Clawsweeper logo

Clawsweeper

OrganizationPopular
openclaw
clawsweeper

Use for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed autofix/automerge, GitHub Actions monitoring, permissions, gates, and manual backfills.

Overview

Publisheropenclaw
Repositoryopenclaw
Skill nameclawsweeper
Stars
391K
Forks
82.2K
Bundled files
1
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 1 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by openclaw on GitHub. Read the source before you install it.

Installation

Install the Clawsweeper AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
    https://github.com/openclaw/openclaw/tree/main/.agents/skills/clawsweeper
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/openclaw/openclaw.git /tmp/openclaw
mkdir -p .claude/skills
cp -r /tmp/openclaw/.agents/skills/clawsweeper .claude/skills/clawsweeper
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Clawsweeper in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Clawsweeper on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Clawsweeper is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

ClawSweeper

ClawSweeper lives at ~/Projects/clawsweeper. It is the one OpenClaw maintenance bot for sweeping, repair jobs, and guarded fix PRs. Use this skill whenever asked about reports, findings, dispatch health, repair/cloud PR creation, comment commands, automerge, permissions, or gates.

Start

Inspect git status --short --branch in the ClawSweeper checkout. Status and report requests stay read-only: use current reports and live read APIs when freshness matters, without pulling or building just to inspect them.

For authorized implementation or execution, update a clean task-owned checkout and build only when the selected command needs it. Preserve unrelated edits and other operators' active workflows.

One Bot, One App

Use the ClawSweeper repo and the clawsweeper GitHub App. Use only CLAWSWEEPER_* configuration for this automation. Do not use legacy apps, variables, labels, or skills.

Required app setup:

  • CLAWSWEEPER_APP_CLIENT_ID: public app client ID for clawsweeper.
  • CLAWSWEEPER_APP_PRIVATE_KEY: private key used only inside actions/create-github-app-token steps.
  • Target app permissions: read target scan context; write issues and pull requests; contents write for report commits, repair branches, and workflow inputs; Actions write on openclaw/clawsweeper for comment-router re-review dispatch, workflow dispatch, run cancellation, and self-heal.

Token boundary:

  • Codex workers do not get mutation credentials.
  • Review workers run with stripped secret/token env.
  • Deterministic scripts own comments, labels, branch pushes, PR creation, closes, and merges through short-lived GitHub App tokens.
  • Merge and write gates default closed.

Hosted Commit Reviews

Hosted per-commit reports and commit Check Runs are retired. For the retained offline review of a committed branch, use pnpm local-review -- --base main. $autoreview --mode commit --commit <sha> remains a separate general-purpose review path.

Sweep Reports

Issue/PR reports live at:

text
records/<repo-slug>/items/<number>.md
records/<repo-slug>/closed/<number>.md

Lead with counts, concrete findings, and report links. Do not post unsolicited GitHub comments from report-reading work. Public surfaces are markdown reports, durable ClawSweeper review comments, and optional checks.

PR reports include Codex /review-style reviewFindings with priority, confidence, repository-relative file, and line range. Public PR comments show a short Review findings: list when findings exist; full review comments, evidence links, likely owners, and runtime details stay inside the collapsed Review details block.

For a simple status request, read existing reports and bounded live workflow state. Use pnpm run audit only for a requested full audit.

Reconciliation is a separate authorized mutation: bare pnpm run reconcile moves/deletes report and work-plan files. Inspect its dry-run only when that maintenance task is requested; do not run reconciliation during status/report reads. Likewise, apply-decisions belongs to an explicitly authorized apply workflow, beginning with its dry-run.

Create One Repair Job

Create a job from issue/PR refs and a maintainer prompt:

bash
pnpm run repair:create-job -- \
  --repo openclaw/openclaw \
  --refs 123,456 \
  --prompt-file /tmp/clawsweeper-prompt.md

Create from an existing ClawSweeper report:

bash
pnpm run repair:create-job -- \
  --from-report ../clawsweeper/records/openclaw-openclaw/items/123.md

The job creator checks for an existing open PR, body match, or remote clawsweeper/<cluster-id> branch before writing another job. Use --dry-run to inspect. Use --force only after deciding the duplicate guard is stale.

