mirror of
https://github.com/kamranahmedse/developer-roadmap.git
synced 2026-09-24 15:00:31 +08:00
chore: sync content to repo (#9830)
Co-authored-by: kamranahmedse <4921183+kamranahmedse@users.noreply.github.com>
This commit is contained in:
co-authored by
kamranahmedse
parent
626fb5d089
commit
a8a620be98
@@ -0,0 +1,7 @@
|
||||
# Agent Loop
|
||||
|
||||
When Open Claw receives a message, it runs a full agent loop rather than returning a single response. The loop validates the message, resolves the model, assembles the system prompt from skills and context files, and then sends everything to the model for inference. If the model decides to call a tool, like running a command, reading a file, or searching the web, the loop executes it, feeds the result back to the model, and continues until no more tool calls are needed and a final reply is ready. If the session gets too long for the context window, compaction kicks in automatically before retrying.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@article@Agent Loop](https://docs.openclaw.ai/concepts/agent-loop)
|
||||
@@ -1,6 +1,6 @@
|
||||
# AGENTS.md
|
||||
|
||||
AGENTS.md describes the agents available in your workspace, their roles, and how they relate to each other. It is used when running multiple agents to clarify who does what.
|
||||
[AGENTS.md](http://AGENTS.md) describes the agents available in your workspace, their roles, and how they relate to each other. It is used when running multiple agents to clarify who does what.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
# /allowlist
|
||||
|
||||
`/allowlist` lists, adds, or removes entries from the sender allowlist that controls who can interact with the agent. Add and remove operations require `commands.config: true` to be set in your configuration.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
- [@official@Allowlists (DM + groups) - terminology](https://docs.openclaw.ai/gateway/security#allowlists-dm-+-groups-terminology)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Automating Tasks
|
||||
|
||||
Open Claw supports several mechanisms for running tasks automatically, including hooks, webhooks, heartbeats, and cron jobs, so your agent can act without waiting for a human to send a message.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Automation Overview](https://docs.openclaw.ai/automation)
|
||||
@@ -0,0 +1,7 @@
|
||||
# openclaw backup create
|
||||
|
||||
`openclaw backup create` generates a snapshot of your Open Claw configuration and memory files so you can restore your setup if something goes wrong.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@backup](https://docs.openclaw.ai/cli/backup#backup)
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# Bind the Gateway to Localhost
|
||||
|
||||
Binding to localhost means the gateway only accepts connections from the same machine, not from the open internet. You can then use a reverse proxy or Tailscale to selectively expose it.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Gateway Runbook](https://docs.openclaw.ai/gateway)
|
||||
- [@official@Tailscale](https://docs.openclaw.ai/gateway/tailscale)
|
||||
@@ -0,0 +1,7 @@
|
||||
# openclaw channels add --channel
|
||||
|
||||
`openclaw channels add --channel` adds a new communication channel to your Open Claw setup, specifying which platform to connect.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Add / remove accounts](https://docs.openclaw.ai/cli/channels#add-/-remove-accounts)
|
||||
@@ -0,0 +1,7 @@
|
||||
# openclaw channels list
|
||||
|
||||
`openclaw channels list` displays all the communication channels currently connected to your Open Claw gateway, along with their status.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Common Commands](https://docs.openclaw.ai/cli/channels#add-/-remove-accounts)
|
||||
@@ -0,0 +1,7 @@
|
||||
# openclaw channels login
|
||||
|
||||
`openclaw channels login` initiates the authentication flow for a specific channel, allowing Open Claw to connect to it on your behalf.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Login / logout (interactive)](https://docs.openclaw.ai/cli/channels#add-/-remove-accounts)
|
||||
@@ -0,0 +1,7 @@
|
||||
# openclaw channels remove --channel
|
||||
|
||||
`openclaw channels remove --channel` disconnects and removes a channel from your Open Claw configuration.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Add / remove accounts](https://docs.openclaw.ai/cli/channels#add-/-remove-accounts)
|
||||
@@ -0,0 +1,7 @@
|
||||
# openclaw channels status --probe
|
||||
|
||||
`openclaw channels status --probe` actively checks the connection status of your channels by probing them, rather than just reporting cached status.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Status / capabilities / resolve / logs](https://docs.openclaw.ai/cli/channels#status-/-capabilities-/-resolve-/-logs)
|
||||
@@ -0,0 +1,8 @@
|
||||
# /compact
|
||||
|
||||
