What an OpenClaw skill is
A skill is a folder containing a SKILL.md file: a short markdown guide with a name and description at the top. When a skill is relevant, the agent reads it and follows its instructions using the tools it already has. OpenClaw follows the open AgentSkills format.
---
name: weather-brief
description: Short weather summary for a city, for morning briefings
metadata: { "openclaw": { "requires": { "bins": ["curl"] } } }
---
When the user asks for the weather or a morning briefing:
1. Fetch the forecast for their city.
2. Reply in 2 lines: temperature range and rain chance.
3. Warn if rain is above 60%.- Name and description are always in the agent's prompt, so it knows the skill exists.
- Requirements (optional) hide the skill until binaries, environment variables or config it needs are present.
- Instructions are only read when the skill is used, which keeps your prompt small.
Skills are instructions. They teach the agent to use tools it already has. Plugins are code that adds new tools, channels or model providers, installed with openclaw plugins. Plugins can ship skills too.
Where skills come from
Ships with OpenClaw. Some, such as coding-agent, are opt-in.
The public skills registry at clawhub.ai, with security scans shown on each page.
Install straight from a repository or a folder on disk. These aren't scanned by ClawHub.
Skills your agent drafts from your own repeated work, applied after review.
External listings resolved to a pinned GitHub commit, and marked "Not scanned by ClawHub".
Enabled plugins can bring their own skills, such as the browser plugin's browser-automation.
Find skills
Search ClawHub from the terminal, or browse clawhub.ai, where each skill page shows its latest security scan (VirusTotal, ClawScan and static analysis) before you install.
openclaw skills search "calendar"
openclaw skills search "invoice" --limit 20Then check its trust record. The command fails if ClawHub marks verification as failed:
openclaw skills verify @owner/slug
openclaw skills verify @owner/slug --card # print the skill's summary cardUse the owner-qualified name, @owner/slug. It avoids confusion between different publishers with similar skill names.
Install skills
Install command builder
Pick a source and scope. The builder writes the install command, plus the verify and check steps to run with it.
Workspace installs go to the agent's skills/ folder. --global installs to ~/.openclaw/skills. Git and local installs need SKILL.md at the root, and you refresh them by reinstalling, not with update.
Treat every skill as untrusted code
In 2026, attackers uploaded credential-stealing skills to ClawHub, and some became top downloads. ClawHub now refuses releases it has found to be malicious, and shows scans on each page. But a skill runs with your agent's permissions, so check it yourself.
Want a gate for everyone on your machine? security.installPolicy runs your own policy command before any skill install continues, and blocks installs if the check fails. See the security guide.
Use a skill
Most of the time you don't have to do anything. The agent picks a skill when its description matches your request. To call one on purpose:
$skill in a messageType $ in the Control UI to search. Up to 8 skills per message: "Use $github and $release_notes to summarize this change."
/skill as a commandIn chat apps, /release_notes … runs it as a standalone command.
Skills with disable-model-invocation: true only run when you call them by name.
Need a literal dollar sign before a word? Write \$name. Uppercase shell variables like $HOME stay as normal text.
List, update, disable and remove skills
openclaw skills list --eligible # skills ready to use
openclaw skills info weather-brief # details for one skill
openclaw skills check # why a skill isn't showingopenclaw skills update --all # workspace skills
openclaw skills update --all --global # shared skills
openclaw skills update @owner/slugUpdates only track ClawHub installs. Reinstall Git or local skills to refresh them.
{
skills: {
entries: {
"weather-brief": { enabled: false },
"coding-agent": { enabled: true }, // opt-in bundled skill
},
},
}Removal uses the separate ClawHub CLI. Point it at the folder where the skill was installed:
npm i -g clawhub
clawhub uninstall @owner/slug # from the current workspace
clawhub --workdir ~/.openclaw uninstall @owner/slug # a --global skillSkills are loaded when a session starts. File changes are picked up automatically by the skills watcher, and a gateway restart or a new session always refreshes them.