Validate, commit, then dispatch:

bash
pnpm run repair:validate-job -- jobs/openclaw/inbox/clawsweeper-openclaw-openclaw-123.md
pnpm run repair:dispatch -- jobs/openclaw/inbox/clawsweeper-openclaw-openclaw-123.md \
  --mode autonomous \
  --runner blacksmith-4vcpu-ubuntu-2404 \
  --execution-runner blacksmith-16vcpu-ubuntu-2404 \
  --model gpt-6-astra

Do not dispatch a just-created job before the job file is committed and pushed; the workflow reads the job path from GitHub.

Replacement PRs

For a useful but uneditable/stale/unsafe source PR, make the maintainer prompt explicit:

md
Treat #123 as useful source work. If the source branch cannot be safely updated
because it is uneditable, stale, draft-only, unmergeable, or unsafe, create a
narrow ClawSweeper replacement PR instead of waiting. Preserve the source PR
author as co-author, credit the source PR in the replacement PR body, and close
only that source PR after the replacement PR is opened.

The worker should emit repair_strategy=replace_uneditable_branch and list the source PR URL in source_prs. The deterministic executor opens or updates clawsweeper/<cluster-id>, adds non-bot source authors as Co-authored-by trailers, and closes superseded source PRs only after replacement exists.

Gates

Change execution gates only under explicit authority for that window. Record the original state and any agreed restoration before changing it:

bash
gh variable set CLAWSWEEPER_ALLOW_EXECUTE --repo openclaw/clawsweeper --body 1
gh variable set CLAWSWEEPER_ALLOW_FIX_PR --repo openclaw/clawsweeper --body 1
gh variable set CLAWSWEEPER_ALLOW_MERGE --repo openclaw/clawsweeper --body 1
gh variable set CLAWSWEEPER_ALLOW_AUTOMERGE --repo openclaw/clawsweeper --body 1

Restore a gate only when the authorized window includes that restoration and its ownership/state still match. Otherwise leave it unchanged; another active maintainer window may intentionally keep it at 1. Never reset all gates as generic cleanup.

Important gates:

  • CLAWSWEEPER_ALLOW_EXECUTE: allows deterministic write lanes.
  • CLAWSWEEPER_ALLOW_FIX_PR: allows branch repair/replacement PRs.
  • CLAWSWEEPER_ALLOW_MERGE: allows merge-capable applicators.
  • CLAWSWEEPER_ALLOW_AUTOMERGE: allows comment-router automerge.
  • CLAWSWEEPER_COMMENT_ROUTER_EXECUTE: lets scheduled comment routing post replies and dispatch repair.

Maintainer Mentions

Prefer @clawsweeper comments for all maintainer-facing control. Slash commands still parse as compatibility aliases, but examples and live guidance should use mentions.

text
@clawsweeper status
@clawsweeper re-review
@clawsweeper review
@clawsweeper fix ci
@clawsweeper address review
@clawsweeper rebase
@clawsweeper autofix
@clawsweeper automerge
@clawsweeper approve
@clawsweeper explain
@clawsweeper stop
@clawsweeper <question or safe action request>
@clawsweeper[bot] re-review
@openclaw-clawsweeper fix ci
@openclaw-clawsweeper[bot] fix ci

Accepted aliases: review, re-review, rereview, review again, rerun review, and run review. review and re-review dispatch a fresh ClawSweeper issue/PR review without starting repair. fix ci, address review, and rebase dispatch the repair worker only for ClawSweeper PRs or PRs opted into clawsweeper:autofix or clawsweeper:automerge. autofix runs the bounded review/fix loop without merging. automerge runs the bounded review/fix/merge loop, but draft PRs stay fix-only until GitHub marks them ready for review.

Freeform maintainer mentions such as @clawsweeper why did automerge stop? or @clawsweeper: can you explain this failure? dispatch a read-only assist review with the mention text as one-off instructions. The answer lands in the next public ClawSweeper review comment. Action-looking prose does not directly mutate GitHub; it must map to existing structured recommendations and pass the normal deterministic gates.

Default accepted maintainers: OWNER, MEMBER, COLLABORATOR; fallback repository permission accepts admin, maintain, or write. Contributor comments are ignored without a reply.

Run router manually:

bash
pnpm run repair:comment-router -- --repo openclaw/openclaw --lookback-minutes 180
pnpm run repair:comment-router -- --repo openclaw/openclaw --execute --wait-for-capacity

Scheduled routing stays dry unless CLAWSWEEPER_COMMENT_ROUTER_EXECUTE=1.

