Security middleware for all XMTP communications in EverClaw.

MITAuto-check passed

Install Xmtp Comms Guard

skills CLI
$ npx skills add profbernardoj/everclaw-community-branches --skill xmtp-comms-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install profbernardoj/everclaw-community-branches xmtp-comms-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/profbernardoj/everclaw-community-branches.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/xmtp-comms-guard .claude/skills/xmtp-comms-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
xmtp-comms-guard
GitHub stars
112
Token cost
~523 tokens
SKILL.md length
189 words
Files
34
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Security middleware for all XMTP communications in EverClaw.

  • Integrating XMTP messaging
  • SKILL.md covers Mandatory Usage, Three-Shift Integration, Enforcement Model and Fail-Closed Conditions, plus 1 more section
  • Runs TypeScript scripts from its folder
  • Configuring communication security

What it does

Xmtp Comms Guard is an agent skill from profbernardoj/everclaw-community-branches. Security middleware for all XMTP communications in EverClaw. Enforces guarded client usage with validation, integrity checks, and fail-closed security policies. Integrates approval flows for sensitive operations. Use when integrating XMTP messaging, configuring communication security, or auditing guarded client enforcement.

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. The skill folder holds 37 other files (for example `.eslintrc.json`, `PUBLISH-CHECKLIST.md` and `README.md`).

The repository describes itself as: Decentralized AI inference for OpenClaw agents. Powered by Morpheus AI. Stake MOR, access Kimi K2.5 + 10 models, never run out of inference. The licence is MIT.

When your agent uses it

  • Integrating XMTP messaging
  • Configuring communication security
  • Auditing guarded client enforcement

Example prompts

  • “/xmtp-comms-guard”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 0b30b36. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Xmtp Comms Guard loads about 523 tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~523

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from profbernardoj/everclaw-community-branches at commit 0b30b36, republished under its MIT licence (© profbernardoj). 189 words, ~523 tokens.

Download SKILL.mdSave it as .claude/skills/xmtp-comms-guard/SKILL.md (or your agent's skills folder). This skill also uses 33 other files; get the full folder from GitHub.
name
xmtp-comms-guard
description
Security middleware for all XMTP communications in EverClaw. Enforces guarded client usage with validation, integrity checks, and fail-closed security policies. Integrates approval flows for sensitive operations. Use when integrating XMTP messaging, configuring communication security, or auditing guarded client enforcement.

xmtp-comms-guard — Skill Integration Guide (V6)

Type: Critical Security Version: 6.0.0 Required peer dependencies: bagman, pii-guard, prompt-guard

Mandatory Usage

All XMTP communication MUST go through the guarded client:

ts
import { createGuardedXmtpClient } from "xmtp-comms-guard";
const { client, middleware } = await createGuardedXmtpClient(rawClient, userWallet);

Raw @xmtp/client imports are blocked by ESLint rules and SkillGuard scan.

Three-Shift Integration

Three-Shift = EverClaw's standard approval flow with three options:

  • Approve — allow the action
  • Redact — downgrade/sanitize
  • Block — deny the action

Used for: peer revocation review, key rotation re-approval, introduction chain re-evaluation.

Enforcement Model

Enforcement is convention-based + build-time gates:

  • ESLint rule blocks @xmtp/client direct imports
  • SkillGuard scan detects raw client usage patterns
  • No runtime interception of raw imports (honestly documented)

See enforcement.md for full details.

Fail-Closed Conditions

The skill refuses to operate when:

  • Hash chain integrity check fails on startup
  • SQLCipher encryption check fails
  • Nonce cache detects replay
  • Unknown topic in message
  • Unknown sensitivity level
  • Message exceeds 64KB
  • Protocol version is not "6.0"
  • Peer not in registry or blocked

Threat Model

Covered in threat-model.md:

  • Malicious external agent → blocked by schema + checks
  • Compromised internal agent → blocked by middleware + SkillGuard gates
  • Host compromise → limited by Bagman + HMAC chain + fail-closed
  • Replay attacks → nonce cache (90s TTL) + hash chain
  • Data exfiltration → PII Guard + trust context rules

© profbernardoj, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 33 other files in skills/xmtp-comms-guard of profbernardoj/everclaw-community-branches.

  • SKILL.md
  • .eslintrc.json
  • .gitignore
  • PUBLISH-CHECKLIST.md
  • README.md
  • enforcement.md
  • package.json
  • src/checks/handshake.ts
  • src/checks/index.ts
  • src/checks/injectionCheck.ts
  • src/checks/peerAuth.ts
  • src/checks/piiCheck.ts
  • src/checks/rateLimit.ts
  • src/checks/trustContextCheck.ts
  • src/cli/index.ts
  • src/crypto/eip191.ts
  • src/index.ts
  • … and 17 more

