Agent skill

Clawhub Moderation

by openclaw in openclaw/clawhub

A skill your agent uses for ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills, users, org publishers, plugin packages, trusted publishers, official publishers, and…

MITAuto-check passed

Install Clawhub Moderation

skills CLI
$ npx skills add openclaw/clawhub --skill clawhub-moderation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/clawhub clawhub-moderation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/clawhub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/clawhub-moderation .claude/skills/clawhub-moderation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clawhub-moderation
GitHub stars
9.5k
Token cost
~2.1k tokens
SKILL.md length
660 words
Files
1
Skills in repo
55
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills, users, org publishers, plugin packages, trusted publishers, official publishers, and…

  • ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills
  • SKILL.md covers Safety Rules, Command Map, Verification and Impact Notes
  • Calls bun
  • Plugin packages

What it does

Clawhub Moderation is an agent skill from openclaw/clawhub. Use for ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills, users, org publishers, plugin packages, trusted publishers, official publishers, and guarded staff email.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Skill + Plugin Registry for OpenClaw. The licence is MIT.

When your agent uses it

  • ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills
  • Plugin packages
  • Trusted publishers
  • Official publishers

Example prompts

  • “/clawhub-moderation”

What it can do on your machine

Read from SKILL.md and the folder at commit d044664. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clawhub Moderation loads about 2.1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/clawhub at commit d044664, republished under its MIT licence (© openclaw). 660 words, ~2,126 tokens.

Download SKILL.mdSave it as .claude/skills/clawhub-moderation/SKILL.md (or your agent's skills folder).
name
clawhub-moderation
description
Use for ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills, users, org publishers, plugin packages, trusted publishers, official publishers, and guarded staff email.

ClawHub Moderation

Use the repo-local admin tool from a checked-out ClawHub repo. It wraps the existing ClawHub CLI auth/config and HTTP API surfaces. Do not call Convex internal mutations directly for staff actions.

Safety Rules

  • Require an explicit target from the user: skill slug, user handle, or user id.
  • Require a reason for destructive, restorative, ownership, or moderation writes.
  • Before any write, show the exact command and ask for confirmation unless the user already said to proceed or supplied --yes.
  • For email send, the user must explicitly ask for the email and sign off on the final recipient, subject, and body. Dry-run is fine for drafting. Never send until both are true, and only use --send --confirm-user-request --confirm-user-signoff after that approval.
  • Prefer handles for humans. Use --id only when the user provides a user id.
  • Never bypass API-token auth, server role checks, or audit logging.
  • After the write, verify state with the CLI/API and report the result.

Command Map

Run from the ClawHub repo root:

sh
bun run admin -- --help

Authenticate or validate the current token:

sh
bun run admin -- login
bun run admin -- whoami

Current top-level command groups:

text
auth
users
plugins|plugin
packages|package
org
email
skills|skill
Skills

bun run admin -- skills --help exposes:

text
hard-delete <skill>
unhide <slug>
revoke-version <slug>
rescan <slug>
reports
triage-report <report-id>

Examples:

sh
bun run admin -- skills hard-delete @owner/<slug> --reason "<reason>"                    # dry-run
bun run admin -- skills hard-delete @owner/<slug> --reason "<reason>" --apply --confirm "<token>" --yes
bun run admin -- skills unhide <slug> --reason "<reason>" --yes
bun run admin -- skills revoke-version <slug> --version <version> --reason "<reason>" --yes
bun run admin -- skills rescan <slug> --reason "<reason>" --yes
bun run admin -- skills reports --status open
bun run admin -- skills triage-report <report-id> --status confirmed --action hide --note "<note>" --yes

hard-delete requires an owner-qualified ref and defaults to a dry-run. Apply only with the exact confirmation token returned by that dry-run.

Pass --owner <handle> to revoke-version when more than one publisher uses the same slug.

Users

bun run admin -- users --help exposes:

text
ban <handleOrId>
unban <handleOrId>
lift-moderation-hold <handleOrId>
set-role <handleOrId> <role>
reclassify-ban <handleOrId>
remediate-autobans

Examples:

sh
bun run admin -- users ban <handleOrId> --reason "<reason>" --yes
bun run admin -- users unban <handleOrId> --reason "<reason>" --yes
bun run admin -- users lift-moderation-hold <handleOrId> --reason "<reason>" --yes
bun run admin -- users set-role <handleOrId> <user|moderator|admin> --yes
bun run admin -- users reclassify-ban <handleOrId> --reason "<reason>" --apply --yes
bun run admin -- users remediate-autobans --apply --reason "<reason>"

Use --id when <handleOrId> is a user id. Use --fuzzy only when the user has asked for fuzzy handle resolution or the exact handle is ambiguous.

