update-nanoclaw skill
Transactionally update a customized NanoClaw checkout from official upstream without exposing live mounted source, with fork-safe skill refresh, mutable-state snapshots, migration gates, exact-code upgrade markers, detected service restart, health verification, and automatic local rollback. Use for routine merge, rebase, or selective upstream updates.
Is the update-nanoclaw skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the update-nanoclaw skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/nanocoai/nanoclaw.git /tmp/nanoclaw mkdir -p ~/.claude/skills cp -r /tmp/nanoclaw/.claude/skills/update-nanoclaw ~/.claude/skills/update-nanoclaw
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Update NanoClaw
Update a customized install through an isolated, resumable transaction. The live checkout is not touched until the staged result has passed validation.
Use ordinary conversation for decisions and confirmations. Do not depend on Claude Code, Codex, OpenCode, or any provider-specific question/skill tool.
Safety contract
tests in a separate worktree.
- Require a clean live checkout.
- Stage Git integration, dependency installation, installed-skill refresh, and
changing source mounted into agent containers.
- Resolve registry branches from the remote that actually carries them.
- Stop the detected service and drain this install's active containers before
cutover. Sockets and other ephemeral special files are intentionally omitted.
- Snapshot .env, data/, groups/, store/, and manual-service state before
mode; require process state, data/ncl.sock, and bin/ncl groups list.
- Gate every breaking migration and external version-pin move.
- Stamp the exact Git commit/tree only after all required work succeeds.
- Restart through the detected launchd, user-systemd, system-systemd, or nohup
process explicitly, update offline, then start it again manually.
- Refuse cutover while an unmanaged pnpm dev/Node host is running. Stop that
the previous image, restart the previous service, and health-check it.
- On build or health failure, restore Git and the mutable-state snapshot, rebuild
1. Load the newest controller without changing the live tree
Confirm the live tree is clean:
git status --porcelainStop if it prints anything.
Use the official remote if one already exists. Otherwise add it as upstream:
if git remote get-url upstream >/dev/null 2>&1; then
upstream_remote=upstream
elif git remote get-url origin 2>/dev/null | grep -Eq '(^|[:/])nanocoai/nanoclaw(.git)?$'; then
upstream_remote=origin
else
git remote add upstream https://github.com/nanocoai/nanoclaw.git
upstream_remote=upstream
fi
git fetch "$upstream_remote" --pruneSelect main when present, otherwise master:
if git show-ref --verify --quiet "refs/remotes/$upstream_remote/main"; then
upstream_ref="$upstream_remote/main"
elif git show-ref --verify --quiet "refs/remotes/$upstream_remote/master"; then
upstream_ref="$upstream_remote/master"
else
echo "Official remote has neither main nor master" >&2
exit 1
fiMaterialize the newest controller from that ref. This is the self-update seam: an older local skill still executes the newest safety code before any mutation.
# pwd -P: on macOS mktemp returns a path through the /var symlink, and a
# symlinked argv defeats Node's import.meta main-module guard — the controller
# then exits 0 having done NOTHING. Canonicalize before use.
controller_dir="$(cd "$(mktemp -d)" && pwd -P)"
# Extract all of scripts/, not a hand-listed subset. These paths are a
# contract: older copies of this skill extract exactly them from the newest
# ref, so the controller must load from them alone, with no node_modules.
# scripts/update/controller-archive.test.ts enforces it.
git archive "$upstream_ref" scripts src/install-slug.ts | tar -x -C "$controller_dir"2. Choose the Git strategy and prepare
Default to merge. Use rebase only when the user explicitly wants linear history. Use cherry-pick only with an explicit comma-separated commit list.
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" prepare \
--project-root "$PWD" --upstream-ref "$upstream_ref" --strategy mergeThe JSON result is nanoclaw-update/v1. Record its id, stageRoot, backup branch/tag, changed files, and requirements. The live HEAD is still unchanged.
If phase is conflict, resolve conflicts only inside stageRoot, preserving intentional local customizations. Complete the merge/rebase/cherry-pick there, commit it, then run:
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" resume \
--project-root "$PWD" --id "$id"Run every transaction command from $controllerdir, not from stageRoot: a cherry-pick stage can still hold the old controller. If $controllerdir is gone (a reboot clears temp directories), recreate it with the step 1 commands without fetching again.
Show the user the upstream commits, changed-file buckets, requirements, and any resolved conflicts. To stop with no live mutation:
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" abandon \
--project-root "$PWD" --id "$id"3. Validate the staged result
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" validate \
--project-root "$PWD" --id "$id"Validation performs a fork-safe structured refresh of every installed channel and provider, commits refreshed payloads in the staging branch, installs frozen dependencies, runs the host build and full host tests, and runs the container dependency/typecheck leg when Bun is available. A provider skill that declares Bun dependencies does not require Bun on the host: refresh runs the exact Bun version pinned by container/Dockerfile through pnpm. Any selected skill refresh or validation failure blocks cutover and the completion stamp.
