{"slug":"crabbox","title":"crabbox","summary":"Detect and use Crabbox for repository tests and validation on remote runners. Use when crabbox.yaml or .crabbox.yaml exists, the crabbox CLI is available, or work needs remote compute, a clean or reusable environment, target-platform coverage, or auditable execution evidence.","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-08-24T16:56:35.300881Z","repo":{"url":"https://github.com/openclaw/crabbox","stars":1434,"forks":189,"license":"MIT","updatedAt":"2026-09-27T12:27:25Z"},"bodyHtml":"<hr>\n<h2>name: crabbox\ndescription: \"Detect and use Crabbox for repository tests and validation on remote runners. Use when crabbox.yaml or .crabbox.yaml exists, the crabbox CLI is available, or work needs remote compute, a clean or reusable environment, target-platform coverage, or auditable execution evidence.\"\nlicense: MIT</h2>\n<h1>Crabbox</h1>\n<p>Use Crabbox when a project needs remote proof, larger cloud capacity, a fresh\nPR checkout, a reusable warmed box, GitHub Actions-style setup, durable run\nlogs/results, UI proof artifacts, or sync from a dirty local checkout.</p>\n<h2>Detect Crabbox</h2>\n<ul>\n<li>Treat repo-root <code>crabbox.yaml</code> or <code>.crabbox.yaml</code> as an intentional signal to\nuse this skill for validation work. <code>.crabbox.yml</code> is not a supported config\nfilename.</li>\n<li>If neither config exists, <code>command -v crabbox</code> still identifies an installed\nCLI. Run <code>crabbox doctor</code> before depending on it for remote work.</li>\n<li>Inspect config before executing it. Detection does not imply permission to\nexpose secrets, bypass command approval, or start paid infrastructure.</li>\n</ul>\n<h2>Source Of Truth</h2>\n<ul>\n<li>Run Crabbox from the repository root; sync mirrors the current checkout.</li>\n<li>Treat repo-local <code>crabbox.yaml</code> or <code>.crabbox.yaml</code> as executable project\nautomation. Review it before remote runs, especially <code>provider</code>, <code>actions</code>,\n<code>jobs</code>, <code>profiles</code>, <code>env.allow</code>, artifacts, and cleanup policy.</li>\n<li>Verify the installed binary before relying on examples:\n<code>command -v crabbox &amp;&amp; crabbox --version &amp;&amp; crabbox --help | sed -n '1,120p'</code>.</li>\n<li>Use <code>crabbox providers</code> or <code>crabbox providers --json</code> for the current\nprovider/capability matrix; provider docs can lag the compiled binary.</li>\n<li>Use <code>crabbox doctor</code> for live readiness checks and <code>crabbox config show</code> to\ninspect merged config without printing secrets.</li>\n<li>Prefer local targeted tests for tight edit loops. Move to Crabbox for broad\nsuites, package-heavy checks, Docker/E2E/live-provider proof, cross-OS proof,\nUI proof, or commands that bog down the local machine.</li>\n</ul>\n<h2>Auth And Config</h2>\n<p>Brokered operation needs a coordinator URL and token. First login usually needs\nan explicit broker URL:</p>\n<pre><code>crabbox login --url &lt;broker-url&gt;\ncrabbox whoami\ncrabbox doctor\n</code></pre>\n<p>After <code>broker.url</code> is configured, <code>crabbox login</code> can reuse it. Trusted operator\nautomation can store a shared token without putting it on argv:</p>\n<pre><code>printf '%s' \"$CRABBOX_COORDINATOR_TOKEN\" |\n  crabbox login --url &lt;broker-url&gt; --provider aws --token-stdin\n</code></pre>\n<p>Config precedence is <code>flags &gt; env &gt; repo config &gt; user config &gt; defaults</code>.\nDefault user config is <code>~/Library/Application Support/crabbox/config.yaml</code> on\nmacOS, <code>~/.config/crabbox/config.yaml</code> on Linux, or\n<code>$XDG_CONFIG_HOME/crabbox/config.yaml</code> when set. <code>crabbox config path</code> prints\nthe active user config path.</p>\n<p>Keep provider and broker tokens out of repo config and command arguments. Use\nenvironment variables, a credential store, coordinator-managed secrets, or a\nshort-lived token command.