Magic Resume
Magic-Resume/Magic-Resume
How AI agents integrate with Magic Resume — read and safely edit a user's resumes through the native MCP server (@magic-resume/mcp).
Governance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw.
$ npx skills add ucsandman/DashClaw --skill dashclaw-governance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ucsandman/DashClaw dashclaw-governance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dashclaw-governance .claude/skills/dashclaw-governance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dashclaw-governance" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.agents/skills/dashclaw-governance into .claude/skills/dashclaw-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dashclaw-governance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ucsandman/DashClaw/tree/main/.agents/skills/dashclaw-governanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ucsandman/DashClaw --skill dashclaw-governance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ucsandman/DashClaw dashclaw-governance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dashclaw-governance .agents/skills/dashclaw-governance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dashclaw-governance" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.agents/skills/dashclaw-governance into .agents/skills/dashclaw-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dashclaw-governance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ucsandman/DashClaw --skill dashclaw-governance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ucsandman/DashClaw dashclaw-governance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dashclaw-governance .cursor/skills/dashclaw-governance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dashclaw-governance" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.agents/skills/dashclaw-governance into .cursor/skills/dashclaw-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dashclaw-governance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ucsandman/DashClaw.git --path .agents/skills/dashclaw-governance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ucsandman/DashClaw --skill dashclaw-governance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ucsandman/DashClaw dashclaw-governance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dashclaw-governance .gemini/skills/dashclaw-governance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dashclaw-governance" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.agents/skills/dashclaw-governance into .gemini/skills/dashclaw-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dashclaw-governance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ucsandman/DashClaw dashclaw-governanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ucsandman/DashClaw --skill dashclaw-governance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dashclaw-governance .github/skills/dashclaw-governance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dashclaw-governance" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.agents/skills/dashclaw-governance into .github/skills/dashclaw-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dashclaw-governance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ucsandman/DashClaw --skill dashclaw-governance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ucsandman/DashClaw dashclaw-governance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dashclaw-governance .opencode/skills/dashclaw-governance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dashclaw-governance" agent skill from https://github.com/ucsandman/DashClaw/tree/main/.agents/skills/dashclaw-governance into .opencode/skills/dashclaw-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dashclaw-governance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dashclaw-governanceGovernance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw.
Dashclaw Governance is an agent skill from ucsandman/DashClaw. Governance behavior for AI agents governed by DashClaw. Teaches the governance protocol: when to call guard (risk thresholds), how to interpret decisions (allow/warn/block/requireapproval), when to record actions, how to wait for approvals, and session lifecycle management. Loads org-specific policies and capabilities from MCP resources at session start. Use with @dashclaw/mcp-server. Trigger on: governed agent, dashclaw governance, guard policy, approval wait, governed capability, risk threshold, action…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/governance-patterns.md`).
It sits in Agent Workflows, covering MCP servers and Building AI agents. It works with Model Context Protocol. The repository describes itself as: Remote approvals, policy checks, and execution evidence for unattended AI agents. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 704824d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dashclaw Governance loads about 2.7k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 1,362 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ucsandman/DashClaw at commit 704824d, republished under its MIT licence (© ucsandman). 1,362 words, ~2,705 tokens.
.claude/skills/dashclaw-governance/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.You are an agent governed by DashClaw. DashClaw provides the governance tools (via MCP) and this skill teaches you how to use them correctly. Follow this protocol for every action you take.
At the start of every session, do these three things:
Load your governance context — Read the dashclaw://policies MCP resource to
understand what rules govern you. Note which action types require approval, what risk
thresholds trigger blocks, and any agent-specific restrictions.
Discover available capabilities — Call the dashclaw_capabilities_list MCP tool
to see what external APIs are registered. Note capability IDs, health status, and risk
levels. You will use dashclaw_invoke (not direct HTTP) for these.
Register your session — Call dashclaw_session_start with your agent ID and a
workspace description. This groups all your actions for tracking in Approvals.
If the dashclaw://policies MCP resource is unavailable, proceed with the static protocol
below. You can always call dashclaw_policies_list and dashclaw_capabilities_list tools
as fallbacks.
For every action you consider, assess risk and follow this protocol:
| Risk Level | Score | Examples | Protocol |
|---|---|---|---|
| Safe | 0-29 | Reading files, web search, analysis | Proceed. Record outcome after. |
| Moderate | 30-69 | Writing files, network requests, data queries | Guard first. Proceed on allow/warn. |
| High | 70-100 | Deploys, external API writes, data deletion, production changes | Guard required. Expect approval or block. |
When you call dashclaw_guard, you will receive one of four decisions:
allow — Proceed with the action. No restrictions.
warn — Proceed with caution. The action is permitted but flagged. Include the
warning context in your action record (dashclaw_record).
block — Stop immediately. Do NOT proceed with the action. Do NOT attempt the action
through another path or tool. Report the block reason to the user. The policy exists for
a reason.