`/compact` is a text-only command that compresses or summarizes the current conversation context to free up space in the context window without losing essential information. You can optionally pass instructions to guide how the compaction is done.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
- [@official@Compaction](https://docs.openclaw.ai/concepts/compaction)
|
||||
@@ -0,0 +1,8 @@
|
||||
# /config
|
||||
|
||||
`/config` reads and writes your on-disk `openclaw.json` configuration file directly from chat. It is disabled by default and requires `commands.config: true` in your config to enable. It supports `show`, `get`, `set`, and `unset` subcommands and is owner-only.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Config updates](https://docs.openclaw.ai/tools/slash-commands#config-updates)
|
||||
- [@official@Gateway Configuration](https://docs.openclaw.ai/gateway/configuration)
|
||||
@@ -0,0 +1,7 @@
|
||||
# /context
|
||||
|
||||
`/context` explains what context the agent is currently working with. You can use `/context list` for a summary, `/context detail` for a breakdown of per-file, per-tool, per-skill, and system prompt sizes, or `/context json` for machine-readable output.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands#command-list)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Creating Plugins
|
||||
|
||||
You can build your own plugins to add custom functionality to Open Claw, such as integrating a new service or adding a new type of tool the agent can call.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Building Plugins](https://docs.openclaw.ai/plugins/building-plugins)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Creating Skills
|
||||
|
||||
You can write your own skills by creating a `SKILL.md` file with instructions and placing it in your workspace's `skills/` folder. This lets you teach the agent new behaviors tailored to your specific needs.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Creating Skills](https://docs.openclaw.ai/tools/creating-skills)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw cron add
|
||||
|
||||
`openclaw cron add` registers a new scheduled task, letting you define what the agent should do and when it should trigger automatically.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Scheduled Tasks](https://docs.openclaw.ai/automation/cron-jobs)
|
||||
- [@official@Cron](https://docs.openclaw.ai/cli/index#cron)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Cron Jobs
|
||||
|
||||
Cron jobs are scheduled tasks that run at specific times or intervals. They allow you to automate recurring actions like summaries, cleanups, or reports without any human prompt.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Scheduled Tasks](https://docs.openclaw.ai/automation/cron-jobs)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw cron list
|
||||
|
||||
`openclaw cron list` shows all the scheduled tasks currently registered in Open Claw along with their schedules and status.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Scheduled Tasks](https://docs.openclaw.ai/automation/cron-jobs)
|
||||
- [@official@Cron](https://docs.openclaw.ai/cli/index#cron)
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# Deploy on an Isolated VPS, VM, or Dedicated Device
|
||||
|
||||
Running Open Claw on a dedicated, isolated machine rather than your personal computer limits the blast radius if something goes wrong and keeps your agent separate from your sensitive personal data.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Security](https://docs.openclaw.ai/gateway/security)
|
||||
- [@official@Remote Access](https://docs.openclaw.ai/gateway/remote#macos-persistent-ssh-tunnel-via-launchagent)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw doctor --deep
|
||||
|
||||
`openclaw doctor --deep` is an extended version of `openclaw doctor` that performs a more thorough diagnostic check, scanning system services for extra gateway installs and deeper configuration issues that the standard check might miss. You can add the `--yes` flag to automatically accept any prompts without manual input, which is useful for running the command in a headless or
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Doctor](https://docs.openclaw.ai/gateway/doctor)
|
||||
- [@official@doctor](https://docs.openclaw.ai/cli/doctor)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw doctor
|
||||
|
||||
The `openclaw doctor` command checks your Open Claw installation for common configuration problems and misconfigurations. It is the first thing to run when something is not working as expected.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Doctor](https://docs.openclaw.ai/gateway/doctor)
|
||||
- [@official@doctor](https://docs.openclaw.ai/cli/doctor)
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# Enable Device Pairing and Maintain a Minimal Sender Allowlist
|
||||
|
||||
Device pairing ensures only verified devices can talk to your agent. Keeping the allowlist minimal means only the people or systems you explicitly trust can send it messages.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Pairing](https://docs.openclaw.ai/channels/pairing#pairing)
