Agent skill

Manage NanoClaw Mounts

by nanocoai in nanocoai/nanoclaw

Shows, adds and removes the host directories that NanoClaw agent containers may access, recording each as read-only or read-write in an allowlist file.

MITAuto-check passedAgent Workflows

Install Manage NanoClaw Mounts

skills CLI
$ npx skills add nanocoai/nanoclaw --skill manage-mounts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nanocoai/nanoclaw manage-mounts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/manage-mounts .claude/skills/manage-mounts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
manage-mounts
GitHub stars
31k
Token cost
~474 tokens
SKILL.md length
170 words
Files
1
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Shows, adds and removes the host directories that NanoClaw agent containers may access, recording each as read-only or read-write in an allowlist file.

  • Giving an agent container access to a project folder on the host
  • SKILL.md covers Show Current Config, Add Directories, Remove Directories and Reset to Empty, plus 1 more section
  • Calls pnpm
  • Auditing which host directories agents can currently read or write

What it does

The allowlist lives in ~/.config/nanoclaw/mount-allowlist.json. The agent prints the current entries in readable form, and when adding a directory it checks that the path exists and asks whether access should be read-write or read-only, with read-only as the safer default. It then writes the JSON through the project's setup script using the mounts step and the force flag.

Removal follows the same path: read the config, ask which entry to drop, and write back the trimmed version. A reset command empties the list. Because the allowlist is read when a container starts, new mounts reach newly spawned containers without a service restart, and a group that already has a running container can be restarted on its own with the ncl groups restart command.

When your agent uses it

  • Giving an agent container access to a project folder on the host
  • Auditing which host directories agents can currently read or write
  • Revoking access to a directory or clearing the allowlist

Example prompts

  • “Let the NanoClaw agents read ~/Documents/notes but not change anything there.”
  • “Show me the current mount allowlist and remove the downloads folder.”

Requirements

  • A NanoClaw install with pnpm and its setup script
  • The ncl CLI to restart a running group

What it can do on your machine

Read from SKILL.md and the folder at commit af699e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Manage NanoClaw Mounts loads about 474 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 170 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~474

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nanocoai/nanoclaw at commit af699e7, republished under its MIT licence (© nanocoai). 170 words, ~474 tokens.

Download SKILL.mdSave it as .claude/skills/manage-mounts/SKILL.md (or your agent's skills folder).
name
manage-mounts
description
Configure which host directories agent containers can access. View, add, or remove mount allowlist entries. Triggers on "mounts", "mount allowlist", "agent access to directories", "container mounts".

Manage Mounts

Configure which host directories NanoClaw agent containers can access. The mount allowlist lives at ~/.config/nanoclaw/mount-allowlist.json.

Show Current Config

bash
cat ~/.config/nanoclaw/mount-allowlist.json 2>/dev/null || echo "No mount allowlist configured"

Show the current config to the user in a readable format: which directories are allowed, and whether each is read-only or read-write.

Add Directories

Ask which directories the user wants agents to access. For each path:

  • Validate the path exists
  • Ask if it should be read-write (allowReadWrite: true) or read-only (allowReadWrite: false, the safer default)

Build the JSON config and write it:

bash
pnpm exec tsx setup/index.ts --step mounts --force -- --json '{"allowedRoots":[{"path":"/path/to/dir","allowReadWrite":true}],"blockedPatterns":[]}'

Use --force to overwrite the existing config.

Remove Directories

Read the current config, show it, ask which entry to remove, then write the updated config through the same write path (build the trimmed JSON and pass it to --step mounts --force -- --json):

bash
pnpm exec tsx setup/index.ts --step mounts --force -- --json '{"allowedRoots":[],"blockedPatterns":[]}'

Reset to Empty

bash
pnpm exec tsx setup/index.ts --step mounts --force -- --empty

After Changes

The allowlist is read fresh when a container is spawned, so new mounts apply to newly spawned containers automatically — no service restart needed.

To apply the new config to a group that already has a running container, restart just that group:

bash
ncl groups restart --id <group-id>

© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/manage-mounts of nanocoai/nanoclaw.

Open the folder on GitHubat commit af699e7

Compare with similar skills

Manage NanoClaw Mounts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Manage NanoClaw Mounts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Manage NanoClaw Mounts this skillnanocoai/nanoclaw31k—~474Automated safety check: PassMIT
Devcontainer Devstacklok/toolhive-studio171—~3.8kAutomated safety check: NotesApache-2.0
DeerFlow Smoke Testbytedance/deer-flow84k—~2.5kAutomated safety check: NotesMIT
Pwa ReleaseAHS12/thoth-blueprint625—~505Automated safety check: PassGPL-3.0
Devops SpecialistCaoMeiYouRen/caomei-auth220—~446Automated safety check: NotesMIT
Weft FrontendWeaveMindAI/weft2k—~8kAutomated safety check: NotesCustom licence

Similar skills

  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    171 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • DeerFlow Smoke Test

    bytedance/deer-flow

    Walks through an end-to-end smoke test of a DeerFlow deployment: pull the latest code, deploy with Docker or locally, verify services, run health checks and write a report.

