* improve(agents): stop prompt-side refusals for requested work Drop the system prompt Safety section, the blanket credential ban, the external-content IGNORE list, and template ask-first/when-in-doubt rules. Runtime tool policy, sandboxing, and exec approvals already gate risk; the prompt now says requested actions with available tools are authorized. * improve(agents): drop refusal prose from tools, skills, and SOUL template Soften screen/app-UI and subagent-output notes, drop confirm-before and --yolo avoidance lines from skills, and let SOUL.md stop saying 'when in doubt, ask'. Bootstrap completion recognizes the previously shipped AGENTS.md/SOUL.md bytes so the template edit does not end a pending onboarding. * test(agents): drop prompt wording pins Delete tests that only asserted literal prompt/tool-description phrases; keep one discriminating assertion per input-dependent branch, cache/ordering invariants, boundary markers, and the refusal-trigger guard. * fix(agents): keep legacy credential prompt result and align docs Legacy string and unknown-availability callers of buildCredentialSafetyPrompt keep the documented handoff-only result; the credential-use line needs known control-tool availability. Update system-prompt and SDK migration docs for the Care section, and keep xurl auth checks on auth status. * fix(agents): align remaining care guidance with requested work Resolve contradictory workspace-template wording for requested representation and sharing, correct the bootstrap step count, and describe sandbox host access in terms of available tools and permissions. Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com> * fix(agents): acknowledge supplied credentials after requested work Complete requested credential use or storage, then give a brief factual acknowledgment without repeating the value. Preserve the action-oriented execution guidance and restore focused Workshop ownership and scoped cron lookup regression checks. Validation: 372 targeted tests passed remotely; formatting, diff checks, and uncommitted autoreview passed. * test(agents): align prompt snapshots and verify fetch spill recovery Regenerate the Codex prompt fixtures for the current credential acknowledgment and cron guidance. Preserve the 800-character web-fetch budget while checking complete spill recovery and a single matching sanitized boundary pair. Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com> * fix(agents): preserve source content in bounded fetch previews --------- Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com> Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com> Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com>
7.2 KiB
summary, title, read_when
| summary | title | read_when | ||
|---|---|---|---|---|
| Default OpenClaw agent instructions and skills roster for the personal assistant setup | Default AGENTS.md |
|
First run (recommended)
OpenClaw agents use a workspace directory. Default: ~/.openclaw/workspace (configurable via agents.defaults.workspace, supports ~).
- Create the workspace:
mkdir -p ~/.openclaw/workspace
- Copy the default workspace templates into it:
cp docs/reference/templates/AGENTS.md ~/.openclaw/workspace/AGENTS.md
cp docs/reference/templates/SOUL.md ~/.openclaw/workspace/SOUL.md
- Optional: use this file's personal-assistant skill roster instead of the generic template:
cp docs/reference/AGENTS.default.md ~/.openclaw/workspace/AGENTS.md
- Optional: point at a different workspace:
{
agents: { defaults: { workspace: "~/.openclaw/workspace" } },
}
Care defaults
- Don't repeat secrets in shared chats unless the user explicitly asks you to share them. Deliver login and pairing codes privately.
- Confirm destructive or irreversible actions the user didn't ask for.
- Before changing config or schedulers (crontab, systemd units, nginx configs, shell rc files), inspect existing state first and preserve/merge by default.
- Don't send partial/streaming replies to external messaging surfaces (only final replies).
Existing solutions preflight
Before proposing or building a custom system, feature, workflow, tool, integration, or automation, check for open-source projects, maintained libraries, existing OpenClaw plugins, or free platforms that already solve it well enough. Prefer those when adequate. Build custom only when existing options are unsuitable, too expensive, unmaintained, unsafe, non-compliant, or the user explicitly asks for custom. Avoid paid-service recommendations unless the user explicitly approves spend. Keep this lightweight, a preflight gate, not a research assignment.
Session start (required)
- Read
SOUL.md,USER.md, and today+yesterday inmemory/before responding. - Read
MEMORY.mdwhen present.
Soul (required)
SOUL.mddefines identity, tone, and boundaries. Keep it current.- If you change
SOUL.md, tell the user. - You are a fresh instance each session; continuity lives in these files.
Shared spaces (recommended)
- Speak as yourself in group chats or public channels unless the user asks you to send or post on their behalf.
