Official agent skill

Nemoclaw Maintainer Runtime Provider

by NVIDIA in NVIDIA/NemoClaw

Implement or review a native managed NemoClaw runtime provider and its activation or qualification.

OfficialApache-2.0Auto-check passed

Install Nemoclaw Maintainer Runtime Provider

skills CLI
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-runtime-provider -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-runtime-provider --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-runtime-provider .claude/skills/nemoclaw-maintainer-runtime-provider && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nemoclaw-maintainer-runtime-provider
GitHub stars
23k
Token cost
~1.2k tokens
SKILL.md length
560 words
Files
5 (incl. references)
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement or review a native managed NemoClaw runtime provider and its activation or qualification.

  • Works in 5 steps: Read… → Read activation.ts, current.ts, and… → Read the candidate provider factory and… → …
  • SKILL.md covers Confirm Product Scope, Load Current Authority, Choose the Delivery State and Implement One Provider Identity, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nemoclaw Maintainer Runtime Provider is an agent skill from NVIDIA/NemoClaw, published by the product's own GitHub organization. Implement or review a native managed NemoClaw runtime provider and its activation or qualification. Excludes the portable experimental profile.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `agents/openai.yaml`, `references/activation-and-qualification.md` and `references/api-contract.md`).

The repository describes itself as: Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference. The licence is Apache-2.0.

Example prompts

  • “/nemoclaw-maintainer-runtime-provider”

Requirements

  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read src/lib/onboard/runtime-provider/contract.ts and registry.ts.
  2. Read activation.ts, current.ts, and native-qualification-authority.ts.
  3. Read the candidate provider factory and its provider-owned helpers.
  4. Trace SandboxEntry.openshellDriver through onboarding and every lifecycle action in scope.
  5. Read the focused contract, activation, provider, architecture, and E2E-support tests.

What it can do on your machine

Read from SKILL.md and the folder at commit b95c0be. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nemoclaw Maintainer Runtime Provider loads about 1.2k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 45 tokens; SKILL.md has 560 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/NemoClaw at commit b95c0be, republished under its Apache-2.0 licence (© NVIDIA). 560 words, ~1,245 tokens.

Download SKILL.mdSave it as .claude/skills/nemoclaw-maintainer-runtime-provider/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
nemoclaw-maintainer-runtime-provider
description
Implement or review a native managed NemoClaw runtime provider and its activation or qualification. Excludes the portable experimental profile.
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->

Add a Managed Runtime Provider

Add one provider through the repository's runtime-provider contract. Keep generic orchestration independent of provider implementations and provider names.

Confirm Product Scope

Apply the product scope gate in AGENTS.md before implementation or approval. Require an accepted issue or accepted design decision that defines ownership, lifecycle, compatibility, security, and validation. A valid bundle or passing test does not establish a supported surface.

Keep the portable experimental profile independent. Do not change portable selection, lifecycle, or compatibility behavior as part of a native managed-provider change.

Load Current Authority

Before planning, editing, or reviewing:

  1. Read src/lib/onboard/runtime-provider/contract.ts and registry.ts.
  2. Read activation.ts, current.ts, and native-qualification-authority.ts.
  3. Read the candidate provider factory and its provider-owned helpers.
  4. Trace SandboxEntry.openshellDriver through onboarding and every lifecycle action in scope.
  5. Read the focused contract, activation, provider, architecture, and E2E-support tests.

Use checked-in source and tests as behavior authority. Use these references for interpretation:

Choose the Delivery State

Name the intended state before coding:

  • Candidate bundle: The registry accepts one complete 14-surface object. Optional surfaces may declare supported: false with a reason. The provider is not production-selectable.
  • Activated provider: Every required surface and qualification field passes the current activation contract. The provider enters through createCurrentRuntimeProviderBundles(...).
  • Activation-contract extension: The provider topology cannot satisfy the current activation contract. Stop implementation until maintainers accept the contract change and its validation.
  • Review: Evaluate the claimed state only. Do not turn an incomplete candidate into an activated provider during review.

Do not add a candidate to the established-provider registry to bypass activation. Do not emulate Docker commands or invent container-engine identities to satisfy a contract that does not match the provider topology.

Show full SKILL.md (253 more words)Show less

Implement One Provider Identity

Resolve configuration once to one opaque provider ID. Register one RuntimeProviderBundle under that identity. Bind every surface, receipt, resource handle, and persisted sandbox record to it.

Provider-owned modules must own provider-specific commands, endpoint or socket authority, runtime resource identity, network preparation, lifecycle operations, recovery, and cleanup. Generic orchestration must consume bundle surfaces. It must not import a provider implementation or branch on a provider name.

If the current contract lacks a required provider-owned behavior, propose the narrow contract extension and its tests. Do not add an ambient environment switch or a central provider-name branch as a substitute.

Persist the selected provider ID in SandboxEntry.openshellDriver. Start, stop, rebuild, snapshot, restore, recovery, inference changes, and destroy must resolve the same bundle from persisted state. Reject missing, unknown, reused, or drifted authority before mutation.

