Agent skill

Setup Dashclaw

by ucsandman in ucsandman/DashClaw

Set up a DashClaw instance, install the CLI tool, and configure Claude Code hooks

MITAuto-check: notesAgent Workflows

Install Setup Dashclaw

skills CLI
$ npx skills add ucsandman/DashClaw --skill setup-dashclaw -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ucsandman/DashClaw setup-dashclaw --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dashclaw-agent/setup-dashclaw .claude/skills/setup-dashclaw && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
setup-dashclaw
GitHub stars
310
Token cost
~2.6k tokens
SKILL.md length
853 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Set up a DashClaw instance, install the CLI tool, and configure Claude Code hooks

  • Works in 6 steps: Fork the DashClaw repo on GitHub → Deploy to Vercel (connect the fork) → Create a free Neon Postgres database → …
  • Tasks that involve Hooks and plugins
  • SKILL.md covers Instance Setup, CLI Installation and Claude Code Hooks
  • Calls git, npm and node; needs DASHCLAW_API_KEY and ENCRYPTION_KEY

What it does

Setup Dashclaw is an agent skill from ucsandman/DashClaw. Set up a DashClaw instance, install the CLI tool, and configure Claude Code hooks

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Hooks and plugins and Building AI agents. It works with Model Context Protocol. The repository describes itself as: Remote approvals, policy checks, and execution evidence for unattended AI agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Hooks and plugins
  • Tasks that involve Building AI agents

Example prompts

  • “/setup-dashclaw”

Requirements

  • Python 3
  • Node.js
  • A credential in ENCRYPTION_KEY
  • A credential in NEXTAUTH_SECRET

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Fork the DashClaw repo on GitHub
  2. Deploy to Vercel (connect the fork)
  3. Create a free Neon Postgres database
  4. Set DATABASE_URL in Vercel environment variables
  5. Run node scripts/setup.mjs locally pointing to your cloud instance
  6. Grab your API key from the dashboard

What it can do on your machine

Read from SKILL.md and the folder at commit 704824d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • node
    • npx
    • curl
    • claude
    • vercel
    • terraform
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm, npx, curl, vercel and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DASHCLAW_API_KEY
    • ENCRYPTION_KEY
    • NEXTAUTH_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Setup Dashclaw loads about 2.6k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 853 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:29
    # Run interactive setup (creates .env, initializes database)
  • NoteMentions a .env fileSKILL.md:37
    **Required environment variables (.env):**
  • NoteMentions a .env fileSKILL.md:249
    | `.env`, `secret`, `key` file access | security | 85 | false |
  • NoteMentions a .env fileSKILL.md:256
    | `.env`, `secrets`, `credentials` | security | 85 |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ucsandman/DashClaw at commit 704824d, republished under its MIT licence (© ucsandman). 853 words, ~2,564 tokens.

Download SKILL.mdSave it as .claude/skills/setup-dashclaw/SKILL.md (or your agent's skills folder).
name
setup-dashclaw
description
Set up a DashClaw instance, install the CLI tool, and configure Claude Code hooks
license
MIT
metadata.author
ucsandman
metadata.version
1.0.0
metadata.category
setup

Set Up DashClaw

Three ways to get DashClaw running, plus CLI and Claude Code hook setup.


Instance Setup

Option 1: Local Development
bash
# Clone the repo
git clone git@github.com:ucsandman/DashClaw.git
cd DashClaw

# Install dependencies
npm install

# Run interactive setup (creates .env, initializes database)
node scripts/setup.mjs

# Start dev server
npm run dev
# → http://localhost:3000

Required environment variables (.env):

bash
DATABASE_URL=postgresql://user:pass@localhost:5432/dashclaw
ENCRYPTION_KEY=<32-char-random-string>
NEXTAUTH_URL=http://localhost:3000
NEXTAUTH_SECRET=<32-char-random-string>
DASHCLAW_API_KEY=<your-api-key>
DASHCLAW_MODE=self_host
Option 2: Cloud (Vercel + Neon)
  1. Fork the DashClaw repo on GitHub
  2. Deploy to Vercel (connect the fork)
  3. Create a free Neon Postgres database
  4. Set DATABASE_URL in Vercel environment variables
  5. Run node scripts/setup.mjs locally pointing to your cloud instance
  6. Grab your API key from the dashboard
Option 3: Demo Mode
bash
npx dashclaw-demo
# Runs a local demo instance with fixture data
# Opens Decision Replay automatically
# Agent attempts risky deployment, DashClaw blocks it

Demo mode is read-only — no writes allowed. Good for exploring the UI.

