Agent Builder
n8n-io/n8n
Load immediately after an Agent intent. An agent skill from n8n-io/n8n.
Create and test DashClaw guard policies for agent governance
$ npx skills add ucsandman/DashClaw --skill create-policies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ucsandman/DashClaw create-policies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dashclaw-agent/create-policies .claude/skills/create-policies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "create-policies" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.claude/skills/dashclaw-agent/create-policies into .claude/skills/create-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-policies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ucsandman/DashClaw/tree/main/.claude/skills/dashclaw-agent/create-policiesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ucsandman/DashClaw --skill create-policies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ucsandman/DashClaw create-policies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/dashclaw-agent/create-policies .agents/skills/create-policies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "create-policies" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.claude/skills/dashclaw-agent/create-policies into .agents/skills/create-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-policies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ucsandman/DashClaw --skill create-policies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ucsandman/DashClaw create-policies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/dashclaw-agent/create-policies .cursor/skills/create-policies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "create-policies" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.claude/skills/dashclaw-agent/create-policies into .cursor/skills/create-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-policies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ucsandman/DashClaw.git --path .claude/skills/dashclaw-agent/create-policies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ucsandman/DashClaw --skill create-policies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ucsandman/DashClaw create-policies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/dashclaw-agent/create-policies .gemini/skills/create-policies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "create-policies" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.claude/skills/dashclaw-agent/create-policies into .gemini/skills/create-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-policies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ucsandman/DashClaw create-policiesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ucsandman/DashClaw --skill create-policies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/dashclaw-agent/create-policies .github/skills/create-policies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "create-policies" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.claude/skills/dashclaw-agent/create-policies into .github/skills/create-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-policies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ucsandman/DashClaw --skill create-policies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ucsandman/DashClaw create-policies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/dashclaw-agent/create-policies .opencode/skills/create-policies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "create-policies" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.claude/skills/dashclaw-agent/create-policies into .opencode/skills/create-policies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-policies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
create-policiesCreate and test DashClaw guard policies for agent governance
Create Policies is an agent skill from ucsandman/DashClaw. Create and test DashClaw guard policies for agent governance
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in AI & LLM Engineering, covering Building AI agents. It works with Model Context Protocol. The repository describes itself as: Remote approvals, policy checks, and execution evidence for unattended AI agents. The licence is MIT.
Read from SKILL.md and the folder at commit 704824d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DASHCLAW_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Create Policies loads about 1.3k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 186 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ucsandman/DashClaw at commit 704824d, republished under its MIT licence (© ucsandman). 186 words, ~1,335 tokens.
.claude/skills/create-policies/SKILL.md (or your agent's skills folder).Help developers define, import, and test guard policies that control what agents can and cannot do.
| Type | Purpose | Example |
|---|---|---|
risk_threshold | Block/warn when risk score exceeds limit | Block actions with risk > 80 |
action_type_restriction | Allow/deny specific action types | Block security actions without approval |
approval_gate | Require human approval for matching actions | Require approval for deploys |
webhook_check | Call external endpoint for policy decision | Check Jira ticket status before deploy |
semantic_guardrail | LLM-based content analysis | Block PII in action metadata |
off — No policy enforcement (development only)warn — Log policy violations but allow executionenforce — Block policy violations (production recommended)name: high-risk-blocker
type: risk_threshold
mode: enforce
conditions:
risk_score_min: 80
reversible: false
action: block
reason: "Irreversible actions with risk >= 80 require manual execution"name: no-unattended-deploys
type: action_type_restriction
mode: enforce
conditions:
action_types:
- deploy
- database
action: require_approval
reason: "Deploy and database actions require human approval"name: production-approval-gate
type: approval_gate
mode: enforce
conditions:
systems_touched:
- production
risk_score_min: 50
action: require_approval
reason: "Production access with risk >= 50 requires approval"name: cost-ceiling
type: risk_threshold
mode: enforce
conditions:
cost_estimate_max: 100.00
action: block
reason: "Actions exceeding $100 estimated cost are blocked"name: no-secrets-in-metadata
type: semantic_guardrail
mode: enforce
conditions:
scan_fields:
- declared_goal
- output_summary
patterns:
- "password"
- "api_key"
- "secret"
action: block
reason: "Sensitive data detected in action metadata"// POST /api/policies
const response = await fetch(`${baseUrl}/api/policies`, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'x-api-key': process.env.DASHCLAW_API_KEY
},
body: JSON.stringify({
name: 'high-risk-blocker',
type: 'risk_threshold',
mode: 'enforce',
conditions: { risk_score_min: 80, reversible: false },
action: 'block',
reason: 'Irreversible high-risk actions are blocked'
})
});import { DashClaw } from 'dashclaw/legacy';
const claw = new DashClaw({ baseUrl, apiKey, agentId });
// Import a preset pack
await claw.importPolicies({ pack: 'enterprise-strict' });
// Available packs: enterprise-strict, smb-safe, startup-growth, development// POST /api/policies/test
const result = await fetch(`${baseUrl}/api/policies/test`, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'x-api-key': process.env.DASHCLAW_API_KEY
},
body: JSON.stringify({
action_type: 'deploy',
risk_score: 85,
reversible: false,
systems_touched: ['production']
})
});
// Response: which policies would trigger and what decisions they'd produceconst results = await claw.testPolicies();
// Returns pass/fail for each policy with explanationconst report = await claw.getProofReport({ format: 'md' });
// Generates compliance-ready report showing all policies and their test results# Permissive — warn only, don't block
- name: dev-risk-warning
type: risk_threshold
mode: warn
conditions: { risk_score_min: 50 }
action: warn
reason: "High risk action detected (dev mode — not blocked)"# Strict — enforce everything
- name: prod-risk-gate
type: risk_threshold
mode: enforce
conditions: { risk_score_min: 70 }
action: require_approval
- name: prod-deploy-gate
type: action_type_restriction
mode: enforce
conditions: { action_types: [deploy, database, security] }
action: require_approval
- name: prod-irreversible-block
type: risk_threshold
mode: enforce
conditions: { risk_score_min: 90, reversible: false }
action: blockPolicies can be scoped to specific agents or apply org-wide:
{
"name": "deploy-agent-only",
"agent_id": "deploy-agent-1",
"type": "approval_gate",
"conditions": { "action_types": ["deploy"] },
"action": "require_approval"
}If agent_id is omitted, the policy applies to all agents in the org.
