Agent skill

Update NanoClaw Safely

by nanocoai in nanocoai/nanoclaw

Updates a customized NanoClaw install from the official upstream in a staged worktree, with state snapshots, migration gates, health checks and automatic rollback.

MITAuto-check: notesDevOps & Cloud

Install Update NanoClaw Safely

skills CLI
$ npx skills add nanocoai/nanoclaw --skill update-nanoclaw -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nanocoai/nanoclaw update-nanoclaw --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/update-nanoclaw .claude/skills/update-nanoclaw && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-nanoclaw
GitHub stars
31k
Token cost
~2.9k tokens
SKILL.md length
1,204 words
Files
1
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Updates a customized NanoClaw install from the official upstream in a staged worktree, with state snapshots, migration gates, health checks and automatic rollback.

  • Works in 7 steps: Load the newest controller without… → Choose the channel, the Git strategy,… → Validate the staged result → …
  • Pulling the latest official NanoClaw changes into a customized fork
  • SKILL.md covers Safety contract, 1. Load the newest controller…, 2. Choose the channel, the Git… and 3. Validate the staged result, plus 4 more sections
  • Calls pnpm and git

What it does

The live checkout must be clean, and nothing in it changes until a staged copy has passed validation. Git integration, dependency installation, skill refresh and tests happen in a separate worktree, the service is stopped and active containers drained, and .env, data, groups and store are snapshotted before cutover. Breaking migrations and external version-pin moves each need your confirmation.

After cutover the agent restarts the service in whichever mode it detects, launchd, user or system systemd, or nohup, and requires a running process, the ncl socket and a successful groups list before stamping the exact Git commit. If the build or health check fails, it restores Git and the state snapshot, rebuilds the previous image and restarts the old service. It refuses to proceed while an unmanaged pnpm dev host is running.

When your agent uses it

  • Pulling the latest official NanoClaw changes into a customized fork
  • Doing a merge, rebase or selective upstream update with a way back
  • Updating an install whose source is mounted into running containers

Example prompts

  • “Update my NanoClaw install from upstream and roll back if the health check fails.”
  • “Rebase my customized NanoClaw checkout on the official main branch, with a snapshot first.”

Requirements

  • A clean Git checkout of NanoClaw
  • Access to the official upstream remote
  • A detected launchd or systemd service, or a nohup start

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Load the newest controller without changing the live tree
  2. Choose the channel, the Git strategy, and prepare
  3. Validate the staged result
  4. Confirm and cut over
  5. Complete every requirement
  6. Finish and health-check
  7. Report and retain one rollback point

What it can do on your machine

Read from SKILL.md and the folder at commit a0c79dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update NanoClaw Safely loads about 2.9k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,204 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:22
    - Snapshot `.env`, `data/`, `groups/`, `store/`, and manual-service state before
  • NoteMentions a .env fileSKILL.md:93
    Channels (`NANOCLAW_UPDATE_CHANNEL` in `.env`; `--channel <name>` overrides it
  • NoteMentions a .env fileSKILL.md:96
    `set-channel` (below), never by editing `.env`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nanocoai/nanoclaw at commit a0c79dd, republished under its MIT licence (© nanocoai). 1,204 words, ~2,903 tokens.

Download SKILL.mdSave it as .claude/skills/update-nanoclaw/SKILL.md (or your agent's skills folder).
name
update-nanoclaw
description
Transactionally update a customized NanoClaw checkout from official upstream without exposing live mounted source, with fork-safe skill refresh, mutable-state snapshots, migration gates, exact-code upgrade markers, detected service restart, health verification, and automatic local rollback. Use for routine merge, rebase, or selective upstream updates.

Update NanoClaw

Update a customized install through an isolated, resumable transaction. The live checkout is not touched until the staged result has passed validation.

Use ordinary conversation for decisions and confirmations. Do not depend on Claude Code, Codex, OpenCode, or any provider-specific question/skill tool.

Safety contract

  • Require a clean live checkout.
  • Stage Git integration, dependency installation, installed-skill refresh, and tests in a separate worktree.
  • Resolve registry branches from the remote that actually carries them.
  • Stop the detected service and drain this install's active containers before changing source mounted into agent containers.
  • Snapshot .env, data/, groups/, store/, and manual-service state before cutover. Sockets and other ephemeral special files are intentionally omitted.
  • Gate every breaking migration and external version-pin move.
  • Stamp the exact Git commit/tree only after all required work succeeds.
  • Restart through the detected launchd, user-systemd, system-systemd, or nohup mode; require process state, data/ncl.sock, and bin/ncl groups list.
  • Refuse cutover while an unmanaged pnpm dev/Node host is running. Stop that process explicitly, update offline, then start it again manually.
  • On build or health failure, restore Git and the mutable-state snapshot, rebuild the previous image, restart the previous service, and health-check it.

