Show Me Your Work Decision Log
cursor/plugins
Keeps a TSV decision log for long or unattended agent runs, one row per decision with what, why, evidence and result, so a reviewer can check the work later.
Precision decisioning, agentic trust, and verifiable identity for autonomous agents
$ npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills kevros --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kevros .claude/skills/kevros && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kevros" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/kevros into .claude/skills/kevros/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kevros", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/kevrosType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills kevros --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kevros .agents/skills/kevros && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kevros" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/kevros into .agents/skills/kevros/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kevros", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills kevros --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kevros .cursor/skills/kevros && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kevros" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/kevros into .cursor/skills/kevros/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kevros", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/kevros--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills kevros --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kevros .gemini/skills/kevros && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kevros" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/kevros into .gemini/skills/kevros/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kevros", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills kevrosInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kevros .github/skills/kevros && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kevros" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/kevros into .github/skills/kevros/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kevros", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills kevros --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kevros .opencode/skills/kevros && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kevros" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/kevros into .opencode/skills/kevros/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kevros", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kevrosPrecision decisioning, agentic trust, and verifiable identity for autonomous agents
Kevros is an agent skill from LeoYeAI/openclaw-master-skills. Precision decisioning, agentic trust, and verifiable identity for autonomous agents
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files (for example `README.md`, `_meta.json` and `dist/client.d.ts`).
It sits in Agent Workflows, covering Autonomous loops. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (TypeScript and JavaScript), which the agent can run.
Shell commands in SKILL.md call:
curlpipuvFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
governance.taskhawktech.comtaskhawktech.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
KEVROS_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kevros loads about 4.9k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 1,423 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,423 words, ~4,896 tokens.
.claude/skills/kevros/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.Cryptographic governance for autonomous agents: precision decisioning, provenance attestation, intent binding, capability delegation, policy analysis, and compliance export.
Every decision gets a signed release token. Every action gets a hash-chained record. Every intent gets a cryptographic binding to its command. Downstream services verify independently — no callbacks, no trust assumptions.
Base URL: https://governance.taskhawktech.com
This plugin sends data to the Kevros governance gateway. Understand what is transmitted before installing.
Before tool execution (before_tool_call hook):
POST /governance/verify for policy evaluation.After tool execution (after_tool_call hook):
POST /governance/attest.autoAttest: false in config.Network behavior:
https://governance.taskhawktech.com.KEVROS_API_KEY is not set, the plugin calls POST /signup to auto-provision a free-tier key on first use (1,000 calls/month). Set the key explicitly to avoid implicit network signup.enforce mode (default), unreachable gateway blocks high-risk tool calls. Use advisory mode for evaluation — it logs decisions without blocking.Get an API key (free, instant, no payment):
curl -X POST https://governance.taskhawktech.com/signup \
-H "Content-Type: application/json" \
-d '{"agent_id": "your-agent-id"}'Response:
{
"api_key": "kvrs_...",
"tier": "free",
"monthly_limit": 1000,
"usage": {
"header": "X-API-Key"
}
}Use the API key in all subsequent requests via the X-API-Key header.
POST /governance/verify
Verify an action against policy bounds before execution. Returns ALLOW, CLAMP, or DENY with a cryptographic release token that any downstream service can verify independently.
Request:
{
"action_type": "api_call",
"action_payload": {
"endpoint": "/deploy",
"service": "api-v2",
"replicas": 3
},
"agent_id": "your-agent-id",
"policy_context": {
"max_values": { "replicas": 5 },
"forbidden_keys": ["sudo", "force"]
}
}Response:
{
"decision": "ALLOW",
"verification_id": "a1b2c3d4-...",
"release_token": "f7a8b9c0...",
"applied_action": {
"endpoint": "/deploy",
"service": "api-v2",
"replicas": 3
},
"reason": "All values within policy bounds",
"epoch": 42,
"provenance_hash": "e3b0c442...",
"timestamp_utc": "2026-02-26T12:00:00Z"
}release_token is proof.applied_action instead of your original.release_token is null.Share the release_token with collaborating agents so they can independently verify the decision.
