Agent skill

NanoClaw OneCLI Gateway Installer

by nanocoai in nanocoai/nanoclaw

Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

MITAuto-check: notesAgent Workflows

Install NanoClaw OneCLI Gateway Installer

skills CLI
$ npx skills add nanocoai/nanoclaw --skill add-onecli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nanocoai/nanoclaw add-onecli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-onecli .claude/skills/add-onecli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-onecli
GitHub stars
31k
Token cost
~1.1k tokens
SKILL.md length
357 words
Files
23 (incl. scripts, references)
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

  • Setting up NanoClaw with OneCLI as its gateway provider
  • SKILL.md covers Install the provider payload, Register once, Install the pinned SDK and Configure the gateway, plus 2 more sections
  • Runs TypeScript scripts from its folder; needs NANOCLAW_ONECLI_API_TOKEN and ONECLI_API_KEY
  • Migrating an existing OneCLI-backed install to the gateway seam

What it does

This skill owns the whole OneCLI integration for NanoClaw, while NanoClaw core supplies the generic gateway seam and the approval workflow. It copies the package's native adapter, tests and agent guidance into their normal paths, registers the provider with a single import line, and installs a pinned OneCLI SDK with pnpm.

A setup script reuses a healthy existing gateway, installs the pinned local gateway when none exists, or connects to a remote one through NANOCLAW_ONECLI_API_HOST and NANOCLAW_ONECLI_API_TOKEN. Only the gateway version pinned in the skill's versions.json is supported, which is 1.42.0 today, and 1.43 and later are not supported because they remove the secret-assignment API. Setup does not check an existing gateway's version, so an upgrade guide is included.

For provider credentials, such as those stored by /add-opencode, the group's OneCLI agent must be granted access to the secret: read the existing assignments, merge in the new secret ID and verify with onecli agents secrets, because set-secrets replaces assignments. Keys never go in .env, command arguments or the container environment. A removal guide and a ChatGPT OAuth refresh reference are included.

When your agent uses it

  • Setting up NanoClaw with OneCLI as its gateway provider
  • Migrating an existing OneCLI-backed install to the gateway seam
  • Restoring the OneCLI runtime, approval bridge or agent guidance from the in-tree package

Example prompts

  • “Add OneCLI as the gateway for my NanoClaw install.”
  • “Refresh the OneCLI provider files in NanoClaw from the in-tree package.”
  • “Point NanoClaw at our remote OneCLI gateway using the API host and token variables.”

Requirements

  • A NanoClaw checkout
  • pnpm and Node.js
  • For a remote gateway, its API host and token

What it can do on your machine

Read from SKILL.md and the folder at commit 66f0823. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (TypeScript, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NANOCLAW_ONECLI_API_TOKEN
    • ONECLI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

NanoClaw OneCLI Gateway Installer loads about 1.1k tokens when it runs, and up to ~1.3k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 357 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:56
    a key in `.env`, command arguments, or the container environment.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from nanocoai/nanoclaw at commit 66f0823, republished under its MIT licence (© nanocoai). 357 words, ~1,050 tokens.

Download SKILL.mdSave it as .claude/skills/add-onecli/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.
name
add-onecli
description
Install or refresh OneCLI as NanoClaw's gateway provider. Use when setup selects OneCLI, an existing OneCLI-backed install is migrated to the gateway seam, or its runtime, approval bridge, setup, and agent guidance must be restored from the in-tree package.

Add OneCLI gateway

This skill owns the full OneCLI integration. NanoClaw core supplies the generic gateway seam and existing skill engine.

Install the provider payload

Copy the package's native adapter, tests, and agent guidance into their normal NanoClaw paths. NanoClaw core owns the approval workflow.

nccopy
payload/src/gateway-providers/onecli-files.ts -> src/gateway-providers/onecli-files.ts
payload/src/gateway-providers/onecli-files.test.ts -> src/gateway-providers/onecli-files.test.ts
payload/src/gateway-providers/onecli.ts -> src/gateway-providers/onecli.ts
payload/src/gateway-providers/onecli.test.ts -> src/gateway-providers/onecli.test.ts
payload/src/gateway-providers/onecli-install.test.ts -> src/gateway-providers/onecli-install.test.ts
payload/container/skills/onecli-gateway/SKILL.md -> container/skills/onecli-gateway/SKILL.md
payload/container/skills/onecli-gateway/instructions.md -> container/skills/onecli-gateway/instructions.md
payload/docs/onecli-upgrades.md -> docs/onecli-upgrades.md

Register once

The provider file makes the only product registration call. It translates OneCLI sessions and native approval events into the generic contract.

ncappend
import './onecli.js';

Install the pinned SDK

ncdep
@onecli-sh/sdk@2.2.1

Configure the gateway

The setup script safely reuses a healthy existing installation, installs the pinned local gateway when absent, or uses NANOCLAW_ONECLI_API_HOST and NANOCLAW_ONECLI_API_TOKEN for a remote gateway.