|
||||
- [@official@Allowlists (DM + groups) - terminology](https://docs.openclaw.ai/gateway/security/index#allowlists-dm-+-groups-terminology)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Event Types
|
||||
|
||||
Open Claw hooks support a range of event types, including command events like `/new` and `/reset`, session events like compaction, agent bootstrap events, gateway startup events, and message received and sent events.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Event Types](https://docs.openclaw.ai/automation/hooks#event-types)
|
||||
@@ -0,0 +1,8 @@
|
||||
# /fast
|
||||
|
||||
`/fast` is a directive that toggles fast mode for the current session. It takes `on`, `off`, or `status` as arguments. Fast mode maps to different provider-level behaviors depending on your model — for example, `service_tier=priority` on OpenAI or `service_tier=auto` on Anthropic. Omitting the argument shows the current effective fast-mode state.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Fast mode (/fast)](https://docs.openclaw.ai/tools/thinking#fast-mode-/fast)
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# openclaw gateway start | stop | restart
|
||||
|
||||
`openclaw gateway start`, `openclaw gateway stop`, and `openclaw gateway restart` control the lifecycle of the Open Claw gateway process, starting it up, shutting it down, or restarting it after a configuration change.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Gateway Runbook](https://docs.openclaw.ai/gateway)
|
||||
- [@official@Manage the Gateway service](https://docs.openclaw.ai/cli/gateway#manage-the-gateway-service)
|
||||
@@ -1,4 +1,4 @@
|
||||
# Gateway
|
||||
# Gateway
|
||||
|
||||
The Gateway is the single always-on process that handles routing, the control plane, and all channel connections. It runs on a single multiplexed port that serves the WebSocket control and RPC interface, HTTP APIs, the Control UI, and hooks. By default, it binds to localhost and requires an auth token before accepting any connections.
|
||||
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw gateway
|
||||
|
||||
`openclaw gateway` is the main command for interacting with the gateway process. It is the entry point for all gateway-related operations from the command line.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Gateway Runbook](https://docs.openclaw.ai/gateway)
|
||||
- [@official@gateway](https://docs.openclaw.ai/cli/gateway#gateway)
|
||||
@@ -0,0 +1,8 @@
|
||||
# HEARTBEAT.md
|
||||
|
||||
HEARTBEAT.md is a workspace configuration file where you define what the agent should do during each heartbeat cycle — essentially a set of instructions for proactive, time-based behavior.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@HEARTBEAT.md](https://docs.openclaw.ai/gateway/heartbeat#heartbeat-md-optional)
|
||||
- [@official@HEARTBEAT.md Template](https://docs.openclaw.ai/reference/templates/HEARTBEAT)
|
||||
@@ -0,0 +1,8 @@
|
||||
# Heartbeats
|
||||
|
||||
Heartbeats are periodic signals the Gateway emits on a regular interval. They can be used to confirm the agent is alive and to trigger recurring background tasks without any human input.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Scheduled Tasks (Cron) vs Heartbeat](https://docs.openclaw.ai/automation#scheduled-tasks-cron-vs-heartbeat)
|
||||
- [@official@Heartbeat](https://docs.openclaw.ai/gateway/heartbeat)
|
||||
@@ -0,0 +1,7 @@
|
||||
# /help
|
||||
|
||||
`/help` displays a list of available slash commands and a brief description of what each one does. It also works as an inline shortcut, meaning it can be embedded in a normal message and will be stripped before the model sees the rest of the text.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Hook Structure
|
||||
|
||||
Each hook is a directory containing a `HOOK.md` file with metadata and a `handler.ts` file with the logic to run. The metadata defines which events to listen for and what requirements the hook needs to be eligible.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Hook Structure](https://docs.openclaw.ai/automation/hooks#hook-structure)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Hooks
|
||||
|
||||
Hooks are small scripts that run inside the Gateway when specific agent events fire, like `/new`, `/reset`, `/stop`, or lifecycle events. They are automatically discovered from directories and can be inspected with `openclaw hooks`.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Hooks](https://docs.openclaw.ai/automation/hooks)
|
||||
@@ -1,3 +1,5 @@
|
||||
# undefined
|
||||
|
||||
#How Open Claw Works
|
||||
|
||||
Open Claw runs a single long-lived Gateway that owns all messaging surfaces and exposes a typed WebSocket API for control-plane clients like the macOS app, CLI, and web UI. When a message arrives, the Gateway routes it to the appropriate agent, which then runs through a full loop of context assembly, model inference, and tool execution before streaming a reply back.