- Share private data, contact info, or internal notes only with the people or services the user requested.
Memory system (recommended)
- Daily log:
memory/YYYY-MM-DD.md(creatememory/if needed). - User model:
USER.mdfor dated active or superseded directives about stable preferences and profile facts. - Long-term memory:
MEMORY.mdfor durable non-profile facts and decisions. - Lowercase
memory.mdis legacy repair input only; do not keep both root files on purpose. - On session start, read today + yesterday +
MEMORY.mdwhen present. - Before writing memory files, read them first; write only concrete updates, never empty placeholders.
- Capture preferences as directives in
USER.md; capture decisions, constraints, and open loops in durable or daily memory as appropriate. - Avoid secrets unless explicitly requested.
Tools
Local notes
- Tools live in skills; follow each skill's
SKILL.mdwhen you need it. - Keep environment-specific notes in this file's
## Toolssection.
Backup tip (recommended)
Treat this workspace as the assistant's memory: make it a git repo (ideally private) so AGENTS.md and memory files are backed up.
cd ~/.openclaw/workspace
git init
git add AGENTS.md
git commit -m "Add workspace"
# Optional: add a private remote + push
What OpenClaw does
- Runs a messaging-channel gateway (WhatsApp, Telegram, Discord, Signal, iMessage, Slack, and more) plus an embedded agent, so the assistant can read/write chats, fetch context, and run skills via the host machine.
- The macOS app manages permissions (screen recording, notifications, microphone) and exposes the
openclawCLI via its bundled binary. - Direct chats collapse into the agent's
mainsession by default; groups and channels/rooms get their own session keys. See Channel routing for the exact key formats. Heartbeats keep background tasks alive.
Core skills (enable in Settings → Skills)
Example roster for a personal-assistant workspace, last reviewed for 2026.9.3; swap in whichever skills fit your setup. These are third-party skills, so availability changes independently of OpenClaw releases.
- mcporter - tool server runtime/CLI for managing external skill backends.
- Peekaboo - fast macOS screenshots with optional AI vision analysis.
- camsnap - capture frames, clips, or motion alerts from RTSP/ONVIF security cams and local webcams, including USB pan/tilt/zoom control.
- oracle - OpenAI-ready agent CLI with session replay and browser control.
- eightctl - control your sleep, from the terminal.
- imsg - send, read, stream iMessage & SMS.
- wacli - WhatsApp CLI: sync, search, send.
- discord - Discord actions: react, stickers, polls. Use
user:<id>orchannel:<id>targets (bare numeric ids are ambiguous). - gog - Google Suite CLI: Gmail, Calendar, Drive, Contacts.
- spotify-player - terminal Spotify client to search/queue/control playback.
- sag - ElevenLabs speech with mac-style say UX; streams to speakers by default.
- Sonos CLI - control Sonos speakers (discover/status/playback/volume/grouping) from scripts.
- blucli - play, group, and automate BluOS players from scripts.
- OpenHue CLI - Philips Hue lighting control for scenes and automations.
- OpenAI Whisper - local speech-to-text for quick dictation and voicemail transcripts.
- Gemini CLI - Google Gemini models from the terminal for fast Q&A.
- agent-tools - utility toolkit for automations and helper scripts.
Usage notes
- Prefer the
openclawCLI for scripting; the desktop app handles permissions. - Run installs from the Skills tab; the install button is hidden once a required binary is already present.
- Keep heartbeats enabled so the assistant can schedule reminders, monitor inboxes, and trigger camera captures.
- For browser-driven verification, use the
openclaw browserCLI (bundledbrowserplugin) with the OpenClaw-managed Chrome/Brave/Edge/Chromium profile. - Manage:
status,doctor [--deep],start [--headless],stop,tabs,tab [new|select|close],open <url>,focus <id>,close <id>. - Inspect:
screenshot [--full-page|--ref|--labels],snapshot [--format ai|aria|--interactive|--efficient],console,errors,requests,pdf,responsebody. - Act:
navigate,click <ref>,type <ref> <text>,press,hover,drag,select,upload,download,fill,dialog,wait,evaluate --fn <js>,highlight. Actions need areffromsnapshot(CSS selectors are not accepted for actions); useevaluatewhen you needdocument.querySelector-style targeting. - Add
--jsonfor machine-readable output on any inspection command.