</p>\n<h2>Choose The Remote Surface</h2>\n<ul>\n<li><code>crabbox run -- &lt;command&gt;</code>: one command on a fresh or reused box.</li>\n<li><code>crabbox warmup</code>: create a reusable lease and run commands later with <code>--id</code>.</li>\n<li><code>crabbox prewarm</code>: warm a reusable lease and hydrate it from configured\nGitHub Actions.</li>\n<li><code>crabbox job run &lt;name&gt;</code>: use a repo-local named flow that expands to\nwarmup, optional hydration, run, and stop.</li>\n<li><code>crabbox run --pool &lt;key&gt;</code>: borrow a hydrated broker ready-pool lease, run,\nthen return/drain/release it according to <code>--pool-return</code>.</li>\n<li><code>crabbox run --fresh-pr ...</code>: ignore local sync and check out a GitHub PR on\nthe remote; add <code>--apply-local-patch</code> to test local uncommitted changes on\ntop of that PR.</li>\n<li><code>crabbox run --provider ssh</code>: use an existing macOS, Linux, or Windows host.</li>\n<li><code>crabbox warmup --desktop --browser</code>: provision a visible desktop/browser for\nUI testing, WebVNC, screenshots, and artifacts.</li>\n</ul>\n<p>If remote proof is blocked, name the missing capability precisely: auth,\ncoordinator, capacity, provider support, target OS, hydration, secret access,\nartifact storage, desktop support, or a delegated-provider limitation.</p>\n<h2>Common Remote Proof</h2>\n<p>One-shot command:</p>\n<pre><code>crabbox run --preflight --timing-json -- pnpm test\n</code></pre>\n<p>Warm and reuse a lease:</p>\n<pre><code>crabbox warmup --class beast --idle-timeout 90m\ncrabbox status --id &lt;cbx_id-or-slug&gt; --wait\ncrabbox run --id &lt;cbx_id-or-slug&gt; -- pnpm test:changed\ncrabbox run --id &lt;cbx_id-or-slug&gt; --full-resync -- pnpm test:changed\ncrabbox stop &lt;cbx_id-or-slug&gt;\n</code></pre>\n<p>Use a repo-local job when configured:</p>\n<pre><code>crabbox job list\ncrabbox job run --dry-run &lt;job-name&gt;\ncrabbox job run &lt;job-name&gt;\ncrabbox job run --id &lt;cbx_id-or-slug&gt; &lt;job-name&gt;\n</code></pre>\n<p>Use a ready-pool lease when the coordinator has hydrated pool capacity:</p>\n<pre><code>crabbox pool ready\ncrabbox run --pool &lt;pool-key&gt; -- pnpm test\ncrabbox run --pool &lt;pool-key&gt; --pool-return drain -- pnpm test:flaky\n</code></pre>\n<p>Use GitHub Actions hydration when the repository already owns setup in CI:</p>\n<pre><code>crabbox warmup --idle-timeout 90m\ncrabbox actions hydrate --id &lt;cbx_id-or-slug&gt;\ncrabbox run --id &lt;cbx_id-or-slug&gt; -- pnpm test\n</code></pre>\n<p>Use <code>--github-runner</code> only when the workflow needs full GitHub Actions\nsemantics such as repository secrets, OIDC, service containers, job containers,\nor unsupported <code>uses:</code> steps:</p>\n<pre><code>crabbox actions hydrate --github-runner --id &lt;cbx_id-or-slug&gt;\n</code></pre>\n<h2>Sync And Fresh Checkouts</h2>\n<p>Normal sync transfers tracked files plus non-ignored untracked files, excludes\nignored dependency/build/cache output, honors <code>.crabboxignore</code> and\n<code>sync.exclude</code>, seeds the remote checkout from <code>origin</code> when possible, and skips\nrsync when the sync fingerprint matches.</p>\n<p>Use <code>crabbox sync-plan</code> before large runs. Unexpected counts usually mean\nlocal generated churn; update <code>.crabboxignore</code> or <code>sync.exclude</code> instead of\nforcing huge uploads.</p>\n<pre><code>crabbox sync-plan\ncrabbox run --debug --timing-json -- pnpm test\ncrabbox run --full-resync -- pnpm test\n</code></pre>\n<p>Use fresh PR checkout when local dependency churn or dirty sync would confuse\nthe result:</p>\n<pre><code>crabbox run --fresh-pr example-org/my-app#123 --script ./scripts/e2e-smoke.sh\ncrabbox run --fresh-pr 123 --apply-local-patch -- pnpm test\n</code></pre>\n<p><code>--fresh-pr</code> accepts <code>owner/repo#number</code>, GitHub PR URLs, or a numeric PR from\nthe current GitHub origin. Non-GitHub hosts are rejected. Fresh PR checkout is\nan SSH-run sync feature; delegated providers reject it. Native Windows SSH\ntargets are supported.