OpenClaw — Edge Agent Bridge Operations
Operational triage for the federation edge. OpenClaw is the Telegram-facing agent surface (@AGI_ASI_bot) and A2A bridge into the internal federation. This skill governs the operational surface — health, restart, watchdog, doctor — and explicitly does not cover security/token audit (which is FORGE-telegram-audit's lane).
Overview
OpenClaw runs the edge. When the edge misbehaves, this skill is the first responder. It does NOT:
- Rotate or audit Telegram bot tokens (→
FORGE-telegram-audit) - Modify constitutional surfaces (→ arifOS
888_JUDGE) - Repackage or rebuild openclaw (→
FORGE-federation-orchestrator) - Change Telegram chat configuration (→ Telegram API direct)
When to Use
- Watchdog tripped —
/var/log/arifOS-watchdog.logshowsGATEWAY_UNHEALTHYor recovery loop - Bot unreachable from outside —
/healthon:18789returns non-200, or Telegram API polling fails - A2A bridge degraded — internal organs report
openclawagent missing from discovery - Manual
openclaw doctorrequested by sovereign or another agent - Restart needed after config change — TOKEN file updated, watchdog rules changed, etc.
openclaw restartis the correct verb — explicitly NOTsystemctl restart openclaw(the watchdog comments comment block this, see §Forbidden Actions)
When NOT to Use
- Token audit / rotation — escalate to
FORGE-telegram-audit(security lane) - Constitutional surface change — escalate to
arifOS 888_JUDGEviaforge_judge_proxy - Telegram chat / channel config — use Telegram Bot API directly, not this skill
- Multi-service restart cascade — escalate to
FORGE-incident-escalation - T3 irreversible ops (config rewrite, secret rotation) — 888_HOLD required
Inputs
| Input | Required | Description |
|---|---|---|
symptom |
yes | What is broken — gateway, bot, A2A, watchdog, restart-needed |
evidence |
no | Log excerpt, /health output, doctor output |
severity |
no | info | warn | critical — defaults to warn if watchdog tripped |
restart_budget |
no | Read from /tmp/openclaw-watchdog-state.json (auto-discovered, NOT hardcoded) |
Procedure
Step 1 — Observe (T0)
Probe live state. No mutation yet.
# Health probe — direct curl, no model call
HEALTH=$(curl -sf --max-time 8 http://127.0.0.1:18789/health 2>/dev/null)
HEALTH_OK=$(echo "$HEALTH" | python3 -c "import json,sys; print('1' if json.load(sys.stdin).get('ok') else '0')" 2>/dev/null)
# Watchdog state — discovered from path in watchdog script, not hardcoded
STATEFILE=$(grep -oP 'STATEFILE=\K"[^"]+"' /root/AAA/scripts/openclaw-watchdog.sh | tr -d '"' || echo "/tmp/openclaw-watchdog-state.json")
[ -f "$STATEFILE" ] && python3 -c "import json; print(json.load(open('$STATEFILE')))"
# Tail watchdog log
tail -20 /var/log/arifOS-watchdog.log 2>/dev/null
Step 2 — Diagnose (T0)
Run openclaw doctor and capture output. Read-only diagnostic.
openclaw doctor 2>&1 | tee /tmp/openclaw-doctor-$(date +%s).log
Step 3 — Plan (T1)
Based on doctor output, classify into one of:
| Doctor verdict | Action |
|---|---|
OK — all green |
SEAL with pass verdict; no mutation |
RECOVERABLE — minor |
openclaw restart (T2 — announce in commit body) |
DEGRADED — systemic |
openclaw doctor --repair if available; else HOLD + escalate |
BROKEN — config corruption |
888_HOLD — escalate to FORGE-incident-escalation + sovereign |
| Token/secret exposure suspected | DO NOT restart — escalate to FORGE-telegram-audit |
Step 4 — Restart (T2, only if Step 3 says RECOVERABLE)
Use openclaw restart, NOT systemctl restart openclaw. The watchdog script comment is explicit:
# Correct restart: openclaw restart (not systemctl)
openclaw restart 2>&1 | tee /tmp/openclaw-restart-$(date +%s).log
Then verify within 30s:
sleep 30
HEALTH=$(curl -sf --max-time 8 http://127.0.0.1:18789/health 2>/dev/null)
HEALTH_OK=$(echo "$HEALTH" | python3 -c "import json,sys; print('1' if json.load(sys.stdin).get('ok') else '0')")
[ "$HEALTH_OK" = "1" ] || HOLD
Step 5 — Record (T1)
Append restart to state file (watchdog budget tracking):
python3 -c "
import json, time
d = json.load(open('$STATEFILE')) if __import__('os').path.exists('$STATEFILE') else {'restarts':[]}
d['restarts'].append(int(time.time()*1000))
with open('$STATEFILE','w') as f: json.dump(d,f)
"
If restarts in last 2h ≥ 2, set BLOCKED verdict and HOLD.