Fix only failures caused by the staged update, inside stageRoot, commit the fix, and re-run validation. Do not mutate the live checkout to repair staging.
4. Confirm and cut over
Before downtime, show the exact changed files, required migrations, detected backup tag, and rollback command. Ask for one confirmation to begin cutover.
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" cutover \
--project-root "$PWD" --id "$id"Cutover stops the detected service, then stops this install's labeled agent containers (an agent mid-turn loses that turn; wait for a quiet moment if that matters), snapshots mutable state, resets the live branch to the validated target, installs frozen dependencies, builds the host, and updates the agent image when container/ changed. Hardened-image installs use pull; local-image installs build locally. The service remains stopped while required migrations are pending.
5. Complete every requirement
Process requirements one at a time.
its detect, fix, verify, and rollback sections.
- For a referenced local guide, read it from the cut-over checkout and follow
it directly. Do not require a harness-specific skill invocation feature.
- For a referenced /, read that skill's current SKILL.md and follow
version or rollback command because OneCLI is outside the Git snapshot.
- For OneCLI pin moves, follow docs/onecli-upgrades.md; record the exact old
If a migration intentionally changes tracked files, review and commit those changes before acknowledging it. Finish refuses a dirty cut-over checkout.
After verification, acknowledge the requirement:
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" ack \
--project-root "$PWD" --id "$id" \
--requirement "$requirement_id" --status succeededFor an external component, also pass a concise exact rollback instruction:
... ack ... --rollback "restore onecli-gateway to <old-version>"Use --status failed when verification fails. A pending or failed requirement blocks finish; never offer “restart anyway.” The state snapshot is the recovery path for forward local migrations.
6. Finish and health-check
pnpm exec tsx "$controller_dir/scripts/update-nanoclaw.ts" finish \
--project-root "$PWD" --id "$id"Finish stamps the exact version/commit/tree, restarts the service mode detected before cutover, and waits for the process, CLI socket, and a real CLI request. Only phase: complete is success.
More skills from nanocoai/nanoclaw
- Aadd-anydocAdd local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
- Aadd-atomic-chat-toolAdd Atomic Chat MCP server so the container agent can call local models served by the Atomic Chat desktop app via its OpenAI-compatible API.
- Fadd-clidashAdd clidash — a zero-dependency, read-only web dashboard that derives its tabs and tables at runtime from any CLI that lists resources as JSON. Ships pre-wired for NanoClaw's ncl CLI (agent groups, sessions, channels, users, roles), plus message-activity charts, a log tail, and a read-only file viewer for group skills/CLAUDE.md/profiles.
- Aadd-codexUse Codex (OpenAI's codex app-server) as a full agent provider — planning, tool orchestration, MCP tools, server-side history, session resume — alongside or instead of Claude. ChatGPT subscription or OpenAI API key, vault-only via the selected gateway. Per-group via `ncl groups config update --provider codex`. Distinct from using OpenAI as an MCP tool (where Claude remains the planner).
- Aadd-dashboardAdd a monitoring dashboard to NanoClaw. Installs @nanoco/nanoclaw-dashboard and a pusher that sends periodic JSON snapshots.
- Aadd-deltachatAdd DeltaChat channel integration via @deltachat/stdio-rpc-server. Native adapter — no Chat SDK bridge. Email-based messaging with end-to-end encryption.
- Cadd-dialAdd Dial channel integration — a real phone number for SMS and AI voice calls via the Dial platform (getdial.ai). Native adapter — no Chat SDK bridge.
- Aadd-dial-numberAdd another phone number to an existing Dial channel — a second (or third) public line for the agent, so one NanoClaw install answers SMS and AI voice calls on multiple numbers. Use when Dial is already installed and the operator wants an additional number (e.g. a personal line plus a support line). Requires the Dial channel to already be installed (see /add-dial).
- Aadd-dial-toolGive chosen NanoClaw agents a real phone number as a container tool — the `dial` CLI baked into the agent image plus OneCLI credential injection for api.getdial.ai, scoped per agent, so the agents you pick can send SMS, place AI voice calls, and receive verification codes from inside the sandbox. Independent of the Dial channel; idempotent; re-run to change which agents may use it. Use when the user wants agents to text, call, or run `dial …` from a chat, without wiring Dial as a messaging channel.
- Aadd-discordAdd Discord bot channel integration via Chat SDK.
- Aadd-emacsAdd Emacs as a channel. Opens an interactive chat buffer and org-mode integration so you can talk to NanoClaw from within Emacs (Doom, Spacemacs, or vanilla). Local HTTP bridge — no bot token or external service needed.
- Aadd-gchatAdd Google Chat channel integration via Chat SDK.