Z | auto\n\n**Endpoint AIops v0.4.0** — Significant update with new guardrails docs, tool count, and governance details.\n\n- Added comprehensive agent guardrails documentation (see `references/agent-guardrails.md`)\n- Increased total MCP tools governed to 13 (from 11), reflecting expanded capabilities\n- Improved governance and test status documentation (mock-based test suite, verification details in docs/VERIFICATION.md)\n- SKILL.md now follows a more concise, structured format, with clearer summary, versioning, and tool details\n- Deprecated and removed legacy `skill-card.md`\n- Updated references, CLI documentation, and setup guides for clarity and alignment with new governance features\n\nv0.3.0 | 2026-07-17T05:56:18.662Z | auto\n\n- Removed the sample file skill-card.md.\n- No functional changes to skill logic or features.\n- Documentation and existing features remain unchanged.\n\nv0.2.0 | 2026-07-13T13:09:34.153Z | auto\n\n**Adds per-endpoint health scoring, patch compliance, and risk-based fleet ranking.**\n\n- Added new composite per-endpoint health score and fleet risk ranking tools (`endpoint_health_score`, `patch_compliance`).\n- Expanded coverage from 9 to 11 governed MCP tools, including new read-only analysis features.\n- Updated descriptions and usage guidance to include \"which endpoints are worst,\" \"endpoint health score,\" and risk ranking scenarios.\n- Removed `skill-card.md` file as part of documentation cleanup.\n- Improved documentation for offline analysis and clarified tool injection/usage methods.\n\nv0.1.0 | 2026-07-12T03:06:21.482Z | auto\n\nInitial release of endpoint-aiops (preview).\n\n- Provides managed-endpoint fleet operations: health overview, endpoint inventory, session and login-storm analysis, drift reporting, and limited remediation actions.\n- All operations are governed with audit logging, policy/risk checks, undo/budget safeguards, and enforced API key encryption.\n- Write actions (assign-profile, reboot) require double confirmation and support dry runs; high-risk changes are reversible where possible.\n- No support for OT/industrial, hypervisor, storage, cluster, or network devices.\n- Currently mock-validated only—live endpoint-management server integration pending.\n\nArchive index:\n\nArchive v0.10.3: 7 files, 16351 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (2882b), SKILL.md (12766b), _meta.json (134b)\n\nFile v0.10.3:SKILL.md\n\n---\nname: endpoint-aiops\nslug: endpoint-aiops\ndisplayName: \"Endpoint AIops\"\nsummary: \"Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Endpoint-AIops\ntags: [aiops, mcp, governance, endpoint]\ndescription: >\n  Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint).\n  Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet.\n  Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only).\n  Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).\ninstaller:\n  kind: uv\n  package: endpoint-aiops\nargument-hint: \"[endpoint id or describe your fleet task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"endpoint-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"ENDPOINT_AIOPS_CONFIG\",\"ENDPOINT_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Endpoint-AIops\",\"emoji\":\"💻\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed managed-endpoint operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  All write operations are audited to a local SQLite DB under ~/.endpoint-aiops/ (relocatable via ENDPOINT_AIOPS_HOME).\n  Credentials: the endpoint-management server's API key is stored ENCRYPTED in ~/.endpoint-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'endpoint-aiops init' to onboard, or 'endpoint-aiops secret set <target>' to add one. The store is unlocked by a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var ENDPOINT_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'endpoint-aiops secret migrate'). The credential is presented using the scheme the target's dialect declares — a static Authorization: Bearer header for the generic dialect, or an HTTP Basic login yielding a session cookie for igel-ums (which also needs a 'username' on the target). It is held only in memory; credentials are never logged or echoed.\n  State-changing operations (assign-profile, reboot) require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label). endpoint_assign_profile is high-risk and reversible (captures the prior profile, records an inverse reassign undo descriptor); endpoint_reboot is medium-risk with no undo (a reboot has no safe inverse).\n  Webhooks: none — no outbound network calls beyond the configured endpoint-management REST API.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Verification status: the test suite is mock-based; the REST paths are modelled generically (/endpoints, /sessions, /version) and have not yet been exercised against a live server — docs/VERIFICATION.md defines the checklist.\n---\n\n# Endpoint AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any endpoint-management vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops) under the MIT license.\n\nGoverned managed-endpoint operations — **13 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.endpoint-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk tiers. The management-server API key is stored **encrypted** (`~/.endpoint-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n> **Standalone**: the governance harness is bundled in the package (`endpoint_aiops.governance`) — endpoint-aiops has no external skill-family dependency. The test suite is mock-based; a live management server has not yet been exercised (see `docs/VERIFICATION.md`).\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Overview** | fleet health overview | 1 | 1 read |\n| **Inventory** | endpoint list, get, health score | 3 | 3 read |\n| **Sessions** | session list, login-storm analysis | 2 | 2 read |\n| **Drift** | drift report, patch status, patch compliance | 3 | 3 read |\n| **Remediation** | assign profile (high) | 1 | 1 write |\n| | reboot (medium) | 1 | 1 write |\n\nThe analysis tools (`login_storm_analysis`, `drift_report`, `patch_status`, `patch_compliance`, `endpoint_health_score`) accept injected records for pure/offline analysis; `endpoint_health_score` and `patch_compliance` are injected-only, the others also pull live from a configured target.\n\n## Quick Install\n\n```bash\nuv tool install endpoint-aiops\nendpoint-aiops init       # interactive wizard: connection + encrypted API key\nendpoint-aiops doctor\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/endpoint-aiops\nopenclaw skills info endpoint-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Triage a fleet (`overview`): online/offline counts, stale endpoints, agent/patch spread\n- Rank the fleet by risk (`endpoint_health_score`): a composite 0-100 per-endpoint score, worst first, with every deduction cited\n- Diagnose a morning login storm (`session storm` / `login_storm_analysis`) and find the slowest login/boot contributors\n- Find endpoints drifted from the fleet baseline (`drift report`) or behind on patches (`drift patch`)\n- Assign a config profile to an endpoint (reversible) or reboot one (dry-run + double-confirm)\n\n**Do NOT use when** the target is OT/industrial equipment (use industrial-aiops), a hypervisor, a storage appliance, a backup product, a container cluster, or a network device.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Managed-endpoint fleet: login storms, drift, profiles | **endpoint-aiops** (this skill) |\n| OT / industrial edge (Modbus, OPC-UA, PLC, PROFINET) | the **industrial-aiops** line |\n| Hypervisor VM lifecycle (power, snapshot, migrate) | a hypervisor ops skill |\n| Container/cluster lifecycle | a cluster ops skill |\n\n## Common Workflows\n\n### \"Nobody can log in this morning\" — diagnose the 9am login storm\n\n1. `endpoint-aiops overview` → is this fleet-wide (offline/stale counts spiking) or confined to logins?\n2. `endpoint-aiops session storm --since-hours 12 --window-s 300 --min-concurrent 10` → storm episodes with peak concurrency and distinct users/endpoints, plus `slowestByLogin` / `slowestByBoot`\n3. `endpoint-aiops session list --since-hours 12` → inspect the raw sessions behind a suspicious episode (confirm the timestamps, don't trust the summary alone)\n4. `endpoint-aiops drift report` → cross-check the laggards; a stray agent version or divergent profile is a common cause of slow logins\n5. **Failure branch**: if `session storm` reports no episodes but users still complain, widen the window (`--window-s 900`) and lower `--min-concurrent` before concluding there is no storm; if the CLI errors on connectivity, run `endpoint-aiops doctor` first — the analysis is only as good as the session feed.\n\n### Bring a drifted endpoint back to the fleet baseline (reversible)\n\n1. `endpoint-aiops drift report` → the drifted endpoints and exactly which fields deviate from the fleet-majority baseline\n2. `endpoint-aiops endpoint get <id>` → confirm you are about to change the right device and note its current profile\n3. `endpoint-aiops endpoint assign-profile <id> <profile-id> --dry-run` → preview the exact `POST /endpoints/<id>/profile` call, changes nothing\n4. `endpoint-aiops endpoint assign-profile <id> <profile-id>` → double confirmation; `high` risk. The prior profile is captured and an inverse reassign undo descriptor is recorded\n5. **Failure branch**: if the endpoint misbehaves on the new profile, `endpoint-aiops undo list` then `endpoint-aiops undo apply <id>` restores the *captured* prior profile (not a guess); re-run `drift report` to confirm the fleet picture.\n\n### Patch-compliance sweep before a maintenance window\n\n1. `endpoint-aiops drift patch --target-patch 2024-06` → distribution of patch levels plus the endpoints behind the target\n2. `endpoint-aiops endpoint list` → resolve the behind-target ids to hostnames/owners for the change ticket\n3. `endpoint-aiops overview` → check how many of those are currently offline (an offline endpoint will not take the patch)\n4. Reboot a stuck endpoint that has staged its patch: `endpoint-aiops endpoint reboot <id> --dry-run`, then without `--dry-run` (double confirmation)\n5. **Failure branch**: `endpoint_reboot` is `medium` risk and declares **no undo** — a reboot has no safe inverse. If the endpoint does not come back, the audit record in `~/.endpoint-aiops/audit.db` holds its prior online state for the incident write-up; recovery is out-of-band (console/PXE), not via this tool.\n\n### Offline post-incident analysis (no live server)\n\n1. Export the incident's session and endpoint records from the management server into JSON\n2. Call the analysis tools with injected records — `login_storm_analysis(sessions=[...])`, `drift_report(endpoints=[...])`, `patch_compliance(endpoints=[...])`, `endpoint_health_score(endpoints=[...])` — no connection or credentials required\n3. `endpoint_health_score` returns a composite 0-100 per endpoint, worst first, with every deduction cited — use it to rank the remediation queue\n4. **Failure branch**: if a tool rejects the injected records, the export is missing fields the analysis needs (e.g. session start/login-duration, or endpoint patch level) — re-export rather than hand-patching the data, so the numbers stay traceable to the source.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the account you connect it with (a management-console account or API token\nscoped to a read-only role — writes then fail at the server). There is no\nread-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.endpoint-aiops/audit.db` (relocatable via `ENDPOINT_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `ENDPOINT_AUDIT_APPROVED_BY` / `ENDPOINT_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `ENDPOINT_RUNAWAY_MAX=0`.\n- Writes support `--dry-run` / `dry_run=True` and double confirmation at the CLI.\n- Reversible writes fetch the real before-state and record an inverse descriptor (`endpoint_assign_profile`→restore prior profile); the reboot (no safe inverse) records only the before-state.\n\n## References\n\n- `references/capabilities.md` — full tool + field reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, and connectivity\n\nFile v0.10.3:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"endpoint-aiops\",\n  \"version\": \"0.10.3\",\n  \"publishedAt\": 1789451698702\n}\n\nFile v0.10.3:references/agent-guardrails.md\n\n# Agent guardrails — running endpoint-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The account you connect with.** Give it a management-console account or API\n  token scoped to a read-only role. A write then fails at the server, which is\n  the only place the permission actually lives — no skill-side flag can be\n  argued around by a model, but a revoked permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.endpoint-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |\n| \"Don't invent a value when a field is missing\" | A field the management server did not return comes back as `null`, never as `\"\"`. An endpoint with no reported `patchLevel` is distinguishable from one reporting a blank level, and the key is always present. |\n| \"Tell me if the output was cut off\" | Every capped list is `{\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured against the full result, not guessed from the row count matching the limit. |\n| \"Give me the real totals, not just what you can see\" | Counts are computed over the whole fleet, never over the capped list: `driftedCount`, `behindCount`, `nonCompliantCount`, `stormCount`, and the health-score `summary` are all uncapped. `complianceRatePct` is likewise a whole-fleet figure. |\n| \"Explain why something was flagged\" | Every flag carries its number: each health-score deduction is cited in that endpoint's `reasons`, each drift row states `expected` vs `actual`, and `login_storm_analysis` returns the `thresholds` it used. |\n| \"Confirm before anything destructive\" | `endpoint assign-profile` and `endpoint reboot` require `--dry-run`-able preview + double confirmation at the CLI. |\n| \"Remember the previous profile so we can roll back\" | `endpoint_assign_profile` reads the endpoint's current profile *before* changing it and records an inverse undo token — the before-state is captured, never guessed. (A reboot has no safe inverse and honestly declares none.) |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a managed-endpoint fleet (thin clients / VDI / managed devices)\nthrough the endpoint-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current fleet, you MUST call a tool.\n  Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. A list arrives as\n  {\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": bool}; when\n  \"truncated\" is true, say so and re-run with a higher limit instead of\n  treating the partial list as the whole fleet.\n- Use the uncapped counts (driftedCount, behindCount, nonCompliantCount,\n  stormCount, summary) for \"how many\", and the items list only for \"which ones\".\n- A null field means the management server did not report that value. Report it\n  as \"not available\" — never infer a patch level, agent version, or hostname.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  patch levels, agent versions, profile ids, or hostnames.\n- A health score is advisory: it is 100 minus the deductions listed in that\n  endpoint's \"reasons\". Quote the reasons rather than restating the score alone.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a login-storm, drift, or patch-compliance problem unless a tool\n  result supports it — a storm is only a storm when an episode was returned.\n- A drift finding is an exact string mismatch against a baseline, and that\n  baseline may be the fleet majority rather than a declared gold image. Say\n  which (the payload tells you: baselineSource / targetSource).\n- Do not confuse an endpoint id with a hostname, or a profile id with either.\n- Do not add generic advice that does not follow from the tool output.