Trusted Autofix And Automerge

@clawsweeper autofix opts an existing PR into the bounded review/fix loop. @clawsweeper automerge opts an existing PR into the bounded review/fix/merge loop. The router:

  • verifies maintainer authorization;
  • labels the PR clawsweeper:autofix or clawsweeper:automerge;
  • dispatches ClawSweeper review for the current head SHA;
  • creates or reuses a durable adopted job;
  • repairs at most the configured caps;
  • never merges autofix PRs or draft PRs;
  • merges automerge PRs only when ClawSweeper passed the exact current head, checks are green, GitHub says mergeable, no human-review label is present, the PR is not draft, and both merge gates are open.

Missing changelog is never a review finding or merge blocker. CHANGELOG.md is release-only; record user-facing release-note context in the PR body or squash message, never edit the changelog for normal repairs.

If ClawSweeper passes while merge gates are closed, it labels clawsweeper:merge-ready and comments instead of merging. @clawsweeper stop adds clawsweeper:human-review.

When asked to create a PR and enable ClawSweeper automerge, do not leave the local OpenClaw checkout on the PR branch. After the PR is created, pushed, and the @clawsweeper automerge request is posted or otherwise confirmed, return the local checkout to main and fast-forward it when the working tree is clean:

bash
git switch main
git pull --ff-only

If unrelated local edits or an in-progress rebase prevent switching, report the blocker instead of stashing, deleting, or overwriting work.

Repair caps:

bash
CLAWSWEEPER_MAX_REPAIRS_PER_PR=10
CLAWSWEEPER_MAX_REPAIRS_PER_HEAD=1

Security Boundary

Do not stage unapproved security-sensitive work for ClawSweeper Repair. Route vulnerability reports, CVE/GHSA/advisory work, leaked secrets/tokens/keys, plaintext secret storage, SSRF, XSS, CSRF, RCE, auth bypass, privilege escalation, and sensitive data exposure to central OpenClaw security handling.

For PRs explicitly opted into clawsweeper:autofix or clawsweeper:automerge, security-sensitive review findings may dispatch bounded repair, but merge remains blocked until a later exact-head review is clean and the normal merge gates pass. Trust deterministic ClawSweeper security markers, labels, and job frontmatter; do not infer security handling from vague prose.

Monitoring

Receiver workflows:

bash
gh run list --repo openclaw/clawsweeper --workflow sweep.yml \
  --limit 12 --json databaseId,displayTitle,event,status,conclusion,createdAt,updatedAt,url
gh run list --repo openclaw/clawsweeper --workflow repair-cluster-worker.yml \
  --limit 12 --json databaseId,displayTitle,event,status,conclusion,createdAt,updatedAt,url
gh run list --repo openclaw/clawsweeper --workflow repair-comment-router.yml \
  --limit 12 --json databaseId,displayTitle,event,status,conclusion,createdAt,updatedAt,url
gh run list --repo openclaw/clawsweeper --workflow github-activity.yml \
  --limit 12 --json databaseId,displayTitle,event,status,conclusion,createdAt,updatedAt,url

Target dispatcher:

bash
gh run list --repo openclaw/openclaw --workflow "ClawSweeper Dispatch" \
  --limit 8 --json databaseId,displayTitle,event,status,conclusion,headSha,url

Reading Output

For findings or failures, summarize:

  • target repo, item/PR, run, report path
  • result, confidence, severity, and exact blocker
  • affected files or cluster refs
  • validation commands and whether they passed
  • whether mutation gates were open or closed
  • next deterministic action

Keep the broom small: one cluster, one branch, one PR, narrow proof, clear owner-visible evidence.

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Clawsweeper AI skill do?

Use for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed autofix/automerge, GitHub Actions monitoring, permissions, gates, and manual backfills.

Why use Clawsweeper on TypingMind?

Because you install it once and use it with any model. Clawsweeper is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Clawsweeper in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/openclaw/openclaw/tree/main/.agents/skills/clawsweeper. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Clawsweeper?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Clawsweeper?

As many as you like. As long as a model supports skills, you can use Clawsweeper with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Clawsweeper AI skill free?

It is published on GitHub by openclaw. Check the repository for licensing terms. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