Agent skill

Crabbox Apps

by openclaw in openclaw/openclaw

A skill your agent uses when asked to open, run, test, or show an app in Crabbox, including native desktops, web previews, and computer use on a temporary machine.

MITAuto-check passedProductivity & Automation

Install Crabbox Apps

skills CLI
$ npx skills add openclaw/openclaw --skill crabbox-apps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/openclaw crabbox-apps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/extensions/crabbox/skills/crabbox-apps .claude/skills/crabbox-apps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crabbox-apps
GitHub stars
392k
Token cost
~1.5k tokens
SKILL.md length
830 words
Files
1
Skills in repo
93
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when asked to open, run, test, or show an app in Crabbox, including native desktops, web previews, and computer use on a temporary machine.

  • Works in 4 steps: Install or build the app using remote… → Launch it with exec and background:… → When the computer tool is available,… → …
  • Show an app in Crabbox
  • SKILL.md covers Native apps, Web apps, Apps that call a model API and Follow-ups and cleanup
  • Needs OPENAI_API_KEY

What it does

Crabbox Apps is an agent skill from openclaw/openclaw. Use when asked to open, run, test, or show an app in Crabbox, including native desktops, web previews, and computer use on a temporary machine.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Desktop control. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.

When your agent uses it

  • Show an app in Crabbox
  • Including native desktops
  • Computer use on a temporary machine

Example prompts

  • “/crabbox-apps”

Requirements

  • Node.js
  • A credential in OPENAI_API_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Install or build the app using remote exec as needed.
  2. Launch it with exec and background: true. Retain its processId for
  3. When the computer tool is available, select the returned environmentId
  4. When the screen tool is available, call desktop_show with that

What it can do on your machine

Read from SKILL.md and the folder at commit 1eb5970. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.openclaw.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crabbox Apps loads about 1.5k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 830 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/openclaw at commit 1eb5970, republished under its MIT licence (© openclaw). 830 words, ~1,498 tokens.

Download SKILL.mdSave it as .claude/skills/crabbox-apps/SKILL.md (or your agent's skills folder).
name
crabbox-apps
description
Use when asked to open, run, test, or show an app in Crabbox, including native desktops, web previews, and computer use on a temporary machine.
user-invocable
false

Apps in Crabbox

"Open in Crabbox and show me" means launch the working application and open its view in the requesting user's chat side panel. Finish both operations.

Use the enabled crabbox tool to inspect the current attachment before creating one. Reuse that environment for follow-ups. profiles discovers configured profiles; choose one compatible with the application. Native desktop viewing and CUA require a desktop-enabled profile. Never silently substitute another OS for an application that requires a particular platform.

create attaches the machine to this conversation without moving the agent or its primary workspace. For an open-and-show request with the screen capability available, pass presentation: "desktop" for a native app or presentation: "portal" for a web app. This opens the right sidebar with machine startup progress before provisioning finishes. Its result identifies the environment. Use exec for commands on that environment; the ordinary shell still has its existing target. Copy or recreate the task's required files explicitly. Do not assume the local project was synchronized.

Native apps

  1. Install or build the app using remote exec as needed.
  2. Launch it with exec and background: true. Retain its processId for status, logs, and stop. Do not detach a shell process to escape lifecycle ownership.
  3. When the computer tool is available, select the returned environmentId and observe the application. CUA operates on the same desktop shown by VNC.
  4. When the screen tool is available, call desktop_show with that environmentId and dock: "right". Verify the app is ready before claiming success. An allocated machine or a blank desktop alone is insufficient.

Web apps

  1. When the portal tool is available, open a portal for the environment and application's port using environmentId. Keep its portal ID and public URL.
  2. Start the web server with remote exec, background: true, and the application's PORT and PUBLIC_URL set explicitly. Verify it responds.
  3. When the screen tool is available, use portal_show with the returned portalId and dock: "right". Show the web application directly in the portal.
  4. For CUA testing, use the attached environment's browser against the same server. The remote browser and the user's portal have separate cookies and browser state; do not assume they share a login or page navigation.

If an essential tool or desktop capability is unavailable, report the missing capability and the actual completed state. A portal that the user's browser cannot reach is not a completed preview. Preserve the separate-origin portal transport; never expose arbitrary application scripts on the Gateway origin.

