setup-ghostclaw

A first-time setup guide for GhostClaw, including its dependencies, login details, communication channels, personality, and service configuration.

In plain words
What is it for?
Use it when installing GhostClaw for the first time, choosing its AI model and name, connecting channels, and configuring its service.
Why use it?
It brings together the setup decisions and installation steps needed before a new GhostClaw instance can be used.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/b1rdmania/ghostclaw/setup-ghostclaw
Any agent
npx skills add b1rdmania/ghostclaw --skill setup-ghostclaw
Clone the repo
git clone --depth 1 https://github.com/b1rdmania/ghostclaw

Made for: Claude Code, Codex.

Per session 39 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,963 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00039 $0.01963
Opus 5 $0.00019 $0.00981
Sonnet 5 $0.00008 $0.00393
Haiku 4.5 $0.00004 $0.00196

Measured 3d ago against content hash 20fac0cf1b93, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

setup-ghostclaw scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/setup-ghostclaw/SKILL.md · 271 lines

How it starts

The opening of the file, as written. The whole thing — 271 lines — stays where its author put it; the contents beside it link to each section on GitHub.

GhostClaw Setup

Interactive setup for a fresh GhostClaw install. Handles everything from dependencies to personality.

Phase 1: Dependencies

npm install

Check Node.js version:

node --version  # Must be 20+

Phase 2: Authentication

Claude Code token

Ask: "Do you have a Claude Max subscription or an API key?"

Claude Max (recommended): Tell the user to run this in a separate terminal (not inside Claude Code):

claude setup-token

Then ask them to paste the token. Add to .env:

CLAUDE_CODE_OAUTH_TOKEN=<token>

API key:

ANTHROPIC_API_KEY=<key>

Model selection

AskUserQuestion: Which model should the bot use?

  • Sonnet (Recommended) — fast, capable, cost-effective for most tasks
  • Opus — most capable, slower, higher cost
  • Haiku — fastest, cheapest, good for simple tasks

Add to .env based on choice:

GHOSTCLAW_MODEL=claude-sonnet-4-6    # Sonnet (recommended)
# GHOSTCLAW_MODEL=claude-opus-4-6    # Opus
# GHOSTCLAW_MODEL=claude-haiku-4-5-20251001  # Haiku

If they skip or aren't sure, default to Sonnet. Tell them: "You can change this any time by editing GHOSTCLAW_MODEL in .env and restarting."

Bot name

AskUserQuestion: What should the bot be called?

Add to .env:

ASSISTANT_NAME=<name>

Phase 3: Channels

AskUserQuestion: Which channels do you want?

  • Telegram only (recommended — bot gets own identity)
  • WhatsApp only
  • Both

Telegram setup

If Telegram selected:

  1. Tell the user:

    Create a Telegram bot:

    1. Open @BotFather in Telegram
    2. Send /newbot
    3. Pick a name and username
    4. Copy the token
  2. Add to .env:

    TELEGRAM_BOT_TOKEN=<token>
    
  3. If Telegram-only, add:

    TELEGRAM_ONLY=true
    

WhatsApp setup

If WhatsApp selected:

  1. Run the app temporarily to get QR code:
    npm run build && node dist/index.js
    
  2. Scan QR code with WhatsApp
  3. Stop the process (Ctrl+C)

Phase 4: Build and start

Read the full file on GitHub · 271 lines

Files

What ships with it

5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 271 lines · 39 tokens per session scan A 20fac0cf1b93

Subscribe to this mod's changes

setup-ghostclaw is a skill published in the GitHub repository b1rdmania/ghostclaw (91 stars, last pushed 4mo ago), licensed MIT. It adds 39 tokens to every session and 1,963 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

lobu-operator

Contribute safely to the Lobu monorepo: worktrees, package rules, red-to-green fixes, validation gates, SDK-first operations, PRs, and rollout checks.

lobu-ai/lobu · 41 tokens

company-agent-infrastructure

Use when designing or building internal/company AI agents that need shared context across company systems, durable organizational memory across sessions or agents, user-scoped permissions, approvals, audit, or governed actions. Also use when deciding whether ordinary MCP tools, RAG, or local agent memory are enough…

lobu-ai/lobu · 70 tokens

lobu-builder

Use when working inside a Lobu project generated by @lobu/cli or any repository centered on lobu.config.ts, AGENTS.md, agent prompt files, local skills, and evals. This skill helps a coding agent inspect the right files, make Lobu-native changes, keep the stack runnable, and validate semantics with chat tests and…

lobu-ai/lobu · 76 tokens

crm-ops

How to operate the Lobu funnel CRM — create and enrich leads, log interactions, advance funnel stages, open and update pilots, and produce the weekly digest. Use whenever the task touches the pipeline.

lobu-ai/lobu · 44 tokens

deliveroo-order

Turn collected lunch orders into a clean per-person order list for a human to place on Deliveroo. Use in step 2 of the lunch run, after orders are collected. The live menu is fetched automatically by the lobu-team-lunch-finalize reaction (via the Owletto Chrome extension) — this skill never places an order or touches…

lobu-ai/lobu · 75 tokens

lobu

Use Lobu MCP for shared, permission-aware company context, durable organizational memory, and governed actions. Trigger when the user asks what the organization knows, needs context from connected company systems, wants to preserve a durable fact or decision, or needs to discover and use Lobu SDK capabilities.

lobu-ai/lobu · 60 tokens