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — a mistaken `endpoint_reboot` across a\nfleet is cheap to invoke and has no safe inverse:\n\n```bash\n# e.g. use a management-console account or API token with a read-only role. Then:\nendpoint-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport ENDPOINT_AUDIT_RATIONALE=\"scheduled patch window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer the analysis tools —\n  `overview`, `login_storm_analysis`, `drift_report`, `endpoint_health_score`\n  each do the multi-step correlation inside one call, so the model does not have\n  to chain reads and keep endpoint ids straight.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `--limit` deliberately rather than pulling a whole fleet\n  inventory into the context window.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.10.3:references/capabilities.md\n\n# endpoint-aiops capabilities\n\n> 13 MCP tools (10 read, 3 write). REST paths are modelled generically against\n> an endpoint-management API and have not yet been exercised live\n> (see docs/VERIFICATION.md).\n\n## Read tools (10)\n\n| Tool | REST path | Returns |\n|------|----------------|---------|\n| `overview` | `GET /endpoints` (fold) | total, online, offline, stale[], agentVersionSpread, patchLevelSpread |\n| `endpoint_list` | `GET /endpoints` | id, hostname, os, osBuild, agentVersion, patchLevel, profileId, online, lastSeenHours |\n| `endpoint_get` | `GET /endpoints/{id}` | single endpoint detail (normalised) |\n| `endpoint_health_score` | injected only | endpointsEvaluated, baseline{agentVersion,patchLevel,source}, summary{healthy,degraded,critical}, worst{items[]{endpoint,score,band,reasons[]},returned,limit,truncated}, note |\n| `session_list` | `GET /sessions?since_hours=` | endpoint, user, loginMs, bootMs, timestamp, result |\n| `login_storm_analysis` | `GET /sessions` or injected | stormCount, storms/slowestByLogin/slowestByBoot (each {items[],returned,limit,truncated}), slowLoginCount, failedLogins, thresholds |\n| `drift_report` | `GET /endpoints` or injected | baseline, driftByField, driftedEndpoints{items[],returned,limit,truncated}, drifted/compliant counts |\n| `patch_status` | `GET /endpoints` or injected | targetPatch, distribution, behind{items[],returned,limit,truncated}, behindCount |\n| `patch_compliance` | injected only | endpointsEvaluated, targetPatch, targetSource, slaTargetPct, complianceRatePct, compliantCount, verdict, nonCompliantCount, nonCompliant{items[],returned,limit,truncated}, note |\n| `undo_list` | local undo store | recorded, not-yet-applied reversible writes: undos[]{undoId, ts, originalTool, inverseTool, note}, returned, limit, truncated |\n\nThe analysis tools accept an injected `sessions=` / `endpoints=` list for\npure/offline analysis. `login_storm_analysis`, `drift_report` and `patch_status`\nalso pull live from a configured `target`; `endpoint_health_score` and\n`patch_compliance` are injected-only (they score rows you already hold, e.g.\nfrom `endpoint_list`).\n\n## Write tools (3)\n\n| Tool | Risk | REST path | Undo / safety |\n|------|------|----------------|---------------|\n| `endpoint_assign_profile` | **high** | `POST /endpoints/{id}/profile` | captures the prior profile; records an inverse \"reassign prior profile\" undo descriptor; CLI double-confirm + dry-run |\n| `endpoint_reboot` | medium | `POST /endpoints/{id}/reboot` | captures prior online state; no safe inverse, no undo; CLI double-confirm + dry-run |\n| `undo_apply` | medium | local undo store → inverse tool | executes a recorded inverse; the inverse runs through its own governed tool (its real risk tier is recorded there); single-use token; supports `dry_run` |\n\n## Out of scope (by design)\n\n- Endpoint **enrollment / de-enrollment**\n- Image / OTA / firmware push\n- Profile CRUD (create/delete config profiles) and user/group management\n- OT / industrial equipment (use the `industrial-aiops` line)\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n\n## Two payload conventions worth knowing\n\n**Absent is not empty.** A field the management server did not report comes back\nas `null`, never as `\"\"`. The key is always present, so \"the server had no value\nfor this\" is visible rather than inferred.\n\n**Capped lists announce themselves.** Every list that a `limit` can cut short is\na truncation envelope:\n\n```json\n{\"items\": [...], \"returned\": 25, \"limit\": 25, \"truncated\": true}\n```\n\n`truncated` is measured against the full result, not guessed from the returned\ncount matching the limit. When it is `true`, re-run with a higher `limit`.\nCompanion totals (`driftedCount`, `behindCount`, `stormCount`,\n`nonCompliantCount`, the health `summary`) are always the full, uncapped\nfigures.\n\nFile v0.10.3:references/cli-reference.md\n\n# endpoint-aiops CLI reference\n\n> REST paths are modelled generically against an endpoint-management API and\n> have not yet been exercised live (see docs/VERIFICATION.md).\n\n## Setup & diagnostics\n\n```bash\nendpoint-aiops init                      # interactive onboarding wizard\nendpoint-aiops doctor [--skip-auth]      # config + secret store + connectivity (/version)\nendpoint-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n## Secrets (encrypted store ~/.endpoint-aiops/secrets.enc)\n\n```bash\nendpoint-aiops secret set <target> [--value <key>]   # store API key (hidden prompt if no --value)\nendpoint-aiops secret list                            # names only — values never shown\nendpoint-aiops secret rm <target>\nendpoint-aiops secret migrate                         # import legacy plaintext .env (ENDPOINT_<T>_APIKEY)\nendpoint-aiops secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Read commands\n\n```bash\nendpoint-aiops overview [--target <t>]        # online/offline, stale endpoints, agent/patch spread\nendpoint-aiops endpoint list                  # all managed endpoints\nendpoint-aiops endpoint get <endpoint_id>     # one endpoint detail\nendpoint-aiops session list [--since-hours 24]           # recent login/boot sessions\nendpoint-aiops session storm [--since-hours 24] [--window-s 300] [--min-concurrent 10]\nendpoint-aiops drift report                   # endpoints drifted from the fleet-majority baseline\nendpoint-aiops drift patch [--target-patch <level>]      # patch-level distribution + who's behind\n```\n\n## Write commands (governed; risk tier in parentheses)\n\n```bash\nendpoint-aiops endpoint assign-profile <endpoint_id> <profile_id> [--dry-run]   # (high) reversible; double confirm\nendpoint-aiops endpoint reboot <endpoint_id> [--dry-run]                        # (medium) no undo; double confirm\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- State-changing commands (`endpoint assign-profile`, `endpoint reboot`) require two confirmations\n\nFile v0.10.3:references/setup-guide.md\n\n# endpoint-aiops setup & security guide\n\n> Not yet exercised against a live endpoint-management server (see docs/VERIFICATION.md).\n\n## 1. Install\n\n```bash\nuv tool install endpoint-aiops\n```\n\n## 2. Create credentials — the shape depends on the dialect\n\nThe target's **dialect** decides the port, the API base path *and* how to\nauthenticate, so create the credential the dialect expects:\n\n**`generic` (default) — a static API key.** In your endpoint-management\nserver's web UI, create an API key (usually under a Credentials / API Keys\nsection). It is sent as `Authorization: Bearer <key>` against the REST API base\n`<scheme>://<host>:<port><api_path>`.\n\n**`igel-ums` — a UMS administrator account.** IMI does not accept a static\nBearer token; it logs in with HTTP Basic at `POST /umsapi/v3/login` and then\ncarries the returned `JSESSIONID` cookie. So an `igel-ums` target needs a\n`username:` in `config.yaml` plus that account's **password** in the encrypted\nstore — not an API key. No gateway or auth adapter is needed.\n\n⚠️ Give that account at least **Read/Browse permission at the Devices level**.\nWith fewer permissions IMI returns **empty lists rather than an error**, so an\nunder-privileged account looks exactly like an empty fleet. `endpoint-aiops\ndoctor` warns when a successful login returns no endpoints — do not dismiss it.\n\n⚠️ The `igel-ums` dialect is **documented but not live-verified** (IGEL UMS has\nno free edition). See `docs/VERIFICATION.md` in the repository.\n\n## 3. Onboard\n\n```bash\nendpoint-aiops init\n```\n\nThe wizard collects (non-secret) connection details into\n`~/.endpoint-aiops/config.yaml` and stores the API key **encrypted** into\n`~/.endpoint-aiops/secrets.enc`. Example config:\n\n```yaml\ntargets:\n  - name: ums1\n    host: 10.0.0.30\n    dialect: igel-ums          # sets IMI paths + port 8443 + /umsapi/v3\n    scheme: https              # 'http' for a reverse-proxied server\n    verify_ssl: false          # self-signed lab certs only\n```\n\nThe wizard asks which **dialect** to use and prints the one it configured.\n`generic` (the default) is a neutral placeholder — `/api/v2.0` on 443 — that no\nshipped management server actually serves; it is only useful once you describe\nyour server's paths in a `dialect:` block. `igel-ums` targets IGEL UMS via IMI\nand is **modelled from vendor documentation, not live-verified**.\n\n`port` and `api_path` are still accepted and win over the dialect's defaults\nwhen you set them.\n\n## 4. Non-interactive use (MCP server / CI / cron)\n\nExport the master password so the encrypted store can be unlocked without a\nprompt:\n\n```bash\nexport ENDPOINT_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Credential security\n\n- The API key is **never** written to disk in plaintext. It lives only in\n  `~/.endpoint-aiops/secrets.enc`, encrypted with Fernet (AES-128-CBC + HMAC),\n  the key derived from your master password via scrypt. Only a per-store random\n  salt and the ciphertext are on disk (chmod 600); the master password itself is\n  never stored.\n- A legacy plaintext env var `ENDPOINT_<TARGET_NAME_UPPER>_APIKEY` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `endpoint-aiops secret migrate` (it imports then renames the old `.env`).\n- The key is held only in memory during a session and is never logged or echoed;\n  exception text and tracebacks are scrubbed of secret-shaped strings before\n  being written to the audit log.\n\n## Audit-annotation env vars (optional)\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement or the connecting account's role. If you want the audit trail to\nrecord *who* ran a destructive op and *why*, set these; they are recorded on the\nrow, never required, and gate nothing:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY='you@example.com'\nexport ENDPOINT_AUDIT_RATIONALE='why this destructive op is justified'\n```\n\n## Governance harness state\n\nState lives under `~/.endpoint-aiops/` (relocate with `ENDPOINT_AIOPS_HOME`):\n\n- `audit.db` — every tool call (SQLite), with risk tier and any approver/rationale\n- `undo.db` — inverse descriptors for reversible writes (e.g. `endpoint_assign_profile`)\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops\n\n## Verify\n\n```bash\nendpoint-aiops doctor\n```\n\n`doctor` checks the config file, the encrypted store and its permissions,\nthat an API key is present per target, and (unless `--skip-auth`) connectivity\nby hitting `/version`.\n\nFile v0.10.3:skill-card.md\n\n## Description:\n\nEndpoint AIops helps agents operate managed-endpoint fleets by producing fleet health summaries, inventory views, login and boot session analysis, drift and patch reports, endpoint health rankings, and guarded remediation guidance.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, endpoint administrators, and operations engineers use this skill to inspect managed-endpoint fleet health, diagnose login storms or drift, rank endpoints by risk, and prepare controlled endpoint remediation actions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can reboot or reconfigure managed endpoints without a tool-enforced approval gate.\n\nMitigation: Use read-only or tightly scoped management credentials by default, require operator review before write tools, and prefer dry-run previews before any endpoint change.\n\nRisk: The skill relies on sensitive endpoint-management credentials and may run in non-interactive MCP or CI contexts.\n\nMitigation: Keep HTTPS certificate verification enabled, avoid exporting the master password unless needed, and protect the encrypted credential store and local state directory.\n\nRisk: The security review notes an unpinned external package and recommends review before installation.\n\nMitigation: Review the endpoint-aiops package source and exact version that will run before installing or enabling the skill.\n\nRisk: The artifact says live endpoint-management server testing has not yet been completed.\n\nMitigation: Validate connectivity and representative read/write workflows in a controlled environment before using the skill against production fleets.\n\n## Reference(s):\n\n- [endpoint-aiops capabilities](references/capabilities.md)\n- [endpoint-aiops CLI reference](references/cli-reference.md)\n- [endpoint-aiops setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n- [Project homepage](https://github.com/AIops-tools/Endpoint-AIops)\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/endpoint-aiops)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and structured tool-result summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include capped fleet lists, endpoint risk summaries, audit and undo guidance, and dry-run remediation steps.]\n\n## Skill Version(s):\n\n0.10.3 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.2: 7 files, 16395 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (2932b), SKILL.md (12766b), _meta.json (134b)\n\nFile v0.10.2:SKILL.md\n\n---\nname: endpoint-aiops\nslug: endpoint-aiops\ndisplayName: \"Endpoint AIops\"\nsummary: \"Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Endpoint-AIops\ntags: [aiops, mcp, governance, endpoint]\ndescription: >\n  Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint).\n  Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet.\n  Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only).\n  Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).\ninstaller:\n  kind: uv\n  package: endpoint-aiops\nargument-hint: \"[endpoint id or describe your fleet task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"endpoint-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"ENDPOINT_AIOPS_CONFIG\",\"ENDPOINT_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Endpoint-AIops\",\"emoji\":\"💻\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed managed-endpoint operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  All write operations are audited to a local SQLite DB under ~/.endpoint-aiops/ (relocatable via ENDPOINT_AIOPS_HOME).\n  Credentials: the endpoint-management server's API key is stored ENCRYPTED in ~/.endpoint-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'endpoint-aiops init' to onboard, or 'endpoint-aiops secret set <target>' to add one. The store is unlocked by a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var ENDPOINT_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'endpoint-aiops secret migrate'). The credential is presented using the scheme the target's dialect declares — a static Authorization: Bearer header for the generic dialect, or an HTTP Basic login yielding a session cookie for igel-ums (which also needs a 'username' on the target). It is held only in memory; credentials are never logged or echoed.\n  State-changing operations (assign-profile, reboot) require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label). endpoint_assign_profile is high-risk and reversible (captures the prior profile, records an inverse reassign undo descriptor); endpoint_reboot is medium-risk with no undo (a reboot has no safe inverse).\n  Webhooks: none — no outbound network calls beyond the configured endpoint-management REST API.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Verification status: the test suite is mock-based; the REST paths are modelled generically (/endpoints, /sessions, /version) and have not yet been exercised against a live server — docs/VERIFICATION.md defines the checklist.\n---\n\n# Endpoint AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any endpoint-management vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops) under the MIT license.