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
# Installation
|
||||
|
||||
Installation covers the steps to get Open Claw onto your chosen environment. It requires a recent version of Node.js, an API key from your chosen model provider, and takes around five minutes. The core install command is `npm install -g openclaw@latest`, after which you run openclaw onboard to connect your first model and channel. Always check the official documentation for the current Node.js version requirements before installing, as these may change between releases.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Getting Started](https://docs.openclaw.ai/start/getting-started)
|
||||
@@ -0,0 +1,8 @@
|
||||
# Installing from ClawHub
|
||||
|
||||
ClawHub is a community repository of pre-built skills. You can browse and install skills from ClawHub directly, saving time compared to building them from scratch.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@ClawHub](https://clawhub.ai/)
|
||||
- [@official@What is ClawHub?](https://docs.openclaw.ai/tools/clawhub)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Installing Plugins
|
||||
|
||||
Plugins are installed via `openclaw plugins install` followed by the package name or path. Once installed, they become available to all agents in your workspace.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Install and Configure](https://docs.openclaw.ai/tools/plugin)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Interval & Active Hours
|
||||
|
||||
You can configure how often heartbeats fire and restrict them to certain hours of the day, so your agent only runs automated tasks during times you define as active.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Heartbeat](https://docs.openclaw.ai/gateway/heartbeat#heartbeat-gateway)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Managing & Disabling Jobs
|
||||
|
||||
You can list, pause, and delete cron jobs from the command line, giving you control over which scheduled tasks are active at any given time.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Managing jobs](https://docs.openclaw.ai/automation/cron-jobs#managing-jobs)
|
||||
@@ -0,0 +1,8 @@
|
||||
# /mcp
|
||||
|
||||
`/mcp` manages OpenClaw-managed MCP server definitions from chat. It is disabled by default and requires `commands.mcp: true` to enable. It supports `show`, `get`, `set`, and `unset` subcommands and is owner-only
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@MCP Updates](https://docs.openclaw.ai/tools/slash-commands#mcp-updates)
|
||||
- [@official@mcp](https://docs.openclaw.ai/cli/mcp#mcp)
|
||||
@@ -0,0 +1,7 @@
|
||||
# MCP
|
||||
|
||||
MCP (Model Context Protocol) is an open standard for connecting AI models to external tools and data sources. Open Claw supports MCP, allowing your agent to call tools from any MCP-compatible server.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@mcp](https://docs.openclaw.ai/cli/mcp#mcp)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw memory index
|
||||
|
||||
`openclaw memory index` rebuilds the search index for all memory files, ensuring the agent can efficiently retrieve relevant information from its stored memories.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Memory overview](https://docs.openclaw.ai/concepts/memory#memory-overview)
|
||||
- [@official@memory](https://docs.openclaw.ai/cli/index#memory)
|
||||
@@ -0,0 +1,7 @@
|
||||
# openclaw memory search "query"
|
||||
|
||||
`openclaw memory search "query"` lets you search through the agent's stored memories using a keyword or phrase, useful for checking what the agent has remembered about past conversations or preferences.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Memory](https://docs.openclaw.ai/cli/index#memory)
|
||||
@@ -1,6 +1,6 @@
|
||||
# MEMORY.md
|
||||
|
||||
MEMORY.md is a persistent file where the agent stores important facts it has learned over time. It is regularly updated so the agent can recall relevant information in future conversations.
