Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
96 lines
2.9 KiB
Markdown
96 lines
2.9 KiB
Markdown
---
|
|
summary: "How ClawHub publishing works for skills, plugins, owners, scopes, releases, and review."
|
|
read_when:
|
|
- Publishing a skill or plugin
|
|
- Debugging owner or package scope errors
|
|
- Adding publish UI, CLI, or backend behavior
|
|
---
|
|
|
|
# Publishing on ClawHub
|
|
|
|
ClawHub publishing is owner-scoped: every publish targets a publisher, and the
|
|
server decides whether the signed-in user can publish there.
|
|
|
|
## Owners
|
|
|
|
An owner is a ClawHub publisher handle, such as `@alice` or `@openclaw`.
|
|
Every user gets a personal owner; org owners can have multiple members with
|
|
`owner`, `admin`, or `publisher` roles.
|
|
|
|
When you publish, you use your personal owner or an org owner where you have
|
|
publisher access.
|
|
|
|
## Skills
|
|
|
|
Skills publish from a skill folder (`clawhub skill publish <path>`). The
|
|
public page is:
|
|
|
|
```text
|
|
https://clawhub.ai/<owner>/<slug>
|
|
```
|
|
|
|
Example:
|
|
|
|
```text
|
|
https://clawhub.ai/alice/review-helper
|
|
```
|
|
|
|
The publish request includes the selected owner, slug, version, changelog, and
|
|
files. The server verifies the actor can publish as that owner before creating
|
|
the release.
|
|
|
|
## Plugins
|
|
|
|
Plugins use npm-style package names (`clawhub package publish <source>`).
|
|
Scoped names include the owner in the first path segment:
|
|
|
|
```text
|
|
@owner/package-name
|
|
```
|
|
|
|
The scope must match the selected publish owner. A package named
|
|
`@openclaw/dronzer` can only be published as `@openclaw`. To publish as
|
|
`@vintageayu`, rename the package to `@vintageayu/dronzer`.
|
|
|
|
This stops a package from claiming an org namespace the publisher does not
|
|
control.
|
|
|
|
## Release flow
|
|
|
|
1. The UI, CLI, or GitHub workflow gathers package metadata and files.
|
|
2. The publish request goes to ClawHub with the selected owner.
|
|
3. The server validates owner permissions, package scope, package name,
|
|
version, file limits, and source metadata. Validation failure means no
|
|
release is created.
|
|
4. ClawHub stores the release and starts automated security checks.
|
|
5. The release stays hidden from normal install/download surfaces until
|
|
review and verification finish.
|
|
|
|
## FAQ
|
|
|
|
### Package scope must match selected owner
|
|
|
|
If the package scope and selected owner do not match, ClawHub rejects the
|
|
publish:
|
|
|
|
```text
|
|
Package scope "@openclaw" must match selected owner "@vintageayu".
|
|
Publish as "@openclaw" or rename this package to "@vintageayu/dronzer".
|
|
```
|
|
|
|
Fix it by either publishing as the owner named in the scope, or renaming the
|
|
package so its scope matches the owner you can publish as.
|
|
|
|
If the package already has the right scope but the wrong publisher owns it,
|
|
transfer it instead:
|
|
|
|
```sh
|
|
clawhub package transfer @opik/opik-openclaw --to opik
|
|
```
|
|
|
|
Package transfer needs admin access to both the current owner and the
|
|
destination publisher; it does not let you publish into a scope you do not
|
|
control. This is the same namespace protection: a package named
|
|
`@openclaw/dronzer` claims the `@openclaw` namespace, so only publishers with
|
|
access to `@openclaw` can publish or transfer into it.
|