\n\nGoverned managed-endpoint operations — **13 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.endpoint-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk tiers. The management-server API key is stored **encrypted** (`~/.endpoint-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n> **Standalone**: the governance harness is bundled in the package (`endpoint_aiops.governance`) — endpoint-aiops has no external skill-family dependency. The test suite is mock-based; a live management server has not yet been exercised (see `docs/VERIFICATION.md`).\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Overview** | fleet health overview | 1 | 1 read |\n| **Inventory** | endpoint list, get, health score | 3 | 3 read |\n| **Sessions** | session list, login-storm analysis | 2 | 2 read |\n| **Drift** | drift report, patch status, patch compliance | 3 | 3 read |\n| **Remediation** | assign profile (high) | 1 | 1 write |\n| | reboot (medium) | 1 | 1 write |\n\nThe analysis tools (`login_storm_analysis`, `drift_report`, `patch_status`, `patch_compliance`, `endpoint_health_score`) accept injected records for pure/offline analysis; `endpoint_health_score` and `patch_compliance` are injected-only, the others also pull live from a configured target.\n\n## Quick Install\n\n```bash\nuv tool install endpoint-aiops\nendpoint-aiops init       # interactive wizard: connection + encrypted API key\nendpoint-aiops doctor\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/endpoint-aiops\nopenclaw skills info endpoint-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Triage a fleet (`overview`): online/offline counts, stale endpoints, agent/patch spread\n- Rank the fleet by risk (`endpoint_health_score`): a composite 0-100 per-endpoint score, worst first, with every deduction cited\n- Diagnose a morning login storm (`session storm` / `login_storm_analysis`) and find the slowest login/boot contributors\n- Find endpoints drifted from the fleet baseline (`drift report`) or behind on patches (`drift patch`)\n- Assign a config profile to an endpoint (reversible) or reboot one (dry-run + double-confirm)\n\n**Do NOT use when** the target is OT/industrial equipment (use industrial-aiops), a hypervisor, a storage appliance, a backup product, a container cluster, or a network device.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Managed-endpoint fleet: login storms, drift, profiles | **endpoint-aiops** (this skill) |\n| OT / industrial edge (Modbus, OPC-UA, PLC, PROFINET) | the **industrial-aiops** line |\n| Hypervisor VM lifecycle (power, snapshot, migrate) | a hypervisor ops skill |\n| Container/cluster lifecycle | a cluster ops skill |\n\n## Common Workflows\n\n### \"Nobody can log in this morning\" — diagnose the 9am login storm\n\n1. `endpoint-aiops overview` → is this fleet-wide (offline/stale counts spiking) or confined to logins?\n2. `endpoint-aiops session storm --since-hours 12 --window-s 300 --min-concurrent 10` → storm episodes with peak concurrency and distinct users/endpoints, plus `slowestByLogin` / `slowestByBoot`\n3. `endpoint-aiops session list --since-hours 12` → inspect the raw sessions behind a suspicious episode (confirm the timestamps, don't trust the summary alone)\n4. `endpoint-aiops drift report` → cross-check the laggards; a stray agent version or divergent profile is a common cause of slow logins\n5. **Failure branch**: if `session storm` reports no episodes but users still complain, widen the window (`--window-s 900`) and lower `--min-concurrent` before concluding there is no storm; if the CLI errors on connectivity, run `endpoint-aiops doctor` first — the analysis is only as good as the session feed.\n\n### Bring a drifted endpoint back to the fleet baseline (reversible)\n\n1. `endpoint-aiops drift report` → the drifted endpoints and exactly which fields deviate from the fleet-majority baseline\n2. `endpoint-aiops endpoint get <id>` → confirm you are about to change the right device and note its current profile\n3. `endpoint-aiops endpoint assign-profile <id> <profile-id> --dry-run` → preview the exact `POST /endpoints/<id>/profile` call, changes nothing\n4. `endpoint-aiops endpoint assign-profile <id> <profile-id>` → double confirmation; `high` risk. The prior profile is captured and an inverse reassign undo descriptor is recorded\n5. **Failure branch**: if the endpoint misbehaves on the new profile, `endpoint-aiops undo list` then `endpoint-aiops undo apply <id>` restores the *captured* prior profile (not a guess); re-run `drift report` to confirm the fleet picture.\n\n### Patch-compliance sweep before a maintenance window\n\n1. `endpoint-aiops drift patch --target-patch 2024-06` → distribution of patch levels plus the endpoints behind the target\n2. `endpoint-aiops endpoint list` → resolve the behind-target ids to hostnames/owners for the change ticket\n3. `endpoint-aiops overview` → check how many of those are currently offline (an offline endpoint will not take the patch)\n4. Reboot a stuck endpoint that has staged its patch: `endpoint-aiops endpoint reboot <id> --dry-run`, then without `--dry-run` (double confirmation)\n5. **Failure branch**: `endpoint_reboot` is `medium` risk and declares **no undo** — a reboot has no safe inverse. If the endpoint does not come back, the audit record in `~/.endpoint-aiops/audit.db` holds its prior online state for the incident write-up; recovery is out-of-band (console/PXE), not via this tool.\n\n### Offline post-incident analysis (no live server)\n\n1. Export the incident's session and endpoint records from the management server into JSON\n2. Call the analysis tools with injected records — `login_storm_analysis(sessions=[...])`, `drift_report(endpoints=[...])`, `patch_compliance(endpoints=[...])`, `endpoint_health_score(endpoints=[...])` — no connection or credentials required\n3. `endpoint_health_score` returns a composite 0-100 per endpoint, worst first, with every deduction cited — use it to rank the remediation queue\n4. **Failure branch**: if a tool rejects the injected records, the export is missing fields the analysis needs (e.g. session start/login-duration, or endpoint patch level) — re-export rather than hand-patching the data, so the numbers stay traceable to the source.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the account you connect it with (a management-console account or API token\nscoped to a read-only role — writes then fail at the server). There is no\nread-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.endpoint-aiops/audit.db` (relocatable via `ENDPOINT_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `ENDPOINT_AUDIT_APPROVED_BY` / `ENDPOINT_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `ENDPOINT_RUNAWAY_MAX=0`.\n- Writes support `--dry-run` / `dry_run=True` and double confirmation at the CLI.\n- Reversible writes fetch the real before-state and record an inverse descriptor (`endpoint_assign_profile`→restore prior profile); the reboot (no safe inverse) records only the before-state.\n\n## References\n\n- `references/capabilities.md` — full tool + field reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, and connectivity\n\nFile v0.10.2:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"endpoint-aiops\",\n  \"version\": \"0.10.2\",\n  \"publishedAt\": 1789222187642\n}\n\nFile v0.10.2:references/agent-guardrails.md\n\n# Agent guardrails — running endpoint-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The account you connect with.** Give it a management-console account or API\n  token scoped to a read-only role. A write then fails at the server, which is\n  the only place the permission actually lives — no skill-side flag can be\n  argued around by a model, but a revoked permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.endpoint-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |\n| \"Don't invent a value when a field is missing\" | A field the management server did not return comes back as `null`, never as `\"\"`. An endpoint with no reported `patchLevel` is distinguishable from one reporting a blank level, and the key is always present. |\n| \"Tell me if the output was cut off\" | Every capped list is `{\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured against the full result, not guessed from the row count matching the limit. |\n| \"Give me the real totals, not just what you can see\" | Counts are computed over the whole fleet, never over the capped list: `driftedCount`, `behindCount`, `nonCompliantCount`, `stormCount`, and the health-score `summary` are all uncapped. `complianceRatePct` is likewise a whole-fleet figure. |\n| \"Explain why something was flagged\" | Every flag carries its number: each health-score deduction is cited in that endpoint's `reasons`, each drift row states `expected` vs `actual`, and `login_storm_analysis` returns the `thresholds` it used. |\n| \"Confirm before anything destructive\" | `endpoint assign-profile` and `endpoint reboot` require `--dry-run`-able preview + double confirmation at the CLI. |\n| \"Remember the previous profile so we can roll back\" | `endpoint_assign_profile` reads the endpoint's current profile *before* changing it and records an inverse undo token — the before-state is captured, never guessed. (A reboot has no safe inverse and honestly declares none.) |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a managed-endpoint fleet (thin clients / VDI / managed devices)\nthrough the endpoint-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current fleet, you MUST call a tool.\n  Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. A list arrives as\n  {\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": bool}; when\n  \"truncated\" is true, say so and re-run with a higher limit instead of\n  treating the partial list as the whole fleet.\n- Use the uncapped counts (driftedCount, behindCount, nonCompliantCount,\n  stormCount, summary) for \"how many\", and the items list only for \"which ones\".\n- A null field means the management server did not report that value. Report it\n  as \"not available\" — never infer a patch level, agent version, or hostname.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  patch levels, agent versions, profile ids, or hostnames.\n- A health score is advisory: it is 100 minus the deductions listed in that\n  endpoint's \"reasons\". Quote the reasons rather than restating the score alone.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a login-storm, drift, or patch-compliance problem unless a tool\n  result supports it — a storm is only a storm when an episode was returned.\n- A drift finding is an exact string mismatch against a baseline, and that\n  baseline may be the fleet majority rather than a declared gold image. Say\n  which (the payload tells you: baselineSource / targetSource).\n- Do not confuse an endpoint id with a hostname, or a profile id with either.\n- Do not add generic advice that does not follow from the tool output.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — a mistaken `endpoint_reboot` across a\nfleet is cheap to invoke and has no safe inverse:\n\n```bash\n# e.g. use a management-console account or API token with a read-only role. Then:\nendpoint-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport ENDPOINT_AUDIT_RATIONALE=\"scheduled patch window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer the analysis tools —\n  `overview`, `login_storm_analysis`, `drift_report`, `endpoint_health_score`\n  each do the multi-step correlation inside one call, so the model does not have\n  to chain reads and keep endpoint ids straight.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `--limit` deliberately rather than pulling a whole fleet\n  inventory into the context window.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.10.2:references/capabilities.md\n\n# endpoint-aiops capabilities\n\n> 13 MCP tools (10 read, 3 write). REST paths are modelled generically against\n> an endpoint-management API and have not yet been exercised live\n> (see docs/VERIFICATION.md).\n\n## Read tools (10)\n\n| Tool | REST path | Returns |\n|------|----------------|---------|\n| `overview` | `GET /endpoints` (fold) | total, online, offline, stale[], agentVersionSpread, patchLevelSpread |\n| `endpoint_list` | `GET /endpoints` | id, hostname, os, osBuild, agentVersion, patchLevel, profileId, online, lastSeenHours |\n| `endpoint_get` | `GET /endpoints/{id}` | single endpoint detail (normalised) |\n| `endpoint_health_score` | injected only | endpointsEvaluated, baseline{agentVersion,patchLevel,source}, summary{healthy,degraded,critical}, worst{items[]{endpoint,score,band,reasons[]},returned,limit,truncated}, note |\n| `session_list` | `GET /sessions?since_hours=` | endpoint, user, loginMs, bootMs, timestamp, result |\n| `login_storm_analysis` | `GET /sessions` or injected | stormCount, storms/slowestByLogin/slowestByBoot (each {items[],returned,limit,truncated}), slowLoginCount, failedLogins, thresholds |\n| `drift_report` | `GET /endpoints` or injected | baseline, driftByField, driftedEndpoints{items[],returned,limit,truncated}, drifted/compliant counts |\n| `patch_status` | `GET /endpoints` or injected | targetPatch, distribution, behind{items[],returned,limit,truncated}, behindCount |\n| `patch_compliance` | injected only | endpointsEvaluated, targetPatch, targetSource, slaTargetPct, complianceRatePct, compliantCount, verdict, nonCompliantCount, nonCompliant{items[],returned,limit,truncated}, note |\n| `undo_list` | local undo store | recorded, not-yet-applied reversible writes: undos[]{undoId, ts, originalTool, inverseTool, note}, returned, limit, truncated |\n\nThe analysis tools accept an injected `sessions=` / `endpoints=` list for\npure/offline analysis. `login_storm_analysis`, `drift_report` and `patch_status`\nalso pull live from a configured `target`; `endpoint_health_score` and\n`patch_compliance` are injected-only (they score rows you already hold, e.g.\nfrom `endpoint_list`).\n\n## Write tools (3)\n\n| Tool | Risk | REST path | Undo / safety |\n|------|------|----------------|---------------|\n| `endpoint_assign_profile` | **high** | `POST /endpoints/{id}/profile` | captures the prior profile; records an inverse \"reassign prior profile\" undo descriptor; CLI double-confirm + dry-run |\n| `endpoint_reboot` | medium | `POST /endpoints/{id}/reboot` | captures prior online state; no safe inverse, no undo; CLI double-confirm + dry-run |\n| `undo_apply` | medium | local undo store → inverse tool | executes a recorded inverse; the inverse runs through its own governed tool (its real risk tier is recorded there); single-use token; supports `dry_run` |\n\n## Out of scope (by design)\n\n- Endpoint **enrollment / de-enrollment**\n- Image / OTA / firmware push\n- Profile CRUD (create/delete config profiles) and user/group management\n- OT / industrial equipment (use the `industrial-aiops` line)\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n\n## Two payload conventions worth knowing\n\n**Absent is not empty.** A field the management server did not report comes back\nas `null`, never as `\"\"`. The key is always present, so \"the server had no value\nfor this\" is visible rather than inferred.\n\n**Capped lists announce themselves.** Every list that a `limit` can cut short is\na truncation envelope:\n\n```json\n{\"items\": [...], \"returned\": 25, \"limit\": 25, \"truncated\": true}\n```\n\n`truncated` is measured against the full result, not guessed from the returned\ncount matching the limit. When it is `true`, re-run with a higher `limit`.\nCompanion totals (`driftedCount`, `behindCount`, `stormCount`,\n`nonCompliantCount`, the health `summary`) are always the full, uncapped\nfigures.\n\nFile v0.10.2:references/cli-reference.md\n\n# endpoint-aiops CLI reference\n\n> REST paths are modelled generically against an endpoint-management API and\n> have not yet been exercised live (see docs/VERIFICATION.md).