Overview
Skills are SKILL.md files (YAML frontmatter + markdown prompt) that extend the agent’s behavior through prompt-level instructions. Unlike code-level tools (WASM/MCP), skills operate in the LLM context and are subject to trust-based authority attenuation.Trust Model
Skills have two trust states that determine their authority:- Trusted: User-placed skills (local/workspace) with full tool access
- Installed: Registry/external skills, restricted to read-only tools
Trust Assignment
Skill trust is determined by location:SKILL.md Format
Structure
Frontmatter Fields
Required
name: Alphanumeric, hyphens, underscores, dots. Max 64 chars. Pattern:^[a-zA-Z0-9][a-zA-Z0-9._-]{0,63}$
Optional
version: Semantic version (default:"0.0.0")description: Short summaryactivation: When to activate this skillmetadata: OpenClaw-specific metadata (gating requirements)
Activation Criteria
- Keywords: Max 20, min length 3 chars
- Patterns: Max 5 regex patterns
- Tags: Max 10, min length 3 chars
- Token budget: Max 2x declared
max_context_tokens
Gating Requirements
Skills can declare dependencies:Discovery and Loading
Directory Layouts
Two layouts are supported:Flat Layout
Subdirectory Layout
Discovery Order
Earlier locations win on name collision:- Workspace skills (
<workspace>/skills/) - Trusted - User skills (
~/.ironclaw/skills/) - Trusted - Installed skills (
~/.ironclaw/installed_skills/) - Installed
Load-Time Validation
- File size: Max 64 KiB
- Name validation: Matches
^[a-zA-Z0-9][a-zA-Z0-9._-]{0,63}$ - Frontmatter parsing: Valid YAML
- Activation limits: Keywords/patterns/tags within caps
- Token budget: Prompt size < 2x declared
max_context_tokens - Gating checks: Required bins/env/config present
- Symlink rejection: No symlinks allowed
- Line ending normalization: CRLF → LF
Loading Pipeline
Activation and Selection
Scoring Algorithm
Selection Process
- Score all skills against incoming message
- Filter skills with score > 0
- Sort by score (descending)
- Take top N skills (default: 3)
- Check total token budget
- Return selected skills
Tool Attenuation
When skills are active, tool access is restricted:ReadGlobGrepWebFetchSkillCatalog
WriteEditBashTask- All other tools
Skill Injection
Skills are injected into the LLM context:Security: Tag Breakout Prevention
Skill content is escaped to prevent tag injection:- Closing their own
</skill>tag prematurely - Injecting fake
<skill trust="trusted">blocks - Breaking out via mixed case, whitespace, or null bytes
Managing Skills
Via CLI
Via Tool Call
The agent can manage skills:Programmatic API
Creating Skills
Simple Skill
Advanced Skill
ClawHub Integration
Skills can be published to and installed from ClawHub:~/.ironclaw/installed_skills/ with Installed trust.
Best Practices
Skill Design
- Focused scope: One skill per domain (writing, code review, etc.)
- Clear activation: Use specific keywords and patterns
- Token budget: Keep prompts under 2000 tokens
- Gating: Declare binary/config dependencies
- Examples: Include example interactions in the prompt
Security
- Trust isolation: Don’t mix trusted and installed skills for sensitive tasks
- Review installed skills: Always review skill content before installing
- Workspace override: Place custom versions in workspace to override installed skills
- Symlink prohibition: Never use symlinks in skills directories
Performance
- Keyword limits: Use < 10 keywords per skill
- Pattern complexity: Avoid complex regex (max 64 KiB compiled size)
- Token budget: Larger prompts consume more context window
- Selective activation: Use precise patterns to avoid activating unnecessarily
Troubleshooting
Skill Not Loading
Skill Not Activating
Tool Access Denied
- Override the skill by placing a trusted version in workspace/user dir
- Remove the installed skill
- Use read-only tools only
Source Code
Key files:src/skills/mod.rs- Module overview, types, escapingsrc/skills/registry.rs- Discovery, loading, managementsrc/skills/parser.rs- SKILL.md parsingsrc/skills/selector.rs- Activation scoring and selectionsrc/skills/attenuation.rs- Tool restriction based on trustsrc/skills/gating.rs- Dependency checks (bins/env/config)src/skills/catalog.rs- ClawHub integration