Verify Setup
bash
# Health check
curl http://localhost:3000/api/health

# Expected response:
# { "status": "ok", "database": "connected", "version": "2.x.x" }

Visit http://localhost:3000/setup for the instance readiness verification page.


CLI Installation

The @dashclaw/cli provides terminal-based approval workflows.

Install
bash
npm install -g @dashclaw/cli
Configure
bash
export DASHCLAW_BASE_URL=http://localhost:3000
export DASHCLAW_API_KEY=your-api-key
# Optional: export DASHCLAW_AGENT_ID=cli-operator
Commands
bash
# Interactive approval inbox (TUI with live updates)
dashclaw approvals

# Approve a specific action
dashclaw approve act_abc123 --reason "Reviewed and safe"

# Deny a specific action
dashclaw deny act_abc123 --reason "Risk too high for current sprint"

# Help
dashclaw help
Interactive Mode Keyboard Shortcuts
KeyAction
↑/↓Navigate approvals
AApprove selected
DDeny selected
RRefresh list
OOpen replay link in browser
QQuit

Risk scores are color-coded: green (<40), yellow (40-70), red (70+).


Claude Code Hooks

DashClaw provides pre/post tool hooks for Claude Code that create a policy-enforced execution pipeline. Hooks v2 govern 40+ tool types (not just Bash/Edit/Write/MultiEdit) with semantic classification via the bundled dashclaw_agent_intel module.

How It Works
Claude Code Tool Call (Bash/Edit/Write/MultiEdit)
        ↓
[PreToolUse: dashclaw_pretool.py]
   → Classify action (type, risk, systems)
   → POST to /api/guard
   → Allow / Warn / Block / Require Approval
   → Store action_id in temp file
        ↓
[Tool Executes] (unless blocked)
        ↓
[PostToolUse: dashclaw_posttool.py]
   → Read action_id from temp file
   → Determine outcome (completed/failed)
   → PATCH /api/actions/:id with result
        ↓
Full audit trail in DashClaw dashboard
Install Hooks

Recommended: use the one-command installer from your DashClaw checkout:

bash
node /path/to/DashClaw/scripts/install-hooks.mjs --target=.

This copies all three governance hooks (dashclaw_pretool.py, dashclaw_posttool.py, dashclaw_stop.py) and the dashclaw_agent_intel/ Python module into .claude/hooks/, then merges the PreToolUse / PostToolUse / Stop blocks into .claude/settings.json. Idempotent — safe to re-run after each git pull.

Manual install (if you need to control file placement):

  1. Copy hook files into your project's .claude/hooks/ directory:
bash
mkdir -p .claude/hooks
cp /path/to/DashClaw/hooks/dashclaw_pretool.py .claude/hooks/
cp /path/to/DashClaw/hooks/dashclaw_posttool.py .claude/hooks/
cp /path/to/DashClaw/hooks/dashclaw_stop.py    .claude/hooks/
cp -r /path/to/DashClaw/hooks/dashclaw_agent_intel .claude/hooks/

The dashclaw_agent_intel/ module is required — dashclaw_pretool.py imports it for semantic tool classification, so omitting it raises ImportError on the first governed tool call.

  1. Add hook configuration to .claude/settings.json — three entries are needed: PreToolUse (governance gate), PostToolUse (outcome recorder), and Stop (LLM token + cost capture, plus auto-close fallback for any actions that PostToolUse missed):
json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|Edit|Write|MultiEdit",
        "hooks": [
          {
            "type": "command",
            "command": "python .claude/hooks/dashclaw_pretool.py",
            "timeout": 3660
          }
        ]
      }
    ],
    "PostToolUse": [
      {
        "matcher": "Bash|Edit|Write|MultiEdit",
        "hooks": [
          {
            "type": "command",
            "command": "python .claude/hooks/dashclaw_posttool.py"
          }
        ]
      }
    ],
    "Stop": [
      {
        "hooks": [
          {
            "type": "command",
            "command": "python .claude/hooks/dashclaw_stop.py"
          }
        ]
      }
    ]
  }
}
  1. Set environment variables:
bash
export DASHCLAW_BASE_URL=http://localhost:3000
export DASHCLAW_API_KEY=your-api-key
export DASHCLAW_AGENT_ID=claude-code
export DASHCLAW_HOOK_MODE=observe    # Start with observe, switch to enforce later
export DASHCLAW_RISK_THRESHOLD=60    # Default risk threshold
export DASHCLAW_GOVERNED_CATEGORIES=all  # Comma-separated tool categories or "all" (see below before narrowing)
export DASHCLAW_PERMISSION_MODE=standard # standard | elevated | admin
Hook Modes
  • observe — Logs all decisions but never blocks. Use this first to understand what would be caught.
  • enforce — Blocks tool execution when guard returns block or approval is denied/times out.
Action Type Mapping (Pretool)

