Agent skill

Instrument Agent

by ucsandman in ucsandman/DashClaw

Integrate DashClaw SDK into any agent using the 4-step governance loop

MITAuto-check passedAI & LLM Engineering

Install Instrument Agent

skills CLI
$ npx skills add ucsandman/DashClaw --skill instrument-agent -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ucsandman/DashClaw instrument-agent --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dashclaw-agent/instrument-agent .claude/skills/instrument-agent && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
instrument-agent
GitHub stars
310
Token cost
~2.2k tokens
SKILL.md length
352 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Integrate DashClaw SDK into any agent using the 4-step governance loop

  • Works in 6 steps: Install & Initialize → 5: Session Lifecycle (Optional but… → Guard — Check Policy Before Acting → …
  • Tasks that involve Building AI agents
  • SKILL.md covers The 4-Step Governance Loop, Step 0: Install & Initialize, Step 0.5: Session Lifecycle… and Step 1: Guard — Check Policy…, plus 8 more sections
  • Calls node, npm and pip; needs DASHCLAW_API_KEY

What it does

Instrument Agent is an agent skill from ucsandman/DashClaw. Integrate DashClaw SDK into any agent using the 4-step governance loop

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering Building AI agents. It works with Model Context Protocol. The repository describes itself as: Remote approvals, policy checks, and execution evidence for unattended AI agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Building AI agents

Example prompts

  • “/instrument-agent”

Requirements

  • Python 3
  • Node.js
  • A credential in DASHCLAW_API_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Install & Initialize
  2. 5: Session Lifecycle (Optional but Recommended)
  3. Guard — Check Policy Before Acting
  4. Record — Log the Action
  5. Verify — Record Assumptions
  6. Outcome — Record the Result

What it can do on your machine

Read from SKILL.md and the folder at commit 704824d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • npm
    • pip
    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pip and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DASHCLAW_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Instrument Agent loads about 2.2k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 352 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ucsandman/DashClaw at commit 704824d, republished under its MIT licence (© ucsandman). 352 words, ~2,210 tokens.

Download SKILL.mdSave it as .claude/skills/instrument-agent/SKILL.md (or your agent's skills folder).
name
instrument-agent
description
Integrate DashClaw SDK into any agent using the 4-step governance loop
license
MIT
metadata.author
ucsandman
metadata.version
1.0.0
metadata.category
integration

Instrument Your Agent with DashClaw

Help developers add DashClaw governance to any AI agent. Walk through the 4-step governance loop with working code.

The 4-Step Governance Loop

Every governed decision follows this deterministic flow:

1. Guard  → "Can I do this?"           (POST /api/guard)
2. Record → "I am doing this."         (POST /api/actions)
3. Verify → "I believe this is true."  (POST /api/assumptions)
4. Outcome → "This was the result."    (PATCH /api/actions/:id)

Step 0: Install & Initialize

Node.js
bash
npm install dashclaw
javascript
import { DashClaw } from 'dashclaw';

const claw = new DashClaw({
  baseUrl: process.env.DASHCLAW_BASE_URL,
  apiKey: process.env.DASHCLAW_API_KEY,
  agentId: 'my-agent'
});
Python
bash
pip install dashclaw
python
from dashclaw import DashClaw

claw = DashClaw(
    base_url=os.environ["DASHCLAW_BASE_URL"],
    api_key=os.environ["DASHCLAW_API_KEY"],
    agent_id="my-agent"
)

Create a session to track the full lifecycle of your agent's work. Sessions enable monitoring, recovery, and continuity across restarts.

javascript
// Create a session at agent startup
const session = await fetch(`${baseUrl}/api/sessions`, {
  method: 'POST',
  headers: { 'Authorization': `Bearer ${apiKey}`, 'Content-Type': 'application/json' },
  body: JSON.stringify({ agent_id: 'my-agent', metadata: { task: 'deploy-pipeline' } })
}).then(r => r.json());

// Report status during execution
await fetch(`${baseUrl}/api/sessions/${session.id}`, {
  method: 'PATCH',
  headers: { 'Authorization': `Bearer ${apiKey}`, 'Content-Type': 'application/json' },
  body: JSON.stringify({ status: 'running', checkpoint: { step: 'guard-check' } })
});

Session lifecycle is optional — all governance loop steps work without it — but it provides visibility into long-running agent tasks and enables automatic recovery when sessions are interrupted.

