claims

A read-only Crabbox command that lists machine lease claims stored locally. A lease claim is a local record showing that a machine or environment was assigned to a repository or provider.

In plain words
What is it for?
Use it to review local claim records, check their provider and repository details, or feed a versioned claims list into automation.
Why use it?
It lets you inspect local claims without contacting a cloud provider, loading credentials, refreshing records, or deleting stale data. JSON output is available for scripts.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/openclaw/crabbox/claims
Clone the repo
git clone --depth 1 https://github.com/openclaw/crabbox
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 651 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00651
Opus 5 $0.00000 $0.00326
Sonnet 5 $0.00000 $0.00130
Haiku 4.5 $0.00000 $0.00065

Measured 2d ago against content hash a250a8f9acb6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

claims scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/commands/claims.md · 80 lines

How it starts

The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.

claims

crabbox claims list prints the lease claims stored on the current machine. It is a read-only, credential-free inventory: it does not load provider configuration, initialize a provider backend, contact a provider, refresh a claim, or remove stale state.

crabbox claims list
crabbox claims list --json

Human output is headed unverified local state because a structurally valid claim may be stale. Provider-scoped crabbox list remains the command for provider-backed machine inventory.

JSON

--json emits this versioned envelope, including empty arrays when no claims or problems exist:

{
  "version": 1,
  "source": "local-claims",
  "claims": [],
  "problems": []
}

Each claim contains only these public fields:

{
  "leaseId": "cbx_abcdef123456",
  "slug": "blue-lobster",
  "provider": "aws",
  "repoRoot": "/path/to/repo",
  "pond": "",
  "targetOS": "linux",
  "windowsMode": "",
  "claimedAt": "2026-08-16T10:00:00Z",
  "lastUsedAt": "2026-08-16T10:05:00Z",
  "idleTimeoutSeconds": 1800
}

Cloud and resource identifiers, provider scope, hosts and endpoints, SSH details, labels, login and registration URLs or IDs, credentials, cache metadata, revisions, and fixed-create internals are never included. Claims are sorted by lease ID, provider, and slug.

Malformed files do not hide valid claims. For this read-only inventory, each local claim file has an inclusive 1 MiB implementation limit. Files that exceed the limit while being read use claim_too_large and are never read into memory in full; other concurrent changes remain read_error. This inventory limit does not change the runtime claim loader. Each problem has stable file, code, and message fields. Supported codes are invalid_filename, invalid_json, claim_too_large, empty_lease_id, lease_id_mismatch, read_error, and invalid_claim. Unsafe or overlong filenames are represented by a short SHA-256 fingerprint instead of their contents. Non-regular claim paths use non_regular_file. At most 100 problem entries are emitted; the final problems_truncated entry reports when additional files were omitted. Problems are sorted by file reference and code.

Read the full file on GitHub · 80 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 80 lines · 0 tokens per session scan A a250a8f9acb6

Subscribe to this mod's changes

claims is a command published in the GitHub repository openclaw/crabbox (1,343 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 651 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.