Agent skill

Release Openclaw Plugin Testing

by openclaw in openclaw/openclaw

Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E…

MITAuto-check passedTesting & QA

Install Release Openclaw Plugin Testing

skills CLI
$ npx skills add openclaw/openclaw --skill release-openclaw-plugin-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/openclaw release-openclaw-plugin-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release-openclaw-plugin-testing .claude/skills/release-openclaw-plugin-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-openclaw-plugin-testing
GitHub stars
392k
Token cost
~3.1k tokens
SKILL.md length
1,238 words
Files
2
Skills in repo
93
Repo updated
First seen
Licence
MIT

At a glance

Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E…

  • Works in 5 steps: GitHub Package Acceptance for… → Current dedicated Linux worker for… → ci-build-artifacts-testbox.yml Testbox… → …
  • Tasks that involve Containers
  • SKILL.md covers Goal, First Checks, Runner Choice and Existing Baseline, plus 10 more sections
  • Calls pnpm, gh and git

What it does

Release Openclaw Plugin Testing is an agent skill from openclaw/openclaw. Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E, Package Acceptance, and Testbox proof.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Testing & QA, covering Containers and End-to-end testing. It works with Docker. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve End-to-end testing

Example prompts

  • “/release-openclaw-plugin-testing”

Requirements

  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. GitHub Package Acceptance for installable-package product proof.
  2. Current dedicated Linux worker for trusted source/package/Docker proof
  3. ci-build-artifacts-testbox.yml Testbox when Docker/package lanes need
  4. ci-check-testbox.yml Testbox for source checks, targeted Vitest,
  5. Workstation targeted commands only for small format/static/unit probes.

What it can do on your machine

Read from SKILL.md and the folder at commit 1eb5970. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Openclaw Plugin Testing loads about 3.1k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 1,238 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/openclaw at commit 1eb5970, republished under its MIT licence (© openclaw). 1,238 words, ~3,099 tokens.

Download SKILL.mdSave it as .claude/skills/release-openclaw-plugin-testing/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
release-openclaw-plugin-testing
description
Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E, Package Acceptance, and Testbox proof.

OpenClaw Pre-Release Plugin Testing

Use this skill when the user asks for plugin release confidence, plugin lifecycle sweeps, package-artifact plugin proof, or "what else should we test before release?" It complements openclaw-testing; use that skill too when choosing the cheapest safe runner or debugging a failing lane.

Goal

Prove the plugin system as a product surface, not just as source tests:

  • bundled plugin lifecycle: install, inspect, enable, disable, uninstall
  • package artifact behavior from a clean HOME
  • doctor/fix/config validation and idempotence
  • config discovery and config round-trip
  • status/log visibility and diagnostics
  • gateway startup/bootstrap with plugin metadata snapshots
  • public SDK compatibility for real external plugins
  • live-ish provider/channel probes only when safe credentials exist

First Checks

From the OpenClaw repo root:

bash
pnpm docs:list
git status --short --branch
pnpm changed:lanes --json

Follow openclaw-testing for dependency ownership and the choice of local or remote proof.

Runner Choice

Prefer this order:

  1. GitHub Package Acceptance for installable-package product proof.
  2. Current dedicated Linux worker for trusted source/package/Docker proof when it has the required dependencies and capabilities.
  3. ci-build-artifacts-testbox.yml Testbox when Docker/package lanes need seeded dist, dist-runtime, and package caches.
  4. ci-check-testbox.yml Testbox for source checks, targeted Vitest, package-boundary checks, or focused Docker lanes.
  5. Workstation targeted commands only for small format/static/unit probes.

Avoid long package Docker runs from a stale sparse worktree. If Testbox sync reports hundreds of changed files or starts deleting package inputs, stop and warm a fresh box from current main, or switch to Package Acceptance.

Existing Baseline

Run or verify these before inventing new coverage:

bash
OPENCLAW_TESTBOX=1 pnpm check:changed
pnpm run test:extensions:package-boundary:canary
pnpm run test:extensions:package-boundary:compile
pnpm test:docker:plugins
OPENCLAW_PLUGINS_E2E_CLAWHUB=0 pnpm test:docker:plugins
pnpm test:docker:plugin-update

For full bundled install/uninstall proof, shard the packaged sweep:

bash
OPENCLAW_BUNDLED_PLUGIN_SWEEP_TOTAL=8 \
OPENCLAW_BUNDLED_PLUGIN_SWEEP_INDEX=<0-7> \
pnpm test:docker:bundled-plugin-install-uninstall

This example partitions the selected package's plugin inventory over shards 0-7. Private QA plugins are source-mode only unless a package explicitly includes them.

