Agent skill

Node Connect

by openclaw in openclaw/openclaw

Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states.

MITAuto-check passedMobile

Install Node Connect

skills CLI
$ npx skills add openclaw/openclaw --skill node-connect -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/openclaw node-connect --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/node-connect .claude/skills/node-connect && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
node-connect
GitHub stars
392k
Token cost
~1.6k tokens
SKILL.md length
799 words
Files
1
Skills in repo
93
Repo updated
First seen
Licence
MIT

At a glance

Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states.

  • Works in 5 steps: Lock the target → Classify the client → Observe the failing attempt → …
  • Mobile work in your project
  • SKILL.md covers 1. Lock the target, 2. Classify the client, 3. Observe the failing attempt and 4. Prove the route, plus 3 more sections
  • Calls jq

What it does

Node Connect is an agent skill from openclaw/openclaw. Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile. It works with Android, iOS and macOS. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.

When your agent uses it

  • Mobile work in your project

Example prompts

  • “/node-connect”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Lock the target
  2. Classify the client
  3. Observe the failing attempt
  4. Prove the route
  5. Correlate and finish

What it can do on your machine

Read from SKILL.md and the folder at commit 1eb5970. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Node Connect loads about 1.6k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 799 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/openclaw at commit 1eb5970, republished under its MIT licence (© openclaw). 799 words, ~1,638 tokens.

Download SKILL.mdSave it as .claude/skills/node-connect/SKILL.md (or your agent's skills folder).
name
node-connect
description
Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states.

Node Connect

Goal: fix one exact client against one exact Gateway, then prove that client's fresh connection.

1. Lock the target

Record the target environment/profile, OpenClaw binary, config/state root, Gateway URL/port, and service before changing anything.

  • Use the named deployment wrapper/profile for every config, log, service, device, and node command.
  • Never drift to a bare openclaw, proof environment, or similarly named deployment.
  • If the global executable is stale, invoke the target through its owner.
  • Verify status, config, logs, and process identity describe the same Gateway.

Identify the target Gateway before changing pairing or auth.

2. Classify the client

Classify from the request and Gateway log before choosing commands:

  • Control UI browser: the user says browser, dashboard, Control UI, or webchat; logs show client=openclaw-control-ui or mode=webchat.
  • Native mobile/node: the official app shows Connect, Scan QR, or setup code; logs/request metadata show a native client or role=node.

A phone can be either client. Do not use openclaw qr or openclaw nodes status for a phone browser; those belong to native mobile/node pairing.

3. Observe the failing attempt

Run these through the locked target:

bash
openclaw gateway status --deep
openclaw logs --follow --json
openclaw devices list
openclaw config get gateway.mode
openclaw config get gateway.bind
openclaw config get gateway.remote.url
openclaw config get gateway.auth.mode
openclaw config get gateway.auth.allowTailscale
openclaw config get gateway.tailscale.mode

Have the client retry once while logs are live. Correlate its client ID, mode, platform, address, auth result, device ID, user, and close code. Ignore other paired devices.

Interpret the first failed transition:

  • No matching Gateway attempt: route, DNS, TLS, origin, or proxy problem.
  • token_missing, password_missing, mismatch, or Tailscale identity failure: auth failed before pairing, so an empty pending list is expected.
  • pairing required: route and auth succeeded; approve the exact pending request.
  • authenticated user connected / webchat connected: match the exact client; if followed by 1006, preserve auth/pairing and inspect lifecycle, transport, proxy, or reconnect.
  • 1006 without either application-level connected log does not prove auth/pairing; inspect the earlier handshake transition.

4. Prove the route

Choose one topology: same machine, LAN, tailnet, or public reverse proxy. Do not mix them.

  • Browser Control UI needs HTTPS or localhost for browser device identity. A remote plain-HTTP Tailnet/LAN URL is not a valid substitute.
  • gateway.tailscale.mode=off means OpenClaw is not managing Serve/Funnel. It does not prove that Tailscale or an externally managed Serve route is absent.
  • When Tailscale is involved, inspect live state rather than inferring it from OpenClaw config:
bash
tailscale status --json
tailscale serve status --json

Match the client's URL to the listener/proxy route reaching the locked Gateway.

5A. Control UI browser lane

Restore browser auth before looking for a pairing request:

  • For token/password auth, enter the credential in Control UI settings. Never put permanent secrets in chat, logs, or URLs.
  • Prefer openclaw dashboard on the Gateway host for a one-time signed handoff. Use --no-open only when the operator can retrieve that host's clipboard, and keep the host browser/clipboard outside agent tooling. Never capture dashboard --json: it can expose the handoff and shared credentials. Never relay, rewrite, or send a loopback handoff URL to a remote phone.
  • For Tailscale Serve, verify the live route and forwarded identity. Enable gateway.auth.allowTailscale only for that intended trust boundary. Verified Tailscale Control UI auth with browser device identity can skip pairing.

After auth succeeds:

  • Retry; never infer pairing from the pre-auth attempt. Token/password auth can reveal pairing required; verified Tailscale identity can skip it.
  • If logs say pairing required, re-list devices and approve the exact request ID.
  • A successful verified-Tailscale connection may correctly create no pending or paired-device row.
  • After a repeated 1006, preserve auth/pairing and inspect reconnect evidence.
Show full SKILL.md (244 more words)Show less

5B. Native mobile/node lane

Inspect the native route through the locked target without exposing the setup credential:

bash
openclaw qr --json | jq '{gatewayUrl, gatewayUrls, auth, access, accessDowngraded, urlSource}'

For a CLI controlling a remote Gateway, add --remote before --json; it selects gateway.remote.url and remote credentials. If the redaction filter is unavailable, do not run raw QR JSON in agent-visible output.