Show full SKILL.md (417 more words)Show less

Apps that call a model API

Cloud-agent inference already uses Gateway-held authentication. An application inside the lease making its own API calls needs a separate protected route. For an exclusively owned coordinator-backed Linux lease, use the host CLI:

sh
openclaw crabbox run --id <lease-id> --model <provider/model> -- <command> <args>

Run from the credential-owning host and the local project directory that owns the lease. Prepare source and dependencies first: the command skips sync and hydration, and its bridge permits only the model host. A lease ID does not override Crabbox's repository claim. Require no active egress session and a Crabbox binary supporting egress run --upstream-proxy-env. Crabbox owns the foreground bridge, remote command, and session cleanup.

The provider must have a configured API-key SecretRef and an OpenAI-compatible HTTPS endpoint on port 443. Auth-profile/OAuth credentials, custom headers, and request transport overrides are unsupported. The CLI injects a sentinel as OPENAI_API_KEY, plus OPENAI_BASE_URL, OPENAI_MODEL, proxy settings, and public CA trust. The actual key and upstream proxy credentials stay on the host. Use a client that honors the proxy and CA environment; Node.js needs NODE_USE_ENV_PROXY support, while Python's default urllib.request opener honors the environment. Custom SDK clients may need explicit proxy/trust setup.

Keep this command alive for the full app lifetime. Do not detach the app or copy a key into the box. Ordinary tool exec and background do not acquire this model grant. Cancellation revokes access before cleanup; if settlement is uncertain, inspect the named session and remote process before reusing the lease. This path needs no Gateway restart or persistent egress setting. See the setup, runnable example, and recovery guide.

Follow-ups and cleanup

Reopen the current environment or portal for "show me again". A viewer reconnect must not allocate another machine. Before showing a remembered portal, confirm it still exists with portal list; portal IDs can expire across Gateway restarts. If it is gone, open a replacement for the same environment and running app port, then show and verify that new portal. Refresh the app's PUBLIC_URL if it relies on that URL for links or redirects. Use process_status to inspect a launched app and process_stop to stop just that process. stop releases the entire temporary environment. Closing the side panel only hides the view.

Observe again before CUA input. When the user takes desktop control, stop sending input until they release control; screenshot reads may continue. Never work around a control-ownership refusal with shell-injected clicks.

The machine is disposable and follows its configured lifetime. Preserve requested outputs before stopping it; the conversation transcript alone is not a backup of remote files.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in extensions/crabbox/skills/crabbox-apps of openclaw/openclaw.

Open the folder on GitHubat commit 1eb5970

Compare with similar skills

Crabbox Apps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crabbox Apps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crabbox Apps this skillopenclaw/openclaw392k—~1.5kAutomated safety check: PassMIT
Vision SkillsAnionex/agent-vision-toolkit1.2k1 repos~4kAutomated safety check: PassMIT
Mac Computer UseTo3akaRin/mac-computer-use1.1k1 repos~495Automated safety check: PassMIT
Agent Managementautonomous-ai/Physical-AI-Operating-System381—~1.7kAutomated safety check: PassApache-2.0
Computer Usebam-bam-2/solo-skills3671 repos~915Automated safety check: PassMIT
Cloud Computer Usedavidondrej/cloudroom-core272—~881Automated safety check: NotesApache-2.0

Similar skills

  • Vision Skills

    Anionex/agent-vision-toolkit

    Local vision CLIs: glance (describe/ask/OCR an image), ground (locate a target, pixel box), detect (element inventory), trace (image to SVG geometry), crop (cut a pixel box to a file), and…

    1.2k GitHub starsUsed in 1 repo~4k tokens
    Productivity & AutomationAuto-check passed
  • Mac Computer Use

    To3akaRin/mac-computer-use

    操作 macOS 桌面应用,探测窗口和自动化接口、截图、读取或修改辅助功能元素、执行鼠标键盘动作,以及通过 CDP 操作内嵌 Chromium 页面。适用于桌面应用自动化与界面验收;普通网页任务优先使用已有浏览器工具。

    1.1k GitHub starsUsed in 1 repo~495 tokens
    Productivity & AutomationAuto-check passed
  • Agent Management

    autonomous-ai/Physical-AI-Operating-System

    Legacy Autonomous Buddy control for explicitly requested Buddy coding sessions.