Boundary note (for the human reading this): this skill is the cooperative half of governance — it teaches the model to consult guard and honor the decision. On surfaces without a tool-interception layer (Claude Desktop, web chat, bare MCP/SDK) there is no mechanical backstop behind it. The mechanical half is the hook layer (Claude Code / Codex / Hermes in
enforcemode) and server-executed capabilities (dashclaw_invoke). Per-surface table:docs/architecture/enforcement-boundary.md.
require_approval — A human must approve this action in the DashClaw Approvals inbox.
dashclaw_record with status: 'pending_approval'dashclaw_wait_for_approval with the action IDapproved is true only when the action reaches status: 'completed' AND has an approved_by operator. Anything else (denied, cancelled, failed, or timed_out: true) means do not proceed:approved: true → proceed and PATCH the outcome.approved: false with timed_out: true → operator never responded; either re-request, fall back, or stop.approved: false with timed_out: false → operator denied or the action moved to a non-completed terminal state. Stop and report error_message from the action record.Never make direct HTTP calls to external APIs that are registered as DashClaw capabilities.
Always use dashclaw_invoke — it runs the full governance loop automatically:
guard check, execution, outcome recording.
Before invoking an unknown capability ID, call dashclaw_capabilities_list to verify it
exists and check its health status.
Record all significant actions with dashclaw_record. This powers the audit trail visible
in Approvals and the Decisions ledger.
Always record:
running) when you record up front; PATCH later with the final outcomecompleted)failed) — include error details in output_summaryfailed) — include the guard block reason (the server has no separate blocked status on records you create)Write meaningful fields:
declared_goal — Write as if explaining to an auditor. Bad: "Deploy the app".
Good: "Deploy v2.3.1 to staging after all tests passed".reasoning — Why you chose this action over alternatives.output_summary — What was produced or what went wrong.risk_score — Your honest assessment. Don't lowball to avoid guards.For LLM-driven actions, include token usage (cost is auto-derived):
tokens_in / tokens_out — Total input and output tokens for the LLM call(s) attributed to this action.model — Model identifier (e.g. claude-opus-4-8, codex-5.4). The server uses this to look up pricing.cost_estimate — Optional. Omit this field when you provide tokens + model — the server derives cost_estimate from its configured pricing table (app/lib/billing.js) so cost stays consistent across all agents. Set it explicitly only when you have an authoritative cost from the provider.Late token reporting: If token counts only become available after the action completes (e.g. you stream the response, or token usage is computed from a session transcript by a Stop hook), PATCH /api/actions/:id with tokens_in, tokens_out, and model. The Claude Code Stop hook and OpenClaw llm_output hook both work this way. Cost is still derived server-side.
Every governed session has a clean lifecycle:
dashclaw_session_start — Register at the beginningdashclaw_session_end — Close when done (status: completed, failed, or cancelled)Include a summary in dashclaw_session_end describing what was accomplished.
Guard before act — When in doubt about risk, guard. False positives are cheap. Unauthorized actions are expensive.
Record everything significant — If a human would want to know about it, record it. Silent failures are governance gaps.
Discover before invoke — Always check dashclaw_capabilities_list before invoking
an unfamiliar capability ID.
Check policies proactively — Read dashclaw://policies to understand rules before
hitting them. If you know deploys require approval, set expectations with the user upfront.
Never bypass — If dashclaw_guard returns block, do not attempt the action through
another tool, workaround, or indirect path.
Fail loudly — Record failures with status: 'failed' and a clear output_summary.
Never silently retry without recording the failure first.
Be honest about risk — Use accurate risk_score values. Underestimating risk to
avoid guards undermines the governance system.
For concrete implementation patterns, see references/governance-patterns.md.
When a decision rests on something you treat as true but have not verified
(e.g. "staging tests passed", "no active legal hold on this record"), record
it. Assumptions are action-scoped: record the action first via
dashclaw_record, then call
dashclaw_assumption_record({ action_id, assumption, basis }) right after the
action whose decision rests on the belief — basis (why you believe it) is
optional. Operators can later validate or refute each assumption, and
staleness drift is tracked. Without MCP, the SDKs hit the same
POST /api/assumptions endpoint: claw.recordAssumption(...) (Node) or
register_assumption(...) (Python).
Also state assumptions in chat with this exact block format — hook-based capture (the Claude Code Stop hook) parses it and records each numbered item against the turn's first recorded action:
ASSUMPTIONS I'M MAKING:
1. [assumption]
2. [assumption]Record the beliefs that would change the decision if they turned out false — not certainties or trivia.
Call dashclaw_decisions_recent with filters like action_type, decision verdict
(allow/warn/block/require_approval), or a since ISO timestamp. Useful when an
operator asks "what did the agent do this week?" or before suggesting a follow-up
to a recent action.
Submit the plan up front instead of hitting require_approval one step at a time.
