CustomizeCAUTION
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
Overview
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
b336cb34f655OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| codex | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: customize description: Add new capabilities or modify NanoClaw behavior. Use when user wants to add channels (Telegram, Slack, email input), change triggers, add integrations, modify the router, or make any other customizations. This is an interactive skill that asks questions to understand what the user wants. --- # NanoClaw Customization This skill helps users add capabilities or modify behavior. Use AskUserQuestion to understand what they want before making changes. ## Workflow 1. **Understand the request** — Ask clarifying questions. 2. **Prefer a dedicated skill** — If a skill covers the request, invoke it instead of editing core by hand: - Channels: `/add-telegram`, `/add-slack`, `/add-discord`, `/add-whatsapp`, `/add-signal`, `/add-imessage`, and the rest of the `/add-<channel>` family. - Wiring channels to agents and isolation levels: `/manage-channels`. - Container directory access: `/manage-mounts`. - Agent providers (non-default): `/add-opencode`, `/add-codex`, `/add-ollama-provider`. - MCP tools: `/add-ollama-tool`, `/add-atomic-chat-tool`. 3. **Plan the changes** — Identify the v2 surface the change belongs to (entity model in the central DB, per-agent-group container config, per-group `CLAUDE.md`, or core code). 4. **Implement** — Make the change on the right surface. 5. **Test guidance** — Tell the user how to verify. ## Entity Model Customizations route through the v2 entity model: users → messaging groups → agent groups → sessions. A messaging group is one chat/channel on one platform; an agent group holds the workspace, personality, and container config; a wiring links a messaging group to an agent group with a session mode and trigger rules. Inspect and edit all of this with the `ncl` admin CLI. See `docs/isolation-model.md` for the three isolation levels. ## Key Files | File | Purpose | |------|---------| | `src/index.ts` | Entry point: init DB, migrations, channel adapters, delivery polls, sweep, shutdown | | `src/router.ts` | Inbound routing: messaging group → agent group → session → `inbound.db` → wake | | `src/delivery.ts` | Polls `outbound.db`, delivers via adapter, handles system actions | | `src/session-manager.ts` | Resolves sessions; opens `inbound.db` / `outbound.db`; heartbeat path | | `src/container-runner.ts` | Spawns per-agent-group containers with session DB + outbox mounts, OneCLI `ensureAgent` | | `src/channels/` | Channel adapter infra (registry, Chat SDK bridge); specific adapters install from the `channels` branch | | `src/config.ts` | Process-level config (assistant name, paths, timeouts) read from `.env` | | `data/v2.db` | Central DB: users, roles, agent_groups, messaging_groups, wirings, container_configs | | `data/v2-sessions/<session>/` | Per-session `inbound.db` (host→container) + `outbound.db` (container→host) | | `groups/<folder>/CLAUDE.md` | Per-agent-group memory/persona and instructions | For ad-hoc DB queries, use `pnpm exec tsx scripts/q.ts <db> "<sql>"`. ## Common Customization Patterns ### Adding a New Input Channel (e.g., Telegram, Slack, Email) Questions to ask: - Which channel? (Telegram, Slack, Discord, WhatsApp, Signal, email, etc.) - Should this channel reach an existing agent group or a new one? - What isolation level — share an agent group with other channels, or keep it separate? - Same trigger rules as other channels on that agent group, or different? Implementation: 1. Run the matching install skill (`/add-telegram`, `/add-slack`, ...). It fetches the adapter from the `channels` branch, wires the registration import, installs the pinned package, and builds. 2. Run `/manage-channels` (or use `ncl messaging-groups` + `ncl wirings`) to create the messaging group, choose the isolation level, and wire it to an agent group with a session mode and trigger rules. ### Adding a New MCP Integration Questions to ask: - What service? (Calendar, Notion, database, etc.) - What operations are needed? (read, write, both) - Which agent group should have access? Implementation: - If a dedicated `/add-<service>-tool` skill exists, run it — it wires the MCP server and routes credentials through OneCLI so no raw keys reach the container. - Otherwise wire the MCP server into the agent group's container config with either `--command <cmd> [--args <json-array>] [--env <json-object>]` for stdio or `--url <url>` for Streamable HTTP (HTTPS, or plain HTTP for localhost / host.docker.internal): `ncl groups config add-mcp-server --id <group-id> --name <name> ...`. Then run `ncl groups restart --id <group-id>` to take effect. From inside a container the agent uses the `add_mcp_server` self-mod tool, which requires one admin approval. ### Changing Assistant Behavior Questions to ask: - What aspect? (persona, response style, instructions) - Apply to one agent group or several? Implementation: - Persona, instructions, and personality live per agent group in `groups/<folder>/CLAUDE.md` — edit that file for the target group. - Container runtime behavior (provider, model, packages, MCP servers) lives in the `container_configs` table: `ncl groups config get/update --id <group-id>`. ### Adding New Commands Questions to ask: - What should the command do? - Which agent group(s)? - Does it need new MCP tools? Implementation: - The agent interprets requests naturally — add instructions to the agent group's `groups/<folder>/CLAUDE.md`. - For routing or trigger changes (which messages wake which agent group), update the wiring's trigger rules: `ncl wirings update --id <wiring-id> ...`. ### Changing Deployment Questions to ask: - Target platform? (Linux server, different Mac) - Service manager? (launchd, systemd) Implementation: 1. Create the appropriate service files. 2. Update paths in `.env` / config. 3. Provide setup instructions. ## After Changes Always tell the user. Run from your NanoClaw project root: ```bash # Rebuild and restart pnpm run build source setup/lib/install-slug.sh # macOS: launchctl unload ~/Li
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
| `src/config.ts` | Process-level config (assistant name, paths, timeouts) read from `.env` |
.agents/skills
AGENTS.md
Gates applied: no_behavioural_pass.
b336cb34f655full audit observations/trust-audit/skill/gavrielc__customize.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b336cb34f655 | CAUTION | B | 89 | first audit |
Questions
What does the Customize skill do?
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
Is Customize safe to install?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Customize access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
What do I need installed to use Customize?
Its own instructions reference channels. Dependencies are pinned to exact versions.
Which assistants does Customize work with?
Its documentation mentions codex. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (b336cb34f655), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.