How-to

OpenClaw Skills: Where They Live, How to Install Them and What ClawHub Is

How OpenClaw skills work: the seven folders it reads and which wins, how to install one from ClawHub or GitHub, what gating does, and what to vet first.

By Updated 6 min read

OpenClaw skills are ordinary SKILL.md folders that the OpenClaw assistant loads from seven places, in a fixed order of precedence, and you can install them from ClawHub, from GitHub or by copying a folder. This how-to explains where OpenClaw looks, which copy wins when names collide, the commands for each install route, how requirement gating works and what to check before trusting a skill you did not write.

It is built from the OpenClaw documentation for skills and ClawHub, plus the verified install data on the directory's OpenClaw page. The editorial team did not run a live OpenClaw instance for this guide.

What an OpenClaw skill is

OpenClaw is an open-source assistant that runs on your own machine and answers through chat apps. Its skills follow the same Agent Skills format as skills for Claude Code and Codex: a folder with a SKILL.md, YAML frontmatter on top and Markdown instructions below. The post on what Claude skills are explains the format in general terms.

Two frontmatter keys are required, name and description. Optional keys include user-invocable, disable-model-invocation, command-dispatch, command-tool and homepage. A skill can also carry a metadata.openclaw block that declares what it needs, which OpenClaw checks when it loads the skill:

  • requires.bins for binaries that must be on the PATH
  • requires.env for environment variables
  • requires.config for paths that must exist in openclaw.json
  • os to restrict the skill to darwin, linux or win32
  • always to skip the other checks

A skill whose requirements are not met does not appear in the agent's list. That makes gating useful for skills that wrap a command-line tool, because the skill disappears instead of failing halfway through a task.

Where OpenClaw looks for skills, and which one wins

OpenClaw reads skills from seven sources. If the same skill name appears in more than one, the highest source takes precedence.

RankSourceLocation
1Workspace skills<workspace>/skills
2Project agent skills<workspace>/.agents/skills
3Personal agent skills~/.agents/skills
4Managed or local skills<state-dir>/skills, by default ~/.openclaw/skills
5Workshop skills<state-dir>/agents/<agentId>/agent/workshop-skills
6Bundled skillsShipped with OpenClaw
7Extra directoriesskills.load.extraDirs and plugin skills

The practical difference is reach. A skill in a workspace is visible to that agent only, while one in the managed folder is shared by every agent on the same state directory. The personal ~/.agents/skills folder applies in the default state only, according to the directory's verified install data. If a shared skill behaves oddly, look in the workspace folder first for a same-named override.

OpenClaw finds SKILL.md files up to six levels below a skills root, so you can group skills in subfolders. The slash command comes from the name field, or from the folder name when name is missing.

How to install an OpenClaw skill

There are four routes. Pick the one that matches where the skill lives.

From ClawHub

ClawHub is the quickest route for published skills. Search, then install by publisher and slug:

openclaw skills search "calendar"
openclaw skills install @owner/<slug>
openclaw skills update --all

The documentation's own example is openclaw skills install @openclaw/demo. Add --global to put the skill in the managed folder for every agent, and use openclaw skills verify @owner/<slug> to check its trust information first. openclaw skills update covers ClawHub installs only.

From a Git repository

OpenClaw's installer expects SKILL.md at the root of the source. For a repository where the root is the skill, one command is enough:

openclaw skills install git:owner/repo@ref

For a skill inside a larger repository, clone it and point the installer at the folder, using --as to set the slug. Reinstall to refresh a Git install, since update does not track it.

With the skills CLI or GitHub CLI

Two cross-agent tools list OpenClaw as a target:

npx skills add owner/repo --skill name -a openclaw
gh skill install owner/repo name --agent openclaw

OpenClaw's own documentation does not mention either tool, and GitHub's manual does not say which folder gh skill writes to for OpenClaw. After either command, run openclaw skills check to confirm the skill loaded.

By copying the folder

Copy the skill folder into <workspace>/skills for one agent or ~/.openclaw/skills for all of them. This is the right route when you want to read every file first.

Check, update and migrate

openclaw skills check reports a skill that is installed but not ready, for example because a binary is missing, or one hidden by an allowlist. OpenClaw snapshots eligible skills when a session starts and refreshes the list when its watcher sees a SKILL.md change. An existing chat keeps its snapshot until the next turn picks up the new one.

