Agent Passport is a comprehensive security framework providing OAuth-style consent-gating, behavioral contracts, and threat-shielding for autonomous AI agents.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install agent-passport
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install agent-passport using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Agent Passport serves as the essential security firewall for the agentic era, introducing a sophisticated consent layer between AI agents and sensitive system resources. By implementing this within your Openclaw Skills environment, you transition from risky, all-access permissions to granular, time-bound mandates. This ensures that every action—whether it involves shell execution, financial transactions, or communication—is governed by a strict behavioral contract.
The skill incorporates advanced protection mechanisms, including an Injection Shield, SSRF Shield, and Path Traversal Guard. With over 75 data-driven threat definitions, Agent Passport provides the governance necessary for scaling agent autonomy safely. It allows users to define exactly what an agent can do, for how long, and under what specific constraints, providing an immutable audit trail for complete accountability.
To deploy Agent Passport in your Openclaw Skills setup, run the following initialization commands:
# Initialize the ledger and register your primary agent
./mandate-ledger.sh init agent:my-assistant "Your Name" "personal assistant" "openclaw"
# Apply a standard development tools template
./mandate-ledger.sh create-from-template dev-tools
# Initialize the threat signature database
./mandate-ledger.sh init-definitions
Ensure the AGENT_PASSPORT_LEDGER_DIR environment variable is defined in your environment configuration.
Agent Passport maintains a structured local database within ~/.openclaw/agent-passport/ to manage security states:
| File | Purpose |
|---|---|
mandates.json |
Stores active permission scopes, TTLs, and usage limits. |
agents.json |
Contains the Know Your Agent (KYA) registry and agent metadata. |
audit.json |
A chronological log of all authorized and unauthorized agent attempts. |
threat-definitions.json |
A library of security patterns used to identify and block malicious activities. |
.threat-meta.json |
Metadata regarding definition versions and update history. |
Loading
A structured memory management system that distills complex troubleshooting and development experiences into a permanent knowledge base for AI agents.

A standardized workflow for synchronizing agent behavior, routing rules, and long-term preferences across multiple markdown-based configuration files.

A governance and optimization utility designed to maintain high-performance memory structures and reduce token bloat in AI agents.

A decentralized social network and economy where AI agents earn XP and passive income by collaborating on YouTube channel growth.

A Mixture of Agents workflow that simulates a rigorous Oxford Union-style formal debate to stress-test arguments and explore complex topics.

An AI-driven YouTube content strategist that transforms any topic into high-performing video scripts, SEO-optimized metadata, and visual concepts.








































