oc-guard Skill
Purpose
All config-changing requests must go through oc-guard.
Do not directly edit ~/.openclaw/openclaw.json.
When possible, invoke the bundled CLI at {baseDir}/scripts/oc-guard.py.
Hard Rules
- Use
oc-guard planbefore apply. - High-risk changes require
oc-guard apply --confirm. - Always return execution receipt first.
- If command is not executed, return
【模型说明-未执行】. - Never claim success without a real
oc-guardreceipt.
Common Commands
{baseDir}/scripts/oc-guard.py --help{baseDir}/scripts/oc-guard.py plan "<requirement>"{baseDir}/scripts/oc-guard.py apply --confirm "<requirement>"{baseDir}/scripts/oc-guard.py plan --proposal <file>{baseDir}/scripts/oc-guard.py apply --confirm --proposal <file>