Mmcp.market

init-first-agent skill

by nanocoai·nanocoai/nanoclaw·31k stars·MIT

Walk the operator through wiring the first NanoClaw agent to a DM channel — resolve the operator's channel identity, select or create the agent, and trigger a welcome DM via the normal delivery path. Use after channel credentials are configured and the service is running.

A100/100content scan

Is the init-first-agent skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the init-first-agent skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/nanocoai/nanoclaw.git /tmp/nanoclaw
mkdir -p ~/.claude/skills
cp -r /tmp/nanoclaw/.claude/skills/init-first-agent ~/.claude/skills/init-first-agent
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Init First Agent

Wire the first NanoClaw agent to a channel and verify end-to-end delivery by having the agent DM the operator. Everything the skill does is idempotent — rerunning is safe.

Prerequisites

  • Service running. Check: launchctl list | grep "$(. setup/lib/install-slug.sh && launchdlabel)" (macOS) or systemctl --user status "$(. setup/lib/install-slug.sh && systemdunit)" (Linux). If stopped, tell the user to run /setup first.
  • Target channel installed. At least one /add- skill has run, credentials are in .env, and the adapter is uncommented in src/channels/index.ts.
  • Adapter connected. Tail logs/nanoclaw.log — look for a recent channel setup / adapter connected line for the target channel.

1. Pick the channel

Read src/channels/index.ts to find enabled channels (uncommented imports). Cross-check .env for the relevant credentials.

AskUserQuestion: "Which channel should host the welcome DM?" with one option per enabled channel (Discord, Slack, Telegram, WhatsApp, Webex, Teams, Google Chat, Matrix, iMessage, Resend, …).

Record the choice as CHANNEL (lowercase, e.g. discord).

2. Ask for the operator's identity

Read the channel's own skill for its ## Channel Info > how-to-find-id section (e.g. .claude/skills/add-discord/SKILL.md, .claude/skills/add-telegram/SKILL.md). Show those instructions to the user in plain text.

Then ask in plain text (NOT AskUserQuestion — these are free-form):

  1. Your user id on this channel — e.g. a Discord user ID, Telegram user ID, Slack user ID. Record as USER_HANDLE.
  2. Your display name — human name, used to name the agent group (dm-with-) and as the welcome-message addressee. Record as DISPLAY_NAME.
  3. Agent persona name — the assistant's display name. Default: DISPLAYNAME. Record as AGENTNAME.

3. Resolve the DM platform id

This depends on whether the channel supports cold DM via adapter.openDM.

Channels without cold DM (direct-addressable): telegram, whatsapp, imessage, matrix, resend. The user handle doubles as the DM chat id. Set:

PLATFORM_ID=${CHANNEL}:${USER_HANDLE}

Skip to step 4.

Channels with cold DM (resolution-required): discord, slack, teams, webex, gchat. The bot can DM cold at runtime via Chat SDK, but this skill runs standalone — it can't call the adapter. Two resolutions:

3a. User DMs the bot once (Discord / Slack / Teams / Webex / gChat)

Tell the user:

Send any single message to the bot as a DM from your account on ${CHANNEL}. The router will record the DM as a messaging group. Reply done here when you've sent the message.

Wait for the user's confirmation. Then look up the most recent DM messaging groups:

pnpm exec tsx scripts/q.ts data/v2.db "SELECT id, platform_id, name, created_at FROM messaging_groups WHERE channel_type='${CHANNEL}' AND is_group=0 ORDER BY created_at DESC LIMIT 5"

Show the top rows to the user and confirm which platformid is theirs (usually the most recent). Record as PLATFORMID. If none appeared, check logs/nanoclaw.log for unknown_sender drops — the adapter might be rejecting inbound due to connection or permission issues.