1. Load the newest controller without changing the live tree

Confirm the live tree is clean:

bash
git status --porcelain

Stop if it prints anything. Setup commits the files it applies as setup: apply <skill> commits unless NANOCLAW_SETUP_COMMIT=0 was set. Treat anything left as part of the install: show it, ask the user to commit it as a local customization, then re-check. Never stash it, since the updater discovers installed skills from these files.

Use the official remote if one already exists. Otherwise add it as upstream:

bash
if git remote get-url upstream >/dev/null 2>&1; then
  upstream_remote=upstream
elif git remote get-url origin 2>/dev/null | grep -Eq '(^|[:/])nanocoai/nanoclaw(.git)?$'; then
  upstream_remote=origin
else
  git remote add upstream https://github.com/nanocoai/nanoclaw.git
  upstream_remote=upstream
fi
git fetch "$upstream_remote" --prune

Select main when present, otherwise master:

bash
if git show-ref --verify --quiet "refs/remotes/$upstream_remote/main"; then
  upstream_ref="$upstream_remote/main"
elif git show-ref --verify --quiet "refs/remotes/$upstream_remote/master"; then
  upstream_ref="$upstream_remote/master"
else
  echo "Official remote has neither main nor master" >&2
  exit 1
fi

Materialize the newest controller from that ref. This is the self-update seam: an older local skill still executes the newest safety code before any mutation. The controller always comes from main; the ref it merges follows the channel (step 2).

bash
# pwd -P: on macOS mktemp returns a path through the /var symlink, and a
# symlinked argv defeats Node's import.meta main-module guard — the controller
# then exits 0 having done NOTHING. Canonicalize before use.
controller_dir="$(cd "$(mktemp -d)" && pwd -P)"
# Extract all of scripts/, not a hand-listed subset. These paths are a
# contract: older copies of this skill extract exactly them from the newest
# ref, so the controller must load from them alone, with no node_modules.
# scripts/update/controller-archive.test.ts enforces it.
git archive "$upstream_ref" scripts src/install-slug.ts | tar -x -C "$controller_dir"

2. Choose the channel, the Git strategy, and prepare

Channels (NANOCLAW_UPDATE_CHANNEL in .env; --channel <name> overrides it once): stable (default) = newest annotated vX.Y.Z tag; beta = newest -rc.N if newer than stable; edge = upstream main. Change the default only with set-channel (below), never by editing .env.

Default to merge. Use rebase only when the user explicitly wants linear history. Use cherry-pick only with an explicit comma-separated commit list.

bash
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" prepare \
  --project-root "$PWD" --remote "$upstream_remote" --strategy merge

The JSON result is nanoclaw-update/v1. Record its id, stageRoot, backup branch/tag, changed files, and requirements. The live HEAD is still unchanged. Tell the user the channel and upstreamRef. Then:

  • Nothing new (stable/beta, phase: prepared, targetHead equals originalHead): say "Already on the newest release (vX.Y.Z)", still run step 3 (it refreshes installed skills), and abandon if targetHead is still unchanged.

  • Error code: ahead-of-release (nothing staged): ask once, "This install is newer than the latest release, <tag>. Keep getting the newest code from main (edge), or switch to releases and wait for the next one (stable)?" Save the answer, then on edge re-run prepare with --channel edge; on stable stop, as there is nothing to update until the next release:

    bash
    pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" set-channel \
      --project-root "$PWD" --channel edge   # or stable

If phase is conflict, resolve conflicts only inside stageRoot, preserving intentional local customizations. Complete the merge/rebase/cherry-pick there, commit it, then run:

bash
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" resume \
  --project-root "$PWD" --id "$id"

Run every transaction command from $controller_dir, not from stageRoot: a cherry-pick stage can still hold the old controller. If $controller_dir is gone (a reboot clears temp directories), recreate it with the step 1 commands without fetching again.