|
||||
[MEMORY.md](http://MEMORY.md) is a persistent file where the agent stores important facts it has learned over time. It is regularly updated so the agent can recall relevant information in future conversations.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
# /model
|
||||
|
||||
`/model` is a directive that lets you switch the AI model the agent is currently using. You can pass a number from the model picker, a full `provider/model` string, or use `/model list` to see available options.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Model selection (/model)](https://docs.openclaw.ai/tools/slash-commands#model-selection-/model)
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# openclaw models auth add
|
||||
|
||||
`openclaw models auth add` is the interactive auth helper. It can launch a provider auth flow (OAuth/API key) or guide you into manual token paste, depending on the provider you choose.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Model Providers](https://docs.openclaw.ai/concepts/model-providers#model-providers)
|
||||
- [@official@Auth Providers](https://docs.openclaw.ai/cli/models#auth-profiles)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw models auth setup-token
|
||||
|
||||
`openclaw models auth setup-token` stores the authentication token for a model provider, allowing Open Claw to make authenticated API calls on your behalf. It is part of the broader `models auth` command group, which also includes `add`, `login`, and `paste-token`.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Model Providers](https://docs.openclaw.ai/concepts/model-providers#model-providers)
|
||||
- [@official@Auth Providers](https://docs.openclaw.ai/cli/models#auth-profiles)
|
||||
@@ -0,0 +1,9 @@
|
||||
# openclaw models list | set | status
|
||||
|
||||
`openclaw models list`, `openclaw models set`, and `openclaw models status` let you view the AI models available in your setup, switch between them, and check which one is currently active.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@model list](https://docs.openclaw.ai/concepts/models#models-list)
|
||||
- [@official@models status](https://docs.openclaw.ai/concepts/models#models-status)
|
||||
- [@official@Common commands](https://docs.openclaw.ai/concepts/models?search=openclaw+models+set)
|
||||
@@ -0,0 +1,8 @@
|
||||
# Multi-Agents
|
||||
|
||||
Multi-agent mode lets you run several specialized agents in the same Open Claw gateway, each with its own workspace, auth profiles, and session store. They can operate independently or be coordinated through routing rules and shared memory.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Multi-Agent Routing](https://docs.openclaw.ai/concepts/multi-agent)
|
||||
- [@official@Sub-Agents](https://docs.openclaw.ai/tools/subagents)
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
# Never Hardcode API Keys
|
||||
|
||||
API keys stored directly in code or config files can be accidentally exposed through logs, version control, or error messages. Always use environment variables or a secrets manager instead.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Security](https://docs.openclaw.ai/gateway/security)
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
# Never Trust External Content to Prevent Prompt Injection
|
||||
|
||||
Prompt injection is an attack where malicious text in an email, webpage, or file tricks the agent into taking unintended actions. Treating all external content as untrusted input is a core security principle in Open Claw.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Threat Model](https://docs.openclaw.ai/security/THREAT-MODEL-ATLAS)
|
||||
@@ -0,0 +1,7 @@
|
||||
# /new
|
||||
|
||||
`/new` starts a fresh conversation with the agent, clearing the current context so you are beginning from a clean slate. It also triggers the session-memory hook to save the previous session before resetting. You can optionally pass a model name after `/new` to start the session with a specific model.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw onboard
|
||||
|
||||
`openclaw onboard` walks you through the initial setup process interactively, helping you connect your model provider and first channel step by step.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Onboarding: CLI](https://docs.openclaw.ai/start/wizard)