Step 1: Guard — Check Policy Before Acting

javascript
const decision = await claw.guard({
  action_type: 'deploy',
  declared_goal: 'Deploy build #402 to production',
  risk_score: 85,
  systems_touched: ['production', 'database'],
  reversible: false
});

// decision.decision: 'allow' | 'warn' | 'block' | 'require_approval'
if (decision.decision === 'block') {
  console.log('Blocked:', decision.reason);
  return;
}
python
decision = claw.guard(
    action_type="deploy",
    declared_goal="Deploy build #402 to production",
    risk_score=85,
    systems_touched=["production", "database"],
    reversible=False
)

if decision["decision"] == "block":
    print(f"Blocked: {decision['reason']}")
    return

Guard response shape:

json
{
  "decision": "require_approval",
  "action_id": "act_gd_abc123",
  "reason": "Risk score exceeds org threshold",
  "signals": ["Production access", "High risk score"],
  "risk_score": 75,
  "agent_risk_score": 85,
  "recovery_recipes": [
    { "action": "reduce_scope", "description": "Deploy to staging first" }
  ]
}
Guard Policy Types to Handle

The guard may enforce these policy types — your agent should be prepared to respond to each:

  • permission_escalation — The action requires a higher permission_level than currently granted. Re-request with elevated permissions or abort.
  • green_contract — The action requires test verification before execution (e.g., tests must pass before deploying). Run tests and include evidence in the guard request.
  • branch_freshness — The action targets a stale branch. Pull latest changes or rebase before retrying.

When the guard blocks an action, check the recovery_recipes array in the response for actionable remediation steps.

Step 2: Record — Log the Action

javascript
const action = await claw.createAction({
  action_type: 'deploy',
  declared_goal: 'Deploy build #402 to production',
  risk_score: 85,
  reversible: false,
  systems_touched: ['production']
});
// action.action_id: 'ar_abc123'
python
action = claw.create_action(
    action_type="deploy",
    declared_goal="Deploy build #402 to production",
    risk_score=85,
    reversible=False,
    systems_touched=["production"]
)

Step 3: Verify — Record Assumptions

javascript
await claw.recordAssumption({
  action_id: action.action_id,
  assumption: 'Staging tests passed successfully',
  source: 'ci-pipeline'
});
python
claw.record_assumption(
    action_id=action["action_id"],
    assumption="Staging tests passed successfully",
    source="ci-pipeline"
)

Step 4: Outcome — Record the Result

javascript
await claw.updateOutcome(action.action_id, {
  status: 'completed',        // or 'failed'
  output_summary: 'Build #402 deployed successfully to production',
  timestamp_end: new Date().toISOString(),
  // Optional — populates Analytics cost/token charts. When tokens + model
  // are supplied without an explicit cost_estimate, the server derives
  // cost from the configured pricing table.
  tokens_in: result.usage?.input_tokens,
  tokens_out: result.usage?.output_tokens,
  model: result.model,
});
python
claw.update_outcome(action["action_id"],
    status="completed",
    output_summary="Build #402 deployed successfully to production",
    # Optional — populates Analytics cost/token charts.
    tokens_in=response.usage.input_tokens,
    tokens_out=response.usage.output_tokens,
    model=response.model,
)
Show full SKILL.md (140 more words)Show less

Complete Example

javascript
import { DashClaw } from 'dashclaw';

const claw = new DashClaw({
  baseUrl: process.env.DASHCLAW_BASE_URL,
  apiKey: process.env.DASHCLAW_API_KEY,
  agentId: 'deploy-agent'
});

async function governedDeploy(buildId) {
  // 1. Guard
  const decision = await claw.guard({
    action_type: 'deploy',
    declared_goal: `Deploy build #${buildId} to production`,
    risk_score: 85,
    systems_touched: ['production'],
    reversible: false
  });

  if (decision.decision === 'block') {
    console.log('Blocked:', decision.reason);
    return;
  }