</p>\n<p>When a warm lease smells stale, prefer <code>--full-resync</code> (alias <code>--fresh-sync</code>) to\nreset the remote workdir, skip the sync fingerprint fast path, reseed Git when\npossible, and upload the checkout from scratch.</p>\n<h2>Scripts, Shells, And Windows Targets</h2>\n<p>Use plain argv after <code>--</code> for one executable. Use <code>--shell</code> for multi-statement\nshell snippets, pipes, or shell expansion:</p>\n<pre><code>crabbox run --id &lt;lease&gt; -- go test ./...\ncrabbox run --id &lt;lease&gt; --shell 'corepack enable &amp;&amp; pnpm install --frozen-lockfile &amp;&amp; pnpm test'\n</code></pre>\n<p>Prefer uploaded scripts for multi-line commands. Scripts are included in failure\nbundles and avoid brittle quoted shell strings:</p>\n<pre><code>crabbox run --script ./scripts/e2e-smoke.sh --timing-json\nprintf '%s\\n' 'echo CRABBOX_PHASE:test' 'pnpm test' | crabbox run --script-stdin\n</code></pre>\n<p>Native Windows targets use PowerShell and tar-based manifest sync. Prefer plain\nargv for one executable such as <code>dotnet test</code>; use <code>--shell</code> for multi-statement\nPowerShell and <code>--script &lt;file.ps1&gt;</code> for longer scripts.</p>\n<h3>Hyper-V Windows leases</h3>\n<p><code>hyperv</code> needs a Generation 2 VHDX, DHCP, and a known local administrator\npassword in trusted config or <code>CRABBOX_HYPERV_GUEST_PASSWORD</code>. It installs\npinned, verified OpenSSH and MinGit packages when missing, using PowerShell\nDirect. See <code>docs/providers/hyperv.md</code> for template and lifecycle details.</p>\n<p>For provider testing, prefer an elevated headless runner; early PowerShell\nDirect failures can show credential UI. Keep passwords out of arguments and\nlogs, and verify the lease becomes ready, runs over SSH, and releases.</p>\n<h2>Secrets And Environment Forwarding</h2>\n<p>Crabbox does not forward the whole local environment. Forwarding is name-based:\nonly allowlisted names that are actually set locally or in an allowed profile\ncross the boundary. Avoid allowlisting secret-shaped names unless the run is an\nexplicit live-secret smoke.</p>\n<pre><code>crabbox run --allow-env CI,NODE_OPTIONS -- pnpm test\ncrabbox run \\\n  --env-from-profile ~/.project-live.profile \\\n  --allow-env API_TOKEN \\\n  --preflight \\\n  --script ./scripts/live-smoke.sh\n</code></pre>\n<p><code>--env-from-profile</code> parses simple <code>export NAME=value</code> and <code>NAME=value</code> lines\nwithout executing the profile. Crabbox prints redacted presence/length metadata,\nnot values. POSIX SSH leases can persist a helper for later commands on a lease\nyou control:</p>\n<pre><code>crabbox run \\\n  --id &lt;lease&gt; \\\n  --env-from-profile ~/.project-live.profile \\\n  --allow-env API_TOKEN \\\n  --env-helper live \\\n  -- true\ncrabbox run --id &lt;lease&gt; -- ./.crabbox/env/live ./scripts/live-smoke.sh\n</code></pre>\n<p>The generated helper and matching secret profile remain in the remote workdir\nuntil cleanup, lease reset, or <code>--full-resync</code>; do not persist helpers on shared\nor untrusted leases.</p>\n<h2>Profiles, Presets, Proof, And Results</h2>\n<p>Repo config can define profiles, presets, doctor requirements, artifact globs,\nrequired artifacts, and proof templates. Use them for stable validation lanes\ninstead of encoding project knowledge in agent prompts.