add-clidash skill
Add clidash — a zero-dependency, read-only web dashboard that derives its tabs and tables at runtime from any CLI that lists resources as JSON. Ships pre-wired for NanoClaw's ncl CLI (agent groups, sessions, channels, users, roles), plus message-activity charts, a log tail, and a read-only file viewer for group skills/CLAUDE.md/profiles.
Is the add-clidash skill safe?
A critical finding: do not install it without reading the flagged line. We read 30 files in the folder on 2026-09-28.
- high
add/tools/clidash/test/docs-server.test.js:93Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.
const res = await fetch(`${base}/api/doc?c=skills&p=${encodeURIComponent('../../../../etc/passwd')}`); - high
add/tools/clidash/test/docs.test.js:100Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.
assert.throws(() => resolveDoc(root, SKILLS, '../../etc/passwd', DENY), /not allowed/i); - high
add/tools/clidash/test/logs.test.js:72Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.
assert.equal((await fetch(`${base}/api/log/${encodeURIComponent('../../etc/passwd')}`)).status, 404); - medium
SKILL.md:123Edits shell startup files, cron or launch agents, so something runs again after the skill is done.
systemctl --user enable --now clidash
Install the add-clidash skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description. Read the findings above first.
git clone --depth 1 https://github.com/nanocoai/nanoclaw.git /tmp/nanoclaw mkdir -p ~/.claude/skills cp -r /tmp/nanoclaw/.claude/skills/add-clidash ~/.claude/skills/add-clidash
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
/add-clidash — CLI-derived read-only dashboard
clidash is a small, read-only web dashboard. You point it at any CLI that can list resources as JSON (NanoClaw's ncl, docker, kubectl, …) and it builds the dashboard at runtime: one tab per resource, a generic table over whatever columns the rows have. A new ncl resource becomes a new tab and a new column becomes a new table column with zero code changes.
It ships pre-wired for NanoClaw's ncl CLI and adds three NanoClaw-aware panels driven entirely by config:
groups + wirings (green <15m / amber <2h / red older).
- Agents overview — status cards joining groups + sessions + messaging
read directly from the session DBs (ncl has no messages resource).
- Activity — per-session inbound/outbound message totals and a daily series,
- Logs — last N lines of allowlisted host log files.
- Files — a read-only viewer for group skills, CLAUDE.md, and profiles.
Why it's safe
clidash is read-only by construction: the server can only execFile the argv templates in its config. {resource} is the sole substitution and is allowlist-validated against the discovered/static resource set before exec — never a shell, no free-form input reaches argv. There is no auth; the network is the auth boundary — it binds 127.0.0.1 by default. Only ever bind a private interface (e.g. a tailnet IP), never a public one.
It's distinct from /add-dashboard (which pushes JSON snapshots to a separate @nanoco/nanoclaw-dashboard npm package): clidash has zero dependencies, no build step, no push pipeline, and no edits to NanoClaw source — it just reads ncl and the session DBs.
Steps
1. Copy the tool into place
clidash is fully self-contained — copy the whole directory in:
tools/ is not a standard NanoClaw directory and cp -R won't create it, so make it first:
mkdir -p tools
cp -R .claude/skills/add-clidash/add/tools/clidash tools/clidashThat is the only file change this skill makes. Nothing in NanoClaw src/ is touched, no dependency is added.
2. Create the config
The example config is pre-wired for NanoClaw with paths relative to the repo root, so it works as-is when you run clidash from tools/clidash/:
cd tools/clidash
cp clidash.config.example.json clidash.config.jsonclidash.config.json is your local config — add it to .gitignore if you don't want to commit install-specific paths:
echo 'tools/clidash/clidash.config.json' >> ../../.gitignoreThe example assumes ncl is built at bin/ncl. If bin/ncl doesn't exist, build it first (pnpm run build) or point clis.ncl.bin at the right path.
3. Test
Tests use a stub CLI — no real ncl or docker needed:
npm testAll tests should pass (Node ≥ 22.5, node:test, zero dependencies).
4. Run and verify
node server.js # serves http://127.0.0.1:4690In another shell, confirm it's live and that ncl discovery worked:
curl -s http://127.0.0.1:4690/api/clis | head -c 400 # CLIs + discovered resources
curl -s http://127.0.0.1:4690/api/r/ncl/groups | head -c 400 # a real resource tableThen open http://127.0.0.1:4690/ in a browser. You should see the Agents overview plus a tab per ncl resource.
