SQLGuard Authorize Before Mutate is an Openclaw Skills safety gate that requires a verified permission receipt before any production SQL write is executed.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install sqlguard-authorize
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install sqlguard-authorize using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
SQLGuard 8 Authorize Before Mutate is a fail-closed control for AI agents that work with real databases. It enforces a simple rule: do not run mutating SQL until a PASS Ed25519 permission receipt has been obtained and verified. This makes Openclaw Skills safer for INSERT, UPDATE, DELETE, DDL, ALTER, TRUNCATE, and DROP operations across production SQL, Postgres MCP, Supabase, and other SQL write paths.
The skill is explicitly not a linter and not a confidence check. It is an authorization workflow that adds a payment-backed verification layer before mutation, with support for multiple paths such as Pilot, Workday, Session, and one-shot Cert flows. Openclaw Skills users can use it to reduce destructive mistakes, enforce operational discipline, and ensure that every write is backed by an approved, verifiable receipt.
ok: true.Detect a mutating SQL action.
Request authorization from SQLGuard.
Obtain a PASS receipt.
Verify the receipt.
Execute only on success.
ok: true; otherwise, do not run the SQL.Fail closed on error.
FAIL, or verification does not pass, fix the SQL or authorization path and retry instead of bypassing the gate.Choose the authorization path that fits your workflow:
Wire the MCP or HTTP integration into your agent or toolchain.
# Example endpoints and flows referenced by the skill
# MCP: sqlguard_pilot / sqlguard_workday / sqlguard_session / sqlguard_cert
# HTTP: POST https://sqlguard.io/v1/gateway/pilot
# HTTP: POST https://sqlguard.io/v1/workday
# HTTP: POST https://sqlguard.io/v1/cert
For Workday HTTP flows, settle the required amount, then request the session certificate and verify it.
# Workday flow outline
# 1) POST /v1/workday
# 2) settle amount 2500000
# 3) POST /v1/session/cert
# 4) POST /v1/verify
Ensure your agent blocks SQL execution until verification succeeds.
# Pseudocode
# if verify.ok != true: halt
# else: execute SQL mutation
Keep the fail-closed rule enabled.
Use the official gateway and MCP references when onboarding production systems.
SQLGuard organizes authorization around receipts, settlement, and verification state rather than around SQL text itself.
| Entity | Purpose | Notes |
|---|---|---|
| Authorization receipt | Proof that a mutating SQL action is allowed | PASS receipt, Ed25519-based, must be verified before execution |
| Verification result | Final gate before mutation | Proceed only when ok: true |
| Payment/settlement record | Tracks the chosen billing path | Pilot, Workday, Session, or Cert |
| Flow type | Selects the authorization mode | sqlguard_pilot, sqlguard_workday, sqlguard_session, sqlguard_cert |
| HTTP/MCP endpoint | Transport for issuing and verifying authorization | Supports gateway, workday, cert, probe, and decide paths |
Loading
Openclaw Skills for WorkBuddy lets you inject, update, and roll back the app skin entirely from the command line.

Openclaw Skills turns an AI agent into a Zetrix wallet that can prove identity, pay for gated resources, and issue verifiable credentials.

Career Toolkit is an Openclaw Skills module suite for career planning, resume generation, and job application optimization from one workflow.

Openclaw Skills helps generate enterprise-grade IT integration solution proposals in polished Word .docx format.

SandBase Openclaw Skills helps you safely connect, configure, and verify the SandBase MCP server in supported AI clients without exposing secrets.

Openclaw Skills for Schedulala automate social post creation, validation, scheduling, publishing, and monitoring across 12 platforms.








