Show the user the upstream commits, changed-file buckets, requirements, and any resolved conflicts. To stop with no live mutation:

bash
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" abandon \
  --project-root "$PWD" --id "$id"

3. Validate the staged result

bash
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" validate \
  --project-root "$PWD" --id "$id"

Validation performs a fork-safe structured refresh of every installed channel and provider, and of the selected gateway when gateway core or that gateway's own skill changed. On a skill-only change, a gateway it cannot resolve is skipped and named in the validation checks. It commits refreshed payloads in the staging branch, installs frozen dependencies, runs the host build and full host tests, and runs the container dependency/typecheck leg when Bun is available. A provider skill that declares Bun dependencies does not require Bun on the host: refresh runs the exact Bun version pinned by container/Dockerfile through pnpm. Any selected skill refresh or validation failure blocks cutover and the completion stamp.

Fix only failures caused by the staged update, inside stageRoot, commit the fix, and re-run validation. Do not mutate the live checkout to repair staging.

Show full SKILL.md (483 more words)Show less

4. Confirm and cut over

Before downtime, show the exact changed files, required migrations, detected backup tag, and rollback command. Ask for one confirmation to begin cutover.

bash
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" cutover \
  --project-root "$PWD" --id "$id"

Cutover stops the detected service, then stops this install's labeled agent containers (an agent mid-turn loses that turn; wait for a quiet moment if that matters), snapshots mutable state, resets the live branch to the validated target, installs frozen dependencies, builds the host, and updates the agent image when container/ changed. Hardened-image installs use pull; local-image installs build locally. The service remains stopped while required migrations are pending.

5. Complete every requirement

Process requirements one at a time.

  • For a referenced local guide, read it from the cut-over checkout and follow its detect, fix, verify, and rollback sections.
  • For a referenced /<skill>, read that skill's current SKILL.md and follow it directly. Do not require a harness-specific skill invocation feature.
  • For OneCLI pin moves, follow docs/onecli-upgrades.md; record the exact old version or rollback command because OneCLI is outside the Git snapshot.

If a migration intentionally changes tracked files, review and commit those changes before acknowledging it. Finish refuses a dirty cut-over checkout.

After verification, acknowledge the requirement:

bash
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" ack \
  --project-root "$PWD" --id "$id" \
  --requirement "$requirement_id" --status succeeded

For an external component, also pass a concise exact rollback instruction:

bash
... ack ... --rollback "restore onecli-gateway to <old-version>"

Use --status failed when verification fails. A pending or failed requirement blocks finish; never offer “restart anyway.” The state snapshot is the recovery path for forward local migrations.

6. Finish and health-check

bash
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" finish \
  --project-root "$PWD" --id "$id"

Finish stamps the exact version/commit/tree, restarts the service mode detected before cutover, and waits for the process, CLI socket, and a real CLI request. Only phase: complete is success.

After success, remove the staging worktree and its temporary branch from the live checkout. This keeps the backup branch/tag and mutable snapshot intact for rollback:

bash
pnpm exec tsx scripts/update-nanoclaw.ts cleanup --id "$id"

If health fails, the controller restores the previous Git commit and mutable state, rebuilds the previous image, restarts the old service, and verifies it. If an external component was changed, also execute the recorded external rollback instruction and verify that component; Git cannot restore it.

7. Report and retain one rollback point

Report:

  • transaction id and final phase;
  • old, target, and official upstream commits;
  • backup branch/tag and mutable snapshot location;
  • conflicts resolved;
  • registry remotes and refreshed skills;
  • validation and image result;
  • completed migrations and external rollback instructions;
  • detected service mode and health result; and
  • remaining diff from official upstream.

Manual rollback remains available while the snapshot is retained:

bash
pnpm exec tsx scripts/update-nanoclaw.ts rollback --id "$id"

Do not describe the Git tag alone as full rollback. The transaction snapshot is what restores SQLite and other mutable local state. Keep the newest successful transaction until the next update completes. Then preview older terminal transactions that are safe to prune:

bash
pnpm exec tsx scripts/update-nanoclaw.ts prune --id "$id" --dry-run

Show the removed list and ask for confirmation. If confirmed, run the same command without --dry-run. Pruning keeps the selected transaction, every newer transaction, and every nonterminal transaction. It removes older terminal snapshots and their staging/backup Git references. Never delete transaction directories directly.

© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/update-nanoclaw of nanocoai/nanoclaw.