\n\n## Setup & diagnostics\n\n```bash\nendpoint-aiops init                      # interactive onboarding wizard\nendpoint-aiops doctor [--skip-auth]      # config + secret store + connectivity (/version)\nendpoint-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n## Secrets (encrypted store ~/.endpoint-aiops/secrets.enc)\n\n```bash\nendpoint-aiops secret set <target> [--value <key>]   # store API key (hidden prompt if no --value)\nendpoint-aiops secret list                            # names only — values never shown\nendpoint-aiops secret rm <target>\nendpoint-aiops secret migrate                         # import legacy plaintext .env (ENDPOINT_<T>_APIKEY)\nendpoint-aiops secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Read commands\n\n```bash\nendpoint-aiops overview [--target <t>]        # online/offline, stale endpoints, agent/patch spread\nendpoint-aiops endpoint list                  # all managed endpoints\nendpoint-aiops endpoint get <endpoint_id>     # one endpoint detail\nendpoint-aiops session list [--since-hours 24]           # recent login/boot sessions\nendpoint-aiops session storm [--since-hours 24] [--window-s 300] [--min-concurrent 10]\nendpoint-aiops drift report                   # endpoints drifted from the fleet-majority baseline\nendpoint-aiops drift patch [--target-patch <level>]      # patch-level distribution + who's behind\n```\n\n## Write commands (governed; risk tier in parentheses)\n\n```bash\nendpoint-aiops endpoint assign-profile <endpoint_id> <profile_id> [--dry-run]   # (high) reversible; double confirm\nendpoint-aiops endpoint reboot <endpoint_id> [--dry-run]                        # (medium) no undo; double confirm\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- State-changing commands (`endpoint assign-profile`, `endpoint reboot`) require two confirmations\n\nFile v0.10.2:references/setup-guide.md\n\n# endpoint-aiops setup & security guide\n\n> Not yet exercised against a live endpoint-management server (see docs/VERIFICATION.md).\n\n## 1. Install\n\n```bash\nuv tool install endpoint-aiops\n```\n\n## 2. Create credentials — the shape depends on the dialect\n\nThe target's **dialect** decides the port, the API base path *and* how to\nauthenticate, so create the credential the dialect expects:\n\n**`generic` (default) — a static API key.** In your endpoint-management\nserver's web UI, create an API key (usually under a Credentials / API Keys\nsection). It is sent as `Authorization: Bearer <key>` against the REST API base\n`<scheme>://<host>:<port><api_path>`.\n\n**`igel-ums` — a UMS administrator account.** IMI does not accept a static\nBearer token; it logs in with HTTP Basic at `POST /umsapi/v3/login` and then\ncarries the returned `JSESSIONID` cookie. So an `igel-ums` target needs a\n`username:` in `config.yaml` plus that account's **password** in the encrypted\nstore — not an API key. No gateway or auth adapter is needed.\n\n⚠️ Give that account at least **Read/Browse permission at the Devices level**.\nWith fewer permissions IMI returns **empty lists rather than an error**, so an\nunder-privileged account looks exactly like an empty fleet. `endpoint-aiops\ndoctor` warns when a successful login returns no endpoints — do not dismiss it.\n\n⚠️ The `igel-ums` dialect is **documented but not live-verified** (IGEL UMS has\nno free edition). See `docs/VERIFICATION.md` in the repository.\n\n## 3. Onboard\n\n```bash\nendpoint-aiops init\n```\n\nThe wizard collects (non-secret) connection details into\n`~/.endpoint-aiops/config.yaml` and stores the API key **encrypted** into\n`~/.endpoint-aiops/secrets.enc`. Example config:\n\n```yaml\ntargets:\n  - name: ums1\n    host: 10.0.0.30\n    dialect: igel-ums          # sets IMI paths + port 8443 + /umsapi/v3\n    scheme: https              # 'http' for a reverse-proxied server\n    verify_ssl: false          # self-signed lab certs only\n```\n\nThe wizard asks which **dialect** to use and prints the one it configured.\n`generic` (the default) is a neutral placeholder — `/api/v2.0` on 443 — that no\nshipped management server actually serves; it is only useful once you describe\nyour server's paths in a `dialect:` block. `igel-ums` targets IGEL UMS via IMI\nand is **modelled from vendor documentation, not live-verified**.\n\n`port` and `api_path` are still accepted and win over the dialect's defaults\nwhen you set them.\n\n## 4. Non-interactive use (MCP server / CI / cron)\n\nExport the master password so the encrypted store can be unlocked without a\nprompt:\n\n```bash\nexport ENDPOINT_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Credential security\n\n- The API key is **never** written to disk in plaintext. It lives only in\n  `~/.endpoint-aiops/secrets.enc`, encrypted with Fernet (AES-128-CBC + HMAC),\n  the key derived from your master password via scrypt. Only a per-store random\n  salt and the ciphertext are on disk (chmod 600); the master password itself is\n  never stored.\n- A legacy plaintext env var `ENDPOINT_<TARGET_NAME_UPPER>_APIKEY` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `endpoint-aiops secret migrate` (it imports then renames the old `.env`).\n- The key is held only in memory during a session and is never logged or echoed;\n  exception text and tracebacks are scrubbed of secret-shaped strings before\n  being written to the audit log.\n\n## Audit-annotation env vars (optional)\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement or the connecting account's role. If you want the audit trail to\nrecord *who* ran a destructive op and *why*, set these; they are recorded on the\nrow, never required, and gate nothing:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY='you@example.com'\nexport ENDPOINT_AUDIT_RATIONALE='why this destructive op is justified'\n```\n\n## Governance harness state\n\nState lives under `~/.endpoint-aiops/` (relocate with `ENDPOINT_AIOPS_HOME`):\n\n- `audit.db` — every tool call (SQLite), with risk tier and any approver/rationale\n- `undo.db` — inverse descriptors for reversible writes (e.g. `endpoint_assign_profile`)\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops\n\n## Verify\n\n```bash\nendpoint-aiops doctor\n```\n\n`doctor` checks the config file, the encrypted store and its permissions,\nthat an API key is present per target, and (unless `--skip-auth`) connectivity\nby hitting `/version`.\n\nFile v0.10.2:skill-card.md\n\n## Description:\n\nEndpoint AIops helps agents operate managed endpoint fleets by gathering fleet health, inventory, login and boot sessions, login-storm analysis, drift and patch reports, and guarded profile assignment or reboot actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and endpoint operations teams use this skill to triage thin-client, VDI, or centrally managed endpoint fleets, diagnose login storms and drift, and prepare governed remediation actions such as profile assignment or reboot.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can reboot endpoints and change configuration profiles through an external endpoint-management package.\n\nMitigation: Use a read-only management account by default, enable write-capable credentials only for deliberate maintenance, and preview state-changing actions with dry-run before execution.\n\nRisk: The connected endpoint-management account determines whether writes are permitted; the skill does not provide its own read-only authorization gate.\n\nMitigation: Enforce least privilege on the management server account and use the agent prompt or operating procedure to restrict write tools during observe-only sessions.\n\nRisk: Legacy plaintext API-key environment variables are still honored as a fallback.\n\nMitigation: Prefer the encrypted secret store, avoid plaintext legacy environment variables, and migrate existing legacy secrets before production use.\n\nRisk: The artifact states that REST paths are modeled generically and have not yet been exercised against a live management server.\n\nMitigation: Validate connectivity and behavior against a non-production endpoint-management server before relying on results or remediation actions in production.\n\n## Reference(s):\n\n- [Endpoint AIops repository](https://github.com/AIops-tools/Endpoint-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and structured tool-result summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can include capped-list metadata, fleet counts, health scoring reasons, dry-run previews, and audit or undo references when supported by the tool.]\n\n## Skill Version(s):\n\n0.10.2 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.1: 7 files, 16397 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (2953b), SKILL.md (12772b), _meta.json (134b)\n\nFile v0.10.1:SKILL.md\n\n---\nname: endpoint-aiops\nslug: endpoint-aiops\ndisplayName: \"Endpoint AIops\"\nsummary: \"Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Endpoint-AIops\ntags: [aiops, mcp, governance, endpoint]\ndescription: >\n  Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint).\n  Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet.\n  Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only).\n  Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).\ninstaller:\n  kind: uv\n  package: endpoint-aiops\nargument-hint: \"[endpoint id or describe your fleet task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"endpoint-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"ENDPOINT_AIOPS_CONFIG\",\"ENDPOINT_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Endpoint-AIops\",\"emoji\":\"💻\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed managed-endpoint operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  All write operations are audited to a local SQLite DB under ~/.endpoint-aiops/ (relocatable via ENDPOINT_AIOPS_HOME).\n  Credentials: the endpoint-management server's API key is stored ENCRYPTED in ~/.endpoint-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'endpoint-aiops init' to onboard, or 'endpoint-aiops secret set <target>' to add one. The store is unlocked by a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var ENDPOINT_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'endpoint-aiops secret migrate'). The credential is presented using the scheme the target's dialect declares — a static Authorization: Bearer header for the generic dialect, or an HTTP Basic login yielding a session cookie for igel-ums (which also needs a 'username' on the target). It is held only in memory; credentials are never logged or echoed.\n  State-changing operations (assign-profile, reboot) require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label). endpoint_assign_profile is high-risk and reversible (captures the prior profile, records an inverse reassign undo descriptor); endpoint_reboot is medium-risk with no undo (a reboot has no safe inverse).\n  Webhooks: none — no outbound network calls beyond the configured endpoint-management REST API.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Verification status: the test suite is mock-based; the REST paths are modelled generically (/endpoints, /sessions, /version) and have not yet been exercised against a live server — docs/VERIFICATION.md defines the checklist.\n---\n\n# Endpoint AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any endpoint-management vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops) under the MIT license.\n\nGoverned managed-endpoint operations — **13 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.endpoint-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk tiers. The management-server API key is stored **encrypted** (`~/.endpoint-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n> **Standalone**: the governance harness is bundled in the package (`endpoint_aiops.governance`) — endpoint-aiops has no external skill-family dependency. The test suite is mock-based; a live management server has not yet been exercised (see `docs/VERIFICATION.md`).\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Overview** | fleet health overview | 1 | 1 read |\n| **Inventory** | endpoint list, get, health score | 3 | 3 read |\n| **Sessions** | session list, login-storm analysis | 2 | 2 read |\n| **Drift** | drift report, patch status, patch compliance | 3 | 3 read |\n| **Remediation** | assign profile (high) | 1 | 1 write |\n| | reboot (medium) | 1 | 1 write |\n\nThe analysis tools (`login_storm_analysis`, `drift_report`, `patch_status`, `patch_compliance`, `endpoint_health_score`) accept injected records for pure/offline analysis; `endpoint_health_score` and `patch_compliance` are injected-only, the others also pull live from a configured target.\n\n## Quick Install\n\n```bash\nuv tool install endpoint-aiops\nendpoint-aiops init       # interactive wizard: connection + encrypted API key\nendpoint-aiops doctor\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@aiops-tools/endpoint-aiops\nopenclaw skills info endpoint-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Triage a fleet (`overview`): online/offline counts, stale endpoints, agent/patch spread\n- Rank the fleet by risk (`endpoint_health_score`): a composite 0-100 per-endpoint score, worst first, with every deduction cited\n- Diagnose a morning login storm (`session storm` / `login_storm_analysis`) and find the slowest login/boot contributors\n- Find endpoints drifted from the fleet baseline (`drift report`) or behind on patches (`drift patch`)\n- Assign a config profile to an endpoint (reversible) or reboot one (dry-run + double-confirm)\n\n**Do NOT use when** the target is OT/industrial equipment (use industrial-aiops), a hypervisor, a storage appliance, a backup product, a container cluster, or a network device.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Managed-endpoint fleet: login storms, drift, profiles | **endpoint-aiops** (this skill) |\n| OT / industrial edge (Modbus, OPC-UA, PLC, PROFINET) | the **industrial-aiops** line |\n| Hypervisor VM lifecycle (power, snapshot, migrate) | a hypervisor ops skill |\n| Container/cluster lifecycle | a cluster ops skill |\n\n## Common Workflows\n\n### \"Nobody can log in this morning\" — diagnose the 9am login storm\n\n1. `endpoint-aiops overview` → is this fleet-wide (offline/stale counts spiking) or confined to logins?\n2. `endpoint-aiops session storm --since-hours 12 --window-s 300 --min-concurrent 10` → storm episodes with peak concurrency and distinct users/endpoints, plus `slowestByLogin` / `slowestByBoot`\n3. `endpoint-aiops session list --since-hours 12` → inspect the raw sessions behind a suspicious episode (confirm the timestamps, don't trust the summary alone)\n4. `endpoint-aiops drift report` → cross-check the laggards; a stray agent version or divergent profile is a common cause of slow logins\n5. **Failure branch**: if `session storm` reports no episodes but users still complain, widen the window (`--window-s 900`) and lower `--min-concurrent` before concluding there is no storm; if the CLI errors on connectivity, run `endpoint-aiops doctor` first — the analysis is only as good as the session feed.\n\n### Bring a drifted endpoint back to the fleet baseline (reversible)\n\n1. `endpoint-aiops drift report` → the drifted endpoints and exactly which fields deviate from the fleet-majority baseline\n2. `endpoint-aiops endpoint get <id>` → confirm you are about to change the right device and note its current profile\n3. `endpoint-aiops endpoint assign-profile <id> <profile-id> --dry-run` → preview the exact `POST /endpoints/<id>/profile` call, changes nothing\n4. `endpoint-aiops endpoint assign-profile <id> <profile-id>` → double confirmation; `high` risk. The prior profile is captured and an inverse reassign undo descriptor is recorded\n5. **Failure branch**: if the endpoint misbehaves on the new profile, `endpoint-aiops undo list` then `endpoint-aiops undo apply <id>` restores the *captured* prior profile (not a guess); re-run `drift report` to confirm the fleet picture.\n\n### Patch-compliance sweep before a maintenance window\n\n1. `endpoint-aiops drift patch --target-patch 2024-06` → distribution of patch levels plus the endpoints behind the target\n2. `endpoint-aiops endpoint list` → resolve the behind-target ids to hostnames/owners for the change ticket\n3. `endpoint-aiops overview` → check how many of those are currently offline (an offline endpoint will not take the patch)\n4. Reboot a stuck endpoint that has staged its patch: `endpoint-aiops endpoint reboot <id> --dry-run`, then without `--dry-run` (double confirmation)\n5. **Failure branch**: `endpoint_reboot` is `medium` risk and declares **no undo** — a reboot has no safe inverse. If the endpoint does not come back, the audit record in `~/.endpoint-aiops/audit.db` holds its prior online state for the incident write-up; recovery is out-of-band (console/PXE), not via this tool.