5. (Optional) Run as a service
clidash binds 127.0.0.1 by default. To reach it from other devices, bind a private (e.g. tailnet) IP via the BIND env var or bind in config — never a public interface.
# ~/.config/systemd/user/clidash.service (Linux)
[Unit]
Description=clidash read-only CLI dashboard
[Service]
WorkingDirectory=%h/nanoclaw/tools/clidash
ExecStart=/usr/bin/node %h/nanoclaw/tools/clidash/server.js
Environment=BIND=127.0.0.1
Restart=on-failure
[Install]
WantedBy=default.targetsystemctl --user enable --now clidashOn macOS, wrap node server.js (with WorkingDirectory = tools/clidash) in a launchd plist the same way the main NanoClaw service is configured.
Configuration reference
clidash.config.json keys (see tools/clidash/README.md and clidash.config.example.json for the full shape):
Adding a second CLI is config-only — e.g. docker is included as a jsonlines example. View plugins (views/-.js) are the only per-CLI code and are optional.
Troubleshooting
copied clidash.config.example.json to clidash.config.json (step 2), or set CLIDASH_CONFIG=/abs/path.json.
- ENOENT / config not found — run from tools/clidash/ and make sure you
is wrong. Build it (pnpm run build) or fix clis.ncl.bin.
- No ncl resources / discovery empty — bin/ncl isn't built or the path
docker CLI from config if you don't need it.
- docker tab errors — the docker daemon isn't running, or remove the
BIND= (tailnet), never a public interface.
- Can't reach it from another device — it binds 127.0.0.1; set
logs.dir, and docs.root resolve to your NanoClaw root (relative to where you launch node server.js).
- Empty Activity/Logs/Files — check that activity.sessionsRoot,
Removal
See REMOVE.md.
More skills from nanocoai/nanoclaw
- Aadd-anydocAdd local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
- Aadd-atomic-chat-toolAdd Atomic Chat MCP server so the container agent can call local models served by the Atomic Chat desktop app via its OpenAI-compatible API.
- Aadd-codexUse Codex (OpenAI's codex app-server) as a full agent provider — planning, tool orchestration, MCP tools, server-side history, session resume — alongside or instead of Claude. ChatGPT subscription or OpenAI API key, vault-only via the selected gateway. Per-group via `ncl groups config update --provider codex`. Distinct from using OpenAI as an MCP tool (where Claude remains the planner).
- Aadd-dashboardAdd a monitoring dashboard to NanoClaw. Installs @nanoco/nanoclaw-dashboard and a pusher that sends periodic JSON snapshots.
- Aadd-deltachatAdd DeltaChat channel integration via @deltachat/stdio-rpc-server. Native adapter — no Chat SDK bridge. Email-based messaging with end-to-end encryption.
- Cadd-dialAdd Dial channel integration — a real phone number for SMS and AI voice calls via the Dial platform (getdial.ai). Native adapter — no Chat SDK bridge.
- Aadd-dial-numberAdd another phone number to an existing Dial channel — a second (or third) public line for the agent, so one NanoClaw install answers SMS and AI voice calls on multiple numbers. Use when Dial is already installed and the operator wants an additional number (e.g. a personal line plus a support line). Requires the Dial channel to already be installed (see /add-dial).
- Aadd-dial-toolGive chosen NanoClaw agents a real phone number as a container tool — the `dial` CLI baked into the agent image plus OneCLI credential injection for api.getdial.ai, scoped per agent, so the agents you pick can send SMS, place AI voice calls, and receive verification codes from inside the sandbox. Independent of the Dial channel; idempotent; re-run to change which agents may use it. Use when the user wants agents to text, call, or run `dial …` from a chat, without wiring Dial as a messaging channel.
- Aadd-discordAdd Discord bot channel integration via Chat SDK.
- Aadd-emacsAdd Emacs as a channel. Opens an interactive chat buffer and org-mode integration so you can talk to NanoClaw from within Emacs (Doom, Spacemacs, or vanilla). Local HTTP bridge — no bot token or external service needed.
- Aadd-gchatAdd Google Chat channel integration via Chat SDK.
- Aadd-githubAdd GitHub channel integration via Chat SDK. PR and issue comment threads as conversations.