Control which agent gets which skills
Where a skill is installed decides who can see it. An allowlist decides who does:
{
agents: {
defaults: { skills: ["github", "weather"] }, // shared baseline
entries: {
writer: { default: true }, // inherits github, weather
docs: { skills: ["docs-search"] }, // replaces the baseline
"locked-down": { skills: [] }, // no skills
},
},
}When two skills share a name, the higher source wins:
<workspace>/skillsWorkspace skills, the highest priority<workspace>/.agents/skillsProject agent skills~/.agents/skillsPersonal agent skills~/.openclaw/skillsShared managed skills (--global)…/workshop-skillsSkills learned in Skill WorkshopbundledShipped with OpenClawskills.load.extraDirsExtra folders and plugin skills, the lowest priority
An allowlist controls which skills an agent sees. It isn't a security boundary for shell access, so limit exec separately.
Create your own skill
The fastest way: ask your agent. "Every time I send a receipt photo, add it to my expenses sheet. Save that as a skill." Skill Workshop turns it into a proposal you review before it goes live:
openclaw skills workshop list
openclaw skills workshop inspect <proposal-id>
openclaw skills workshop apply <proposal-id>
openclaw skills workshop reject <proposal-id> --reason "Not reusable"Or write one by hand with the generator:
SKILL.md generator
Save the result as <workspace>/skills/<name>/SKILL.md. Keep the description short, because it's in every prompt.
Use {baseDir} in the body to point at files in the skill's folder. Give a skill its API key with skills.entries.<name>.apiKey. Note that these keys are injected on the host, not inside a sandbox.
How much do skills cost in tokens?
Every eligible skill adds its name, description and location to the system prompt. That's about 24 tokens per skill, plus the length of those fields, on every model call. Full instructions are only loaded when used.
≈ 1,000 extra tokens per model call
An estimate: (97 characters + description + about 40 characters for name and location) ÷ 4 per skill. Too many skills? OpenClaw shortens descriptions to fit skills.limits.maxSkillsPromptChars. Trim unused skills with allowlists to save money. See pricing.
Fix common skill problems
Skill installed but not showingRun openclaw skills check. It may be missing a program, an env var or config, or be hidden by an agent allowlist.
Still using the old versionSessions snapshot skills at start. Start a new session or restart the gateway.
Verify failsClawHub flagged the release. Don't install it. Publishers can request a rescan if it's a false positive.
API key not reaching the skillskills.entries.*.env and apiKey only apply on the host, not in a sandbox.
Wrong skill runsTwo skills share a name, and the higher-priority location wins. Rename one, or remove the duplicate.
update does nothingGit and local installs aren't tracked. Reinstall them from the source.
OpenClaw skills questions
What are OpenClaw skills?
Skills are folders with a SKILL.md file that teach the agent how and when to use its tools for a specific job. They follow the AgentSkills format, and only their name and description sit in the prompt until they're used.
How do I install an OpenClaw skill?
Run openclaw skills search to find one, openclaw skills verify @owner/slug to check it, then openclaw skills install @owner/slug. Add --global to share it with all local agents.
Are ClawHub skills safe?
Not automatically. Malicious skills were found on ClawHub in 2026. ClawHub now scans releases and refuses known-malicious ones, but you should still read a skill's files, run openclaw skills verify and test it in a sandbox.
How do I remove a skill?
Use the ClawHub CLI: install it with npm i -g clawhub, then run clawhub uninstall @owner/slug in the workspace, or add --workdir ~/.openclaw for a global skill.
Can OpenClaw create its own skills?
Yes. Skill Workshop lets the agent draft a skill from your repeated work as a proposal. You inspect it and apply or reject it with the openclaw skills workshop commands.
Why isn't my skill showing up?
Run openclaw skills check. The skill may need a program, environment variable or config setting that's missing, or an agent allowlist may hide it. Start a new session after changes.