  // 2. Record
  const action = await claw.createAction({
    action_type: 'deploy',
    declared_goal: `Deploy build #${buildId} to production`,
    risk_score: 85,
    reversible: false
  });

  // 3. Verify assumptions
  await claw.recordAssumption({
    action_id: action.action_id,
    assumption: 'All CI checks passed'
  });

  // 4. Execute and record outcome
  try {
    await actualDeploy(buildId);
    await claw.updateOutcome(action.action_id, {
      status: 'completed',
      output_summary: `Build #${buildId} deployed successfully`
    });
  } catch (err) {
    await claw.updateOutcome(action.action_id, {
      status: 'failed',
      output_summary: err.message
    });
  }
}

Action Type & Risk Score Guide

Action TypeRisk ScoreReversibleExample
deploy75-90falseProduction deployment
api_call20-40trueExternal API request
file_write15-30trueLocal file modification
database50-80falseSchema migration, data deletion
security80-95falseKey rotation, permission changes
build10-25truenpm install, compilation
notify5-15trueSend email, Slack message

Risk scoring rule: DashClaw uses the HIGHER of computed risk and agent-reported risk. Always report honestly — inflating risk is better than under-reporting.

HITL Approval Flow

When guard returns require_approval:

javascript
if (decision.decision === 'require_approval') {
  console.log('Waiting for human approval...');
  await claw.waitForApproval(decision.action_id, {
    timeout: 300000  // 5 minutes
  });
  // Continues after approval, throws ApprovalDeniedError if denied
}

Environment Variables

VariableRequiredDescription
DASHCLAW_BASE_URLYesDashClaw instance URL
DASHCLAW_API_KEYYesAPI authentication key
DASHCLAW_AGENT_IDNoDefault agent identifier

Validation

After instrumenting, drive a real end-to-end check against your DashClaw instance with the live SDK smoke test:

bash
# Node SDK round-trip (guard → createAction → updateOutcome)
node scripts/_run-with-env.mjs scripts/test-sdk-live.mjs

# Python equivalent
node scripts/_run-with-env.mjs scripts/run-sdk-live-python.mjs

# Or just confirm the instance is reachable
curl -sf "$DASHCLAW_BASE_URL/api/health" | jq '.status'

Then refresh /decisions on your DashClaw instance — your most recent governed action should appear within seconds.

© ucsandman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dashclaw-agent/instrument-agent of ucsandman/DashClaw.

Open the folder on GitHubat commit 704824d

Compare with similar skills

Instrument Agent next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Instrument Agent compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Instrument Agent this skillucsandman/DashClaw310—~2.2kAutomated safety check: PassMIT
Agent Buildern8n-io/n8n207k—~2.5kAutomated safety check: PassCustom licence
Summarizeswarmclawai/swarmclaw688—~531Automated safety check: PassMIT
Agent Squad Python Guide2FastLabs/agent-squad7.8k—~4.7kAutomated safety check: PassApache-2.0
Agent Squad for TypeScript2FastLabs/agent-squad7.8k—~4.3kAutomated safety check: PassApache-2.0
Agent Frameworkjihadkhawaja/Egroo178—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Agent Builder

    n8n-io/n8n

    Official

    Load immediately after an Agent intent. An agent skill from n8n-io/n8n.

    207k GitHub stars~2.5k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Summarize

    swarmclawai/swarmclaw

    Summarize or extract text/transcripts from URLs, podcasts, YouTube videos, and local files using the summarize CLI.

    688 GitHub stars~531 tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check passed
  • Agent Squad Python Guide

    2FastLabs/agent-squad

    Map of the agent-squad Python framework for async multi-agent orchestration: which agent, classifier, storage and tool provider to pick, and the pitfalls to avoid.