|
||||
- [@official@onboard](https://docs.openclaw.ai/cli/onboard)
|
||||
@@ -0,0 +1,8 @@
|
||||
# Onboarding
|
||||
|
||||
Onboarding is the guided first-run process that walks you through connecting your first AI model provider and communication channel so your agent is ready to receive and respond to messages. You can run it with `openclaw onboard`.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Onboarding Overview](https://docs.openclaw.ai/start/onboarding-overview)
|
||||
- [@official@Onboarding CLI](https://docs.openclaw.ai/start/wizard)
|
||||
@@ -1,6 +1,6 @@
|
||||
# Other Workspace Files
|
||||
|
||||
Open Claw recognizes several other special markdown files that are automatically injected into the agent's context at startup. BOOT.md contains instructions that the agent runs once when the Gateway starts. TOOLS.md describes the tools available to the agent and how they should be used. IDENTITY.md is an alternative or complement to SOUL.md for defining the agent's persona. BOOTSTRAP.md is a general-purpose file for injecting additional context into every session. On top of these recognized filenames, you can also add any other markdown files to your workspace, such as project notes, reference documents, or custom instructions for specific tasks.
|
||||
Open Claw recognizes several other special markdown files that are automatically injected into the agent's context at startup. [BOOT.md](http://BOOT.md) contains instructions that the agent runs once when the Gateway starts. [TOOLS.md](http://TOOLS.md) describes the tools available to the agent and how they should be used. [IDENTITY.md](http://IDENTITY.md) is an alternative or complement to [SOUL.md](http://SOUL.md) for defining the agent's persona. [BOOTSTRAP.md](http://BOOTSTRAP.md) is a general-purpose file for injecting additional context into every session. On top of these recognized filenames, you can also add any other markdown files to your workspace, such as project notes, reference documents, or custom instructions for specific tasks.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
# /plugins
|
||||
|
||||
`/plugins` lets you inspect discovered plugins and toggle their enablement from chat. It is disabled by default and requires `commands.plugins: true` to enable. It supports `list`, `show`, `install`, `enable`, and `disable` subcommands. Write operations are owner-only. Alias: `/plugin`.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
- [@official@Install and Configure](https://docs.openclaw.ai/tools/plugin)
|
||||
@@ -0,0 +1,9 @@
|
||||
# Plugins
|
||||
|
||||
Plugins are packages that can register any combination of capabilities: channels, model providers, tools, skills, speech, image generation, and more. Some are bundled with Open Claw, and others are published by the community on npm.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Tools and Plugins](https://docs.openclaw.ai/tools)
|
||||
- [@official@https://docs.openclaw.ai/tools/plugin](https://docs.openclaw.ai/tools/plugin)
|
||||
- [@official@https://docs.openclaw.ai/plugins/community](https://docs.openclaw.ai/plugins/community)
|
||||
@@ -0,0 +1,8 @@
|
||||
# /reasoning
|
||||
|
||||
`/reasoning` is a directive that enables or disables extended reasoning mode. It takes `on`, `off`, or `stream` as arguments. When set to `on`, the agent sends a separate message prefixed with `Reasoning:` before its final reply. `stream` enables Telegram draft streaming only. Alias: `/reason`.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
- [@official@Reasoning visibility (/reasoning)](https://docs.openclaw.ai/tools/thinking#reasoning-visibility-%2Freasoning)
|
||||
@@ -0,0 +1,7 @@
|
||||
# /reset
|
||||
|
||||
`/reset` resets the agent's current state, clearing any ongoing task or context and returning it to its idle state. Like `/new`, it triggers the session-memory hook before resetting.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
+3
@@ -0,0 +1,3 @@
|
||||
# Rotate All Credentials Immediately if a Breach is Suspected
|
||||
|
||||
If you think your setup has been compromised, changing all API keys, tokens, and passwords immediately limits how long an attacker can maintain access.