</p>\n<pre><code>crabbox run \\\n  --profile live-qa \\\n  --preset qa-live \\\n  --scenario login-regression \\\n  --emit-proof /tmp/proof.md \\\n  --stop-after success\n</code></pre>\n<p>Use <code>--preflight</code> for a target capability snapshot before the command, not as\nan installer. Use <code>--preflight-tools</code> to tune probes:</p>\n<pre><code>crabbox run --preflight --preflight-tools node,bun,docker -- bun test\ncrabbox run --preflight --preflight-tools default,uv -- node --test\n</code></pre>\n<p>Attach structured results and proof artifacts when the command emits them:</p>\n<pre><code>crabbox run --junit reports/junit.xml -- ./scripts/test-with-junit.sh\ncrabbox run --artifact-glob 'reports/**' --require-artifact reports/summary.json -- pnpm test:e2e\ncrabbox run --download reports/summary.json=.crabbox/logs/summary.json -- pnpm test:e2e\n</code></pre>\n<p><code>--require-artifact</code> fails the run if the remote command exits 0 but the proof\nfile is missing. Keep required artifacts bounded and scrubbed; do not collect\nraw datasets, secrets, credentials, signed URLs, or unredacted customer rows.</p>\n<h2>Run Handles And Observability</h2>\n<p>Coordinator-backed runs print a durable <code>run_...</code> handle before leasing starts.\nKeep that run ID in status updates and PR notes.</p>\n<pre><code>crabbox history --limit 20\ncrabbox history --lease &lt;cbx_id-or-slug&gt; --limit 20\ncrabbox attach &lt;run_id&gt;\ncrabbox attach &lt;run_id&gt; --after &lt;seq&gt;\ncrabbox events &lt;run_id&gt; --after &lt;seq&gt; --limit 100\ncrabbox events &lt;run_id&gt; --json\ncrabbox logs &lt;run_id&gt;\ncrabbox results &lt;run_id&gt;\n</code></pre>\n<p>Use <code>--timing-json</code> on <code>run</code>, <code>warmup</code>, and <code>actions hydrate</code> when a stable\nmachine-readable timing record is needed. Commands can mark subphases by\nprinting markers on stdout or stderr:</p>\n<pre><code>echo CRABBOX_PHASE:install\npnpm install --frozen-lockfile\necho CRABBOX_PHASE:test\npnpm test\n</code></pre>\n<p>Output events are capped previews. Use <code>logs</code> for retained output tails and\n<code>results</code> for parsed test summaries.</p>\n<h2>Desktop, WebVNC, And UI Proof</h2>\n<p>Create desktop/browser leases for visual QA, headed browser automation, or UI\nproof:</p>\n<pre><code>crabbox warmup --desktop --browser\ncrabbox warmup --provider aws --os ubuntu:26.04 --desktop --browser --desktop-env wayland\ncrabbox warmup --provider aws --os ubuntu:26.04 --desktop --browser --desktop-env gnome\n</code></pre>\n<p><code>ubuntu:26.04</code> is the default portable Linux OS selector where the provider\ncatalog supports it. Use <code>--os ubuntu:24.04</code> only when a test must stay on the\nprevious LTS. Explicit provider image flags still win over <code>--os</code>.</p>\n<p>For human demos, prefer WebVNC over native VNC because <code>crabbox webvnc --open</code>\npreloads the lease password in the browser fragment:</p>\n<pre><code>crabbox webvnc --id &lt;lease&gt; --open --take-control\ncrabbox webvnc status --id &lt;lease&gt;\ncrabbox webvnc reset --id &lt;lease&gt; --open --take-control\ncrabbox vnc --id &lt;lease&gt; --open\n</code></pre>\n<p>For input automation, use first-class helpers instead of hand-written\n<code>xdotool</code>:</p>\n<pre><code>crabbox desktop doctor --id &lt;lease&gt;\ncrabbox desktop launch --id &lt;lease&gt; --browser --url https://example.com --webvnc --open --take-control\ncrabbox desktop click --id &lt;lease&gt; --x 640 --y 420\ncrabbox desktop paste --id &lt;lease&gt; --text \"user@example.com\"\nprintf 'user@example.com' | crabbox desktop paste --id &lt;lease&gt;\ncrabbox desktop type --id &lt;lease&gt; --text \"user+qa@example.com\"\ncrabbox desktop key --id &lt;lease&gt; ctrl+l\ncrabbox screenshot --id &lt;lease&gt; --output desktop.png\n</code></pre>\n<p>When desktop/WebVNC hangs, trust the inline rescue output first: <code>problem:</code> and\n<code>rescue:</code> lines usually name exact next commands such as <code>webvnc status/reset</code>,\n<code>desktop doctor</code>, or native <code>vnc --open</code>.