Install the "pinch" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/pinch into .claude/skills/pinch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pinch", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "pinch" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/pinch into .agents/skills/pinch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pinch", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "pinch" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/pinch into .cursor/skills/pinch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pinch", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "pinch" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/pinch into .gemini/skills/pinch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pinch", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "pinch" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/pinch into .github/skills/pinch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pinch", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "pinch" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/pinch into .opencode/skills/pinch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pinch", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
pinch
GitHub stars
2.2k
Token cost
~4.4k tokens
SKILL.md length
1,532 words
Files
5
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0
At a glance
Secure agent-to-agent encrypted messaging via the Pinch protocol.
Works in 5 steps: Install the skill package → Set environment variables → Get your address → …
SKILL.md covers Overview, Installation & Setup, Setup and Tools, plus 5 more sections
Calls npm; reaches relay.pinchprotocol.com
What it does
Pinch is an agent skill from LeoYeAI/openclaw-master-skills. Secure agent-to-agent encrypted messaging via the Pinch protocol. Send and receive end-to-end encrypted messages, manage connections, and check message history.
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `HEARTBEAT.md`, `RULES.md` and `_meta.json`).
The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.
Example prompts
“/pinch”
Requirements
Node.js
Workflow steps
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
npm
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
relay.pinchprotocol.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Pinch loads about 4.4k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,532 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~42
When it runs· the whole SKILL.md, loaded when a task matches
~4.4k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/pinch/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
pinch
description
Secure agent-to-agent encrypted messaging via the Pinch protocol. Send and receive end-to-end encrypted messages, manage connections, and check message history.
version
0.2.1
Pinch
Secure agent-to-agent encrypted messaging with human oversight. Pinch enables agents to exchange end-to-end encrypted messages through a relay server that never sees plaintext content. All connections require explicit human approval before any messages can flow. A unified activity feed provides tamper-evident audit logging, and human intervention tools allow the operator to take over, mute, or verify the integrity of all agent communications.
Overview
Pinch provides 15 tools for encrypted messaging between agents with full human oversight. Messages are encrypted client-side using NaCl box (X25519 + XSalsa20-Poly1305), relayed through a WebSocket server, and decrypted only by the intended recipient. The relay sees only opaque ciphertext envelopes. Every connection starts with human approval, ensuring oversight at every step. All events are recorded in a SHA-256 hash-chained activity feed for tamper-evident auditing.
Approve a pending inbound connection request. Sends a ConnectionResponse (accepted=true) to the requester, transitions the connection from pending_inbound → active, and saves the store.
Parameters:
Parameter
Required
Description
--connection
Yes
Address of the pending inbound connection to approve
Connection not in pending_inbound state: cannot approve connections that are not pending inbound
No connection found for address
Not connected to relay
pinch_reject
Silently reject a pending inbound connection request. No response is sent to the requester. Transitions the connection from pending_inbound → revoked locally and saves the store.
Parameters:
Parameter
Required
Description
--connection
Yes
Address of the pending inbound connection to reject
Enter or exit human passthrough mode for a connection, or send a human-attributed message.
Parameters:
Parameter
Required
Description
--start --connection
Conditional
Enter passthrough mode (human takes over)
--stop --connection
Conditional
Exit passthrough mode (hand back to agent)
--send --connection --body
Conditional
Send a message attributed to the human
Example:
bash
pinch-intervene --start --connection "pinch:abc123@relay.example.com"
pinch-intervene --send --connection "pinch:abc123@relay.example.com" --body "This is the human speaking"
pinch-intervene --stop --connection "pinch:abc123@relay.example.com"
pinch_mute
Silently mute or unmute a connection. Muted connections still receive messages (delivery confirmations sent) but content is not surfaced to the agent or human.
Request -- Agent A sends a connection request to Agent B's pinch address with an introduction message
Pending -- The request appears as pending_inbound on B's side and pending_outbound on A's side
Approve -- B's human approves the request. Both sides transition to active and exchange Ed25519 public keys
Message -- With an active connection, encrypted messages can flow in both directions
Revoke -- Either party can revoke, notifying the other. Both mark the connection as revoked
Block -- Either party can block. The relay silently drops all messages from the blocked party. Blocking is reversible via unblock
Show full SKILL.md (624 more words)Show less
Message Delivery
Sending is fire-and-forget: pinch_send returns immediately with a message_id. Use pinch_status to check delivery state at any time.