The pretool automatically classifies tool calls:

Bash commands:

PatternAction TypeRiskReversible
git push, git merge, git rebasedeploy80false
npm run deploy, vercel deploydeploy75-85false
terraform applydeploy85false
rm -rf, DROP TABLEsecurity90false
.env, secret, key file accesssecurity85false
npm install, pip installbuild30true
curl, wgetapi40true

File operations (Edit/Write/MultiEdit):

File PatternAction TypeRisk
.env, secrets, credentialssecurity85
migration, schemamigrate70
auth, middlewaresecurity75
Other filesfile_write15
Approval Timeout

When the guard returns require_approval, the pretool polls for 30 seconds. If no decision is made, the tool is blocked (enforce mode) or allowed (observe mode).

Use dashclaw approvals in another terminal to approve in real-time.

Graceful Degradation

If the hook is unconfigured (no DASHCLAW_BASE_URL/DASHCLAW_API_KEY), it exits 0 and the tool runs ungoverned; half-configured warns on stderr and still exits 0. But a server down or network error is not the same case: in enforce mode the hook fails closed and blocks (exit 2), because an action that could not be governed must not proceed. Override with DASHCLAW_GUARD_UNAVAILABLE_POLICY=warn|allow (not recommended). Observe mode never blocks either way, and every outage is written to ~/.dashclaw/orphan-actions.jsonl for backfill on recovery.

Show full SKILL.md (306 more words)Show less
Governed categories — narrowing the scope is visible

DASHCLAW_GOVERNED_CATEGORIES decides which tool categories call the guard at all. This is a scope knob, not a mode knob, and it is sharper than it looks: for a category it excludes, the hook exits before the network call, so those tool calls produce no decision row, no witness and no signal. Their absence from /decisions is indistinguishable from an agent that simply did nothing.

Default governed set: execution,orchestration,file_io,interactive,mcp. search and system are ungoverned out of the box by design. Unknown tools that match no category fail safe to governed.

Since v5.20 the hook declares the categories it is not governing on the calls it does still make, and any category dropped below that default set raises the red Governance scope narrowed (ungoverned_scope) signal naming what is unwatched. A healthy default install declares nothing and raises nothing. This is a visibility guarantee, not an enforcement one — the variable lives on the agent's own machine — but it catches the case that actually happens: a misconfigured agent, or a typo that silently dropped a real category (file-io is not file_io).

Hooks v2 enrichment feeds three guard policy types (these are policies you configure, not signals the dashboard emits):

  • permission_escalation — matches when the action requires elevated permissions
  • green_contract — requires a test-verification level before deploys
  • branch_freshness — matches deploys from a stale or diverged branch

Blocked decisions may also carry a recovery recipe: actionable remediation steps returned alongside the verdict. Monitor the resulting risk signals in the dashboard or via /api/signals.

For long-running Claude Code sessions, create a session to enable lifecycle tracking and recovery:

bash
# Sessions are created automatically by hooks when DASHCLAW_SESSION_TRACKING=true
export DASHCLAW_SESSION_TRACKING=true

Session tracking is optional. When enabled, the pretool hook creates a session on first invocation and reports status updates throughout the session. If a session is interrupted, DashClaw records the last checkpoint for recovery.

© ucsandman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dashclaw-agent/setup-dashclaw of ucsandman/DashClaw.

Open the folder on GitHubat commit 704824d

Compare with similar skills

Setup Dashclaw next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Setup Dashclaw compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Setup Dashclaw this skillucsandman/DashClaw310—~2.6kAutomated safety check: NotesMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
OpenpetsOpenPetsHQ/openpets1.3k—~2.1kAutomated safety check: PassMIT
Claude Automation Recommenderanthropics/claude-plugins-official38k3 repos~2.7kAutomated safety check: NotesApache-2.0
Mistral Vibe Plugin Creatormistralai/mistral-vibe5.1k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Openpets

    OpenPetsHQ/openpets

    A skill your agent uses whenever the user wants to build, extend, debug, test, validate, locally load, package, or publish an OpenPets plugin; work with the OpenPets Plugin SDK v3, plugin manifest…

    1.3k GitHub stars~2.1k tokensUpdated 11 days ago
    Agent WorkflowsAuto-check passed
  • Claude Automation Recommender

    anthropics/claude-plugins-official

    Official

    Scans a codebase and suggests which Claude Code hooks, subagents, skills, plugins and MCP servers fit its stack, without changing any files.