# GET /api/policies
curl -H "x-api-key: $DASHCLAW_API_KEY" $DASHCLAW_BASE_URL/api/policiesResponse includes all active policies with their type, mode, conditions, and scope.
© ucsandman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/dashclaw-agent/create-policies of ucsandman/DashClaw.
Open the folder on GitHubat commit 704824d
Create Policies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Create Policies this skillucsandman/DashClaw | 310 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Agent Buildern8n-io/n8n | 207k | — | ~2.5k | Automated safety check: Pass | Custom licence | |
| Summarizeswarmclawai/swarmclaw | 688 | — | ~531 | Automated safety check: Pass | MIT | |
| Agent Squad Python Guide2FastLabs/agent-squad | 7.8k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Agent Squad for TypeScript2FastLabs/agent-squad | 7.8k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| Agent Frameworkjihadkhawaja/Egroo | 178 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 |
n8n-io/n8n
Load immediately after an Agent intent. An agent skill from n8n-io/n8n.
swarmclawai/swarmclaw
Summarize or extract text/transcripts from URLs, podcasts, YouTube videos, and local files using the summarize CLI.
2FastLabs/agent-squad
Map of the agent-squad Python framework for async multi-agent orchestration: which agent, classifier, storage and tool provider to pick, and the pitfalls to avoid.
2FastLabs/agent-squad
Guide to building Node.js and TypeScript apps on the agent-squad package: orchestrator, agent types, classifier routing, storage, retrievers and MCP tools.
jihadkhawaja/Egroo
Build, extend, and debug AI agents in Egroo using the Microsoft Agent Framework (C .NET).
openma-ai/open-managed-agents
Use the openma platform to build, deploy, and manage AI agents.
ucsandman/DashClaw
Governance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw.
ucsandman/DashClaw
The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist.
ucsandman/DashClaw
Turn a bug symptom into a structured, reproducible bug report — summary, environment, exact repro steps, actual vs expected, and evidence (logs, error text, failing route/test) — and then optionally…
ucsandman/DashClaw
Governance behavior for Muse agents governed by DashClaw. An agent skill from ucsandman/DashClaw.
ucsandman/DashClaw
Contribute to the DashClaw codebase — architecture, scaffolding, tests, CI
ucsandman/DashClaw
Set up compliance exports, drift detection, evaluations, scoring, and learning analytics
Works with
Create and test DashClaw guard policies for agent governance. Create Policies is an agent skill from ucsandman/DashClaw.
Create Policies fits situations like: tasks that involve Building AI agents.
Run `npx skills add ucsandman/DashClaw --skill create-policies -a claude-code`. Or copy the skill folder (.claude/skills/dashclaw-agent/create-policies in ucsandman/DashClaw) into .claude/skills/create-policies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ucsandman/DashClaw --skill create-policies -a codex`. Or copy the skill folder (.claude/skills/dashclaw-agent/create-policies in ucsandman/DashClaw) into .agents/skills/create-policies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ucsandman/DashClaw --skill create-policies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-policies, .gemini/skills/create-policies, .github/skills/create-policies and .opencode/skills/create-policies in your project.
Going by SKILL.md and its folder, Create Policies needs the command-line tools its instructions call (curl) and credentials named DASHCLAW_API_KEY. Our summary lists: A credential in DASHCLAW_API_KEY.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Create Policies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Create Policies: Agent Builder (n8n-io/n8n, 207k stars), Summarize (swarmclawai/swarmclaw, 688 stars), Agent Squad Python Guide (2FastLabs/agent-squad, 7.8k stars) and Agent Squad for TypeScript (2FastLabs/agent-squad, 7.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ucsandman (a GitHub user) maintains it in ucsandman/DashClaw, which has 310 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.
Source: ucsandman/DashClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.