</p>\n<p>Use artifacts for UI QA proof instead of committing screenshots or videos to a\nproduct repo branch:</p>\n<pre><code>crabbox artifacts collect --id &lt;lease&gt; --all --output artifacts/&lt;slug&gt;\ncrabbox artifacts publish --dir artifacts/&lt;slug&gt; --pr &lt;number&gt;\ncrabbox artifacts list &lt;artifact-manifest-url-or-dir&gt;\ncrabbox artifacts pull &lt;artifact-manifest-url-or-dir&gt; --output /tmp/&lt;slug&gt;-proof\n</code></pre>\n<p><code>artifacts publish</code> uses brokered storage when configured, or explicit S3/R2 /\nCloudflare/local hosting flags. Use <code>--dry-run</code> before public PR comments when\nreviewing generated Markdown or storage commands.</p>\n<h2>Provider Boundaries</h2>\n<p>SSH-lease providers support the full sync/run surface when the target supports\nit: scripts, fresh PR checkouts, captures, downloads, Actions hydration, SSH,\nports, WebVNC, code-server, desktop, browser, cache volumes, and cleanup.</p>\n<p>Delegated-run providers own command transport. Expect them to reject SSH-run\nfeatures such as <code>--capture-stdout</code>, <code>--capture-stderr</code>, <code>--capture-on-fail</code>,\n<code>--script</code>, <code>--script-stdin</code>, <code>--fresh-pr</code>, local captures, <code>--download</code>,\n<code>--full-resync</code>, and <code>--env-helper</code> unless <code>crabbox providers --json</code> and the\nprovider docs advertise the matching capability. <code>--keep-on-failure</code> is still\nuseful for one-shot delegated providers that Crabbox would otherwise stop after\na failed command.</p>\n<p>Module-runtime delegated providers, such as Cloudflare Dynamic Workers, run\nsource modules rather than Linux shell commands. Use <code>--script &lt;file&gt;</code> or\n<code>--script-stdin</code> for module source; trailing <code>-- &lt;command&gt;</code>, SSH, rsync, ports,\nActions hydration, desktop, browser, and code-server do not apply unless the\nprovider explicitly documents them.</p>\n<p>Use <code>--market spot|on-demand</code> on AWS <code>warmup</code> or one-shot <code>run</code> when account\nquota or capacity testing needs a temporary market override. An explicit\n<code>--type</code> means exact type; Crabbox reports quota/capacity/policy failures\ninstead of silently falling back.</p>\n<h2>Local And Static Targets</h2>\n<p>Use <code>local-container</code> for fast local proof when the host has Docker or Podman.\n<code>warmup</code> creates a container but does not sync; for an interactive synced\ncontainer, use <code>run --keep --sync-only</code>:</p>\n<pre><code>crabbox run --provider local-container --keep --slug local-smoke --sync-only\neval \"$(crabbox ssh --provider local-container --id local-smoke)\"\n</code></pre>\n<p>Pass <code>--local-container-runtime docker</code> or <code>--local-container-runtime podman</code>\nwhen the engine matters, and keep that flag on reused lease commands such as\n<code>run --id</code>, <code>ssh</code>, <code>status</code>, and <code>stop</code>. <code>crabbox ssh</code> prints an SSH command;\nuse <code>eval \"$(crabbox ssh ...)\"</code> to connect. After login, <code>cd</code> into the workdir\nprinted by <code>run --sync-only</code>.</p>\n<p>Use static SSH for existing machines:</p>\n<pre><code>crabbox run --provider ssh --target macos --static-host mac.example.com -- xcodebuild test\ncrabbox run --provider ssh --target windows --windows-mode normal --static-host win.example.com -- dotnet test\n</code></pre>\n<p>Static hosts are host-managed: Crabbox does not provision or delete them.