    7.8k GitHub stars~4.7k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Agent Squad for TypeScript

    2FastLabs/agent-squad

    Guide to building Node.js and TypeScript apps on the agent-squad package: orchestrator, agent types, classifier routing, storage, retrievers and MCP tools.

    7.8k GitHub stars~4.3k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Agent Framework

    jihadkhawaja/Egroo

    Build, extend, and debug AI agents in Egroo using the Microsoft Agent Framework (C .NET).

    178 GitHub stars~1.9k tokensUpdated 6 mo ago
    AI & LLM EngineeringAuto-check passed
  • Openma

    openma-ai/open-managed-agents

    Use the openma platform to build, deploy, and manage AI agents.

    316 GitHub stars~854 tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from ucsandman/DashClaw

All 13 skills in this repo
  • Dashclaw Governance

    ucsandman/DashClaw

    Governance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    310 GitHub stars~2.7k tokensUpdated 3 days ago
    Auto-check passed
  • Dashclaw Ship

    ucsandman/DashClaw

    The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist.

    310 GitHub stars~7.2k tokensUpdated 3 days ago
    Auto-check passed
  • Repro

    ucsandman/DashClaw

    Turn a bug symptom into a structured, reproducible bug report — summary, environment, exact repro steps, actual vs expected, and evidence (logs, error text, failing route/test) — and then optionally…

    310 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • Muse Governance

    ucsandman/DashClaw

    Governance behavior for Muse agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    310 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Build Dashclaw

    ucsandman/DashClaw

    Contribute to the DashClaw codebase — architecture, scaffolding, tests, CI

    310 GitHub stars~1.3k tokensUpdated 3 days ago
    Auto-check passed
  • Compliance Drift Evals

    ucsandman/DashClaw

    Set up compliance exports, drift detection, evaluations, scoring, and learning analytics

    310 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed

Questions about Instrument Agent

What does Instrument Agent do?

Integrate DashClaw SDK into any agent using the 4-step governance loop. Instrument Agent is an agent skill from ucsandman/DashClaw.

When should I use Instrument Agent?

Instrument Agent fits situations like: tasks that involve Building AI agents.

How do I install Instrument Agent in Claude Code?

Run `npx skills add ucsandman/DashClaw --skill instrument-agent -a claude-code`. Or copy the skill folder (.claude/skills/dashclaw-agent/instrument-agent in ucsandman/DashClaw) into .claude/skills/instrument-agent in your project. Claude Code loads it when a task matches its description.

How do I install Instrument Agent in Codex?

Run `npx skills add ucsandman/DashClaw --skill instrument-agent -a codex`. Or copy the skill folder (.claude/skills/dashclaw-agent/instrument-agent in ucsandman/DashClaw) into .agents/skills/instrument-agent in your project. Codex loads it when a task matches its description.

Can I use Instrument Agent in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ucsandman/DashClaw --skill instrument-agent -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/instrument-agent, .gemini/skills/instrument-agent, .github/skills/instrument-agent and .opencode/skills/instrument-agent in your project.

What does Instrument Agent need to run?

Going by SKILL.md and its folder, Instrument Agent needs the command-line tools its instructions call (node, npm, pip, curl and jq) and credentials named DASHCLAW_API_KEY. Our summary lists: Python 3; Node.js; A credential in DASHCLAW_API_KEY.

Does Instrument Agent access the network?

SKILL.md contains no URLs. Its commands use npm, pip and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Instrument Agent safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Instrument Agent use?

Instrument Agent is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Instrument Agent use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Instrument Agent?

Skills that share tags, products or a category with Instrument Agent: Agent Builder (n8n-io/n8n, 207k stars), Summarize (swarmclawai/swarmclaw, 688 stars), Agent Squad Python Guide (2FastLabs/agent-squad, 7.8k stars) and Agent Squad for TypeScript (2FastLabs/agent-squad, 7.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Instrument Agent?

ucsandman (a GitHub user) maintains it in ucsandman/DashClaw, which has 310 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: ucsandman/DashClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.