Org Publishers

bun run admin -- org --help exposes:

text
official
create <handle>
profile update <handle>
remove-member <handle> <member>
delete <handle>
repair-scoped-packages <csv>

Examples:

sh
bun run admin -- org official list
bun run admin -- org official add <handle> --reason "<reason>" --yes
bun run admin -- org official remove <handle> --reason "<reason>" --yes
bun run admin -- org create <handle> --display-name "<name>" --member <user-handle> --role owner
bun run admin -- org profile update <handle> --bio "<description>" --reason "<reason>" --yes
bun run admin -- org profile update <handle> --logo-file <path> --reason "<reason>" --yes
bun run admin -- org remove-member <handle> <member-handle>
bun run admin -- org delete <handle> --reason "<reason>"          # dry-run
bun run admin -- org delete <handle> --reason "<reason>" --apply
bun run admin -- org repair-scoped-packages <csv>                  # dry-run
bun run admin -- org repair-scoped-packages <csv> --apply

org create requires --member; it must not add the moderator running the command as an implicit owner. org delete only works for empty org publishers and defaults to dry-run. org profile update accepts a bio, a PNG/JPEG/WebP logo under 2 MB, or both, and records the required reason in the audit log.

Plugin Packages

bun run admin -- packages --help exposes:

text
moderate <name>
status|moderation-status <name>
queue|moderation-queue
reports
triage-report <report-id>
hard-delete <name>
transfer <name>
repair-name <name>
migrations
set-migration <bundled-plugin-id>
trusted-publisher

Examples:

sh
bun run admin -- packages status <name>
bun run admin -- packages hard-delete <name> --owner <handle> --reason "<reason>" # dry-run
bun run admin -- packages hard-delete <name> --owner <handle> --reason "<reason>" --apply --confirm "<token>" --yes
bun run admin -- packages transfer <name> --to <owner> --reason "<reason>"       # dry-run
bun run admin -- packages transfer <name> --to <owner> --reason "<reason>" --apply
bun run admin -- packages repair-name <name> --next-name <name> --reason "<reason>"
bun run admin -- packages trusted-publisher get <name>
bun run admin -- packages trusted-publisher set <name> --repository <owner/repo> --workflow-filename <file>
Staff Email

bun run admin -- email send --help exposes:

text
--to <email>
--user <handle>
--subject <subject>
--body-file <path>
--body <text>
--send
--confirm-user-request
--confirm-user-signoff
--json

Draft only:

sh
bun run admin -- email send --user <handle> --subject "<subject>" --body-file <path>

Send only after explicit request and sign-off:

sh
bun run admin -- email send --user <handle> --subject "<subject>" --body-file <path> --send --confirm-user-request --confirm-user-signoff

The server sends through the production noreply provider and writes an audit log only after admin auth succeeds.

Show full SKILL.md (302 more words)Show less

Verification

  • For skills, inspect the page/API status after skills unhide.
  • For skills hard-delete, verify owner-scoped page/API reads return not found.
  • For users, prefer user search/admin surfaces for target accounts where available.
  • For orgs and packages, use the public publisher/plugin pages and the relevant CLI status command after a write.
  • For email, verify the CLI response and audit expectation; do not send a second email just to test delivery.
  • If verification is blocked by auth or missing admin access, report the command result and the verification blocker plainly.

Impact Notes

  • skills unhide is a moderator manual restore. It clears skill hidden state, applies a clean manual override to top-level moderation fields, preserves version-level scanner records, updates public stats, and writes audit logs.
  • skills revoke-version permanently removes one exact version, records staff evidence, advances latest pointers to a safe survivor when one exists, and keeps the skill independently hidden when no usable version remains.
  • There is no standalone skills hide command in clawhub-admin; use report triage with --action hide when resolving a report that should hide a skill.
  • users ban is disruptive: it revokes API tokens, marks the user deleted, hides owned skills, soft-deletes comments, and writes audit logs.
  • users unban is admin-only. It clears ban state and restores skills that were hidden by the matching ban flow; revoked API tokens stay revoked.
  • users lift-moderation-hold is admin-only. It clears the account-level moderation hold, restores skills hidden by that hold, and writes an audit log.
  • packages transfer preserves the package row, stats, releases, and history; it changes the owner publisher.
  • packages hard-delete is admin-only, requires an already-soft-deleted package, exact owner handle, reason, and dry-run token, and permanently removes all package releases and related history.
  • org delete soft-deletes an empty org publisher and retains member rows for history; it refuses orgs with active skills or packages.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/clawhub-moderation of openclaw/clawhub.