</p>\n<h2>Useful Commands</h2>\n<pre><code>crabbox providers\ncrabbox providers --json\ncrabbox doctor\ncrabbox config path\ncrabbox config show\ncrabbox whoami\ncrabbox sync-plan\ncrabbox warmup --class beast\ncrabbox prewarm\ncrabbox status --id &lt;lease&gt; --wait\ncrabbox heartbeat --id &lt;lease&gt; --idle-timeout 90m\ncrabbox inspect --id &lt;lease&gt; --json\ncrabbox run --id &lt;lease&gt; --preflight --timing-json -- pnpm test\ncrabbox job list\ncrabbox job run --dry-run &lt;job-name&gt;\ncrabbox pool ready\ncrabbox history --lease &lt;lease&gt;\ncrabbox events &lt;run_id&gt; --json\ncrabbox attach &lt;run_id&gt;\ncrabbox logs &lt;run_id&gt;\ncrabbox results &lt;run_id&gt;\ncrabbox cache stats --id &lt;lease&gt;\ncrabbox cache volumes\ncrabbox ssh --id &lt;lease&gt;\ncrabbox connect &lt;lease&gt;\ncrabbox ports --id &lt;lease&gt; --publish 8080\ncrabbox cp --id &lt;lease&gt; ./coverage.xml SANDBOX:/tmp/coverage.xml\ncrabbox webvnc --id &lt;lease&gt; --open\ncrabbox code --id &lt;lease&gt; --open\ncrabbox egress start --id &lt;lease&gt; --profile discord --daemon\ncrabbox desktop doctor --id &lt;lease&gt;\ncrabbox desktop proof --id &lt;lease&gt; --output artifacts/&lt;slug&gt;-proof -- ./scripts/visual-smoke.sh\ncrabbox artifacts collect --id &lt;lease&gt; --all --output artifacts/&lt;slug&gt;\ncrabbox artifacts publish --dir artifacts/&lt;slug&gt; --pr &lt;number&gt; --dry-run\ncrabbox usage --scope org\ncrabbox pause &lt;lease&gt;\ncrabbox resume &lt;lease&gt;\ncrabbox stop &lt;lease&gt;\n</code></pre>\n<h2>Failure Triage</h2>\n<ul>\n<li>Provider missing or old CLI: verify <code>crabbox --help</code> and <code>crabbox providers</code>\nlist the provider, then rebuild or install a current binary.</li>\n<li>Bad local config: compare <code>crabbox config show</code>, pass <code>--provider ...</code>\nexplicitly, and run <code>crabbox doctor</code>.</li>\n<li>Sync surprise: run <code>crabbox sync-plan</code>, add excludes, then retry with\n<code>--debug --timing-json</code> or <code>--full-resync</code>.</li>\n<li>Raw box missing Node/pnpm/Docker: use <code>--preflight</code>; hydrate first if the\nrepo has an Actions workflow, or include setup in the command/script.</li>\n<li>Command failed: keep the <code>run_...</code> handle, inspect <code>results</code>, then rerun the\nfocused failing shard/file before a full suite.</li>\n<li>Desktop unhealthy: run <code>desktop doctor</code>, then follow <code>problem:</code> / <code>rescue:</code>\noutput from <code>webvnc status</code> or <code>webvnc reset</code>.</li>\n<li>Cleanup uncertain: use <code>crabbox list</code>, <code>crabbox inspect --json</code>, and only\nstop leases or provider resources you created.</li>\n<li>Broker/auth confusion: use <code>crabbox doctor</code>, <code>crabbox whoami</code>, and\n<code>crabbox config show</code> before asking for cloud credentials.</li>\n</ul>\n<h2>Cleanup</h2>\n<p>Brokered leases have coordinator-owned idle expiry and local lease claims.\nDefault idle timeout is 30 minutes unless config or flags set a different\nvalue. Still stop boxes you created when done:</p>\n<pre><code>crabbox stop &lt;cbx_id-or-slug&gt;\n</code></pre>\n<p>When <code>crabbox list</code> prints <code>orphan=no-active-lease</code>, treat it as an operator\nreview hint: verify the provider machine is not referenced by an active\ncoordinator lease before deleting anything, especially if <code>keep=true</code> is set.</p>\n","files":[{"path":"SKILL.md","sizeBytes":19464,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-08-30T09:02:16.679861Z","sha256":"5CA3D9729773CCDD1FB4CA1D8DC9A6734CA697CE98A408DEC32366563209E5EF","sizeBytes":7351},"review":null,"source":{"repositoryUrl":"https://github.com/openclaw/crabbox","path":"skills/crabbox","license":"MIT","commit":"2e04f7e2f43c7b21b13e81de736725da08944bca","subtreeSha":"F7A002AB604EAA49A3610FB46D3EB17791564CE9F5F56CD541720A6E61F1F93C","lastSyncedAt":"2026-09-27T19:33:28.151774Z"},"reviewedAt":"2026-08-30T09:07:53.87837Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/openclaw/crabbox/tree/main/skills/crabbox"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install openclaw-crabbox@llmmart"},{"target":"git","command":"git clone https://github.com/openclaw/crabbox.git"}]}