3b. Telegram pair-code path (if the user prefers not to DM first)

For Telegram only, there's an existing pair-code primitive. When you run this tool, take the output and extract the pairing code. Then show it to the user in plain text and ask the user to send the code in the Telegram chat to complete the pairing.

npx tsx setup/index.ts --step pair-telegram -- --intent new-agent:dm-with-<folder>

Parse the PAIRTELEGRAMISSUED status block for CODE and follow the REMINDERTOASSISTANT line in that block. Then wait for the PAIRTELEGRAM block — read PLATFORMID and PAIREDUSERID from it. telegram.ts's interceptor has already upserted the user and granted owner if none existed yet. Use PLATFORMID and PAIREDUSER_ID directly in step 5.

4. Pick the agent group

List the existing agent groups and their wirings through the admin CLI:

ncl groups list --json
ncl wirings list --json

If setup already installed a template, it appears in the groups result even when it has no wiring. Show the user each group's name, folder, and id, and note which groups already appear as agentgroupid values in the wirings result.

  • If no group exists, continue without AGENTGROUPID; the init script will create one.
  • If groups exist, ask whether to wire one of them or create a new agent. Recommend the sole unwired group when there is exactly one.
  • When the user picks an existing group, record its exact id as AGENTGROUPID. Do not infer it from the display name or folder.

5. Run the init script

When creating a new agent, first pick the provider. Read src/providers/index.ts and collect the installed providers from its import './.js'; lines — claude is always available as the built-in default. If a non-default provider is installed (e.g. codex), ask the user which one this agent should run on; if only claude is available, skip the question. An existing group keeps the provider and template configuration it already has.

npx tsx scripts/init-first-agent.ts \
  --channel "${CHANNEL}" \
  --user-id "${CHANNEL}:${USER_HANDLE}" \
  --platform-id "${PLATFORM_ID}" \
  --display-name "${DISPLAY_NAME}" \
  --agent-name "${AGENT_NAME}"

When an existing group was selected, append its exact id:

--agent-group-id "${AGENT_GROUP_ID}"

When the channel runs a named adapter instance (e.g. a second Telegram bot registered as telegram-mega), append --instance "${INSTANCE}" with the registry key (never the short name) so the DM row, the wiring and the welcome all target that bot; omitted = the channel's default instance.

The new group is created on the instance default provider (DEFAULTAGENTPROVIDER in .env, or claude when unset). To put it on a different provider, switch after creation with ncl groups config update --id --provider . Add --welcome "System instruction: ..." to override the default welcome prompt.

The script:

  1. Upserts the users row and grants owner role if no owner exists.
  2. Uses the selected agent_groups row, or creates one and calls initGroupFilesystem at groups/dm-with-/.
  3. Reuses or creates the DM messaging_groups row.
  4. Wires them via messaginggroupagents (which auto-creates the companion agent_destinations row).
  5. Hands the welcome message to the running service via its CLI socket (data/cli.sock), targeting the DM messaging group. The service routes it into the DM session, which wakes the container synchronously. If the socket isn't reachable (service down), falls back to a direct inbound.db write that the next host sweep picks up.

Show the script's output to the user.

6. Verify

The welcome DM is queued synchronously; the only wait is container cold-start (~60s on first launch) before the agent processes the message and the reply flows through outbound.db to the channel.

Do not tail the log or poll in a sleep loop. Ask the user in plain text:

The welcome DM should arrive shortly. Let me know when you've received it (or if it doesn't arrive within two minutes).

Wait for the user's reply. If they confirm receipt, the skill is done.

If they say it didn't arrive, then diagnose using the DB directly (no waiting loops required — the message either delivered or it didn't):

  • pnpm exec tsx scripts/q.ts data/v2-sessions///outbound.db "SELECT id, status, createdat FROM messagesout ORDER BY created_at DESC LIMIT 5" — check for stuck pending rows. Replace and with the values from the script's output.
  • grep -E 'Unauthorized channel destination|container.*exited|error' logs/nanoclaw.log | tail -20 — look for ACL rejections or container crashes.
  • ls data/v2-sessions//*/outbound.db — confirm the session exists.

