A highly secure, read-only SQL query and data analysis capability for shell-capable AI agents connecting to AnalyticDB PostgreSQL databases via psql.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install alibabacloud-analyticdb-postgresql-query
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install alibabacloud-analyticdb-postgresql-query using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Alibaba Cloud AnalyticDB PostgreSQL Query Skill is a highly secure, enterprise-grade integration designed for shell-capable AI agents. It enables agents to connect to an AnalyticDB PostgreSQL (ADBPG) database instance via psql, generate compliant read-only queries from natural language, and export structured datasets to CSV format. As a core tool among Openclaw Skills, this capability bridges the gap between deep AI reasoning and structured operational databases.\n\nSecurity is prioritized at every step of execution. By implementing strict pre-query gates, read-only safeguards, resource constraints, and human-in-the-loop (HITL) approval gates, this skill mitigates the risk of destructive actions, resource exhaustion, or data leakage. It serves as an essential runtime capability for organizations that use Openclaw Skills to expose analytical data to AI workflows safely.
First, verify that your runtime environment has the psql client binary installed as required by Openclaw Skills database clients:\n\nbash\npsql --version\n\n\nNext, export the necessary credentials to your runtime environment variables. Never expose database passwords in the agent's prompt history. We recommend configuring these variables via a system env file or secure environment injector:\n\nbash\nexport PGHOST="your-adbpg-instance-endpoint.gpdb.rds.aliyuncs.com"\nexport PGPORT=5432\nexport PGDATABASE="analytics_db"\nexport PGUSER="readonly_agent_user"\nexport PGPASSWORD="your_secure_password_here"\n\n\nAlternatively, configure service connection profiles inside ~/.pg_service.conf to avoid exposing structural parameters inside individual agent contexts.
This skill depends heavily on a structured semantic model layer to validate context and map queries. It uses a custom database schema designated as _agent_meta to verify accessibility limits:\n\n| Table / Metadata Object | Purpose | Requirement Status |\n| :--- | :--- | :--- |\n| _agent_meta.tables | Stores permitted tables and schema properties. | Required (Query fails if missing) |\n| _agent_meta.metric_meta | Houses predefined business metrics (sql_expressions and dimensions). | Optional (Enhances accuracy) |\n| _agent_meta.filters | Map standard business rules and filter scopes (where, measure, etc.). | Optional (Enhances filtering) |\n\nAll file exports generated by the agent are formatted as CSV files and named dynamically with distinct timestamp structures (e.g., export_adbpg_YYYYMMDD_HHMMSS.csv) for traceability.
.pgpass, .pgenv, or parse environment variables containing password text.\n- Granular Semantic Layer Enforcement: Features a hard-stop gate that blocks database queries completely if target tables are not documented in the _agent_meta.tables validation schema.\n- Dynamic Resource Control and Resource Groups: Inspects and warns if the target user is not isolated into a dedicated database Resource Group, safeguarding transactional server performance during analytical queries.\n- Strict Error Halting: Follows a strict 'no act first, ask later' protocol. When configuration anomalies or security warnings arise, the agent immediately terminates processing and requests human feedback, maintaining high trust standards across Openclaw Skills integrations.Loading
A Python-based CLI tool to aggregate LLM execution logs, distinguish internal/external users, and compute detailed multi-dimensional costs.

A high-performance real-time search tool for fetching articles, videos, and media from the WeChat ecosystem without requiring a personal WeChat account.

A read-only, keyless CLI-driven AI agent skill providing real-time football and basketball scores, sharp betting lines, and de-vigged fair probabilities.

OpenClaw Traffic Guardian is a baseline runtime security monitoring tool that provides opt-in HTTP/HTTPS proxy inspection, egress tracking, and policy review for AI agents.

The JisuAPI Agent skill enables AI assistants to search and execute over 500 rich data services using simple natural language query matching.

An AI agent skill translating the classic late Ming Dynasty philosophy of Hong Yingming into actionable guidance for modern workplace resilience and personal growth.








