Allowlists control what each agent can see. agents.defaults.skills sets the default list, and agents.entries.<id>.skills overrides it for one agent. A non-empty per-agent list is final and does not merge with the default, and the documentation's example uses an empty list for a locked-down agent.

If you have Codex skills, note that OpenClaw does not read Codex's skills folder. Run openclaw migrate plan codex to see what would move and openclaw migrate codex to copy them into your workspace. The Codex skills guide explains where those skills come from.

Old metadata no longer works. The directory's data notes that the pre-July 2026 metadata.clawdbot block and .clawdhub folder are not read any more, so rename them to metadata.openclaw and .clawhub.

What ClawHub stores

ClawHub is a registry for skills and plugins. The documentation says it keeps versions as semver, tags such as latest, changelogs, files, downloads, stars and security scan summaries. It runs automated checks on published skills and plugin releases, and signed-in users can report a skill, after which moderators can hide or restore content.

Publishing uses a separate clawhub command-line tool, installed with npm i -g clawhub. Its documented publish command takes a folder plus a slug, name and version. The same tool has its own install command that writes into ./skills and records versions in .clawhub/lock.json, so a lock file in a project is a sign someone used it.

Community collections also exist on GitHub. The directory indexes LeoYeAI/openclaw-master-skills, which its README describes as a curated collection of OpenClaw skills organized by category and installable through ClawHub. The directory lists well over a thousand skill folders from it, most MIT licensed, with some Apache-2.0, MIT-0, GPL and proprietary entries, and it flags a few dozen with a warning from its static check. Treat a collection that large as a catalog to browse, not a set to install in bulk. The directory also lists skills from the openclaw/clawhub repository, which are mostly working skills for the ClawHub codebase itself and for services such as Axiom and Convex.

What to vet before you trust a skill

OpenClaw's documentation says to treat third-party skills as untrusted code, to read them before enabling them, and to prefer sandboxed runs for untrusted inputs and risky tools. That advice deserves attention because an assistant that talks to your chat accounts and files can act on a skill's instructions.

  1. Read SKILL.md and every bundled file. A skill can include scripts as well as instructions.
  2. Check metadata.openclaw. It tells you which binaries, environment variables and config paths the skill wants.
  3. Look at the scan results and run openclaw skills verify. Both help, but neither proves a skill is safe.
  4. Keep credentials out of the skill. The documentation notes that environment injection applies to the host run, not sandboxed execution, and that secrets should stay out of skill content.
  5. Start narrow. Install into one workspace and give it an allowlist before moving a skill to the shared folder.
  6. Count the context cost. The documentation says each eligible skill adds about 24 tokens plus the lengths of its name, description and location to the system prompt, and that OpenClaw shortens descriptions when the block exceeds skills.limits.maxSkillsPromptChars.

For general habits when installing skills from any registry, the skill management topic collects relevant skills, and the Claude Code page shows how another agent handles the same decisions.

Frequently asked questions

What are OpenClaw skills?

OpenClaw skills are folders containing a SKILL.md file with name and description frontmatter, written in the Agent Skills format. They teach the assistant how and when to use tools. Because the format is shared with other agents, a skill written for one tool often loads in OpenClaw unchanged.

What is ClawHub?

ClawHub, at clawhub.ai, is OpenClaw's public registry for skills and plugins. It stores versioned bundles with tags, changelogs and security scan summaries, and OpenClaw can search it and install from it with openclaw skills search and openclaw skills install.

Where do I put a skill so OpenClaw finds it?

For one agent, put the folder in the skills directory of that agent's workspace. For every agent on the same state directory, use the managed skills folder, which is ~/.openclaw/skills by default. A same-named skill in the workspace overrides the shared one.

Is it safe to install skills from ClawHub?

OpenClaw's documentation tells you to treat third-party skills as untrusted code and read them before enabling them. ClawHub shows automated scan results and the openclaw skills verify command checks trust information, but both are aids, not guarantees. Read the SKILL.md and any bundled scripts yourself.

Can I use skills written for Claude Code or Codex in OpenClaw?

Usually yes, since OpenClaw follows the Agent Skills specification and needs only name and description in the frontmatter. Skills that depend on a particular agent's tools or hooks may not work. Codex's own skills folder is not read by OpenClaw, so migrate those skills explicitly.