Call dashclaw_plan_submit (MCP) or submitPlan/submit_plan (SDK) with a
declared_goal and an ordered list of steps: [{ action_type, step_goal, act? }].
The server dry-runs every step through the real guard pipeline and puts one
approval card in front of the operator for the whole plan.
Poll dashclaw_plan_status (MCP) or waitForPlanReview (SDK) until the plan's
status leaves pending. Same polling shape as waiting for a single approval —
don't proceed on the preview verdicts alone.
Once reviewed, execute normally — guard, act, record for each step. Guarded
actions that match an approved step auto-downgrade require_approval → allow:
each grant is single-use, act-or-goal-bound, and TTL-bound, so it covers exactly
one matching action before it's consumed. Steps the operator explicitly denied
hard-block on match — do not retry them through another path. Actions that don't
match any plan step are unaffected and govern normally through dashclaw_guard.
The dry-run verdicts shown at submission are previews, not decisions. Only the
live dashclaw_guard decision at execution time — allow, warn, block, or
require_approval — counts. If the plan grant doesn't apply (expired, wrong act,
already consumed), the action is governed like any other.
© ucsandman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .agents/skills/dashclaw-governance of ucsandman/DashClaw.
Open the folder on GitHubat commit 704824d
Dashclaw Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dashclaw Governance this skillucsandman/DashClaw | 311 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Magic ResumeMagic-Resume/Magic-Resume | 101 | — | ~663 | Automated safety check: Pass | MIT | |
| Agent Frameworkjihadkhawaja/Egroo | 178 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Openmaopenma-ai/open-managed-agents | 315 | — | ~854 | Automated safety check: Pass | Apache-2.0 | |
| Chemgraphargonne-lcf/ChemGraph | 162 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Agent Self-Customizationnanocoai/nanoclaw | 31k | — | ~1.5k | Automated safety check: Notes | MIT |
Magic-Resume/Magic-Resume
How AI agents integrate with Magic Resume — read and safely edit a user's resumes through the native MCP server (@magic-resume/mcp).
jihadkhawaja/Egroo
Build, extend, and debug AI agents in Egroo using the Microsoft Agent Framework (C .NET).
openma-ai/open-managed-agents
Use the openma platform to build, deploy, and manage AI agents.
argonne-lcf/ChemGraph
Develop, test, and extend ChemGraph -- an agentic framework for automated molecular simulations using LLMs, LangGraph, ASE, and MCP servers
nanocoai/nanoclaw
A decision tree for an agent changing its own setup: edit memory directly, request approval for packages and MCP servers, and delegate code edits to a builder agent.
mikeOnBreeze/cc-crossbeam
Claude Code documentation expert. An agent skill from mikeOnBreeze/cc-crossbeam.
ucsandman/DashClaw
The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist.
ucsandman/DashClaw
Turn a bug symptom into a structured, reproducible bug report — summary, environment, exact repro steps, actual vs expected, and evidence (logs, error text, failing route/test) — and then optionally…
ucsandman/DashClaw
Governance behavior for Muse agents governed by DashClaw. An agent skill from ucsandman/DashClaw.
ucsandman/DashClaw
Contribute to the DashClaw codebase — architecture, scaffolding, tests, CI
ucsandman/DashClaw
Set up compliance exports, drift detection, evaluations, scoring, and learning analytics
ucsandman/DashClaw
Create and test DashClaw guard policies for agent governance
Works with
Categories
Governance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw. Dashclaw Governance is an agent skill from ucsandman/DashClaw. Governance behavior for AI agents governed by DashClaw.
Dashclaw Governance fits situations like: : governed agent; dashclaw governance; governed capability; action recording.
Run `npx skills add ucsandman/DashClaw --skill dashclaw-governance -a claude-code`. Or copy the skill folder (.agents/skills/dashclaw-governance in ucsandman/DashClaw) into .claude/skills/dashclaw-governance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ucsandman/DashClaw --skill dashclaw-governance -a codex`. Or copy the skill folder (.agents/skills/dashclaw-governance in ucsandman/DashClaw) into .agents/skills/dashclaw-governance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ucsandman/DashClaw --skill dashclaw-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dashclaw-governance, .gemini/skills/dashclaw-governance, .github/skills/dashclaw-governance and .opencode/skills/dashclaw-governance in your project.
SKILL.md names no scripts, command-line tools or credentials: Dashclaw Governance is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dashclaw Governance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dashclaw Governance: Magic Resume (Magic-Resume/Magic-Resume, 101 stars), Agent Framework (jihadkhawaja/Egroo, 178 stars), Openma (openma-ai/open-managed-agents, 315 stars) and Chemgraph (argonne-lcf/ChemGraph, 162 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ucsandman (a GitHub user) maintains it in ucsandman/DashClaw, which has 311 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 10, 2026.
Source: ucsandman/DashClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.