Validate and Qualify

Follow the focused checks in Implementation and Review. Run the current type, repository, contract, activation, provider, and architecture checks that the diff affects.

Local and CI checks establish contract behavior. They do not replace protected qualification or the complete supported live E2E matrix against the commit under review. When a maintainer requests a GitHub Actions run, follow Run Maintainer E2E.

Report

Return:

  • accepted product scope and intended delivery state;
  • provider ID, topology, authority model, and persisted state boundary;
  • implemented, unsupported, and extended bundle surfaces;
  • remaining provider-name branches in generic orchestration;
  • focused validation tied to the commit under review;
  • protected qualification and full E2E evidence, or the missing gate; and
  • credential, recovery, cleanup, and ownership obligations.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .agents/skills/nemoclaw-maintainer-runtime-provider of NVIDIA/NemoClaw.

  • SKILL.md
  • agents/openai.yaml
  • references/activation-and-qualification.md
  • references/api-contract.md
  • references/implementation-and-review.md

Open the folder on GitHubat commit b95c0be

Compare with similar skills

Nemoclaw Maintainer Runtime Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nemoclaw Maintainer Runtime Provider compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nemoclaw Maintainer Runtime Provider this skillNVIDIA/NemoClaw23k—~1.2kAutomated safety check: PassApache-2.0
Implementing Secrets Management With Vaultmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Implementing Mobile Application Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Implementing Attack Surface Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
OmniRoute Provider Managementdiegosouzapw/OmniRoute74k—~2.4kAutomated safety check: PassMIT
Implementing API Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Secrets Management With Vault

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Mobile Application Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Attack Surface Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    74k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Implementing API Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API Security Posture Management (API-SPM) to continuously discover, classify, and risk-score APIs -- including internal, external, partner, and shadow endpoints -- while aggregating…

    34k GitHub stars~3.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Patch Management For Ot Systems

    mukul975/Anthropic-Cybersecurity-Skills

    Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from NVIDIA/NemoClaw

All 30 skills in this repo
  • Official

    Find open issues that a NemoClaw PR may also fix or conflict with.

    23k GitHub stars~893 tokensUpdated today
    Auto-check passed
  • Official

    Run a NemoClaw daytime maintainer pass over release-targeted work.

    23k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Audit and implement a NemoClaw dependency version upgrade, including Hermes and base images.

    23k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Official

    Continuously maintain automatic NemoClaw main E2E results through coordinated repairs.

    23k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Analyze retained NemoClaw CI timings for slow CLI tests, runner queues, or base-image publication.

    23k GitHub stars~644 tokensUpdated today
    Auto-check passed

Questions about Nemoclaw Maintainer Runtime Provider

What does Nemoclaw Maintainer Runtime Provider do?

Implement or review a native managed NemoClaw runtime provider and its activation or qualification. Nemoclaw Maintainer Runtime Provider is an agent skill from NVIDIA/NemoClaw, published by the product's own GitHub organization. Implement or review a native managed NemoClaw runtime provider and its activation or qualification.

How do I install Nemoclaw Maintainer Runtime Provider in Claude Code?

Run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-runtime-provider -a claude-code`. Or copy the skill folder (.agents/skills/nemoclaw-maintainer-runtime-provider in NVIDIA/NemoClaw) into .claude/skills/nemoclaw-maintainer-runtime-provider in your project. Claude Code loads it when a task matches its description.

How do I install Nemoclaw Maintainer Runtime Provider in Codex?

Run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-runtime-provider -a codex`. Or copy the skill folder (.agents/skills/nemoclaw-maintainer-runtime-provider in NVIDIA/NemoClaw) into .agents/skills/nemoclaw-maintainer-runtime-provider in your project. Codex loads it when a task matches its description.

Can I use Nemoclaw Maintainer Runtime Provider in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-runtime-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nemoclaw-maintainer-runtime-provider, .gemini/skills/nemoclaw-maintainer-runtime-provider, .github/skills/nemoclaw-maintainer-runtime-provider and .opencode/skills/nemoclaw-maintainer-runtime-provider in your project.

What does Nemoclaw Maintainer Runtime Provider need to run?

SKILL.md names no scripts, command-line tools or credentials: Nemoclaw Maintainer Runtime Provider is instructions for the agent only. Our summary lists: Docker.

Does Nemoclaw Maintainer Runtime Provider access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nemoclaw Maintainer Runtime Provider safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nemoclaw Maintainer Runtime Provider use?

Nemoclaw Maintainer Runtime Provider is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nemoclaw Maintainer Runtime Provider use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.

What are the alternatives to Nemoclaw Maintainer Runtime Provider?

Skills that share tags, products or a category with Nemoclaw Maintainer Runtime Provider: Implementing Secrets Management With Vault (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Mobile Application Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Attack Surface Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and OmniRoute Provider Management (diegosouzapw/OmniRoute, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nemoclaw Maintainer Runtime Provider?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/NemoClaw, which has 22,678 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 8, 2026.

Source: NVIDIA/NemoClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.