\n\n### Offline post-incident analysis (no live server)\n\n1. Export the incident's session and endpoint records from the management server into JSON\n2. Call the analysis tools with injected records — `login_storm_analysis(sessions=[...])`, `drift_report(endpoints=[...])`, `patch_compliance(endpoints=[...])`, `endpoint_health_score(endpoints=[...])` — no connection or credentials required\n3. `endpoint_health_score` returns a composite 0-100 per endpoint, worst first, with every deduction cited — use it to rank the remediation queue\n4. **Failure branch**: if a tool rejects the injected records, the export is missing fields the analysis needs (e.g. session start/login-duration, or endpoint patch level) — re-export rather than hand-patching the data, so the numbers stay traceable to the source.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the account you connect it with (a management-console account or API token\nscoped to a read-only role — writes then fail at the server). There is no\nread-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.endpoint-aiops/audit.db` (relocatable via `ENDPOINT_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `ENDPOINT_AUDIT_APPROVED_BY` / `ENDPOINT_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `ENDPOINT_RUNAWAY_MAX=0`.\n- Writes support `--dry-run` / `dry_run=True` and double confirmation at the CLI.\n- Reversible writes fetch the real before-state and record an inverse descriptor (`endpoint_assign_profile`→restore prior profile); the reboot (no safe inverse) records only the before-state.\n\n## References\n\n- `references/capabilities.md` — full tool + field reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, and connectivity\n\nFile v0.10.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"endpoint-aiops\",\n  \"version\": \"0.10.1\",\n  \"publishedAt\": 1789207350835\n}\n\nFile v0.10.1:references/agent-guardrails.md\n\n# Agent guardrails — running endpoint-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The account you connect with.** Give it a management-console account or API\n  token scoped to a read-only role. A write then fails at the server, which is\n  the only place the permission actually lives — no skill-side flag can be\n  argued around by a model, but a revoked permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.endpoint-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |\n| \"Don't invent a value when a field is missing\" | A field the management server did not return comes back as `null`, never as `\"\"`. An endpoint with no reported `patchLevel` is distinguishable from one reporting a blank level, and the key is always present. |\n| \"Tell me if the output was cut off\" | Every capped list is `{\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured against the full result, not guessed from the row count matching the limit. |\n| \"Give me the real totals, not just what you can see\" | Counts are computed over the whole fleet, never over the capped list: `driftedCount`, `behindCount`, `nonCompliantCount`, `stormCount`, and the health-score `summary` are all uncapped. `complianceRatePct` is likewise a whole-fleet figure. |\n| \"Explain why something was flagged\" | Every flag carries its number: each health-score deduction is cited in that endpoint's `reasons`, each drift row states `expected` vs `actual`, and `login_storm_analysis` returns the `thresholds` it used. |\n| \"Confirm before anything destructive\" | `endpoint assign-profile` and `endpoint reboot` require `--dry-run`-able preview + double confirmation at the CLI. |\n| \"Remember the previous profile so we can roll back\" | `endpoint_assign_profile` reads the endpoint's current profile *before* changing it and records an inverse undo token — the before-state is captured, never guessed. (A reboot has no safe inverse and honestly declares none.) |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a managed-endpoint fleet (thin clients / VDI / managed devices)\nthrough the endpoint-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current fleet, you MUST call a tool.\n  Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. A list arrives as\n  {\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": bool}; when\n  \"truncated\" is true, say so and re-run with a higher limit instead of\n  treating the partial list as the whole fleet.\n- Use the uncapped counts (driftedCount, behindCount, nonCompliantCount,\n  stormCount, summary) for \"how many\", and the items list only for \"which ones\".\n- A null field means the management server did not report that value. Report it\n  as \"not available\" — never infer a patch level, agent version, or hostname.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  patch levels, agent versions, profile ids, or hostnames.\n- A health score is advisory: it is 100 minus the deductions listed in that\n  endpoint's \"reasons\". Quote the reasons rather than restating the score alone.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a login-storm, drift, or patch-compliance problem unless a tool\n  result supports it — a storm is only a storm when an episode was returned.\n- A drift finding is an exact string mismatch against a baseline, and that\n  baseline may be the fleet majority rather than a declared gold image. Say\n  which (the payload tells you: baselineSource / targetSource).\n- Do not confuse an endpoint id with a hostname, or a profile id with either.\n- Do not add generic advice that does not follow from the tool output.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — a mistaken `endpoint_reboot` across a\nfleet is cheap to invoke and has no safe inverse:\n\n```bash\n# e.g. use a management-console account or API token with a read-only role. Then:\nendpoint-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport ENDPOINT_AUDIT_RATIONALE=\"scheduled patch window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer the analysis tools —\n  `overview`, `login_storm_analysis`, `drift_report`, `endpoint_health_score`\n  each do the multi-step correlation inside one call, so the model does not have\n  to chain reads and keep endpoint ids straight.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `--limit` deliberately rather than pulling a whole fleet\n  inventory into the context window.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.10.1:references/capabilities.md\n\n# endpoint-aiops capabilities\n\n> 13 MCP tools (10 read, 3 write). REST paths are modelled generically against\n> an endpoint-management API and have not yet been exercised live\n> (see docs/VERIFICATION.md).\n\n## Read tools (10)\n\n| Tool | REST path | Returns |\n|------|----------------|---------|\n| `overview` | `GET /endpoints` (fold) | total, online, offline, stale[], agentVersionSpread, patchLevelSpread |\n| `endpoint_list` | `GET /endpoints` | id, hostname, os, osBuild, agentVersion, patchLevel, profileId, online, lastSeenHours |\n| `endpoint_get` | `GET /endpoints/{id}` | single endpoint detail (normalised) |\n| `endpoint_health_score` | injected only | endpointsEvaluated, baseline{agentVersion,patchLevel,source}, summary{healthy,degraded,critical}, worst{items[]{endpoint,score,band,reasons[]},returned,limit,truncated}, note |\n| `session_list` | `GET /sessions?since_hours=` | endpoint, user, loginMs, bootMs, timestamp, result |\n| `login_storm_analysis` | `GET /sessions` or injected | stormCount, storms/slowestByLogin/slowestByBoot (each {items[],returned,limit,truncated}), slowLoginCount, failedLogins, thresholds |\n| `drift_report` | `GET /endpoints` or injected | baseline, driftByField, driftedEndpoints{items[],returned,limit,truncated}, drifted/compliant counts |\n| `patch_status` | `GET /endpoints` or injected | targetPatch, distribution, behind{items[],returned,limit,truncated}, behindCount |\n| `patch_compliance` | injected only | endpointsEvaluated, targetPatch, targetSource, slaTargetPct, complianceRatePct, compliantCount, verdict, nonCompliantCount, nonCompliant{items[],returned,limit,truncated}, note |\n| `undo_list` | local undo store | recorded, not-yet-applied reversible writes: undos[]{undoId, ts, originalTool, inverseTool, note}, returned, limit, truncated |\n\nThe analysis tools accept an injected `sessions=` / `endpoints=` list for\npure/offline analysis. `login_storm_analysis`, `drift_report` and `patch_status`\nalso pull live from a configured `target`; `endpoint_health_score` and\n`patch_compliance` are injected-only (they score rows you already hold, e.g.\nfrom `endpoint_list`).\n\n## Write tools (3)\n\n| Tool | Risk | REST path | Undo / safety |\n|------|------|----------------|---------------|\n| `endpoint_assign_profile` | **high** | `POST /endpoints/{id}/profile` | captures the prior profile; records an inverse \"reassign prior profile\" undo descriptor; CLI double-confirm + dry-run |\n| `endpoint_reboot` | medium | `POST /endpoints/{id}/reboot` | captures prior online state; no safe inverse, no undo; CLI double-confirm + dry-run |\n| `undo_apply` | medium | local undo store → inverse tool | executes a recorded inverse; the inverse runs through its own governed tool (its real risk tier is recorded there); single-use token; supports `dry_run` |\n\n## Out of scope (by design)\n\n- Endpoint **enrollment / de-enrollment**\n- Image / OTA / firmware push\n- Profile CRUD (create/delete config profiles) and user/group management\n- OT / industrial equipment (use the `industrial-aiops` line)\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n\n## Two payload conventions worth knowing\n\n**Absent is not empty.** A field the management server did not report comes back\nas `null`, never as `\"\"`. The key is always present, so \"the server had no value\nfor this\" is visible rather than inferred.\n\n**Capped lists announce themselves.** Every list that a `limit` can cut short is\na truncation envelope:\n\n```json\n{\"items\": [...], \"returned\": 25, \"limit\": 25, \"truncated\": true}\n```\n\n`truncated` is measured against the full result, not guessed from the returned\ncount matching the limit. When it is `true`, re-run with a higher `limit`.\nCompanion totals (`driftedCount`, `behindCount`, `stormCount`,\n`nonCompliantCount`, the health `summary`) are always the full, uncapped\nfigures.\n\nFile v0.10.1:references/cli-reference.md\n\n# endpoint-aiops CLI reference\n\n> REST paths are modelled generically against an endpoint-management API and\n> have not yet been exercised live (see docs/VERIFICATION.md).\n\n## Setup & diagnostics\n\n```bash\nendpoint-aiops init                      # interactive onboarding wizard\nendpoint-aiops doctor [--skip-auth]      # config + secret store + connectivity (/version)\nendpoint-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n## Secrets (encrypted store ~/.endpoint-aiops/secrets.enc)\n\n```bash\nendpoint-aiops secret set <target> [--value <key>]   # store API key (hidden prompt if no --value)\nendpoint-aiops secret list                            # names only — values never shown\nendpoint-aiops secret rm <target>\nendpoint-aiops secret migrate                         # import legacy plaintext .env (ENDPOINT_<T>_APIKEY)\nendpoint-aiops secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Read commands\n\n```bash\nendpoint-aiops overview [--target <t>]        # online/offline, stale endpoints, agent/patch spread\nendpoint-aiops endpoint list                  # all managed endpoints\nendpoint-aiops endpoint get <endpoint_id>     # one endpoint detail\nendpoint-aiops session list [--since-hours 24]           # recent login/boot sessions\nendpoint-aiops session storm [--since-hours 24] [--window-s 300] [--min-concurrent 10]\nendpoint-aiops drift report                   # endpoints drifted from the fleet-majority baseline\nendpoint-aiops drift patch [--target-patch <level>]      # patch-level distribution + who's behind\n```\n\n## Write commands (governed; risk tier in parentheses)\n\n```bash\nendpoint-aiops endpoint assign-profile <endpoint_id> <profile_id> [--dry-run]   # (high) reversible; double confirm\nendpoint-aiops endpoint reboot <endpoint_id> [--dry-run]                        # (medium) no undo; double confirm\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- State-changing commands (`endpoint assign-profile`, `endpoint reboot`) require two confirmations\n\nFile v0.10.1:references/setup-guide.md\n\n# endpoint-aiops setup & security guide\n\n> Not yet exercised against a live endpoint-management server (see docs/VERIFICATION.md).\n\n## 1. Install\n\n```bash\nuv tool install endpoint-aiops\n```\n\n## 2. Create credentials — the shape depends on the dialect\n\nThe target's **dialect** decides the port, the API base path *and* how to\nauthenticate, so create the credential the dialect expects:\n\n**`generic` (default) — a static API key.** In your endpoint-management\nserver's web UI, create an API key (usually under a Credentials / API Keys\nsection). It is sent as `Authorization: Bearer <key>` against the REST API base\n`<scheme>://<host>:<port><api_path>`.\n\n**`igel-ums` — a UMS administrator account.** IMI does not accept a static\nBearer token; it logs in with HTTP Basic at `POST /umsapi/v3/login` and then\ncarries the returned `JSESSIONID` cookie. So an `igel-ums` target needs a\n`username:` in `config.yaml` plus that account's **password** in the encrypted\nstore — not an API key. No gateway or auth adapter is needed.\n\n⚠️ Give that account at least **Read/Browse permission at the Devices level**.\nWith fewer permissions IMI returns **empty lists rather than an error**, so an\nunder-privileged account looks exactly like an empty fleet. `endpoint-aiops\ndoctor` warns when a successful login returns no endpoints — do not dismiss it.\n\n⚠️ The `igel-ums` dialect is **documented but not live-verified** (IGEL UMS has\nno free edition). See `docs/VERIFICATION.md` in the repository.\n\n## 3. Onboard\n\n```bash\nendpoint-aiops init\n```\n\nThe wizard collects (non-secret) connection details into\n`~/.endpoint-aiops/config.yaml` and stores the API key **encrypted** into\n`~/.endpoint-aiops/secrets.enc`. Example config:\n\n```yaml\ntargets:\n  - name: ums1\n    host: 10.0.0.30\n    dialect: igel-ums          # sets IMI paths + port 8443 + /umsapi/v3\n    scheme: https              # 'http' for a reverse-proxied server\n    verify_ssl: false          # self-signed lab certs only\n```\n\nThe wizard asks which **dialect** to use and prints the one it configured.\n`generic` (the default) is a neutral placeholder — `/api/v2.0` on 443 — that no\nshipped management server actually serves; it is only useful once you describe\nyour server's paths in a `dialect:` block. `igel-ums` targets IGEL UMS via IMI\nand is **modelled from vendor documentation, not live-verified**.\n\n`port` and `api_path` are still accepted and win over the dialect's defaults\nwhen you set them.\n\n## 4. Non-interactive use (MCP server / CI / cron)\n\nExport the master password so the encrypted store can be unlocked without a\nprompt:\n\n```bash\nexport ENDPOINT_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Credential security\n\n- The API key is **never** written to disk in plaintext. It lives only in\n  `~/.endpoint-aiops/secrets.enc`, encrypted with Fernet (AES-128-CBC + HMAC),\n  the key derived from your master password via scrypt. Only a per-store random\n  salt and the ciphertext are on disk (chmod 600); the master password itself is\n  never stored.\n- A legacy plaintext env var `ENDPOINT_<TARGET_NAME_UPPER>_APIKEY` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `endpoint-aiops secret migrate` (it imports then renames the old `.env`).\n- The key is held only in memory during a session and is never logged or echoed;\n  exception text and tracebacks are scrubbed of secret-shaped strings before\n  being written to the audit log.