POST /governance/attest
Record a completed action in a hash-chained, append-only evidence ledger. Each attestation extends your provenance chain. Your raw payload is SHA-256 hashed — actual data is never stored.
Request:
{
"agent_id": "your-agent-id",
"action_description": "Deployed api-v2 with 3 replicas",
"action_payload": {
"service": "api-v2",
"replicas": 3,
"status": "success"
},
"context": {
"environment": "production",
"triggered_by": "scheduled"
}
}Response:
{
"attestation_id": "b2c3d4e5-...",
"epoch": 43,
"hash_prev": "e3b0c442...",
"hash_curr": "a1b2c3d4...",
"timestamp_utc": "2026-02-26T12:00:01Z",
"chain_length": 43
}A longer chain with consistent outcomes builds a higher trust score over time.
POST /governance/bind
Bind a declared intent to a specific command. Creates a cryptographic link between what you plan to do and the command that does it. Prove later that you did exactly what you said you would.
Request:
{
"agent_id": "your-agent-id",
"intent_type": "MAINTENANCE",
"intent_description": "Scale api-v2 to handle traffic spike",
"command_payload": {
"action": "scale",
"service": "api-v2",
"replicas": 5
},
"goal_state": {
"replicas": 5,
"healthy": true
}
}Response:
{
"intent_id": "c3d4e5f6-...",
"intent_hash": "d4e5f6a7...",
"binding_id": "e5f6a7b8-...",
"binding_hmac": "a7b8c9d0...",
"command_hash": "b8c9d0e1...",
"epoch": 44,
"timestamp_utc": "2026-02-26T12:00:02Z"
}Save intent_id and binding_id to verify outcomes later.
POST /governance/verify-outcome
Verify whether a bound intent achieved its goal state. Free when used with a prior bind() call.
Request:
{
"agent_id": "your-agent-id",
"intent_id": "c3d4e5f6-...",
"binding_id": "e5f6a7b8-...",
"actual_state": {
"replicas": 5,
"healthy": true
},
"tolerance": 0.1
}Response:
{
"verification_id": "f6a7b8c9-...",
"intent_id": "c3d4e5f6-...",
"status": "ACHIEVED",
"achieved_percentage": 100.0,
"discrepancy": null,
"evidence_hash": "c9d0e1f2...",
"timestamp_utc": "2026-02-26T12:00:03Z"
}Status values: ACHIEVED, PARTIALLY_ACHIEVED, FAILED, BLOCKED, TIMEOUT. Free when used with a prior bind() call.
POST /governance/bundle — $0.05 per call
Export your agent's full cryptographic trust record for compliance, auditing, or regulatory review.
Request:
{
"agent_id": "your-agent-id",
"time_range_start": "2026-02-25T00:00:00Z",
"time_range_end": "2026-02-26T12:00:00Z",
"include_intent_chains": true,
"include_pqc_signatures": true,
"include_verification_instructions": true
}Response:
{
"bundle_id": "d4e5f6a7-...",
"agent_id": "your-agent-id",
"record_count": 42,
"truncated": false,
"chain_integrity": true,
"time_range": {"start": "2026-02-25T00:00:00Z", "end": "2026-02-26T12:00:00Z"},
"records": ["..."],
"intent_chains": ["..."],
"pqc_signatures": ["..."],
"verification_instructions": "Recompute SHA-256...",
"bundle_hash": "e5f6a7b8...",
"timestamp_utc": "2026-02-26T12:00:04Z"
}POST /governance/batch
Execute up to 100 governance operations (verify, attest, bind) in a single call. Each sub-operation is metered individually at standard rates. Use for bulk processing or multi-step workflows.
Request:
{
"agent_id": "your-agent-id",
"operations": [
{
"type": "verify",
"params": {
"action_type": "api_call",
"action_payload": {"endpoint": "/deploy", "replicas": 3}
}
},
{
"type": "attest",
"params": {
"action_description": "Deployment completed",
"action_payload": {"status": "success"}
}
}
],
"stop_on_deny": false
}Response:
{
"batch_id": "g7h8i9j0-...",
"agent_id": "your-agent-id",
"total": 2,
"executed": 2,
"results": [
{"index": 0, "type": "verify", "status": "ok", "result": {"decision": "ALLOW", "...": "..."}},
{"index": 1, "type": "attest", "status": "ok", "result": {"attestation_id": "...", "...": "..."}}
],
"summary": {"allow": 1, "clamp": 0, "deny": 0, "attest": 1, "bind": 0, "error": 0},
"batch_hash": "a1b2c3d4..."