|
||||
@@ -0,0 +1,8 @@
|
||||
# Routing Rules
|
||||
|
||||
Routing rules determine which agent handles which incoming messages. Open Claw uses a deterministic, most-specific-wins system: peer matches beat channel-wide rules, which beat the fallback default agent.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Multi-Agent Routing](https://docs.openclaw.ai/concepts/multi-agent)
|
||||
- [@official@Channel Routing](https://docs.openclaw.ai/channels/channel-routing)
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
# Run OpenClaw as a Non-Root User
|
||||
|
||||
Running as a non-root user means that even if the agent is compromised, an attacker cannot gain full system access. It is a basic but important layer of defense for any production setup.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Security](https://docs.openclaw.ai/gateway/security)
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# Run `openclaw security audit --deep` After Every Config Change
|
||||
|
||||
Every configuration change is an opportunity to accidentally introduce a vulnerability. Running a deep security audit after changes catches problems before they become incidents.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Quick check: openclaw security audit](https://docs.openclaw.ai/gateway/security/index#quick-check-openclaw-security-audit)
|
||||
- [@official@Formal Verification (Security Models)](https://docs.openclaw.ai/security/formal-verification)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Securing Webhooks
|
||||
|
||||
The Webhooks plugin ensures that each route is protected by shared-secret authentication, rate limiting, request size guards, and in-flight request limiting. Use a strong unique secret per route, store it as a SecretRef rather than inline plaintext, and bind each route to the narrowest session that fits the workflow. If a secret cannot be resolved at startup, the plugin skips that route and logs a warning instead of exposing a broken endpoint.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Webhooks Plugin](https://docs.openclaw.ai/plugins/webhooks)
|
||||
@@ -0,0 +1,8 @@
|
||||
# openclaw security audit
|
||||
|
||||
`openclaw security audit` scans your Open Claw setup for potential security vulnerabilities such as exposed ports, weak tokens, or insecure configurations. You can also run `openclaw security audit --deep` for a live Gateway probe, or openclaw `security audit --fix` to automatically tighten safe defaults.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Quick check: openclaw security audit](https://docs.openclaw.ai/gateway/security#quick-check-openclaw-security-audit)
|
||||
- [@official@security](https://docs.openclaw.ai/cli/security)
|
||||
@@ -0,0 +1,7 @@
|
||||
# Security Risks (Skills)
|
||||
|
||||
Installing third-party skills carries risk since a skill can define instructions or tool access that could be misused. It is important to review skills from external sources before installing them.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Security and moderation](https://docs.openclaw.ai/tools/clawhub#security-and-moderation)
|
||||
@@ -0,0 +1,8 @@
|
||||
Security Risks (Plugins)
|
||||
|
||||
Plugins run at a deeper level than skills and can have significant access to your system. Open Claw installs plugin dependencies with `--ignore-scripts` to reduce risk, but you should still only install plugins from trusted sources.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Install and Configure](https://docs.openclaw.ai/tools/plugin)
|
||||
- [@official@Threat Model](https://docs.openclaw.ai/security/THREAT-MODEL-ATLAS)
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
# Set a Strong Gateway Auth Token
|
||||
|
||||
The auth token is the password that protects your gateway from unauthorized access. It should be long, random, and unique and never shared or committed to version control.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Security](https://docs.openclaw.ai/gateway/security)
|
||||
@@ -0,0 +1,8 @@
|
||||
# Skills
|
||||
|
||||
Skills are modular capability packages that extend what your agent can do. Each skill is a markdown file injected into the system prompt that gives the agent context and guidance for using specific tools or following specific workflows.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Skills](https://docs.openclaw.ai/tools/skills)
|
||||
- [@official@Skills Config](https://docs.openclaw.ai/tools/skills-config)
|
||||
@@ -1,6 +1,6 @@
|
||||
# SOUL.md
|
||||
|
||||
SOUL.md is the file where you define the agent's personality, tone, and core behavioral guidelines. Think of it as the agent's character sheet. It shapes how it communicates and makes decisions across all conversations.