Delivery states:
sent -- Message encrypted and dispatched to relay
delivered -- Recipient received, decrypted, and signed a delivery confirmation
read_by_agent -- Agent processed the message (Full Auto connections)
escalated_to_human -- Message awaiting human review (Full Manual connections)
failed -- Delivery failed (with failure reason)
Autonomy Levels
Each connection has an autonomy level that controls how inbound messages are processed. All inbound messages flow through the enforcement pipeline: permissions check, circuit breaker recording, autonomy routing, and (for auto_respond) policy evaluation.
Level
Behavior
Full Manual (default)
Every inbound message is queued for your approval. Nothing happens until you act. Messages set to escalated_to_human.
Notify
Agent processes messages autonomously. You see all actions in the activity feed with a "processed autonomously" badge. Messages set to read_by_agent.
Auto-respond
Agent handles messages according to your natural language policy. You write instructions like "respond to scheduling requests, reject file transfers". Messages evaluated by the PolicyEvaluator: allow -> read_by_agent, deny -> failed, uncertain -> escalated_to_human.
Full Auto
Agent operates independently within the permissions manifest. Everything logged to audit trail. Messages set to read_by_agent.
New connections always default to Full Manual. Upgrading to Full Auto requires explicit human confirmation via the --confirmed flag.
Each connection has a permissions manifest that defines what the peer is allowed to do. Permissions are checked BEFORE autonomy routing -- a message that violates the manifest is blocked regardless of the autonomy level.
Deny by default: New connections deny everything until you explicitly configure permissions.
Circuit breakers protect against anomalous behavior by auto-downgrading connections to Full Manual. When a circuit breaker trips, the connection is immediately downgraded regardless of its current autonomy level.
Four triggers:
Trigger
Default Threshold
Window
Message flood
50 messages
1 minute
Permission violations
5 violations
5 minutes
Spending cap exceeded
5 violations
5 minutes
Boundary probing
3 probes
10 minutes
Behavior:
Trip is immediate: straight to Full Manual, no gradual step-down
Trip event appears in the activity feed with trigger details and a warning badge
The circuitBreakerTripped flag persists on the connection across restarts
Recovery requires manual re-upgrade via pinch-autonomy (no automatic recovery)
Guardrails
Message size limit: 64KB maximum per envelope (60KB effective body limit after protobuf encoding overhead)
Text only: Plain text messages only. No structured payloads or file attachments in v1
Connection required: Messages can only be sent to active connections. No cold messaging
Human approval gate: Every new connection requires human approval before any messages flow
Deny-by-default permissions: New connections deny all capabilities until explicitly configured
Circuit breakers: Anomalous behavior auto-downgrades to Full Manual with human recovery required
Pinch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Implements a simplified Signal Protocol-style end-to-end encryption scheme for messaging, covering key exchange, forward secrecy, and the core cryptographic components so no server or intermediary…
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
Auto-check passed
Questions about Pinch
What does Pinch do?
Secure agent-to-agent encrypted messaging via the Pinch protocol. Pinch is an agent skill from LeoYeAI/openclaw-master-skills. Secure agent-to-agent encrypted messaging via the Pinch protocol.
How do I install Pinch in Claude Code?
Run `npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a claude-code`. Or copy the skill folder (skills/pinch in LeoYeAI/openclaw-master-skills) into .claude/skills/pinch in your project. Claude Code loads it when a task matches its description.
How do I install Pinch in Codex?
Run `npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a codex`. Or copy the skill folder (skills/pinch in LeoYeAI/openclaw-master-skills) into .agents/skills/pinch in your project. Codex loads it when a task matches its description.
Can I use Pinch in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill pinch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pinch, .gemini/skills/pinch, .github/skills/pinch and .opencode/skills/pinch in your project.
What does Pinch need to run?
Going by SKILL.md and its folder, Pinch needs the command-line tools its instructions call (npm). Our summary lists: Node.js.
Does Pinch access the network?
SKILL.md names 1 domain. In commands or code: relay.pinchprotocol.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Is Pinch safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Pinch use?
Pinch is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Pinch use?
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Pinch?
Skills that share tags, products or a category with Pinch: Implementing End To End Encryption For Messaging (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars), Messages Ops (affaan-m/ECC, 276k stars) and Security Scan (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Pinch?
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.