}If stop_on_deny is true, processing halts on the first DENY decision.
POST /governance/delegate
Grant scoped, time-limited capabilities to another agent. The delegation is HMAC-signed and recorded in the provenance chain. Supports hierarchical sub-delegation with restrictive scope intersection.
Request:
{
"delegator_agent_id": "your-agent-id",
"delegatee_agent_id": "helper-agent-42",
"scope": {
"allowed_endpoints": ["verify", "attest"],
"policy_overrides": {"max_values": {"replicas": 3}},
"max_calls": 100
},
"ttl_seconds": 3600,
"description": "Handle deployment verification",
"allow_subdelegation": false
}Response:
{
"delegation_id": "h8i9j0k1-...",
"delegation_token": "f7a8b9c0...",
"delegator_agent_id": "your-agent-id",
"delegatee_agent_id": "helper-agent-42",
"scope": {"allowed_endpoints": ["verify", "attest"], "max_calls": 100},
"expires_utc": "2026-02-26T13:00:00Z",
"provenance_hash": "b8c9d0e1...",
"chain_depth": 1
}The delegatee passes the delegation_token as X-Delegate-Token header when acting on behalf of the delegator.
GET /governance/delegations/{agent_id} — list active delegations for an agent.
DELETE /governance/delegations/{delegation_id} — revoke an active delegation.
POST /governance/check-reversibility
Check whether an intent chain can be reversed. Pre-abort safety check for multi-step workflows.
Request:
{
"intent_id": "c3d4e5f6-...",
"include_children": true
}Returns reversibility status, constraints, time elapsed, and child dependency analysis.
POST /governance/replay
Replay provenance records through an alternative policy. Deterministic "what-if" analysis: "What would have happened if we'd used policy X instead?"
Request:
{
"agent_id": "your-agent-id",
"template_id": "strict_safety",
"limit": 50
}Response:
{
"total_replayed": 50,
"replay_policy": {"max_values": {"speed": 3.0}},
"changes": {"upgraded": 5, "downgraded": 12, "unchanged": 33},
"results": [
{
"epoch": 42,
"agent_id": "your-agent-id",
"action_type": "motor_command",
"original_decision": "ALLOW",
"replayed_decision": "CLAMP",
"change": "more_restrictive"
}
]
}Use for policy regression testing before deploying new policies, or forensic investigation.
POST /governance/counterfactual
Simulate an action against multiple policies simultaneously. Returns a decision matrix showing how each policy handles the same action.
Request:
{
"action_payload": {"endpoint": "/deploy", "replicas": 10},
"action_type": "api_call",
"policies": [
{"label": "conservative", "template_id": "strict_safety"},
{"label": "permissive", "policy_context": {"max_values": {"replicas": 20}}},
{"label": "deny-all", "policy_context": {"forbidden_keys": ["replicas"]}}
],
"include_historical": true,
"agent_id": "your-agent-id"
}Response includes consensus analysis (do all policies agree?), decision distribution, and optional historical comparison.
GET /governance/intents/{intent_id}/children
Return all direct child intents of a parent intent. Audit multi-agent delegation hierarchies.
GET /governance/intents/{intent_id}/ancestry
Walk up the intent hierarchy from leaf to root. Full authorization chain for auditing.
GET /governance/intents/{intent_id}/tree
Return the full delegation tree rooted at an intent. Accepts optional max_depth query parameter (default 10).
GET /governance/policy-templates — free, no API key required
List available named policy templates. Use template IDs with verify, replay, and counterfactual endpoints instead of inline policy definitions.
POST /governance/export/csv — export provenance records as CSV.
POST /governance/export/sarif — export provenance in SARIF format (Static Analysis Results Interchange Format) for security tooling integration.