Confidence Matrix

Use this matrix for pre-release signoff. Record pass/fail, run URL/Testbox ID, package SHA/version, and skipped-live reason.

SurfaceProofPreferred runner
Package artifactPackage Acceptance suite_profile=package or custom lanesGitHub Actions
Bundled lifecycleSharded test:docker:bundled-plugin-install-uninstallTestbox or release Docker
External pluginstest:docker:plugins and plugins-offlineTestbox/package acceptance
Update no-optest:docker:plugin-updateTestbox/package acceptance
Doctor/fixseeded bad configs + doctor --fix --non-interactivenew Docker/Testbox harness
Config round-tripconfig set/get, inspect, doctor, reload, diff hashnew Docker/Testbox harness
Gateway bootstrapclean HOME, plugin groups enabled/disabled, status JSONnew Docker/Testbox harness
SDK compatibilitydirectory, tgz, and file: external plugins using SDK subpathstest:docker:plugins plus new smoke
Live-ishredacted provider/channel probes only for present envTestbox live lanes

Package Acceptance Plan

Use this when validating a release branch, beta, or candidate package:

bash
gh workflow run package-acceptance.yml \
  --repo openclaw/openclaw \
  --ref main \
  -f workflow_ref=main \
  -f source=ref \
  -f package_ref=<branch-or-sha> \
  -f suite_profile=custom \
  -f docker_lanes='plugins-offline plugin-update doctor-switch update-channel-switch config-reload mcp-channels npm-onboard-channel-agent' \
  -f telegram_mode=mock-openai

Use source=npm -f package_spec=openclaw@beta for published beta proof. Keep workflow_ref as trusted current harness code unless the release process says otherwise.

For extended-stable shared publication, require complete exact-target Full Release Validation from the trusted main-pinned release-ci/* harness. Direct canonical-branch or main producers do not satisfy the protected publisher. Package Acceptance is a post-publish selector smoke:

bash
gh workflow run package-acceptance.yml \
  --repo openclaw/openclaw \
  --ref main \
  -f workflow_ref=main \
  -f source=npm \
  -f package_spec=openclaw@extended-stable \
  -f suite_profile=package \
  -f telegram_mode=mock-openai

Record the resolved version. Still verify every package and selector in the tag's all-publishable inventory; one smoke is not registry readback.

Plugin npm Artifact Qualification

For a publication candidate, Full Release Validation owns plugin npm artifact qualification. Supply its publication selection at dispatch; the all-group parent invokes plugin-npm-release.yml in artifact-only mode against the exact Release SHA, requires successful tarball readback, and records the immutable aggregate descriptor in publicationArtifacts.pluginNpm. Release Prepare and publication must adopt that exact descriptor rather than repacking plugins.

Use a standalone trusted-workflow preflight only for a focused diagnostic or a selected-plugin repair that is outside a regular publication candidate:

bash
release_sha="$(git rev-parse origin/release/2026.7.1)"
gh workflow run plugin-npm-release.yml \
  --repo openclaw/openclaw \
  --ref main \
  -f preflight_only=true \
  -f publish_scope=selected \
  -f plugins=@openclaw/meta-provider \
  -f ref="${release_sha}" \
  -f npm_dist_tag=default

Do not pass release_publish_run_id. Require the workflow to finish verify_plugin_npm_preflight successfully. Record the run URL, workflow SHA, and source SHA. The workflow first creates the staging/readback artifact plugin-npm-package-source-<source-sha>-<extension-id> containing npm-pack.json, preflight-manifest.json, and the tarball. It then uploads the final consumer artifact plugin-npm-package-<extension-id>-<version>-<route>-<run-id>-<attempt> containing the tarball and plugin-publication-manifest.json.

Record the final artifact name and digest separately. The manifest uses openclaw.plugin-publication-artifact/v1 and records the target SHA, package manifest hashes, publication route and policy, and tarball hashes and inventory. This standalone proof is validation-only; it does not authorize or stage publication and cannot replace Full Release Validation's manifest-bound descriptor. The artifact inventory, rather than the unpacked source tree, is the security and package-content boundary: source-only fixtures are irrelevant. Package-owned test and fixture paths outside shipped runtime and skill assets fail qualification; shipped runtime remains security-scanned. Bundled node_modules stays with dependency evidence rather than plugin-source policy. The separate trusted_publisher_preflight=true OIDC check requires a protected release-publish/<tooling-sha12>-<epoch> dispatch tag and runs in npm-publish. Real publication also requires that tooling tag; a direct human dispatch waits for its npm-release approval job before publishing. For an already-published version, require npm dist.integrity and dist.shasum to match the verified tarball. Treat only missing or provably older dist-tags as repairable; newer or incomparable selectors are a blocker.