    38k GitHub starsUsed in 3 repos~2.7k tokens
    Agent WorkflowsAuto-check: notes
  • Mistral Vibe Plugin Creator

    mistralai/mistral-vibe

    Official

    Shows how to build a Vibe plugin package in the Agent Plugins 1.0 format, with a plugin.json manifest and optional skills, MCP servers, hooks and other components.

    5.1k GitHub stars~3.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

    7.2k GitHub stars~5.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes

More from ucsandman/DashClaw

All 13 skills in this repo
  • Dashclaw Governance

    ucsandman/DashClaw

    Governance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    310 GitHub stars~2.7k tokensUpdated 2 days ago
    Auto-check passed
  • Dashclaw Ship

    ucsandman/DashClaw

    The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist.

    310 GitHub stars~7.2k tokensUpdated 2 days ago
    Auto-check passed
  • Repro

    ucsandman/DashClaw

    Turn a bug symptom into a structured, reproducible bug report — summary, environment, exact repro steps, actual vs expected, and evidence (logs, error text, failing route/test) — and then optionally…

    310 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Muse Governance

    ucsandman/DashClaw

    Governance behavior for Muse agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    310 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Build Dashclaw

    ucsandman/DashClaw

    Contribute to the DashClaw codebase — architecture, scaffolding, tests, CI

    310 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Compliance Drift Evals

    ucsandman/DashClaw

    Set up compliance exports, drift detection, evaluations, scoring, and learning analytics

    310 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Setup Dashclaw

What does Setup Dashclaw do?

Set up a DashClaw instance, install the CLI tool, and configure Claude Code hooks. Setup Dashclaw is an agent skill from ucsandman/DashClaw.

When should I use Setup Dashclaw?

Setup Dashclaw fits situations like: tasks that involve Hooks and plugins; tasks that involve Building AI agents.

How do I install Setup Dashclaw in Claude Code?

Run `npx skills add ucsandman/DashClaw --skill setup-dashclaw -a claude-code`. Or copy the skill folder (.claude/skills/dashclaw-agent/setup-dashclaw in ucsandman/DashClaw) into .claude/skills/setup-dashclaw in your project. Claude Code loads it when a task matches its description.

How do I install Setup Dashclaw in Codex?

Run `npx skills add ucsandman/DashClaw --skill setup-dashclaw -a codex`. Or copy the skill folder (.claude/skills/dashclaw-agent/setup-dashclaw in ucsandman/DashClaw) into .agents/skills/setup-dashclaw in your project. Codex loads it when a task matches its description.

Can I use Setup Dashclaw in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ucsandman/DashClaw --skill setup-dashclaw -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setup-dashclaw, .gemini/skills/setup-dashclaw, .github/skills/setup-dashclaw and .opencode/skills/setup-dashclaw in your project.

What does Setup Dashclaw need to run?

Going by SKILL.md and its folder, Setup Dashclaw needs the command-line tools its instructions call (git, npm, node, npx, curl and claude) and credentials named DASHCLAW_API_KEY, ENCRYPTION_KEY and NEXTAUTH_SECRET. Our summary lists: Python 3; Node.js; A credential in ENCRYPTION_KEY; A credential in NEXTAUTH_SECRET.

Does Setup Dashclaw access the network?

SKILL.md contains no URLs. Its commands use git, npm, npx, curl and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Setup Dashclaw safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Setup Dashclaw use?

Setup Dashclaw is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Setup Dashclaw use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Setup Dashclaw?

Skills that share tags, products or a category with Setup Dashclaw: MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars), Crush Configuration (charmbracelet/crush, 29k stars), Openpets (OpenPetsHQ/openpets, 1.3k stars) and Claude Automation Recommender (anthropics/claude-plugins-official, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Setup Dashclaw?

ucsandman (a GitHub user) maintains it in ucsandman/DashClaw, which has 310 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: ucsandman/DashClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.