Verify gatewayUrl and urlSource. The setup code is password-equivalent: have the operator copy it from Control UI → Devices → Pair device, or run openclaw qr --setup-code-only in a terminal outside agent tooling and paste it directly into the official app. Never relay it through agent/chat/tool output. Generate a fresh code after a URL/auth fix or expiry.

If the app reports pairing required:

bash
openclaw devices list
openclaw devices approve --latest   # preview only; exits without approval
openclaw devices approve <requestId>
openclaw nodes status

--latest only previews the current request; never treat it as approval. Re-list immediately before the exact-ID command because retries can supersede the request. Never approve by position, age, or similarity.

6. Correlate and finish

Before approval, match available request, device/public-key, client, mode/role, platform, address, user, and retry-time facts.

Declare success only after a new attempt made after the final change proves all applicable checks:

  • the exact client reaches the locked Gateway;
  • intended auth succeeds;
  • the browser completes initial requests, or the native node appears in openclaw nodes status;
  • approval used the exact request ID; and
  • no immediate auth, pairing, or reconnect failure follows.

A QR/setup code, launched browser, empty pending list, approval, paired-device count, or Tailscale ping proves only one transition.

Report the diagnosis, chosen route/auth lane, exact-client evidence, and any remaining failed transition.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/node-connect of openclaw/openclaw.

Open the folder on GitHubat commit 1eb5970

Compare with similar skills

Node Connect next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Node Connect compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Node Connect this skillopenclaw/openclaw392k—~1.6kAutomated safety check: PassMIT
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause
App Store Screenshots GeneratorParthJadhav/app-store-screenshots7.2k—~14kAutomated safety check: PassMIT
Phoneagentrounak/PhoneAgent798—~2.2kAutomated safety check: PassMIT
Jetpack Composedarriousliu/PiPixiv262—~1.5kAutomated safety check: PassApache-2.0
Learnmakecindy/cindy2.9k—~368Automated safety check: PassApache-2.0

Similar skills

  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • App Store Screenshots Generator

    ParthJadhav/app-store-screenshots

    Scaffolds a Next.js editor for designing App Store and Google Play screenshots as ads and exporting them at every required size, for iOS, Mac and Android.

    7.2k GitHub stars~14k tokensUpdated today
    MobileAuto-check passed
  • Phoneagent

    rounak/PhoneAgent

    Control a connected iPhone, iOS simulator, Android emulator, or Android device from macOS through PhoneAgent's JSON-RPC bridge.

    798 GitHub stars~2.2k tokensUpdated 1 mo ago
    MobileAuto-check passed
  • Jetpack Compose

    darriousliu/PiPixiv

    Jetpack Compose expert skill for Android UI development. An agent skill from darriousliu/PiPixiv.

    262 GitHub stars~1.5k tokensUpdated today
    MobileAuto-check passed
  • Learn

    makecindy/cindy

    Distill a reusable Cindy Skill from the current task, a described workflow, or a SkillHub skill through Cindy's review flow when the user directly invokes /learn or /skill:learn in Pi.

    2.9k GitHub stars~368 tokensUpdated today
    MobileAuto-check passed
  • Ksafe

    ioannisa/KSafe

    Required before any reply that touches KSafe (by ksafe(...), ksafe.get/put, :ksafe-compose, :ksafe-biometrics), even a 'can KSafe do X?' question or a one-line change that looks like plain Kotlin.

    332 GitHub stars~17k tokensUpdated 4 days ago
    MobileAuto-check passed

More from openclaw/openclaw

All 93 skills in this repo
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Tmux

    openclaw/openclaw

    Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.

    392k GitHub starsUsed in 2 repos~640 tokens
    Auto-check passed
  • Feishu Doc

    openclaw/openclaw

    Feishu document read/write workflows. An agent skill from openclaw/openclaw.

    392k GitHub stars~516 tokensUpdated today
    Auto-check passed
  • Openclaw PR Maintainer

    openclaw/openclaw

    Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.

    392k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Browser Automation

    openclaw/openclaw

    A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.

    392k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Clawsweeper

    openclaw/openclaw

    A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…

    392k GitHub stars~3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Node Connect

What does Node Connect do?

Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states. Node Connect is an agent skill from openclaw/openclaw. Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states.

When should I use Node Connect?

Node Connect fits situations like: mobile work in your project.

How do I install Node Connect in Claude Code?

Run `npx skills add openclaw/openclaw --skill node-connect -a claude-code`. Or copy the skill folder (skills/node-connect in openclaw/openclaw) into .claude/skills/node-connect in your project. Claude Code loads it when a task matches its description.

How do I install Node Connect in Codex?

Run `npx skills add openclaw/openclaw --skill node-connect -a codex`. Or copy the skill folder (skills/node-connect in openclaw/openclaw) into .agents/skills/node-connect in your project. Codex loads it when a task matches its description.

Can I use Node Connect in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill node-connect -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/node-connect, .gemini/skills/node-connect, .github/skills/node-connect and .opencode/skills/node-connect in your project.

What does Node Connect need to run?

Going by SKILL.md and its folder, Node Connect needs the command-line tools its instructions call (jq).

Does Node Connect access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Node Connect safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Node Connect use?

Node Connect is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Node Connect use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Node Connect?

Skills that share tags, products or a category with Node Connect: Engine Whats New (flutter/flutter, 179k stars), App Store Screenshots Generator (ParthJadhav/app-store-screenshots, 7.2k stars), Phoneagent (rounak/PhoneAgent, 798 stars) and Jetpack Compose (darriousliu/PiPixiv, 262 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Node Connect?

openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,610 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 8, 2026.

Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.