\n\n## Audit-annotation env vars (optional)\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement or the connecting account's role. If you want the audit trail to\nrecord *who* ran a destructive op and *why*, set these; they are recorded on the\nrow, never required, and gate nothing:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY='you@example.com'\nexport ENDPOINT_AUDIT_RATIONALE='why this destructive op is justified'\n```\n\n## Governance harness state\n\nState lives under `~/.endpoint-aiops/` (relocate with `ENDPOINT_AIOPS_HOME`):\n\n- `audit.db` — every tool call (SQLite), with risk tier and any approver/rationale\n- `undo.db` — inverse descriptors for reversible writes (e.g. `endpoint_assign_profile`)\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops\n\n## Verify\n\n```bash\nendpoint-aiops doctor\n```\n\n`doctor` checks the config file, the encrypted store and its permissions,\nthat an API key is present per target, and (unless `--skip-auth`) connectivity\nby hitting `/version`.\n\nFile v0.10.1:skill-card.md\n\n## Description:\n\nEndpoint AIops helps agents inspect and operate managed-endpoint fleets, including fleet health, inventory, login-storm analysis, patch and configuration drift, health scoring, profile assignment, and endpoint reboots.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and endpoint operations teams use this skill to triage managed-endpoint fleets, rank unhealthy endpoints, investigate login storms, detect patch or configuration drift, and perform guarded remediation actions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: MCP write tools can reboot endpoints or change profiles without an enforced skill-side read-only mode or approval gate.\n\nMitigation: Use a read-only management account by default, expose write tools only where operators can approve changes out of band, and require dry-run review before state-changing actions.\n\nRisk: Broad administrator credentials in shared environments could allow unintended fleet changes.\n\nMitigation: Avoid exporting broad administrator passwords into shared shells, keep credentials scoped to the minimum needed role, and unlock the encrypted store only for trusted sessions.\n\nRisk: Endpoint-management REST paths and dialects are documented as not yet exercised against a live management server.\n\nMitigation: Run endpoint-aiops doctor, validate against a non-production target first, and compare tool output with the management console before relying on remediation workflows.\n\nRisk: Disabling TLS verification for self-signed lab certificates can weaken connection security.\n\nMitigation: Keep TLS verification enabled for normal deployments and disable it only for controlled lab certificates.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/zw008/skills/endpoint-aiops)\n- [Endpoint-AIops Repository](https://github.com/AIops-tools/Endpoint-AIops)\n- [Capabilities Reference](references/capabilities.md)\n- [CLI Reference](references/cli-reference.md)\n- [Setup and Security Guide](references/setup-guide.md)\n- [Agent Guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell command snippets and structured tool-result summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Tool outputs may include capped lists with returned, limit, and truncated fields; write actions are audited and may support dry-run or undo metadata.]\n\n## Skill Version(s):\n\n0.10.1 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.0: 7 files, 16204 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (2829b), SKILL.md (12456b), _meta.json (134b)\n\nFile v0.10.0:SKILL.md\n\n---\nname: endpoint-aiops\nslug: endpoint-aiops\ndisplayName: \"Endpoint AIops\"\nsummary: \"Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Endpoint-AIops\ntags: [aiops, mcp, governance, endpoint]\ndescription: >\n  Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint).\n  Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet.\n  Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only).\n  Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).\ninstaller:\n  kind: uv\n  package: endpoint-aiops\nargument-hint: \"[endpoint id or describe your fleet task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"endpoint-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"ENDPOINT_AIOPS_CONFIG\",\"ENDPOINT_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Endpoint-AIops\",\"emoji\":\"💻\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed managed-endpoint operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  All write operations are audited to a local SQLite DB under ~/.endpoint-aiops/ (relocatable via ENDPOINT_AIOPS_HOME).\n  Credentials: the endpoint-management server's API key is stored ENCRYPTED in ~/.endpoint-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'endpoint-aiops init' to onboard, or 'endpoint-aiops secret set <target>' to add one. The store is unlocked by a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var ENDPOINT_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'endpoint-aiops secret migrate'). The credential is presented using the scheme the target's dialect declares — a static Authorization: Bearer header for the generic dialect, or an HTTP Basic login yielding a session cookie for igel-ums (which also needs a 'username' on the target). It is held only in memory; credentials are never logged or echoed.\n  State-changing operations (assign-profile, reboot) require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label). endpoint_assign_profile is high-risk and reversible (captures the prior profile, records an inverse reassign undo descriptor); endpoint_reboot is medium-risk with no undo (a reboot has no safe inverse).\n  Webhooks: none — no outbound network calls beyond the configured endpoint-management REST API.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Verification status: the test suite is mock-based; the REST paths are modelled generically (/endpoints, /sessions, /version) and have not yet been exercised against a live server — docs/VERIFICATION.md defines the checklist.\n---\n\n# Endpoint AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any endpoint-management vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops) under the MIT license.\n\nGoverned managed-endpoint operations — **13 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.endpoint-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk tiers. The management-server API key is stored **encrypted** (`~/.endpoint-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n> **Standalone**: the governance harness is bundled in the package (`endpoint_aiops.governance`) — endpoint-aiops has no external skill-family dependency. The test suite is mock-based; a live management server has not yet been exercised (see `docs/VERIFICATION.md`).\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Overview** | fleet health overview | 1 | 1 read |\n| **Inventory** | endpoint list, get, health score | 3 | 3 read |\n| **Sessions** | session list, login-storm analysis | 2 | 2 read |\n| **Drift** | drift report, patch status, patch compliance | 3 | 3 read |\n| **Remediation** | assign profile (high) | 1 | 1 write |\n| | reboot (medium) | 1 | 1 write |\n\nThe analysis tools (`login_storm_analysis`, `drift_report`, `patch_status`, `patch_compliance`, `endpoint_health_score`) accept injected records for pure/offline analysis; `endpoint_health_score` and `patch_compliance` are injected-only, the others also pull live from a configured target.\n\n## Quick Install\n\n```bash\nuv tool install endpoint-aiops\nendpoint-aiops init       # interactive wizard: connection + encrypted API key\nendpoint-aiops doctor\n```\n\n## When to Use This Skill\n\n- Triage a fleet (`overview`): online/offline counts, stale endpoints, agent/patch spread\n- Rank the fleet by risk (`endpoint_health_score`): a composite 0-100 per-endpoint score, worst first, with every deduction cited\n- Diagnose a morning login storm (`session storm` / `login_storm_analysis`) and find the slowest login/boot contributors\n- Find endpoints drifted from the fleet baseline (`drift report`) or behind on patches (`drift patch`)\n- Assign a config profile to an endpoint (reversible) or reboot one (dry-run + double-confirm)\n\n**Do NOT use when** the target is OT/industrial equipment (use industrial-aiops), a hypervisor, a storage appliance, a backup product, a container cluster, or a network device.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Managed-endpoint fleet: login storms, drift, profiles | **endpoint-aiops** (this skill) |\n| OT / industrial edge (Modbus, OPC-UA, PLC, PROFINET) | the **industrial-aiops** line |\n| Hypervisor VM lifecycle (power, snapshot, migrate) | a hypervisor ops skill |\n| Container/cluster lifecycle | a cluster ops skill |\n\n## Common Workflows\n\n### \"Nobody can log in this morning\" — diagnose the 9am login storm\n\n1. `endpoint-aiops overview` → is this fleet-wide (offline/stale counts spiking) or confined to logins?\n2. `endpoint-aiops session storm --since-hours 12 --window-s 300 --min-concurrent 10` → storm episodes with peak concurrency and distinct users/endpoints, plus `slowestByLogin` / `slowestByBoot`\n3. `endpoint-aiops session list --since-hours 12` → inspect the raw sessions behind a suspicious episode (confirm the timestamps, don't trust the summary alone)\n4. `endpoint-aiops drift report` → cross-check the laggards; a stray agent version or divergent profile is a common cause of slow logins\n5. **Failure branch**: if `session storm` reports no episodes but users still complain, widen the window (`--window-s 900`) and lower `--min-concurrent` before concluding there is no storm; if the CLI errors on connectivity, run `endpoint-aiops doctor` first — the analysis is only as good as the session feed.\n\n### Bring a drifted endpoint back to the fleet baseline (reversible)\n\n1. `endpoint-aiops drift report` → the drifted endpoints and exactly which fields deviate from the fleet-majority baseline\n2. `endpoint-aiops endpoint get <id>` → confirm you are about to change the right device and note its current profile\n3. `endpoint-aiops endpoint assign-profile <id> <profile-id> --dry-run` → preview the exact `POST /endpoints/<id>/profile` call, changes nothing\n4. `endpoint-aiops endpoint assign-profile <id> <profile-id>` → double confirmation; `high` risk. The prior profile is captured and an inverse reassign undo descriptor is recorded\n5. **Failure branch**: if the endpoint misbehaves on the new profile, `endpoint-aiops undo list` then `endpoint-aiops undo apply <id>` restores the *captured* prior profile (not a guess); re-run `drift report` to confirm the fleet picture.\n\n### Patch-compliance sweep before a maintenance window\n\n1. `endpoint-aiops drift patch --target-patch 2024-06` → distribution of patch levels plus the endpoints behind the target\n2. `endpoint-aiops endpoint list` → resolve the behind-target ids to hostnames/owners for the change ticket\n3. `endpoint-aiops overview` → check how many of those are currently offline (an offline endpoint will not take the patch)\n4. Reboot a stuck endpoint that has staged its patch: `endpoint-aiops endpoint reboot <id> --dry-run`, then without `--dry-run` (double confirmation)\n5. **Failure branch**: `endpoint_reboot` is `medium` risk and declares **no undo** — a reboot has no safe inverse. If the endpoint does not come back, the audit record in `~/.endpoint-aiops/audit.db` holds its prior online state for the incident write-up; recovery is out-of-band (console/PXE), not via this tool.\n\n### Offline post-incident analysis (no live server)\n\n1. Export the incident's session and endpoint records from the management server into JSON\n2. Call the analysis tools with injected records — `login_storm_analysis(sessions=[...])`, `drift_report(endpoints=[...])`, `patch_compliance(endpoints=[...])`, `endpoint_health_score(endpoints=[...])` — no connection or credentials required\n3. `endpoint_health_score` returns a composite 0-100 per endpoint, worst first, with every deduction cited — use it to rank the remediation queue\n4. **Failure branch**: if a tool rejects the injected records, the export is missing fields the analysis needs (e.g. session start/login-duration, or endpoint patch level) — re-export rather than hand-patching the data, so the numbers stay traceable to the source.\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide\nwhether a write is permitted. That is your agent's judgement, or the permission\nof the account you connect it with (a management-console account or API token\nscoped to a read-only role — writes then fail at the server). There is no\nread-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.endpoint-aiops/audit.db` (relocatable via `ENDPOINT_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `ENDPOINT_AUDIT_APPROVED_BY` / `ENDPOINT_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `ENDPOINT_RUNAWAY_MAX=0`.\n- Writes support `--dry-run` / `dry_run=True` and double confirmation at the CLI.\n- Reversible writes fetch the real before-state and record an inverse descriptor (`endpoint_assign_profile`→restore prior profile); the reboot (no safe inverse) records only the before-state.\n\n## References\n\n- `references/capabilities.md` — full tool + field reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, and connectivity\n\nFile v0.10.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"endpoint-aiops\",\n  \"version\": \"0.10.0\",\n  \"publishedAt\": 1789174266996\n}\n\nFile v0.10.0:references/agent-guardrails.md\n\n# Agent guardrails — running endpoint-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The account you connect with.** Give it a management-console account or API\n  token scoped to a read-only role. A write then fails at the server, which is\n  the only place the permission actually lives — no skill-side flag can be\n  argued around by a model, but a revoked permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.endpoint-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |\n| \"Don't invent a value when a field is missing\" | A field the management server did not return comes back as `null`, never as `\"\"`. An endpoint with no reported `patchLevel` is distinguishable from one reporting a blank level, and the key is always present. |\n| \"Tell me if the output was cut off\" | Every capped list is `{\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured against the full result, not guessed from the row count matching the limit. |\n| \"Give me the real totals, not just what you can see\" | Counts are computed over the whole fleet, never over the capped list: `driftedCount`, `behindCount`, `nonCompliantCount`, `stormCount`, and the health-score `summary` are all uncapped. `complianceRatePct` is likewise a whole-fleet figure. |\n| \"Explain why something was flagged\" | Every flag carries its number: each health-score deduction is cited in that endpoint's `reasons`, each drift row states `expected` vs `actual`, and `login_storm_analysis` returns the `thresholds` it used. |\n| \"Confirm before anything destructive\" | `endpoint assign-profile` and `endpoint reboot` require `--dry-run`-able preview + double confirmation at the CLI. |\n| \"Remember the previous profile so we can roll back\" | `endpoint_assign_profile` reads the endpoint's current profile *before* changing it and records an inverse undo token — the before-state is captured, never guessed. (A reboot has no safe inverse and honestly declares none.) |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a managed-endpoint fleet (thin clients / VDI / managed devices)\nthrough the endpoint-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current fleet, you MUST call a tool.\n  Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. A list arrives as\n  {\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": bool}; when\n  \"truncated\" is true, say so and re-run with a higher limit instead of\n  treating the partial list as the whole fleet.\n- Use the uncapped counts (driftedCount, behindCount, nonCompliantCount,\n  stormCount, summary) for \"how many\", and the items list only for \"which ones\".\n- A null field means the management server did not report that value. Report it\n  as \"not available\" — never infer a patch level, agent version, or hostname.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  patch levels, agent versions, profile ids, or hostnames.\n- A health score is advisory: it is 100 minus the deductions listed in that\n  endpoint's \"reasons\". Quote the reasons rather than restating the score alone.