Show full SKILL.md (474 more words)Show less

New Testbox Harness Plan

If more certainty is needed, add or run a plugin-lifecycle-matrix Docker lane that uses one package tarball and sharded plugin lists. Per plugin:

  1. Start with a clean HOME.
  2. Capture plugins list --json.
  3. plugins install <id>.
  4. plugins inspect <id> --json.
  5. plugins disable <id>, then assert disabled visibility.
  6. plugins enable <id>, except config-required plugins without config.
  7. plugins registry --refresh.
  8. doctor --non-interactive.
  9. plugins uninstall <id> --force.
  10. Assert the plugin's plugins.entries value is exactly { enabled: false }, while its allow/deny entries, install record, managed directory, and bundled runtime load paths are gone. Use the existing harness's source-qualified uninstall expectations for historical targets.
  11. Assert diagnostics contain no level: "error" and output redacts secret-looking values.

Keep memory-lancedb special: it is config-required. First assert install does not enable it without embedding config, then run a second configured case.

Doctor/Fix Matrix

Seed bad states and require doctor --fix --non-interactive to repair them, then run doctor again and require idempotence:

  • stale plugins.allow
  • stale plugins.entries
  • stale channel config for missing channel plugin
  • invalid plugins.entries.<id>.config
  • packaged bundled path in plugins.load.paths
  • legacy plugins.installs
  • disabled channel/plugin config that must not stage runtime deps
  • root-owned global package tree that must remain unmodified

Gateway Bootstrap Matrix

Start packaged OpenClaw in Docker with clean state:

  • provider plugins enabled, no credentials: ready with warnings, no crash
  • channel plugins configured disabled: no runtime deps staged
  • startup-activation plugins enabled: ready and reflected in status
  • invalid single plugin config: bad plugin skipped/quarantined, others remain

Assert:

  • gateway reaches ready
  • openclaw status --json includes plugin diagnostics
  • openclaw plugins inspect --all --json is parseable
  • package tree is not mutated
  • logs contain no raw tokens

Config Round-Trip Representatives

Use representative plugin families instead of every plugin for deep config round-trip:

  • providers: openai, anthropic, mistral, openrouter
  • channels: telegram, discord, slack, whatsapp
  • memory: memory-lancedb
  • feature/runtime: browser, acpx, tokenjuice

For each representative:

  1. Write config through CLI when possible.
  2. Read it back through config get or JSON.
  3. Run plugins inspect.
  4. Run doctor --non-interactive.
  5. Trigger gateway config reload if applicable.
  6. Compare config hash before/after no-op commands.

External SDK Smoke

In a package Docker lane, create tiny external plugins and install them from:

  • local directory
  • .tgz
  • file: npm spec

Cover CJS and ESM shapes, plus at least one plugin importing focused openclaw/plugin-sdk/* subpaths. Assert plugins inspect sees its tool, gateway method, CLI command, or service.

Live-Ish Probe Rules

Before live-ish work, source allowed env in Testbox and generate a redacted availability matrix: present/missing only, never values.

Only run probes for credentials that exist. Prefer auth/catalog/status probes over sending user-visible messages. If a probe might contact an external user, channel, or workspace, stop and ask the user.

Reporting

Report in this shape:

text
package/ref:
tbx ids / run urls:
matrix:
  bundled lifecycle:
  package acceptance:
  doctor/fix:
  gateway bootstrap:
  config round-trip:
  sdk external:
  live-ish:
failures:
skips:
next highest-value gap:

Say clearly when a failure is Testbox sync/env damage rather than product behavior, and prove that with a clean rerun or current-main comparison.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/release-openclaw-plugin-testing of openclaw/openclaw.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 1eb5970

Compare with similar skills

Release Openclaw Plugin Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Openclaw Plugin Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Openclaw Plugin Testing this skillopenclaw/openclaw392k—~3.1kAutomated safety check: PassMIT
Crabbox SetupAI-Builder-Club/skills1.3k1 repos~1.9kAutomated safety check: NotesNone
Dqd Labctrsploit/ctrsploit154—~1.6kAutomated safety check: PassNone
Testingwellwelwel/poku1.2k—~1kAutomated safety check: PassMIT
Go Redis Client Test Runnerredis/go-redis22k—~786Automated safety check: PassBSD-2-Clause
Build Imageskubernetes-sigs/cloud-provider-azure294—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Crabbox Setup

    AI-Builder-Club/skills

    Scaffold an isolated CLOUD dev box per agent (via crabbox + Daytona) for any codebase — the parallel-safe counterpart to dev-local-setup.