This integration supports exactly the gateway version pinned in .claude/skills/add-onecli/versions.json (onecli-gateway, today 1.42.0; not the versions.json at the project root). OneCLI 1.43 and later remove the agent secret-assignment API used below, so 1.43+ is not supported for now. Setup reuses an existing gateway without checking its version: follow Upgrading the OneCLI gateway to check it and to move it to the pin. The CLI (onecli-cli) and SDK (onecli-sdk) have their own pins.

ncrun
pnpm exec tsx .claude/skills/add-onecli/scripts/setup.ts
Show full SKILL.md (185 more words)Show less

Provider credentials

Provider skills such as /add-opencode store model credentials here through the gateway seam. OneCLI does not grant them automatically: grant the group's OneCLI agent access to the chosen secret. Read its existing secret assignments first and merge the new secret ID into that list, because onecli agents set-secrets replaces assignments. Verify the result with onecli agents secrets. Do not put a key in .env, command arguments, or the container environment.

  • Only a selected OneCLI adapter uses ONECLI_URL and ONECLI_API_KEY.
  • Moving an API key to another exact host keeps its stored value, so a blank answer at the key prompt completes the move after confirmation.
  • Existing OneCLI credential names and formats remain compatible.
  • ChatGPT logins need manual reauthentication after expiry on the pinned OneCLI 1.42.0; see ChatGPT OAuth refresh for the limitation and upgrade constraints.

Validate

ncrun
pnpm run build
ncrun
pnpm exec vitest run src/gateway-providers/onecli-files.test.ts src/gateway-providers/onecli-install.test.ts src/gateway-providers/onecli.test.ts src/gateway-providers/gateway-provider-registry.test.ts src/gateway-approval-coordinator.test.ts

The setup consumer writes NANOCLAW_GATEWAY_PROVIDER=onecli only after every directive above succeeds. Claude authentication is then completed through scripts/auth.ts; credentials never enter an agent container.

During an atomic NanoClaw upgrade, scripts/detect.ts identifies an older implicit OneCLI installation so the generic updater can preserve that choice before the service restarts.

© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 22 other files (scripts, references) in .claude/skills/add-onecli of nanocoai/nanoclaw.

  • SKILL.md
  • REMOVE.md
  • gateway.json
  • payload/container/skills
  • payload/docs/onecli-upgrades.md
  • payload/src/gateway-providers/onecli-files.test.ts
  • payload/src/gateway-providers/onecli-files.ts
  • payload/src/gateway-providers/onecli-install.test.ts
  • payload/src/gateway-providers/onecli.test.ts
  • payload/src/gateway-providers/onecli.ts
  • references/chatgpt-oauth-refresh.md
  • scripts/auth.ts
  • scripts/credential-store.test.ts
  • scripts/credential-store.ts
  • … and 9 more

Open the folder on GitHubat commit 66f0823

Compare with similar skills

NanoClaw OneCLI Gateway Installer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

NanoClaw OneCLI Gateway Installer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
NanoClaw OneCLI Gateway Installer this skillnanocoai/nanoclaw31k—~1.1kAutomated safety check: NotesMIT
MCP Security Auditgithub/awesome-copilot40k—~3.1kAutomated safety check: PassMIT
Daytona Sandbox Operationsdifferent-ai/openwork24k—~917Automated safety check: PassCustom licence
Dotenvx Secretskortix-ai/suna20k—~4.2kAutomated safety check: NotesCustom licence
MCP Security Auditboshi-xixixi/TraeSkill275—~2.2kAutomated safety check: PassMIT
Warp GUI to Agent CLI Migrationwarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • MCP Security Audit

    github/awesome-copilot

    Official

    Audit MCP (Model Context Protocol) server configurations for security issues.