Troubleshooting

"Missing required args" — the script wants --channel, --user-id, --platform-id, --display-name at minimum. Re-check the command you assembled.

No messaginggroups row appears after the user DMs (step 3a) — auto-created rows are stamped with the channel adapter's declared unknownsenderpolicy (two-level model: adapter declaration → per-row override; strict only when the adapter has no declaration). Under strict the router silently drops messages from unknown senders but still creates the messaginggroups row; under request_approval an approval card goes to an admin instead. If the row is missing entirely, the adapter isn't receiving the inbound message. Check logs/nanoclaw.log for adapter errors (auth, gateway disconnect, rate limit).

Owner already exists — hasAnyOwner() returned true, so the grant is skipped silently. That's fine; the script still creates the agent and wiring. Reassigning ownership needs a separate flow (not this skill).

Wrong person got the welcome DM — the --platform-id you passed is someone else's DM channel. Rerun with the correct one; the script is idempotent on user/messaging-group/agent-group but writes a new session welcome each run.

Agent group name collision — use step 4 to select the intended group by id. If creating a new agent and dm-with- already exists, the script reuses it; pass a different --display-name to get a distinct folder.

More skills from nanocoai/nanoclaw

  • Aadd-anydocAdd local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
  • Aadd-atomic-chat-toolAdd Atomic Chat MCP server so the container agent can call local models served by the Atomic Chat desktop app via its OpenAI-compatible API.
  • Fadd-clidashAdd clidash — a zero-dependency, read-only web dashboard that derives its tabs and tables at runtime from any CLI that lists resources as JSON. Ships pre-wired for NanoClaw's ncl CLI (agent groups, sessions, channels, users, roles), plus message-activity charts, a log tail, and a read-only file viewer for group skills/CLAUDE.md/profiles.
  • Aadd-codexUse Codex (OpenAI's codex app-server) as a full agent provider — planning, tool orchestration, MCP tools, server-side history, session resume — alongside or instead of Claude. ChatGPT subscription or OpenAI API key, vault-only via the selected gateway. Per-group via `ncl groups config update --provider codex`. Distinct from using OpenAI as an MCP tool (where Claude remains the planner).
  • Aadd-dashboardAdd a monitoring dashboard to NanoClaw. Installs @nanoco/nanoclaw-dashboard and a pusher that sends periodic JSON snapshots.
  • Aadd-deltachatAdd DeltaChat channel integration via @deltachat/stdio-rpc-server. Native adapter — no Chat SDK bridge. Email-based messaging with end-to-end encryption.
  • Cadd-dialAdd Dial channel integration — a real phone number for SMS and AI voice calls via the Dial platform (getdial.ai). Native adapter — no Chat SDK bridge.
  • Aadd-dial-numberAdd another phone number to an existing Dial channel — a second (or third) public line for the agent, so one NanoClaw install answers SMS and AI voice calls on multiple numbers. Use when Dial is already installed and the operator wants an additional number (e.g. a personal line plus a support line). Requires the Dial channel to already be installed (see /add-dial).
  • Aadd-dial-toolGive chosen NanoClaw agents a real phone number as a container tool — the `dial` CLI baked into the agent image plus OneCLI credential injection for api.getdial.ai, scoped per agent, so the agents you pick can send SMS, place AI voice calls, and receive verification codes from inside the sandbox. Independent of the Dial channel; idempotent; re-run to change which agents may use it. Use when the user wants agents to text, call, or run `dial …` from a chat, without wiring Dial as a messaging channel.
  • Aadd-discordAdd Discord bot channel integration via Chat SDK.
  • Aadd-emacsAdd Emacs as a channel. Opens an interactive chat buffer and org-mode integration so you can talk to NanoClaw from within Emacs (Doom, Spacemacs, or vanilla). Local HTTP bridge — no bot token or external service needed.
  • Aadd-gchatAdd Google Chat channel integration via Chat SDK.

All agent skills → · MCP servers