    84k GitHub stars~2.5k tokensUpdated today
    Testing & QAAuto-check: notes
  • Pwa Release

    AHS12/thoth-blueprint

    Safely change Vite, service-worker, offline fallback, cache, Docker, Vercel, or release-distribution behavior.

    625 GitHub stars~505 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Devops Specialist

    CaoMeiYouRen/caomei-auth

    修改 Docker、CI/CD、部署配置、环境变量、运行时参数、构建脚本和发布流程时使用。优先覆盖 Docker、Vercel、Cloudflare 与 GitHub Actions 场景。用户提到 deploy、Dockerfile、workflow、CI、CD、environment variables、build pipeline、release config 时都应触发。

    220 GitHub stars~446 tokensUpdated 9 days ago
    DevOps & CloudAuto-check: notes
  • Weft Frontend

    WeaveMindAI/weft

    Read when the user wants a page, app or site for the program, and before dispatching the frontend-builder: the verified scaffold commands, the default stack (pnpm, SvelteKit, PostgreSQL, BetterAuth…

    2k GitHub stars~8k tokensUpdated yesterday
    Frontend & DesignAuto-check: notes
  • Toolchain Commands

    latitude-dev/latitude-llm

    Installing dependencies, running dev/build/test/lint, filtering packages, single-test runs, git hooks, preparing a clone (.env.development / .env.test), or Docker-backed local services and dev…

    4.7k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from nanocoai/nanoclaw

All 59 skills in this repo
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

    31k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes
  • Agent Browser

    nanocoai/nanoclaw

    Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.

    31k GitHub starsUsed in 2 repos~1.6k tokens
    Auto-check passed
  • Add Dial Tool

    nanocoai/nanoclaw

    Installs the `dial` CLI and a credential in NanoClaw agent containers so chosen agents can send SMS, place AI voice calls and receive verification codes.

    31k GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.

    31k GitHub stars~6k tokensUpdated yesterday
    Auto-check: notes
  • Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.

    31k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Manage NanoClaw Mounts

What does Manage NanoClaw Mounts do?

Shows, adds and removes the host directories that NanoClaw agent containers may access, recording each as read-only or read-write in an allowlist file. json. The agent prints the current entries in readable form, and when adding a directory it checks that the path exists and asks whether access should be read-write or read-only, with read-only as the safer default.

When should I use Manage NanoClaw Mounts?

Manage NanoClaw Mounts fits situations like: giving an agent container access to a project folder on the host; auditing which host directories agents can currently read or write; revoking access to a directory or clearing the allowlist.

How do I install Manage NanoClaw Mounts in Claude Code?

Run `npx skills add nanocoai/nanoclaw --skill manage-mounts -a claude-code`. Or copy the skill folder (.claude/skills/manage-mounts in nanocoai/nanoclaw) into .claude/skills/manage-mounts in your project. Claude Code loads it when a task matches its description.

How do I install Manage NanoClaw Mounts in Codex?

Run `npx skills add nanocoai/nanoclaw --skill manage-mounts -a codex`. Or copy the skill folder (.claude/skills/manage-mounts in nanocoai/nanoclaw) into .agents/skills/manage-mounts in your project. Codex loads it when a task matches its description.

Can I use Manage NanoClaw Mounts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill manage-mounts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-mounts, .gemini/skills/manage-mounts, .github/skills/manage-mounts and .opencode/skills/manage-mounts in your project.

What does Manage NanoClaw Mounts need to run?

Going by SKILL.md and its folder, Manage NanoClaw Mounts needs the command-line tools its instructions call (pnpm). Our summary lists: A NanoClaw install with pnpm and its setup script; The ncl CLI to restart a running group.

Does Manage NanoClaw Mounts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Manage NanoClaw Mounts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Manage NanoClaw Mounts use?

Manage NanoClaw Mounts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Manage NanoClaw Mounts use?

About 474 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Manage NanoClaw Mounts?

Skills that share tags, products or a category with Manage NanoClaw Mounts: Devcontainer Dev (stacklok/toolhive-studio, 171 stars), DeerFlow Smoke Test (bytedance/deer-flow, 84k stars), Pwa Release (AHS12/thoth-blueprint, 625 stars) and Devops Specialist (CaoMeiYouRen/caomei-auth, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Manage NanoClaw Mounts?

nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,906 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 9, 2026.

Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.