    381 GitHub stars~1.7k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Computer Use

    bam-bam-2/solo-skills

    Use Orca's computer-use CLI to inspect and operate local desktop app windows through accessibility trees, screenshots, and safe UI actions.

    367 GitHub starsUsed in 1 repo~915 tokens
    Productivity & AutomationAuto-check passed
  • Cloud Computer Use

    davidondrej/cloudroom-core

    See and control desktop apps on this Cloud sandbox’s virtual Linux screen with cloudroom computer-use: launch GUI apps you build or install, read their UI, click, type, and take screenshots.

    272 GitHub stars~881 tokensUpdated yesterday
    Productivity & AutomationAuto-check: notes
  • Verify UI Change In Cloud

    Heartcoolman/warp-cn

    Invoke this automatically after completing any user-facing client change, ONLY in non-sandboxed environments and local environments.

    120 GitHub stars~1.1k tokensUpdated 3 days ago
    Productivity & AutomationAuto-check passed

More from openclaw/openclaw

All 93 skills in this repo
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Tmux

    openclaw/openclaw

    Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.

    392k GitHub starsUsed in 2 repos~640 tokens
    Auto-check passed
  • Feishu Doc

    openclaw/openclaw

    Feishu document read/write workflows. An agent skill from openclaw/openclaw.

    392k GitHub stars~516 tokensUpdated today
    Auto-check passed
  • Openclaw PR Maintainer

    openclaw/openclaw

    Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.

    392k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Browser Automation

    openclaw/openclaw

    A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.

    392k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Clawsweeper

    openclaw/openclaw

    A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…

    392k GitHub stars~3k tokensUpdated today
    Auto-check passed

Questions about Crabbox Apps

What does Crabbox Apps do?

A skill your agent uses when asked to open, run, test, or show an app in Crabbox, including native desktops, web previews, and computer use on a temporary machine. Crabbox Apps is an agent skill from openclaw/openclaw. Use when asked to open, run, test, or show an app in Crabbox, including native desktops, web previews, and computer use on a temporary machine.

When should I use Crabbox Apps?

Crabbox Apps fits situations like: show an app in Crabbox; including native desktops; computer use on a temporary machine.

How do I install Crabbox Apps in Claude Code?

Run `npx skills add openclaw/openclaw --skill crabbox-apps -a claude-code`. Or copy the skill folder (extensions/crabbox/skills/crabbox-apps in openclaw/openclaw) into .claude/skills/crabbox-apps in your project. Claude Code loads it when a task matches its description.

How do I install Crabbox Apps in Codex?

Run `npx skills add openclaw/openclaw --skill crabbox-apps -a codex`. Or copy the skill folder (extensions/crabbox/skills/crabbox-apps in openclaw/openclaw) into .agents/skills/crabbox-apps in your project. Codex loads it when a task matches its description.

Can I use Crabbox Apps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill crabbox-apps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crabbox-apps, .gemini/skills/crabbox-apps, .github/skills/crabbox-apps and .opencode/skills/crabbox-apps in your project.

What does Crabbox Apps need to run?

Going by SKILL.md and its folder, Crabbox Apps needs credentials named OPENAI_API_KEY. Our summary lists: Node.js; A credential in OPENAI_API_KEY.

Does Crabbox Apps access the network?

SKILL.md names 1 domain. As links in the text: docs.openclaw.ai. This is read from the text; nothing was executed.

Is Crabbox Apps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Crabbox Apps use?

Crabbox Apps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crabbox Apps use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Crabbox Apps?

Skills that share tags, products or a category with Crabbox Apps: Vision Skills (Anionex/agent-vision-toolkit, 1.2k stars), Mac Computer Use (To3akaRin/mac-computer-use, 1.1k stars), Agent Management (autonomous-ai/Physical-AI-Operating-System, 381 stars) and Computer Use (bam-bam-2/solo-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crabbox Apps?

openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,610 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 8, 2026.

Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.