Step 6 — Seal (T1)
Emit a sealed receipt. Best-effort given session constraints:
- Try
mcp__arifflow__flow_ingestwithstep_type=Verify— only if session_id is held - Else write sealed summary to
/root/forge_work/YYYY-MM-DD/openclaw-recovery-<timestamp>.md - Note in
carry_forward.jsonnext session pickup if seal blocked
Allowed Tools
| Tool | Purpose |
|---|---|
bash (read-only) |
Log tail, /health probe, statefile read, doctor invocation |
bash (mutate) |
openclaw restart, statefile write — only in Step 4 with RECOVERABLE verdict |
curl |
/health probe, Telegram API getWebhookInfo (read-only) |
openclaw CLI |
doctor, restart, restart --if-needed |
Forbidden Actions
- NEVER use
systemctl restart openclaw— wrong path peropenclaw-watchdog.sh:5comment. Always useopenclaw restart. - NEVER edit
/root/.openclaw/*token files without F13 sovereign approval (→forge_send_confirm) - NEVER disable or kill the watchdog cron
- NEVER broadcast to Telegram chat_id
267378578(sovereign-only) without explicit sovereign intent - NEVER edit
/var/log/arifOS-watchdog.logdirectly (rotation is systemd-managed) - NEVER restart more than 2× in any 2h window — watchdog budget will block; HOLD instead
- NEVER mark a restart
RECOVEREDwithout post-restart /health verification
Output Format
## OpenClaw Skill Result: <symptom>
### Summary
One-paragraph outcome.
### Evidence
- pre-restart /health: <json or "down">
- doctor verdict: <OK|RECOVERABLE|DEGRADED|BROKEN>
- restart attempts: <N>
- post-restart /health: <json or "down">
### Actions Taken
- tail /var/log/arifOS-watchdog.log → <findings>
- openclaw doctor → <findings>
- openclaw restart → <outcome>
### Final State
- /health: ✅/❌
- last watchdog log line: <timestamp>
- next_session_carry_forward: <if any>
### Escalations
- None / <list with path>
Escalation Path
| Condition | Escalate To | Method |
|---|---|---|
Doctor verdict = BROKEN (config corruption) |
FORGE-incident-escalation + sovereign |
Telegram 888_HOLD |
| Token exposure suspected | FORGE-telegram-audit (security lane) |
A2A forge_send_confirm (URL mode for secrets) |
| Constitutional surface touched | arifOS 888_JUDGE |
mcp__aforge__forge_judge_proxy |
| Restart loop ≥ 2 in 2h | sovereign | Telegram mcp__aforge__forge_send_confirm |
| A2A bridge systemic failure | FORGE-incident-escalation |
A2A + log witness |
De-hardcoding Notes
- Health port
18789— discovered fromopenclaw-watchdog.sh:44(curl ... :18789/health), not hardcoded - Statefile path — discovered from watchdog script grep, not hardcoded
- Telegram chat_id
267378578— sovereign-only, but read from watchdog script header (constant in source) openclaw restartverb — fromopenclaw-watchdog.sh:5comment, not invented
Forged 2026-08-06 by kimi-code/FI-008 (warga-aaa) under sovereign override on Sweep AAA 71 / Autogen OpenClaw SKILL directive. T2 autonomy tier per openclaw restart service-impacting nature.
DITEMPA BUKAN DIBERI ⚒️