POST /governance/export/merkle — export provenance as a Merkle tree with root hash and leaf hashes for independent integrity verification.
All export endpoints accept optional agent_id, time_range_start, time_range_end, and limit parameters.
GET /governance/health-score — overall gateway health score including agent count, healthy agent count, and chain integrity rate.
GET /governance/audit-summary — aggregate statistics across all provenance: total records, total agents, decision distribution, and chain integrity status.
GET /governance/agent-compliance/{agent_id} — compliance profile for a specific agent: compliance score, chain integrity, total decisions, and outcome success rate.
POST /media/attest — $0.05 per call
Attest media files (photos, videos, audio, documents) with SHA-256 hashing and provenance chain inclusion.
Request:
{
"agent_id": "your-agent-id",
"media_hash": "a1b2c3d4e5f6...64-char-hex-sha256",
"media_type": "PHOTO",
"media_size_bytes": 2048576,
"capture_timestamp_utc": "2026-02-26T12:00:00Z",
"description": "Generated report screenshot"
}Required fields: agent_id, media_hash (64-char hex SHA-256), media_type (PHOTO | VIDEO | AUDIO | DOCUMENT), media_size_bytes, capture_timestamp_utc.
Optional fields: description, tags, capture_location (lat/lng), device_info, frame_hashes (for video).
Response:
{
"attestation_id": "e5f6a7b8-...",
"certificate_id": "mca_abc123",
"media_hash": "a1b2c3d4e5f6...",
"media_type": "PHOTO",
"epoch": 45,
"hash_prev": "...",
"hash_curr": "b8c9d0e1...",
"verification_url": "https://governance.taskhawktech.com/media/verify/mca_abc123",
"chain_length": 45,
"timestamp_utc": "2026-02-26T12:00:05Z"
}POST /media/verify — free, no API key required
Verify that media content matches a specific attestation certificate.
Request:
{
"media_hash": "a1b2c3d4e5f6...64-char-hex-sha256",
"certificate_id": "mca_abc123"
}Response:
{
"verified": true,
"certificate_id": "mca_abc123",
"media_hash_match": true,
"chain_integrity": true,
"pqc_signature_valid": true,
"reason": "Media hash matches certificate, chain intact"
}GET /media/verify/{certificate_id} — free, no API key required
Look up a specific media attestation by its certificate ID. Returns the full attestation record including attesting agent, epoch, and chain integrity.
All Passport endpoints are free and require no authentication.
GET /passport/{agent_id}
Returns an agent's trust passport including score, tier, badges, and activity stats.
{
"agent_id": "your-agent-id",
"trust_score": 0.95,
"tier": "gold",
"badges": ["verified", "consistent", "high_volume"],
"stats": {
"total_decisions": 1250,
"attestations": 890,
"bindings": 340,
"outcomes_achieved": 310,
"chain_intact": true,
"active_days": 45,
"current_streak": 12
}
}GET /passport/{agent_id}/badge.svg
Returns an embeddable SVG trust badge. Use in agent descriptions, documentation, or dashboards.
GET /passport/{agent_id}/history
Returns full decision history for an agent.
GET /passport/leaderboard
Returns top trusted agents by trust score. Accepts optional limit query parameter (1-200, default 50).
Response:
{
"agents": [
{ "agent_id": "top-agent", "trust_score": 0.98, "tier": "gold" }
],
"total": 150
}POST /passport/{agent_id}/claim — requires API key
Link an agent's passport to your operator account. Must provide X-API-Key header.
Response:
{
"agent_id": "your-agent-id",
"claimed": true,
"profile": { "...passport profile..." }
}Returns 409 if already claimed by another operator, 404 if no passport exists yet.
GET /.well-known/agent.json
Returns the A2A protocol agent card. No authentication required.
curl https://governance.taskhawktech.com/.well-known/agent.jsonReturns capabilities, supported skills, SDK references, and free-tier signup details.