|
||||
[SOUL.md](http://SOUL.md) is the file where you define the agent's personality, tone, and core behavioral guidelines. Think of it as the agent's character sheet. It shapes how it communicates and makes decisions across all conversations.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
|
||||
+8
@@ -0,0 +1,8 @@
|
||||
# Start in Read-Only Mode and Widen Permissions Deliberately
|
||||
|
||||
Starting with minimal permissions and only expanding them as needed is a safer approach than granting broad access upfront. Open Claw supports tool allow and deny lists per agent to help enforce this.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Security](https://docs.openclaw.ai/gateway/security)
|
||||
- [@official@Sandboxing](https://docs.openclaw.ai/gateway/sandboxing)
|
||||
@@ -0,0 +1,7 @@
|
||||
# /status
|
||||
|
||||
`/status` asks the agent to report its current state, including active tasks, connected channels, and any pending operations. It also shows provider usage and quota for the current model provider when usage tracking is enabled.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
@@ -0,0 +1,7 @@
|
||||
# /stop
|
||||
|
||||
`/stop` interrupts the agent if it is currently in the middle of a task or loop, bringing it to a halt immediately. It targets the active chat session directly so it can abort the current run.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
@@ -0,0 +1,8 @@
|
||||
# /think
|
||||
|
||||
`/think` is a directive that sets the agent's thinking level before responding. It takes `off`, `minimal`, `low`, `medium`, `high`, or `xhigh` as arguments. Higher levels make the agent reason more deeply before giving a final answer, which is useful for complex or ambiguous tasks. Aliases: `/thinking`, `/t`.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
- [@official@Thinking Levels](https://docs.openclaw.ai/tools/thinking)
|
||||
+3
@@ -0,0 +1,3 @@
|
||||
# Update OpenClaw Regularly
|
||||
|
||||
Open Claw releases often include security patches. Staying up to date ensures you are not running with known vulnerabilities that have already been fixed upstream.
|
||||
@@ -0,0 +1,7 @@
|
||||
# Usage Best Practices
|
||||
|
||||
To get the most out of Open Claw, run `openclaw doctor` regularly to catch configuration drift early, and always run openclaw `security audit --deep` after any config change. Keep your workspace files like SOUL.md, USER.md, and MEMORY.md up to date so the agent always has accurate context about who you are and how you want it to behave. Use `/new` at the start of a new topic rather than letting a single session grow indefinitely, which keeps the context window clean and triggers the session-memory hook to save what was discussed. Start with a minimal tool allowlist and only expand permissions when you have a specific need, and prefer Tailscale over open ports for any remote access to keep your Gateway secure without extra complexity.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@CLI Reference](https://docs.openclaw.ai/cli)
|
||||
@@ -0,0 +1,7 @@
|
||||
# /usage
|
||||
|
||||
`/usage` controls the per-response usage footer appended to normal replies. It takes `off`, `tokens`, `full`, or `cost` as arguments. `/usage cost` prints a local cost summary from your Open Claw session logs rather than appending it to each reply.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Slash Commands](https://docs.openclaw.ai/tools/slash-commands)
|
||||
@@ -1,6 +1,6 @@
|
||||
# USER.md
|
||||
|
||||
USER.md contains information about you: your preferences, context, and anything you want the agent to know about you by default. The agent reads this to personalize its responses.
|
||||
[USER.md](http://USER.md) contains information about you: your preferences, context, and anything you want the agent to know about you by default. The agent reads this to personalize its responses.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
# Webhooks
|
||||
|
||||
Webhooks allow external services to send HTTP requests to Open Claw to trigger agent actions. This is how you can connect third-party tools like GitHub or custom apps to your agent.
|
||||
|
||||
Visit the following resources to learn more:
|
||||
|
||||
- [@official@Webhooks](https://docs.openclaw.ai/automation/cron-jobs#webhooks)
|
||||
Reference in New Issue
Block a user