    40k GitHub stars~3.1k tokensUpdated today
    SecurityAuto-check passed
  • Daytona Sandbox Operations

    different-ai/openwork

    Covers Daytona CLI setup, sandbox debugging, keeping a sandbox alive and which credentials the CLI uses, for when Daytona itself is the problem rather than the tests.

    24k GitHub stars~917 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Dotenvx Secrets

    kortix-ai/suna

    How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).

    20k GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • MCP Security Audit

    boshi-xixixi/TraeSkill

    Audit MCP (Model Context Protocol) server configurations for security issues.

    275 GitHub stars~2.2k tokensUpdated 4 mo ago
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed
  • OpenGUI Installer for DSH

    Core-Mate/OpenGUI

    Installs and verifies the latest stable OpenGUI release in a DeepSeek Harness web profile on macOS without disturbing existing plugins or settings.

    1.8k GitHub stars~1.1k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from nanocoai/nanoclaw

All 59 skills in this repo
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 2 days ago
    Auto-check: notes
  • Agent Browser

    nanocoai/nanoclaw

    Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.

    31k GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.

    31k GitHub stars~6k tokensUpdated 2 days ago
    Auto-check: notes
  • Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.

    31k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • NanoClaw LLM Wiki Setup

    nanocoai/nanoclaw

    Adds a persistent wiki knowledge base to a NanoClaw group following Karpathy's LLM Wiki pattern, with folders, a tailored container skill and a CLAUDE.md section.

    31k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • NanoClaw Ollama Provider

    nanocoai/nanoclaw

    Routes a NanoClaw agent group to a local Ollama model instead of the Anthropic API, using environment overrides and an optional block on Anthropic hosts.

    31k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed

Works with

Questions about NanoClaw OneCLI Gateway Installer

What does NanoClaw OneCLI Gateway Installer do?

Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script. This skill owns the whole OneCLI integration for NanoClaw, while NanoClaw core supplies the generic gateway seam and the approval workflow. It copies the package's native adapter, tests and agent guidance into their normal paths, registers the provider with a single import line, and installs a pinned OneCLI SDK with pnpm.

When should I use NanoClaw OneCLI Gateway Installer?

NanoClaw OneCLI Gateway Installer fits situations like: setting up NanoClaw with OneCLI as its gateway provider; migrating an existing OneCLI-backed install to the gateway seam; restoring the OneCLI runtime, approval bridge or agent guidance from the in-tree package.

How do I install NanoClaw OneCLI Gateway Installer in Claude Code?

Run `npx skills add nanocoai/nanoclaw --skill add-onecli -a claude-code`. Or copy the skill folder (.claude/skills/add-onecli in nanocoai/nanoclaw) into .claude/skills/add-onecli in your project. Claude Code loads it when a task matches its description.

How do I install NanoClaw OneCLI Gateway Installer in Codex?

Run `npx skills add nanocoai/nanoclaw --skill add-onecli -a codex`. Or copy the skill folder (.claude/skills/add-onecli in nanocoai/nanoclaw) into .agents/skills/add-onecli in your project. Codex loads it when a task matches its description.

Can I use NanoClaw OneCLI Gateway Installer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill add-onecli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-onecli, .gemini/skills/add-onecli, .github/skills/add-onecli and .opencode/skills/add-onecli in your project.

What does NanoClaw OneCLI Gateway Installer need to run?

Going by SKILL.md and its folder, NanoClaw OneCLI Gateway Installer needs TypeScript for the scripts in its folder and credentials named NANOCLAW_ONECLI_API_TOKEN and ONECLI_API_KEY. Our summary lists: A NanoClaw checkout; pnpm and Node.js; For a remote gateway, its API host and token.

Does NanoClaw OneCLI Gateway Installer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is NanoClaw OneCLI Gateway Installer safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does NanoClaw OneCLI Gateway Installer use?

NanoClaw OneCLI Gateway Installer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does NanoClaw OneCLI Gateway Installer use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 289 tokens, read only when the agent opens those files.

What are the alternatives to NanoClaw OneCLI Gateway Installer?

Skills that share tags, products or a category with NanoClaw OneCLI Gateway Installer: MCP Security Audit (github/awesome-copilot, 40k stars), Daytona Sandbox Operations (different-ai/openwork, 24k stars), Dotenvx Secrets (kortix-ai/suna, 20k stars) and MCP Security Audit (boshi-xixixi/TraeSkill, 275 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains NanoClaw OneCLI Gateway Installer?

nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,897 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 6, 2026.

Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.