← 返回 Skills 市场
udiedrichsen

Clawdbot Sync

作者 udiedrichsen · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
2444
总下载
1
收藏
3
当前安装
1
版本数
在 OpenClaw 中安装
/install clawdbot-sync
功能描述
Synchronize memory, preferences, and skills between multiple Clawdbot instances. Supports bi-directional sync via SSH/rsync over Tailscale. Use when asked to sync with another Clawdbot, share memory between instances, or keep multiple agents in sync. Triggers: /sync, 'sync with mac', 'update other clawdbot', 'share this with my other bot'.
使用说明 (SKILL.md)

Clawdbot Sync 🔄

Synchronize memory, preferences, and skills between multiple Clawdbot instances over Tailscale/SSH.

Features

  • Bi-directional sync between Clawdbot instances
  • Smart conflict resolution (newest wins, or merge for logs)
  • Selective sync — choose what to sync
  • Peer discovery via Tailscale
  • Dry-run mode for preview

Commands

Command Action
/sync Show status and configured peers
/sync status Check connection to all peers
/sync now [peer] Sync with peer (or all)
/sync push [peer] Push local changes to peer
/sync pull [peer] Pull changes from peer
/sync add \x3Cname> \x3Chost> [user] [path] Add a peer
/sync remove \x3Cname> Remove a peer
/sync diff [peer] Show what would change
/sync history Show sync history

Setup

1. Configure Peers

handler.sh add mac-mini 100.95.193.55 clawdbot /Users/clawdbot/clawd $WORKSPACE
handler.sh add server 100.89.48.26 clawdbot /home/clawdbot/clawd $WORKSPACE

2. Ensure SSH Access

Both machines need SSH key auth:

ssh-copy-id [email protected]

3. Test Connection

handler.sh status $WORKSPACE

What Gets Synced

Item Default Notes
memory/ ✅ Yes All memory files and skill data
MEMORY.md ✅ Yes Main memory file
USER.md ✅ Yes User profile
IDENTITY.md ❌ No Each instance has its own identity
skills/ ⚙️ Optional Installed skills
config/ ❌ No Instance-specific config

Handler Commands

handler.sh status $WORKSPACE                    # Check peers and connection
handler.sh sync \x3Cpeer> $WORKSPACE               # Bi-directional sync
handler.sh push \x3Cpeer> $WORKSPACE               # Push to peer
handler.sh pull \x3Cpeer> $WORKSPACE               # Pull from peer
handler.sh diff \x3Cpeer> $WORKSPACE               # Show differences
handler.sh add \x3Cname> \x3Chost> \x3Cuser> \x3Cpath> $WS  # Add peer
handler.sh remove \x3Cname> $WORKSPACE             # Remove peer
handler.sh history $WORKSPACE                   # Sync history
handler.sh auto \x3Con|off> $WORKSPACE             # Auto-sync on heartbeat

Conflict Resolution

  1. Timestamp-based: Newer file wins
  2. Merge for logs: Append-only files are merged
  3. Skip conflicts: Option to skip conflicting files
  4. Manual resolution: Flag for review

Data Files

Stored in $WORKSPACE/memory/clawdbot-sync/:

File Purpose
peers.json Configured peers
history.json Sync history log
config.json Sync preferences
conflicts/ Conflicting files for review

Example Session

User: /sync now mac-mini
Bot: 🔄 Syncing with mac-mini (100.95.193.55)...

     📤 Pushing: 3 files changed
     • memory/streaming-buddy/preferences.json
     • memory/2026-01-26.md
     • MEMORY.md
     
     📥 Pulling: 1 file changed
     • memory/2026-01-25.md
     
     ✅ Sync complete! 4 files synchronized.

