Tools
Agent tool surface for OpenClaw (browser, canvas, nodes, message, cron) replacing legacy `openclaw-*` skills
OpenClaw exposes first-class agent tools for browser, canvas, nodes, and cron.
These replace the old ''openclaw-*'' skills: the tools are typed, no shelling,
and the agent should rely on them directly.
Disabling tools
You can globally allow/deny tools via ''tools.allow'' / ''tools.deny'' in ''openclaw.json''
(deny wins). This prevents disallowed tools from being sent to model providers.
{
tools: { deny: ["browser"] },
}Notes:
- Matching is case-insensitive.
- ''*'' wildcards are supported (''"*"'' means all tools).
- If ''tools.allow'' only references unknown or unloaded plugin tool names, OpenClaw logs a warning and ignores the allowlist so core tools stay available.
Tool profiles (base allowlist)
''tools.profile'' sets a ''base tool allowlist'' before ''tools.allow''/''tools.deny''.
Per-agent override: ''agents.list[].tools.profile''.
Profiles:
- ''minimal'': ''session_status'' only
- ''coding'': ''group:fs'', ''group:runtime'', ''group:sessions'', ''group:memory'', ''image''
- ''messaging'': ''group:messaging'', ''sessions_list'', ''sessions_history'', ''sessions_send'', ''session_status''
- ''full'': no restriction (same as unset)
Example (messaging-only by default, allow Slack + Discord tools too):
{
tools: {
profile: "messaging",
allow: ["slack", "discord"],
},
}Example (coding profile, but deny exec/process everywhere):
{
tools: {
profile: "coding",
deny: ["group:runtime"],
},
}Example (global coding profile, messaging-only support agent):
{
tools: { profile: "coding" },
agents: {
list: [
{
id: "support",
tools: { profile: "messaging", allow: ["slack"] },
},
],
},
}Provider-specific tool policy
Use ''tools.byProvider'' to ''further restrict'' tools for specific providers
(or a single ''provider/model'') without changing your global defaults.
Per-agent override: ''agents.list[].tools.byProvider''.
This is applied after the base tool profile and before allow/deny lists,
so it can only narrow the tool set.
Example (keep global coding profile, but minimal tools for Google Antigravity):
{
tools: {
profile: "coding",
byProvider: {
"google-antigravity": { profile: "minimal" },
},
},
}Example (provider/model-specific allowlist for a flaky endpoint):
{
tools: {
allow: ["group:fs", "group:runtime", "sessions_list"],
byProvider: {
"openai/gpt-5.2": { allow: ["group:fs", "sessions_list"] },
},
},
}Example (agent-specific override for a single provider):
{
agents: {
list: [
{
id: "support",
tools: {
byProvider: {
"google-antigravity": { allow: ["message", "sessions_list"] },
},
},
},
],
},
}Tool groups (shorthands)
Tool policies (global, agent, sandbox) support ''group:*'' entries that expand to multiple tools.
Use these in ''tools.allow'' / ''tools.deny''.
Available groups:
- ''group:runtime'': ''exec'', ''bash'', ''process''
- ''group:fs'': ''read'', ''write'', ''edit'', ''apply_patch''
- ''group:sessions'': ''sessions_list'', ''sessions_history'', ''sessions_send'', ''sessions_spawn'', ''session_status''
- ''group:memory'': ''memory_search'', ''memory_get''
- ''group:web'': ''web_search'', ''web_fetch''
- ''group:ui'': ''browser'', ''canvas''
- ''group:automation'': ''cron'', ''gateway''
- ''group:messaging'': ''message''
- ''group:nodes'': ''nodes''
- ''group:openclaw'': all built-in OpenClaw tools (excludes provider plugins)
Example (allow only file tools + browser):
{
tools: {
allow: ["group:fs", "browser"],
},
}Plugins + tools
Plugins can register additional tools (and CLI commands) beyond the core set.
See ''Plugins'' for install + config, and ''Skills'' for how
tool usage guidance is injected into prompts. Some plugins ship their own skills
alongside tools (for example, the voice-call plugin).
Optional plugin tools:
- ''Lobster'': typed workflow runtime with resumable approvals (requires the Lobster CLI on the gateway host).
- ''LLM Task'': JSON-only LLM step for structured workflow output (optional schema validation).
Tool inventory
#
`apply_patch`
Apply structured patches across one or more files. Use for multi-hunk edits.
Experimental: enable via ''tools.exec.applyPatch.enabled'' (OpenAI models only).
#
`exec`
Run shell commands in the workspace.
Core parameters:
- ''command'' (required)
- ''yieldMs'' (auto-background after timeout, default 10000)
- ''background'' (immediate background)
- ''timeout'' (seconds; kills the process if exceeded, default 1800)
- ''elevated'' (bool; run on host if elevated mode is enabled/allowed; only changes behavior when the agent is sandboxed)
- ''host'' (''sandbox | gateway | node'')
- ''security'' (''deny | allowlist | full'')
- ''ask'' (''off | on-miss | always'')
- ''node'' (node id/name for ''host=node'')
- Need a real TTY? Set ''pty: true''.
Notes:
- Returns ''status: "running"'' with a ''sessionId'' when backgrounded.
- Use ''process'' to poll/log/write/kill/clear background sessions.
- If ''process'' is disallowed, ''exec'' runs synchronously and ignores ''yieldMs''/''background''.
`process`
Manage background exec sessions.
Core actions:
- ''list'', ''poll'', ''log'', ''write'', ''kill'', ''clear'', ''remove''
Notes:
- ''poll'' returns new output and exit status when complete.
- ''log'' supports line-based ''offset''/''limit'' (omit ''offset'' to grab the last N lines).