Open the folder on GitHubat commit a0c79dd

Compare with similar skills

Update NanoClaw Safely next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update NanoClaw Safely compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update NanoClaw Safely this skillnanocoai/nanoclaw31k—~2.9kAutomated safety check: NotesMIT
Golem Deployment Versiongolemcloud/golem1.5k—~1.8kAutomated safety check: PassCustom licence
ccLoad Release Publishercaidaoli/ccLoad419—~887Automated safety check: PassMIT
ClawRouter Release ChecklistBlockRunAI/ClawRouter6.6k—~1.4kAutomated safety check: PassMIT
Release Lithoxylmahmoud/lithoxyl146—~1.3kAutomated safety check: PassBSD-3-Clause
Polyphonyalinaqi/maggy707—~980Automated safety check: PassMIT

Similar skills

  • Golem Deployment Version

    golemcloud/golem

    Configuring the deployment logical version in the Golem Application Manifest (golem.yaml): the version: source (git tag, git commit hash, static string, or env var), tuning…

    1.5k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Publishes a ccLoad Beta or explicit stable release through a version-tag workflow, including commit, push, CI wait, GitHub Release and container image checks.

    419 GitHub stars~887 tokensUpdated today
    DevOps & CloudAuto-check passed
  • ClawRouter Release Checklist

    BlockRunAI/ClawRouter

    Walks the agent through every ClawRouter release step in order, from the version bump and changelog entry to build, tests, npm publish, git tag and GitHub release.

    6.6k GitHub stars~1.4k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Release Lithoxyl

    mahmoud/lithoxyl

    Walks through releasing the lithoxyl Python package to PyPI: CalVer version bump, tagging, pushing and checking the published release.

    146 GitHub stars~1.3k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Polyphony

    alinaqi/maggy

    Multi-agent orchestration with container-isolated workspaces — each agent session runs in its own Docker container with independent git branches

    707 GitHub stars~980 tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed

More from nanocoai/nanoclaw

All 59 skills in this repo
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

    31k GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Agent Browser

    nanocoai/nanoclaw

    Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.

    31k GitHub starsUsed in 2 repos~1.6k tokens
    Auto-check passed
  • Add Dial Tool

    nanocoai/nanoclaw

    Installs the `dial` CLI and a credential in NanoClaw agent containers so chosen agents can send SMS, place AI voice calls and receive verification codes.

    31k GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.

    31k GitHub stars~6k tokensUpdated today
    Auto-check: notes
  • Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.

    31k GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Update NanoClaw Safely

What does Update NanoClaw Safely do?

Updates a customized NanoClaw install from the official upstream in a staged worktree, with state snapshots, migration gates, health checks and automatic rollback. The live checkout must be clean, and nothing in it changes until a staged copy has passed validation.env, data, groups and store are snapshotted before cutover.

When should I use Update NanoClaw Safely?

Update NanoClaw Safely fits situations like: pulling the latest official NanoClaw changes into a customized fork; doing a merge, rebase or selective upstream update with a way back; updating an install whose source is mounted into running containers.

How do I install Update NanoClaw Safely in Claude Code?

Run `npx skills add nanocoai/nanoclaw --skill update-nanoclaw -a claude-code`. Or copy the skill folder (.claude/skills/update-nanoclaw in nanocoai/nanoclaw) into .claude/skills/update-nanoclaw in your project. Claude Code loads it when a task matches its description.

How do I install Update NanoClaw Safely in Codex?

Run `npx skills add nanocoai/nanoclaw --skill update-nanoclaw -a codex`. Or copy the skill folder (.claude/skills/update-nanoclaw in nanocoai/nanoclaw) into .agents/skills/update-nanoclaw in your project. Codex loads it when a task matches its description.

Can I use Update NanoClaw Safely in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill update-nanoclaw -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-nanoclaw, .gemini/skills/update-nanoclaw, .github/skills/update-nanoclaw and .opencode/skills/update-nanoclaw in your project.

What does Update NanoClaw Safely need to run?

Going by SKILL.md and its folder, Update NanoClaw Safely needs the command-line tools its instructions call (pnpm and git). Our summary lists: A clean Git checkout of NanoClaw; Access to the official upstream remote; A detected launchd or systemd service, or a nohup start.

Does Update NanoClaw Safely access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update NanoClaw Safely safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Update NanoClaw Safely use?

Update NanoClaw Safely is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update NanoClaw Safely use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update NanoClaw Safely?

Skills that share tags, products or a category with Update NanoClaw Safely: Golem Deployment Version (golemcloud/golem, 1.5k stars), ccLoad Release Publisher (caidaoli/ccLoad, 419 stars), ClawRouter Release Checklist (BlockRunAI/ClawRouter, 6.6k stars) and Release Lithoxyl (mahmoud/lithoxyl, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update NanoClaw Safely?

nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,915 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 10, 2026.

Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.