For MCP-native agents, connect directly via streamable-http transport:
https://governance.taskhawktech.com/mcp/360 tools, 2 resources, 2 prompts. Auto-provisions a free-tier key on first tool call if no API key is provided.
pip install kevros
# or
uv pip install kevrosfrom kevros_governance import GovernanceClient
client = GovernanceClient(agent_id="your-agent-id")
result = client.verify(
action_type="api_call",
action_payload={"endpoint": "/deploy"},
agent_id="your-agent-id",
)
print(result.decision) # ALLOW, CLAMP, or DENYEvery operator key has an enforcement mode that controls how decisions are applied:
/governance/gated/{request_id} for status.The enforcement_mode field is returned in every verify response. Use /enforcement to check your current mode.
Enforcement mode changes require admin-level access and are not available through the plugin. Contact your administrator or use the admin API directly.
When collaborating with another agent:
GET /passport/{agent_id} returns trust score, tier, and historyGET /passport/{agent_id}/badge.svg in your agent's description to show your trust level/governance/verify-token to independently confirm any release token a peer shares with youSubscriptions:
Per-call (via x402 USDC, no subscription required):
Subscription calls are metered against your monthly allowance. x402 per-call pricing applies when paying per-call without a subscription.
Upgrade at https://www.taskhawktech.com/pricing
© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 15 other files in skills/kevros of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Kevros next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kevros this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.9k | Automated safety check: Pass | MIT | |
| Show Me Your Work Decision Logcursor/plugins | 11k | 8 repos | ~1.6k | Automated safety check: Pass | None | |
| Autoresearch Iteration Loopuditgoenka/autoresearch | 6.5k | 1 repos | ~2k | Automated safety check: Pass | MIT | |
| Install Loop Engineeringcobusgreyling/loop-engineering | 11k | 1 repos | ~648 | Automated safety check: Pass | MIT | |
| LoopyForward-Future/loopy | 3.2k | — | ~3.9k | Automated safety check: Pass | MIT | |
| AI Performance Improvement Plantanweai/pua | 20k | 2 repos | ~6.9k | Automated safety check: Pass | MIT |
cursor/plugins
Keeps a TSV decision log for long or unattended agent runs, one row per decision with what, why, evidence and result, so a reviewer can check the work later.
uditgoenka/autoresearch
Runs an autonomous modify, verify, keep-or-discard loop against any metric, with subcommands for planning, debugging, fixing, security audits, shipping and more.
cobusgreyling/loop-engineering
Installs Loop Engineering into a project through the single @cobusgreyling/loop CLI, scaffolding a report-only loop and a readiness score.
Forward-Future/loopy
Discover, find, compare, audit, repair, adapt, craft, run, debrief, save, and prepare repeatable AI-agent loops for publication.
tanweai/pua
Pushes an agent to exhaust every option, investigate before asking and take initiative beyond the literal request, instead of giving up or waiting passively.
loopx-project/loopx
Diagnoses surprising LoopX behavior, such as stale recommendations or tiny progress, assigns it to the responsible layer and repairs it at the lowest durable level.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Categories
Precision decisioning, agentic trust, and verifiable identity for autonomous agents. Kevros is an agent skill from LeoYeAI/openclaw-master-skills.
Kevros fits situations like: tasks that involve Autonomous loops.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a claude-code`. Or copy the skill folder (skills/kevros in LeoYeAI/openclaw-master-skills) into .claude/skills/kevros in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a codex`. Or copy the skill folder (skills/kevros in LeoYeAI/openclaw-master-skills) into .agents/skills/kevros in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill kevros -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kevros, .gemini/skills/kevros, .github/skills/kevros and .opencode/skills/kevros in your project.
Going by SKILL.md and its folder, Kevros needs TypeScript and JavaScript for the scripts in its folder, the command-line tools its instructions call (curl, pip and uv) and credentials named KEVROS_API_KEY. Our summary lists: Node.js; A credential in KEVROS_API_KEY.
SKILL.md names 2 domains. In commands or code: governance.taskhawktech.com and taskhawktech.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kevros is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Kevros: Show Me Your Work Decision Log (cursor/plugins, 11k stars), Autoresearch Iteration Loop (uditgoenka/autoresearch, 6.5k stars), Install Loop Engineering (cobusgreyling/loop-engineering, 11k stars) and Loopy (Forward-Future/loopy, 3.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.