Open the folder on GitHubat commit d044664

Compare with similar skills

Clawhub Moderation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clawhub Moderation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clawhub Moderation this skillopenclaw/clawhub9.5k—~2.1kAutomated safety check: PassMIT
Clawhubopenclaw/openclaw392k—~724Automated safety check: PassMIT
Adminyc-software/qm15k—~3.1kAutomated safety check: PassMIT
Clawhubtrpc-group/trpc-agent-go1.9k7 repos~404Automated safety check: PassApache-2.0
ClawhubPhyAgentOS/PhyAgentOS-core2.8k3 repos~351Automated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0

Similar skills

  • Clawhub

    openclaw/openclaw

    Search ClawHub for plugins by default, or skills when explicitly requested; install, verify, update, uninstall, publish, or sync skills.

    392k GitHub stars~724 tokensUpdated today
    Auto-check passed
  • Admin

    yc-software/qm

    Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…

    15k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Clawhub

    trpc-group/trpc-agent-go

    Use the ClawHub CLI to search, install, update, and publish agent skills from clawhub.com.

    1.9k GitHub starsUsed in 7 repos~404 tokens
    Auto-check passed
  • Clawhub

    PhyAgentOS/PhyAgentOS-core

    Search and install agent skills from ClawHub, the public skill registry.

    2.8k GitHub starsUsed in 3 repos~351 tokens
    Agent WorkflowsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Clawhub

    HKUDS/OpenOPC

    Search and install agent skills from ClawHub, the public skill registry.

    1.8k GitHub stars~467 tokensUpdated 28 days ago
    Agent WorkflowsAuto-check passed

More from openclaw/clawhub

All 55 skills in this repo
  • Creates and manages Axiom monitors and notifiers end to end through the v2 API, with scripts for each CRUD operation and a recommended create-validate-tune workflow.

    9.5k GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Axiom Dashboard Builder

    openclaw/clawhub

    Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana.

    9.5k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Axiom Cost Control

    openclaw/clawhub

    Finds unused data in Axiom by analyzing query patterns, then deploys a cost dashboard and ingest monitors to keep spend under the contract limit.

    9.5k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Axiom Metrics Query

    openclaw/clawhub

    Explores and queries OpenTelemetry metrics in Axiom MetricsDB, listing datasets, metrics and tags first and picking the right aggregation for each metric's type.

    9.5k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated yesterday
    Auto-check passed
  • Axiom Eval Writer

    openclaw/clawhub

    Scaffolds evaluation suites for the Axiom AI SDK: eval files, scorers, flag schemas and axiom.config.ts, generated from plain descriptions of an AI capability.

    9.5k GitHub stars~4.1k tokensUpdated yesterday
    Auto-check: warnings

Questions about Clawhub Moderation

What does Clawhub Moderation do?

A skill your agent uses for ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills, users, org publishers, plugin packages, trusted publishers, official publishers, and…. Clawhub Moderation is an agent skill from openclaw/clawhub. Use for ClawHub staff moderation actions with the repo-local ClawHub admin tool: skills, users, org publishers, plugin packages, trusted publishers, official publishers, and guarded staff email.

When should I use Clawhub Moderation?

Clawhub Moderation fits situations like: clawHub staff moderation actions with the repo-local ClawHub admin tool: skills; plugin packages; trusted publishers; official publishers.

How do I install Clawhub Moderation in Claude Code?

Run `npx skills add openclaw/clawhub --skill clawhub-moderation -a claude-code`. Or copy the skill folder (.agents/skills/clawhub-moderation in openclaw/clawhub) into .claude/skills/clawhub-moderation in your project. Claude Code loads it when a task matches its description.

How do I install Clawhub Moderation in Codex?

Run `npx skills add openclaw/clawhub --skill clawhub-moderation -a codex`. Or copy the skill folder (.agents/skills/clawhub-moderation in openclaw/clawhub) into .agents/skills/clawhub-moderation in your project. Codex loads it when a task matches its description.

Can I use Clawhub Moderation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawhub --skill clawhub-moderation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clawhub-moderation, .gemini/skills/clawhub-moderation, .github/skills/clawhub-moderation and .opencode/skills/clawhub-moderation in your project.

What does Clawhub Moderation need to run?

Going by SKILL.md and its folder, Clawhub Moderation needs the command-line tools its instructions call (bun).

Does Clawhub Moderation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Clawhub Moderation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clawhub Moderation use?

Clawhub Moderation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clawhub Moderation use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Clawhub Moderation?

Skills that share tags, products or a category with Clawhub Moderation: Clawhub (openclaw/openclaw, 392k stars), Admin (yc-software/qm, 15k stars), Clawhub (trpc-group/trpc-agent-go, 1.9k stars) and Clawhub (PhyAgentOS/PhyAgentOS-core, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clawhub Moderation?

openclaw (a GitHub organization) maintains it in openclaw/clawhub, which has 9,500 GitHub stars. The repository holds 55 skills in this directory. The repository was last updated on October 8, 2026.

Source: openclaw/clawhub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.