Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/nanocoai/nanoclaw/claude-mdgit clone --depth 1 https://github.com/nanocoai/nanoclawWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.07210 | $0.07210 |
| Opus 5 | $0.03605 | $0.03605 |
| Sonnet 5 | $0.01442 | $0.01442 |
| Haiku 4.5 | $0.00721 | $0.00721 |
Grade B, and why
nanoclaw CLAUDE.md scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
- **`onlyBuiltDependencies`**: Never add packages to this list without human approval — build scripts execute arbitrary code during install. Copies of this mod
1 near-identical copy found in the catalogue:
- nanoclaw-gws-ea CLAUDE.md — 89% identical, 105 lines differ
How it starts
The opening of the file, as written. The whole thing — 340 lines — stays where its author put it; the contents beside it link to each section on GitHub.
⚠️ STOP — READ THIS FIRST IF YOU ARE CLAUDE ⚠️
If you are reading this because you just ran git pull, git merge, git fetch && git merge, or any equivalent to bring in upstream changes — and you see merge conflicts or a large diff involving this file — HALT IMMEDIATELY.
This is NanoClaw v2, a ground-up rewrite with breaking changes throughout. It cannot be merged into an existing v1 install. Attempting to resolve the conflicts by hand, run builds, or "fix" anything will corrupt the user's install and burn tokens for no result.
Do this instead:
- Abort the merge:
git merge --abort(orgit reset --hard ORIG_HEADif the merge already completed). - Tell the user, verbatim: "This is the v2 rewrite — it can't be merged into your existing install. Exit Claude Code (or open a separate terminal) and run
bash migrate-v2.shfrom the shell." - Wait for the user to confirm before doing anything else. Do not run the migration script yourself — it requires an interactive terminal and cannot be run from within Claude Code.
If you are a fresh install (you ran git clone, not git pull) and there are no conflicts, ignore this banner and continue below.
NanoClaw
Personal AI assistant. See README.md for philosophy and setup. Architecture lives in docs/.
Quick Context
The host is a single Node process that orchestrates per-session agent containers. Platform messages land via channel adapters, route through an entity model (users → messaging groups → agent groups → sessions), get written into the session's inbound DB, and wake a container. The agent-runner inside the container polls the DB, calls the agent, and writes back to the outbound DB. The host polls the outbound DB and delivers through the same adapter.
Everything is a message. There is no IPC, no file watcher, no stdin piping between host and container. The two session DBs are the sole IO surface.
Entity Model
users (id "<channel>:<handle>", kind, display_name)
user_roles (user_id, role, agent_group_id) — owner | admin (global or scoped)
agent_group_members (user_id, agent_group_id) — unprivileged access gate
user_dms (user_id, channel_type, messaging_group_id) — cold-DM cache
agent_groups (workspace, memory, CLAUDE.md, personality, container config)
↕ many-to-many via messaging_group_agents (session_mode, engage_mode/engage_pattern, sender_scope, priority)
messaging_groups (one chat/channel on one platform; instance = adapter-instance name, defaults to channel_type; unknown_sender_policy)
sessions (agent_group_id + messaging_group_id + thread_id → per-session container)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 340 lines · 7,210 tokens per session scan B 6bc8a3872524
nanoclaw CLAUDE.md is an instructions file published in the GitHub repository nanocoai/nanoclaw (30,661 stars, last pushed today), licensed MIT. It adds 7,210 tokens to every session, about $0.0360 per session on Opus 5. A static security scan graded it B with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
pynchy AGENTS.md
Instructions for crypdick/pynchy, covering pynchy, architectural direction, deployment awareness, quick context and key files.
ChatClaw AGENTS.md
AGENTS.md instructions for zhimaAi/ChatClaw, covering chatclaw agents.md, 项目概述, 通用开发规范, 语言约定 and codex superpowers.
openclaw-config AGENTS.md
AGENTS.md instructions for TechNickAI/openclaw-config, covering project context for ai assistants, project overview, tech stack, project structure and code conventions.
openclaw-config CLAUDE.md
Claude Code instructions for TechNickAI/openclaw-config, a project described as: Give your AI assistant memory, skills, and autonomy. Persistent memory, integration skills, and autonomous workflows.
clawe CLAUDE.md
Claude Code instructions for getclawe/clawe, covering clawe, commands, structure, data layer and environment variables.
autoclaw.sh AGENTS.md
Instructions for datopian/autoclaw.sh, covering agent instructions, quick reference, landing the plane (session completion), issue tracking with bd (beads) and why bd?.