    1.3k GitHub starsUsed in 1 repo~1.9k tokens
    Testing & QAAuto-check: notes
  • Dqd Lab

    ctrsploit/ctrsploit

    Manage ctrsploit dqd lab environments from github.com/ctrsploit/dqd.

    154 GitHub stars~1.6k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Testing

    wellwelwel/poku

    Testing deep-dive for poku covering test structure, commands, patterns, fixtures, utils, Docker compatibility, and coverage.

    1.2k GitHub stars~1k tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • Official

    Explains how to run go-redis tests: the Docker Compose stack, make targets, focusing a single Ginkgo spec, the e2e suite and the version environment variables.

    22k GitHub stars~786 tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Build Images

    kubernetes-sigs/cloud-provider-azure

    Official

    Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

    294 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Plugin Test

    apache/skywalking-python

    Build Docker test images and run SkyWalking Python plugin/unit/e2e tests locally, mirroring the CI pipeline

    219 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed

More from openclaw/openclaw

All 93 skills in this repo
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Tmux

    openclaw/openclaw

    Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.

    392k GitHub starsUsed in 2 repos~640 tokens
    Auto-check passed
  • Feishu Doc

    openclaw/openclaw

    Feishu document read/write workflows. An agent skill from openclaw/openclaw.

    392k GitHub stars~516 tokensUpdated today
    Auto-check passed
  • Openclaw PR Maintainer

    openclaw/openclaw

    Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.

    392k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Browser Automation

    openclaw/openclaw

    A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.

    392k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Clawsweeper

    openclaw/openclaw

    A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…

    392k GitHub stars~3k tokensUpdated today
    Auto-check passed

Works with

Questions about Release Openclaw Plugin Testing

What does Release Openclaw Plugin Testing do?

Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E…. Release Openclaw Plugin Testing is an agent skill from openclaw/openclaw. Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E, Package Acceptance, and Testbox proof.

When should I use Release Openclaw Plugin Testing?

Release Openclaw Plugin Testing fits situations like: tasks that involve Containers; tasks that involve End-to-end testing.

How do I install Release Openclaw Plugin Testing in Claude Code?

Run `npx skills add openclaw/openclaw --skill release-openclaw-plugin-testing -a claude-code`. Or copy the skill folder (.agents/skills/release-openclaw-plugin-testing in openclaw/openclaw) into .claude/skills/release-openclaw-plugin-testing in your project. Claude Code loads it when a task matches its description.

How do I install Release Openclaw Plugin Testing in Codex?

Run `npx skills add openclaw/openclaw --skill release-openclaw-plugin-testing -a codex`. Or copy the skill folder (.agents/skills/release-openclaw-plugin-testing in openclaw/openclaw) into .agents/skills/release-openclaw-plugin-testing in your project. Codex loads it when a task matches its description.

Can I use Release Openclaw Plugin Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill release-openclaw-plugin-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-openclaw-plugin-testing, .gemini/skills/release-openclaw-plugin-testing, .github/skills/release-openclaw-plugin-testing and .opencode/skills/release-openclaw-plugin-testing in your project.

What does Release Openclaw Plugin Testing need to run?

Going by SKILL.md and its folder, Release Openclaw Plugin Testing needs the command-line tools its instructions call (pnpm, gh and git). Our summary lists: Docker.

Does Release Openclaw Plugin Testing access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release Openclaw Plugin Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Openclaw Plugin Testing use?

Release Openclaw Plugin Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Openclaw Plugin Testing use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Openclaw Plugin Testing?

Skills that share tags, products or a category with Release Openclaw Plugin Testing: Crabbox Setup (AI-Builder-Club/skills, 1.3k stars), Dqd Lab (ctrsploit/ctrsploit, 154 stars), Testing (wellwelwel/poku, 1.2k stars) and Go Redis Client Test Runner (redis/go-redis, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Openclaw Plugin Testing?

openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,610 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 8, 2026.

Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.