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a login-storm, drift, or patch-compliance problem unless a tool\n  result supports it — a storm is only a storm when an episode was returned.\n- A drift finding is an exact string mismatch against a baseline, and that\n  baseline may be the fleet majority rather than a declared gold image. Say\n  which (the payload tells you: baselineSource / targetSource).\n- Do not confuse an endpoint id with a hostname, or a profile id with either.\n- Do not add generic advice that does not follow from the tool output.\n```\n\n## Recommended setup for a local model\n\nStart with a connection that *cannot* write, verify, and widen the account's\npermission only when you trust the setup — a mistaken `endpoint_reboot` across a\nfleet is cheap to invoke and has no safe inverse:\n\n```bash\n# e.g. use a management-console account or API token with a read-only role. Then:\nendpoint-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport ENDPOINT_AUDIT_RATIONALE=\"scheduled patch window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer the analysis tools —\n  `overview`, `login_storm_analysis`, `drift_report`, `endpoint_health_score`\n  each do the multi-step correlation inside one call, so the model does not have\n  to chain reads and keep endpoint ids straight.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `--limit` deliberately rather than pulling a whole fleet\n  inventory into the context window.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.10.0:references/capabilities.md\n\n# endpoint-aiops capabilities\n\n> 13 MCP tools (10 read, 3 write). REST paths are modelled generically against\n> an endpoint-management API and have not yet been exercised live\n> (see docs/VERIFICATION.md).\n\n## Read tools (10)\n\n| Tool | REST path | Returns |\n|------|----------------|---------|\n| `overview` | `GET /endpoints` (fold) | total, online, offline, stale[], agentVersionSpread, patchLevelSpread |\n| `endpoint_list` | `GET /endpoints` | id, hostname, os, osBuild, agentVersion, patchLevel, profileId, online, lastSeenHours |\n| `endpoint_get` | `GET /endpoints/{id}` | single endpoint detail (normalised) |\n| `endpoint_health_score` | injected only | endpointsEvaluated, baseline{agentVersion,patchLevel,source}, summary{healthy,degraded,critical}, worst{items[]{endpoint,score,band,reasons[]},returned,limit,truncated}, note |\n| `session_list` | `GET /sessions?since_hours=` | endpoint, user, loginMs, bootMs, timestamp, result |\n| `login_storm_analysis` | `GET /sessions` or injected | stormCount, storms/slowestByLogin/slowestByBoot (each {items[],returned,limit,truncated}), slowLoginCount, failedLogins, thresholds |\n| `drift_report` | `GET /endpoints` or injected | baseline, driftByField, driftedEndpoints{items[],returned,limit,truncated}, drifted/compliant counts |\n| `patch_status` | `GET /endpoints` or injected | targetPatch, distribution, behind{items[],returned,limit,truncated}, behindCount |\n| `patch_compliance` | injected only | endpointsEvaluated, targetPatch, targetSource, slaTargetPct, complianceRatePct, compliantCount, verdict, nonCompliantCount, nonCompliant{items[],returned,limit,truncated}, note |\n| `undo_list` | local undo store | recorded, not-yet-applied reversible writes: undos[]{undoId, ts, originalTool, inverseTool, note}, returned, limit, truncated |\n\nThe analysis tools accept an injected `sessions=` / `endpoints=` list for\npure/offline analysis. `login_storm_analysis`, `drift_report` and `patch_status`\nalso pull live from a configured `target`; `endpoint_health_score` and\n`patch_compliance` are injected-only (they score rows you already hold, e.g.\nfrom `endpoint_list`).\n\n## Write tools (3)\n\n| Tool | Risk | REST path | Undo / safety |\n|------|------|----------------|---------------|\n| `endpoint_assign_profile` | **high** | `POST /endpoints/{id}/profile` | captures the prior profile; records an inverse \"reassign prior profile\" undo descriptor; CLI double-confirm + dry-run |\n| `endpoint_reboot` | medium | `POST /endpoints/{id}/reboot` | captures prior online state; no safe inverse, no undo; CLI double-confirm + dry-run |\n| `undo_apply` | medium | local undo store → inverse tool | executes a recorded inverse; the inverse runs through its own governed tool (its real risk tier is recorded there); single-use token; supports `dry_run` |\n\n## Out of scope (by design)\n\n- Endpoint **enrollment / de-enrollment**\n- Image / OTA / firmware push\n- Profile CRUD (create/delete config profiles) and user/group management\n- OT / industrial equipment (use the `industrial-aiops` line)\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n\n## Two payload conventions worth knowing\n\n**Absent is not empty.** A field the management server did not report comes back\nas `null`, never as `\"\"`. The key is always present, so \"the server had no value\nfor this\" is visible rather than inferred.\n\n**Capped lists announce themselves.** Every list that a `limit` can cut short is\na truncation envelope:\n\n```json\n{\"items\": [...], \"returned\": 25, \"limit\": 25, \"truncated\": true}\n```\n\n`truncated` is measured against the full result, not guessed from the returned\ncount matching the limit. When it is `true`, re-run with a higher `limit`.\nCompanion totals (`driftedCount`, `behindCount`, `stormCount`,\n`nonCompliantCount`, the health `summary`) are always the full, uncapped\nfigures.\n\nFile v0.10.0:references/cli-reference.md\n\n# endpoint-aiops CLI reference\n\n> REST paths are modelled generically against an endpoint-management API and\n> have not yet been exercised live (see docs/VERIFICATION.md).\n\n## Setup & diagnostics\n\n```bash\nendpoint-aiops init                      # interactive onboarding wizard\nendpoint-aiops doctor [--skip-auth]      # config + secret store + connectivity (/version)\nendpoint-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n## Secrets (encrypted store ~/.endpoint-aiops/secrets.enc)\n\n```bash\nendpoint-aiops secret set <target> [--value <key>]   # store API key (hidden prompt if no --value)\nendpoint-aiops secret list                            # names only — values never shown\nendpoint-aiops secret rm <target>\nendpoint-aiops secret migrate                         # import legacy plaintext .env (ENDPOINT_<T>_APIKEY)\nendpoint-aiops secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Read commands\n\n```bash\nendpoint-aiops overview [--target <t>]        # online/offline, stale endpoints, agent/patch spread\nendpoint-aiops endpoint list                  # all managed endpoints\nendpoint-aiops endpoint get <endpoint_id>     # one endpoint detail\nendpoint-aiops session list [--since-hours 24]           # recent login/boot sessions\nendpoint-aiops session storm [--since-hours 24] [--window-s 300] [--min-concurrent 10]\nendpoint-aiops drift report                   # endpoints drifted from the fleet-majority baseline\nendpoint-aiops drift patch [--target-patch <level>]      # patch-level distribution + who's behind\n```\n\n## Write commands (governed; risk tier in parentheses)\n\n```bash\nendpoint-aiops endpoint assign-profile <endpoint_id> <profile_id> [--dry-run]   # (high) reversible; double confirm\nendpoint-aiops endpoint reboot <endpoint_id> [--dry-run]                        # (medium) no undo; double confirm\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- State-changing commands (`endpoint assign-profile`, `endpoint reboot`) require two confirmations\n\nFile v0.10.0:references/setup-guide.md\n\n# endpoint-aiops setup & security guide\n\n> Not yet exercised against a live endpoint-management server (see docs/VERIFICATION.md).\n\n## 1. Install\n\n```bash\nuv tool install endpoint-aiops\n```\n\n## 2. Create credentials — the shape depends on the dialect\n\nThe target's **dialect** decides the port, the API base path *and* how to\nauthenticate, so create the credential the dialect expects:\n\n**`generic` (default) — a static API key.** In your endpoint-management\nserver's web UI, create an API key (usually under a Credentials / API Keys\nsection). It is sent as `Authorization: Bearer <key>` against the REST API base\n`<scheme>://<host>:<port><api_path>`.\n\n**`igel-ums` — a UMS administrator account.** IMI does not accept a static\nBearer token; it logs in with HTTP Basic at `POST /umsapi/v3/login` and then\ncarries the returned `JSESSIONID` cookie. So an `igel-ums` target needs a\n`username:` in `config.yaml` plus that account's **password** in the encrypted\nstore — not an API key. No gateway or auth adapter is needed.\n\n⚠️ Give that account at least **Read/Browse permission at the Devices level**.\nWith fewer permissions IMI returns **empty lists rather than an error**, so an\nunder-privileged account looks exactly like an empty fleet. `endpoint-aiops\ndoctor` warns when a successful login returns no endpoints — do not dismiss it.\n\n⚠️ The `igel-ums` dialect is **documented but not live-verified** (IGEL UMS has\nno free edition). See `docs/VERIFICATION.md` in the repository.\n\n## 3. Onboard\n\n```bash\nendpoint-aiops init\n```\n\nThe wizard collects (non-secret) connection details into\n`~/.endpoint-aiops/config.yaml` and stores the API key **encrypted** into\n`~/.endpoint-aiops/secrets.enc`. Example config:\n\n```yaml\ntargets:\n  - name: ums1\n    host: 10.0.0.30\n    dialect: igel-ums          # sets IMI paths + port 8443 + /umsapi/v3\n    scheme: https              # 'http' for a reverse-proxied server\n    verify_ssl: false          # self-signed lab certs only\n```\n\nThe wizard asks which **dialect** to use and prints the one it configured.\n`generic` (the default) is a neutral placeholder — `/api/v2.0` on 443 — that no\nshipped management server actually serves; it is only useful once you describe\nyour server's paths in a `dialect:` block. `igel-ums` targets IGEL UMS via IMI\nand is **modelled from vendor documentation, not live-verified**.\n\n`port` and `api_path` are still accepted and win over the dialect's defaults\nwhen you set them.\n\n## 4. Non-interactive use (MCP server / CI / cron)\n\nExport the master password so the encrypted store can be unlocked without a\nprompt:\n\n```bash\nexport ENDPOINT_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Credential security\n\n- The API key is **never** written to disk in plaintext. It lives only in\n  `~/.endpoint-aiops/secrets.enc`, encrypted with Fernet (AES-128-CBC + HMAC),\n  the key derived from your master password via scrypt. Only a per-store random\n  salt and the ciphertext are on disk (chmod 600); the master password itself is\n  never stored.\n- A legacy plaintext env var `ENDPOINT_<TARGET_NAME_UPPER>_APIKEY` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `endpoint-aiops secret migrate` (it imports then renames the old `.env`).\n- The key is held only in memory during a session and is never logged or echoed;\n  exception text and tracebacks are scrubbed of secret-shaped strings before\n  being written to the audit log.\n\n## Audit-annotation env vars (optional)\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement or the connecting account's role. If you want the audit trail to\nrecord *who* ran a destructive op and *why*, set these; they are recorded on the\nrow, never required, and gate nothing:\n\n```bash\nexport ENDPOINT_AUDIT_APPROVED_BY='you@example.com'\nexport ENDPOINT_AUDIT_RATIONALE='why this destructive op is justified'\n```\n\n## Governance harness state\n\nState lives under `~/.endpoint-aiops/` (relocate with `ENDPOINT_AIOPS_HOME`):\n\n- `audit.db` — every tool call (SQLite), with risk tier and any approver/rationale\n- `undo.db` — inverse descriptors for reversible writes (e.g. `endpoint_assign_profile`)\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops\n\n## Verify\n\n```bash\nendpoint-aiops doctor\n```\n\n`doctor` checks the config file, the encrypted store and its permissions,\nthat an API key is present per target, and (unless `--skip-auth`) connectivity\nby hitting `/version`.\n\nFile v0.10.0:skill-card.md\n\n## Description:\n\nEndpoint AIops helps agents inspect managed-endpoint fleets, analyze login storms and patch or configuration drift, rank endpoint health, and perform audited profile assignment or reboot actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, IT operators, and endpoint administrators use this skill to triage managed endpoint fleets, investigate login or boot slowdowns, identify patch and configuration drift, and carry out limited remediation with audit records.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The release installs or invokes an external endpoint-aiops executable that may not be pinned by the skill artifact.\n\nMitigation: Install a pinned, verified endpoint-aiops package version from a trusted source before enabling the skill.\n\nRisk: The skill can call endpoint-changing actions and does not provide an enforced read-only or approval mode.\n\nMitigation: Start with a read-only endpoint-management account and grant write permissions only when profile assignment or reboot actions are intentionally needed.\n\nRisk: Endpoint credentials, the master password, and local state under ~/.endpoint-aiops/ are sensitive operational data.\n\nMitigation: Protect the master password and local state directory, and avoid exposing them in logs, shared workspaces, or prompts.\n\nRisk: Some REST paths and the igel-ums dialect are documented as not yet live-verified.\n\nMitigation: Run endpoint-aiops doctor and validate against the target management server before relying on the results for operational decisions.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/endpoint-aiops)\n- [Endpoint AIops homepage](https://github.com/AIops-tools/Endpoint-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown and structured JSON-like tool results with inline shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Endpoint lists may be returned in capped envelopes with returned, limit, and truncated fields; analysis summaries include uncapped fleet counts where available.]\n\n## Skill Version(s):\n\n0.10.0 (source: evidence.release.version)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.9.0: 7 files, 16245 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (2787b), SKILL.md (12567b), _meta.json (133b)\n\nFile v0.9.0:SKILL.md\n\n---\nname: endpoint-aiops\nslug: endpoint-aiops\ndisplayName: \"Endpoint AIops\"\nsummary: \"Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Endpoint-AIops\ntags: [aiops, mcp, governance, endpoint]\ndescription: >\n  Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint).\n  Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet.\n  Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only).\n  Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).\ninstaller:\n  kind: uv\n  package: endpoint-aiops\nargument-hint: \"[endpoint id or describe your fleet task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"env\":[\"ENDPOINT_AIOPS_CONFIG\"],\"bins\":[\"endpoint-aiops\"],\"config\":[\"~/.endpoint-aiops/config.yaml\",\"~/.endpoint-aiops/secrets.enc\"]},\"optional\":{\"env\":[\"ENDPOINT_AIOPS_MASTER_PASSWORD\"]},\"primaryEnv\":\"ENDPOINT_AIOPS_CONFIG\",\"homepage\":\"https://github.com/AIops-tools/Endpoint-AIops\",\"emoji\":\"💻\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed managed-endpoint operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  All write operations are audited to a local SQLite DB under ~/.endpoint-aiops/ (relocatable via ENDPOINT_AIOPS_HOME).\n  Credentials: the endpoint-management server's API key is stored ENCRYPTED in ~/.endpoint-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'endpoint-aiops init' to onboard, or 'endpoint-aiops secret set <target>' to add one. The store is unlocked by a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var ENDPOINT_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'endpoint-aiops secret migrate'). The credential is presented using the scheme the target's dialect declares — a static Authorization: Bearer header for the generic dialect, or an HTTP Basic login yielding a session cookie for igel-ums (which also needs a 'username' on the target). It is held only in memory; credentials are never logged or echoed.