Requirements

  • rsync (for efficient file sync)
  • ssh (for secure transport)
  • Tailscale or direct network access between peers
  • SSH key authentication configured

Security

  • Uses SSH for all transfers (encrypted)
  • No passwords stored (key-based auth only)
  • Sync paths are restricted to workspace
  • No system files are ever synced
安全使用建议
This skill appears to do what it claims (rsync/SSH sync of a workspace), but it uses insecure defaults and sloppy shell handling that increase risk if you add untrusted peers. Before installing or using it: - Review scripts/handler.sh yourself (or have an admin do so). Look for places where host/user/path variables are concatenated into ssh/rsync commands without proper quoting/escaping. - Be cautious adding peers: only add hosts you fully trust. A malicious peer entry could cause remote command execution or unexpected writes. - Note check_connection uses StrictHostKeyChecking=no (disables SSH host-key verification); consider changing that to require known_hosts to prevent man-in-the-middle attacks. - The setup docs recommend running curl | sh to install Tailscale — only run that from a trusted environment and preferably inspect the install script first. - Use the skill's dry-run/diff modes first to verify what would be transferred, and test with an isolated workspace. If you want higher assurance, ask the author to: (1) remove StrictHostKeyChecking=no, (2) add robust quoting/validation of peer fields before using them in shell commands, and (3) avoid shell interpolation where possible (use ssh/rsync arguments safely).
功能分析
Type: OpenClaw Skill Name: clawdbot-sync Version: 1.0.0 The skill's core functionality to synchronize OpenClaw agent data via SSH/rsync is aligned with its stated purpose. However, the `scripts/handler.sh` uses `ssh -o StrictHostKeyChecking=no` when checking peer connections and creating remote directories. While this might be intended for convenience in dynamic network environments like Tailscale, it significantly weakens SSH security by disabling host key verification, making connections vulnerable to Man-in-the-Middle (MITM) attacks. This constitutes a risky capability without clear malicious intent, classifying it as suspicious.
能力评估
Purpose & Capability
Name, description, required binaries (rsync, ssh, jq) and provided scripts align with a file-syncing skill. The ability to use Tailscale/SSH and rsync is coherent with the stated goal of syncing memory, preferences, and skills.
Instruction Scope
SKILL.md and references instruct the agent to run SSH/rsync operations and to install Tailscale via curl|sh. The included script executes SSH commands on peers and runs rsync against remote paths. The doc claims 'No system files are ever synced' and the script does constrain SYNC_PATHS to workspace-relative paths, but remote paths and SSH commands are taken from peer configuration and are inserted into shell commands without robust sanitization or quoting. The script also disables SSH host key checking (StrictHostKeyChecking=no) for connection tests, which weakens authentication and enables man-in-the-middle risk. Overall the runtime instructions go beyond simple read-only queries and will execute remote operations that require careful trust of peers.
Install Mechanism
No install spec; this is instruction-only plus an included handler script. Nothing is downloaded or executed at install time by the skill itself. The setup guide suggests running external installers (e.g., curl -fsSL https://tailscale.com/install.sh | sh), which is common but has its own risk and is invoked manually by the operator, not automatically by the skill.
Credentials
The skill requests no environment variables or registry-stored credentials, which is consistent for an SSH/rsync tool that relies on user-provisioned SSH keys. However, the skill assumes key-based SSH auth is configured but does not declare or protect any credentials. Because peer host/user/path are user-provided and later interpolated into shell/ssh commands, a malicious/compromised peer entry could be used to run unexpected commands or access unintended locations.
Persistence & Privilege
always is false and the skill does not request permanent platform-level privileges. It stores its peer/config/history under the provided workspace path only. Nothing in the manifest indicates modification of other skills or global agent settings.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install clawdbot-sync
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /clawdbot-sync 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release: Bi-directional sync between Clawdbot instances via SSH/Tailscale
元数据
Slug clawdbot-sync
版本 1.0.0
许可证
累计安装 3
当前安装数 3
历史版本数 1
常见问题

Clawdbot Sync 是什么?

Synchronize memory, preferences, and skills between multiple Clawdbot instances. Supports bi-directional sync via SSH/rsync over Tailscale. Use when asked to sync with another Clawdbot, share memory between instances, or keep multiple agents in sync. Triggers: /sync, 'sync with mac', 'update other clawdbot', 'share this with my other bot'. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 2444 次。

如何安装 Clawdbot Sync?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install clawdbot-sync」即可一键安装,无需额外配置。

Clawdbot Sync 是免费的吗?

是的,Clawdbot Sync 完全免费(开源免费),可自由下载、安装和使用。

Clawdbot Sync 支持哪些平台?

Clawdbot Sync 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Clawdbot Sync?

由 udiedrichsen(@udiedrichsen)开发并维护,当前版本 v1.0.0。

💬 留言讨论