Open the folder on GitHubat commit 0b30b36

Compare with similar skills

Xmtp Comms Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Xmtp Comms Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Xmtp Comms Guard this skillprofbernardoj/everclaw-community-branches112—~523Automated safety check: PassMIT
Safety Guardaffaan-m/ECC276k2 repos~554Automated safety check: NotesMIT
Internal Commsalirezarezvani/claude-skills28k—~3.4kAutomated safety check: PassMIT
Internal Communicationsickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: PassMIT
Guard Modegarrytan/gstack136k—~1kAutomated safety check: NotesMIT
Team Communicationsalirezarezvani/claude-skills28k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Safety Guard

    affaan-m/ECC

    Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard…

    276k GitHub starsUsed in 2 repos~554 tokens
    DevelopmentAuto-check: notes
  • Internal Comms

    alirezarezvani/claude-skills

    A skill your agent uses when a Head of People Ops, BizOps lead, or Internal Communications owner needs to draft and sequence an internal-only change-management communication — a re-org announcement…

    28k GitHub stars~3.4k tokensUpdated 1 mo ago
    Writing & ContentAuto-check passed
  • Internal Communication

    sickn33/agentic-awesome-skills

    Internal communication log: title, type, date, department, host and attendees, agenda, action items, follow-up date, meeting link and delivery status.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Writing & ContentAuto-check passed
  • Guard Mode

    garrytan/gstack

    Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.

    136k GitHub stars~1k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Team Communications

    alirezarezvani/claude-skills

    Write internal company communications — 3P updates (Progress/Plans/Problems), company-wide newsletters, FAQ roundups, incident reports, leadership updates, status reports, project updates, and…

    28k GitHub stars~1.1k tokensUpdated 1 mo ago
    Writing & ContentAuto-check passed
  • Official

    A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill…

    180k GitHub starsUsed in 38 repos~378 tokens
    Writing & ContentAuto-check passed

More from profbernardoj/everclaw-community-branches

All 12 skills in this repo
  • Memory Upgrade

    profbernardoj/everclaw-community-branches

    Diagnose and fix broken memory search in OpenClaw. An agent skill from profbernardoj/everclaw-community-branches.

    112 GitHub stars~574 tokensUpdated 1 mo ago
    Auto-check passed
  • Relationships

    profbernardoj/everclaw-community-branches

    Relationship CRM for tracking people, connections, and context.

    112 GitHub stars~765 tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Chat

    profbernardoj/everclaw-community-branches

    XMTP real-time agent-to-agent and user-to-agent encrypted messaging daemon for EverClaw.

    112 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Bagman

    profbernardoj/everclaw-community-branches

    Secure key management for AI agents. An agent skill from profbernardoj/everclaw-community-branches.

    112 GitHub stars~4.4k tokensUpdated 1 mo ago
    Auto-check: warnings
  • Night Shift

    profbernardoj/everclaw-community-branches

    Automated overnight task planning and execution engine for EverClaw.

    112 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Pii Guard

    profbernardoj/everclaw-community-branches

    Personally identifiable information (PII) leak prevention for EverClaw.

    112 GitHub stars~921 tokensUpdated 1 mo ago
    Auto-check passed

Questions about Xmtp Comms Guard

What does Xmtp Comms Guard do?

Security middleware for all XMTP communications in EverClaw. Xmtp Comms Guard is an agent skill from profbernardoj/everclaw-community-branches. Security middleware for all XMTP communications in EverClaw.

When should I use Xmtp Comms Guard?

Xmtp Comms Guard fits situations like: integrating XMTP messaging; configuring communication security; auditing guarded client enforcement.

How do I install Xmtp Comms Guard in Claude Code?

Run `npx skills add profbernardoj/everclaw-community-branches --skill xmtp-comms-guard -a claude-code`. Or copy the skill folder (skills/xmtp-comms-guard in profbernardoj/everclaw-community-branches) into .claude/skills/xmtp-comms-guard in your project. Claude Code loads it when a task matches its description.

How do I install Xmtp Comms Guard in Codex?

Run `npx skills add profbernardoj/everclaw-community-branches --skill xmtp-comms-guard -a codex`. Or copy the skill folder (skills/xmtp-comms-guard in profbernardoj/everclaw-community-branches) into .agents/skills/xmtp-comms-guard in your project. Codex loads it when a task matches its description.

Can I use Xmtp Comms Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add profbernardoj/everclaw-community-branches --skill xmtp-comms-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/xmtp-comms-guard, .gemini/skills/xmtp-comms-guard, .github/skills/xmtp-comms-guard and .opencode/skills/xmtp-comms-guard in your project.

What does Xmtp Comms Guard need to run?

Going by SKILL.md and its folder, Xmtp Comms Guard needs TypeScript for the scripts in its folder. Our summary lists: Node.js.

Does Xmtp Comms Guard access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Xmtp Comms Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Xmtp Comms Guard use?

Xmtp Comms Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Xmtp Comms Guard use?

About 523 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Xmtp Comms Guard?

Skills that share tags, products or a category with Xmtp Comms Guard: Safety Guard (affaan-m/ECC, 276k stars), Internal Comms (alirezarezvani/claude-skills, 28k stars), Internal Communication (sickn33/agentic-awesome-skills, 47k stars) and Guard Mode (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Xmtp Comms Guard?

profbernardoj (a GitHub user) maintains it in profbernardoj/everclaw-community-branches, which has 112 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on September 2, 2026.

Source: profbernardoj/everclaw-community-branches on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.