\n  State-changing operations (assign-profile, reboot) require double confirmation at the CLI layer and support --dry-run. All write tools pass through the @governed_tool decorator (pre-check + budget guard + audit + risk-tier label). endpoint_assign_profile is high-risk and reversible (captures the prior profile, records an inverse reassign undo descriptor); endpoint_reboot is medium-risk with no undo (a reboot has no safe inverse).\n  Webhooks: none — no outbound network calls beyond the configured endpoint-management REST API.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Verification status: the test suite is mock-based; the REST paths are modelled generically (/endpoints, /sessions, /version) and have not yet been exercised against a live server — docs/VERIFICATION.md defines the checklist.\n---\n\n# Endpoint AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any endpoint-management vendor.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Endpoint-AIops](https://github.com/AIops-tools/Endpoint-AIops) under the MIT license.\n\nGoverned managed-endpoint operations — **13 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.endpoint-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk tiers. The management-server API key is stored **encrypted** (`~/.endpoint-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n> **Standalone**: the governance harness is bundled in the package (`endpoint_aiops.governance`) — endpoint-aiops has no external skill-family dependency. The test suite is mock-based; a live management server has not yet been exercised (see `docs/VERIFICATION.md`).\n\n## What This Skill Does\n\n| Category | Tools | Count | Read or Write |\n|----------|-------|:-----:|:-------------:|\n| **Overview** | fleet health overview | 1 | 1 read |\n| **Inventory** | endpoint list, get, health score | 3 | 3 read |\n| **Sessions** | session list, login-storm analysis | 2 | 2 read |\n| **Drift** | drift report, patch status, patch compliance | 3 | 3 read |\n| **Remediation** | assign profile (high) | 1 | 1 write |\n| | reboot (medium) | 1 | 1 write |\n\nThe analysis tools (`login_storm_analysis`, `drift_report`, `patch_status`, `patch_compliance`, `endpoint_health_score`) accept injected records for pure/offline analysis; `endpoint_health_score` and `\n\nArchive v0.8.0: 7 files, 16304 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (3087b), SKILL.md (12567b), _meta.json (133b)\n\nArchive v0.7.0: 7 files, 16311 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (3103b), SKILL.md (12567b), _meta.json (133b)\n\nArchive v0.6.0: 7 files, 16244 bytes\n\nFiles: references/agent-guardrails.md (7386b), references/capabilities.md (3846b), references/cli-reference.md (2182b), references/setup-guide.md (4511b), skill-card.md (2919b), SKILL.md (12567b), _meta.json (133b)\n\nArchive v0.5.0: 7 files, 15115 bytes\n\nFiles: references/agent-guardrails.md (6481b), references/capabilities.md (4122b), references/cli-reference.md (2182b), references/setup-guide.md (3410b), skill-card.md (2862b), SKILL.md (11906b), _meta.json (133b)\n\nArchive v0.4.0: 7 files, 14596 bytes\n\nFiles: references/agent-guardrails.md (6481b), references/capabilities.md (4122b), references/cli-reference.md (2182b), references/setup-guide.md (2523b), skill-card.md (2631b), SKILL.md (11906b), _meta.json (133b)","readmeExcerpt":"Skill: endpoint-aiops Owner: zw008 Summary: Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot cont","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"uv tool install endpoint-aiops\nendpoint-aiops init       # interactive wizard: connection + encrypted API key\nendpoint-aiops doctor"},{"language":"bash","snippet":"openclaw plugins install clawhub:@zw008/endpoint-aiops\nopenclaw skills info endpoint-aiops          # expect: Visible to model: yes"},{"language":"text","snippet":"You operate a managed-endpoint fleet (thin clients / VDI / managed devices)\nthrough the endpoint-aiops MCP tools.\n\nTOOL USE\n- Before answering any question about the current fleet, you MUST call a tool.\n  Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nREADING RESULTS\n- Read the whole result before concluding. A list arrives as\n  {\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": bool}; when\n  \"truncated\" is true, say so and re-run with a higher limit instead of\n  treating the partial list as the whole fleet.\n- Use the uncapped counts (driftedCount, behindCount, nonCompliantCount,\n  stormCount, summary) for \"how many\", and the items list only for \"which ones\".\n- A null field means the management server did not report that value. Report it\n  as \"not available\" — never infer a patch level, agent version, or hostname.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  patch levels, agent versions, profile ids, or hostnames.\n- A health score is advisory: it is 100 minus the deductions listed in that\n  endpoint's \"reasons\". Quote the reasons rather than restating the score alone.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a login-storm, drift, or patch-compliance problem unless a tool\n  result supports it — a storm is only a storm when an episode was returned.\n- A drift finding is an exact string mismatch against a baseline, and that\n  baseline may be the fleet majority rather than a declared gold image. Say\n  which (the payload tells you: baselineSource / targetSource).\n- Do not confuse an endpoint id with a hostname, or a profile id with either.\n- Do not add generic advice that does not follow f"},{"language":"bash","snippet":"# e.g. use a management-console account or API token with a read-only role. Then:\nendpoint-aiops doctor"},{"language":"bash","snippet":"export ENDPOINT_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport ENDPOINT_AUDIT_RATIONALE=\"scheduled patch window 2026-07-20\""},{"language":"json","snippet":"{\"items\": [...], \"returned\": 25, \"limit\": 25, \"truncated\": true}"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: endpoint-aiops\nslug: endpoint-aiops\ndisplayName: \"Endpoint AIops\"\nsummary: \"Governed managed-endpoint ops — login-storm & drift analysis, 13 MCP tools with audit/budget/undo.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Endpoint-AIops\ntags: [aiops, mcp, governance, endpoint]\ndescription: >\n  Use this skill whenever the user needs to operate a managed-endpoint fleet (thin clients, VDI endpoints, centrally-managed devices) — a one-shot fleet health overview, endpoint inventory (list/get), a composite per-endpoint health score (which endpoints are worst?), login & boot sessions, login-storm analysis (detect morning login storms and rank the slowest login/boot contributors), patch/config drift (which endpoints deviate from the fleet baseline), and two guarded writes (assign a config profile, reboot an endpoint).\n  Always use this skill for \"endpoint fleet overview\", \"list managed endpoints\", \"which endpoints are worst\", \"endpoint health score\", \"rank endpoints by risk\", \"why is login slow this morning\", \"login storm\", \"boot time analysis\", \"patch drift\", \"config drift\", \"which endpoints are behind on patches\", \"assign a profile to an endpoint\", or \"reboot a thin client\" when the context is an endpoint-management fleet.\n  Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a Kubernetes cluster, or a network device (negative routing hints only).\n  Covers common managed-endpoint operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; not yet exercised against a live management server (see docs/VERIFICATION.md).\ninstaller:\n  kind: uv\n  package: endpoint-aiops\nargument-hint: \"[endpoint id or describe your fleet task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"endpoint-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"ENDPOINT_AIOPS_CONFIG\",\"ENDPOINT_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Endpoint-AIops\",\"emoji\":\"💻\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed managed-endpoint operations. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  All write operations are audited to a local SQLite DB under ~/.endpoint-aiops/ (relocatable via ENDPOINT_AIOPS_HOME).\n  Credentials: the endpoint-management server's API key is stored ENCRYPTED in ~/.endpoint-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'endpoint-aiops init' to onboard, or 'endpoint-aiops secret set <target>' to add one. The store is unlocked by a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var ENDPOINT_<TARGET_NAME_UPPER>_APIKEY is still honoured as a fallback with a deprecation warning (migrate with 'endpoint-aiops s"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"endpoint-aiops\",\n  \"version\": \"0.10.3\",\n  \"publishedAt\": 1789451698702\n}"},{"path":"references/agent-guardrails.md","content":"# Agent guardrails — running endpoint-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a write should happen is your decision, or the account's. The tool does\nnot gate it — there is no read-only switch and no approval prompt to configure.\nThe two right places to control read vs write:\n\n- **The account you connect with.** Give it a management-console account or API\n  token scoped to a read-only role. A write then fails at the server, which is\n  the only place the permission actually lives — no skill-side flag can be\n  argued around by a model, but a revoked permission cannot be.\n- **Your agent's system prompt.** If you want an observe-only session, tell the\n  model not to call the write tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.endpoint-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |\n| \"Don't invent a value when a field is missing\" | A field the management server did not return comes back as `null`, never as `\"\"`. An endpoint with no reported `patchLevel` is distinguishable from one reporting a blank level, and the key is always present. |\n| \"Tell me if the output was cut off\" | Every capped list is `{\"items\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is measured against the full result, not guessed from the row count matching the limit. |\n| \"Give me the real totals, not just what you can see\" | Counts are computed over the whole fleet, never over the capped list: `driftedCount`, `behindCount`, `nonCompliantCount`, `stormCount`, and the health-score `summary` are all uncapped. `complianceRatePct` is likewise a whole-fleet figure. |\n| \"Explain why something was flagged\" | Every flag carries its number: each health-score deduction is cited in that endpoint's `reasons`, each drift row states `expected` vs `actual`, and `login_storm_analysis` returns the `thresholds` it used. |\n| \"Confirm before anything destructive\" | `endpoint assign-profile` and `endpoint reboot` require `--dry-run`-a"},{"path":"references/capabilities.md","content":"# endpoint-aiops capabilities\n\n> 13 MCP tools (10 read, 3 write). REST paths are modelled generically against\n> an endpoint-management API and have not yet been exercised live\n> (see docs/VERIFICATION.md).\n\n## Read tools (10)\n\n| Tool | REST path | Returns |\n|------|----------------|---------|\n| `overview` | `GET /endpoints` (fold) | total, online, offline, stale[], agentVersionSpread, patchLevelSpread |\n| `endpoint_list` | `GET /endpoints` | id, hostname, os, osBuild, agentVersion, patchLevel, profileId, online, lastSeenHours |\n| `endpoint_get` | `GET /endpoints/{id}` | single endpoint detail (normalised) |\n| `endpoint_health_score` | injected only | endpointsEvaluated, baseline{agentVersion,patchLevel,source}, summary{healthy,degraded,critical}, worst{items[]{endpoint,score,band,reasons[]},returned,limit,truncated}, note |\n| `session_list` | `GET /sessions?since_hours=` | endpoint, user, loginMs, bootMs, timestamp, result |\n| `login_storm_analysis` | `GET /sessions` or injected | stormCount, storms/slowestByLogin/slowestByBoot (each {items[],returned,limit,truncated}), slowLoginCount, failedLogins, thresholds |\n| `drift_report` | `GET /endpoints` or injected | baseline, driftByField, driftedEndpoints{items[],returned,limit,truncated}, drifted/compliant counts |\n| `patch_status` | `GET /endpoints` or injected | targetPatch, distribution, behind{items[],returned,limit,truncated}, behindCount |\n| `patch_compliance` | injected only | endpointsEvaluated, targetPatch, targetSource, slaTargetPct, complianceRatePct, compliantCount, verdict, nonCompliantCount, nonCompliant{items[],returned,limit,truncated}, note |\n| `undo_list` | local undo store | recorded, not-yet-applied reversible writes: undos[]{undoId, ts, originalTool, inverseTool, note}, returned, limit, truncated |\n\nThe analysis tools accept an injected `sessions=` / `endpoints=` list for\npure/offline analysis. `login_storm_analysis`, `drift_report` and `patch_status`\nalso pull live from a configured `target`; `endpoint_health_score` and\n`patch_compliance` are injected-only (they score rows you already hold, e.g.\nfrom `endpoint_list`).\n\n## Write tools (3)\n\n| Tool | Risk | REST path | Undo / safety |\n|------|------|----------------|---------------|\n| `endpoint_assign_profile` | **high** | `POST /endpoints/{id}/profile` | captures the prior profile; records an inverse \"reassign prior profile\" undo descriptor; CLI double-confirm + dry-run |\n| `endpoint_reboot` | medium | `POST /endpoints/{id}/reboot` | captures prior online state; no safe inverse, no undo; CLI double-confirm + dry-run |\n| `undo_apply` | medium | local undo store → inverse tool | executes a recorded inverse; the inverse runs through its own governed tool (its real risk tier is recorded there); single-use token; supports `dry_run` |\n\n## Out of scope (by design)\n\n- Endpoint **enrollment / de-enrollment**\n- Image / OTA / firmware push\n- Profile CRUD (create/delete config profiles) and user/group management\n- OT / industrial equipment ("},{"path":"references/cli-reference.md","content":"# endpoint-aiops CLI reference\n\n> REST paths are modelled generically against an endpoint-management API and\n> have not yet been exercised live (see docs/VERIFICATION.md).\n\n## Setup & diagnostics\n\n```bash\nendpoint-aiops init                      # interactive onboarding wizard\nendpoint-aiops doctor [--skip-auth]      # config + secret store + connectivity (/version)\nendpoint-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n## Secrets (encrypted store ~/.endpoint-aiops/secrets.enc)\n\n```bash\nendpoint-aiops secret set <target> [--value <key>]   # store API key (hidden prompt if no --value)\nendpoint-aiops secret list                            # names only — values never shown\nendpoint-aiops secret rm <target>\nendpoint-aiops secret migrate                         # import legacy plaintext .env (ENDPOINT_<T>_APIKEY)\nendpoint-aiops secret rotate-password                 # re-encrypt under a new master password\n```\n\n## Read commands\n\n```bash\nendpoint-aiops overview [--target <t>]        # online/offline, stale endpoints, agent/patch spread\nendpoint-aiops endpoint list                  # all managed endpoints\nendpoint-aiops endpoint get <endpoint_id>     # one endpoint detail\nendpoint-aiops session list [--since-hours 24]           # recent login/boot sessions\nendpoint-aiops session storm [--since-hours 24] [--window-s 300] [--min-concurrent 10]\nendpoint-aiops drift report                   # endpoints drifted from the fleet-majority baseline\nendpoint-aiops drift patch [--target-patch <level>]      # patch-level distribution + who's behind\n```\n\n## Write commands (governed; risk tier in parentheses)\n\n```bash\nendpoint-aiops endpoint assign-profile <endpoint_id> <profile_id> [--dry-run]   # (high) reversible; double confirm\nendpoint-aiops endpoint reboot <endpoint_id> [--dry-run]                        # (medium) no undo; double confirm\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default/first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- State-changing commands (`endpoint assign-profile`, `endpoint reboot`) require two confirmations"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2149,"uniquenessScore":40,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T11:40:15.748Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T11:40:15.748Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T14:46:12.411Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}