Token导航 LogoToken导航TokenDH.com
研究检索敏感数据clawhub未标认证来源可访问clear审计提醒

soulflowsoulflow 开发

Agent Skill

soulflow 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

28,704

周安装

1,233

GitHub Stars

公开资料未说明

下载量

10,061
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:soulflow(soulflow 开发)
来源仓库:https://github.com/0xtommythomas-dev/soulflow
安装命令:
openclaw skills install soulflow
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install soulflow

简介

OpenClaw 的通用 AI 工作流程框架。为任何任务(开发、运营、研究、内容或自动化)构建自定义多步骤工作流程。附带开发工作流程示例。

SKILL.md

name
soulflow
description
General-purpose AI workflow framework for OpenClaw. Build custom multi-step workflows for any task — dev, ops, research, content, or automation. Ships with dev workflow examples.
homepage
https://github.com/0xtommythomas-dev/soulflow
metadata
clawdbot
emoji
⚙️
requires
bins
["node"]
config_files
permissions
config
read
["~/.openclaw/openclaw.json"]
write
["~/.openclaw/openclaw.json"]
gateway
modify
agents
create
filesystem
read
["~/.openclaw/workspace"]
write
["~/.openclaw/workspace/.soulflow", "~/.openclaw/agents/soulflow-worker"]
credentials
inherit
security_note
Creates a dedicated 'soulflow-worker' agent with full tool access (read, write, edit, exec, browser) to execute workflow steps. Reads gateway config (~/.openclaw/openclaw.json) for authentication token. Modifies gateway config to add/manage worker agent. Worker inherits authProfiles from existing agents (grants access to external services like GitHub, cloud providers). All operations run locally with your existing OpenClaw permissions. Only install if you trust the skill author and have reviewed the code.

SoulFlow — Workflow Framework for OpenClaw

A framework for building custom AI workflows. Each workflow is a series of steps that execute in isolated agent sessions with full tool access. Define your workflow in JSON, invoke it naturally, and let the agents handle the execution.

What you can build:

  • Development pipelines (security audits, bug fixes, feature development)
  • Content workflows (research → draft → edit → publish)
  • Operations automation (deploy → verify → rollback-on-fail)
  • Research pipelines (gather → analyze → synthesize → report)
  • Any multi-step task that benefits from isolated, focused agent sessions

Ships with 3 example dev workflows to show you how it works. Build your own for anything.

Quick Start

Natural language (easiest): Just tell your agent what you need:

  • "Run a security audit on my project at ~/myapp"
  • "Fix this bug: users can't login with Google OAuth in ~/webapp"
  • "Build a referral system for ~/webapp"

Your agent reads this SKILL.md and invokes SoulFlow automatically.

Command line:

cd ~/.openclaw/workspace/soulflow

# Run a security audit
node soulflow.js run security-audit "Audit the codebase at ~/project for vulnerabilities"

# Fix a bug
node soulflow.js run bug-fix "Login returns 500 when email has uppercase letters in ~/myapp"

# Build a feature
node soulflow.js run feature-dev "Add dark mode toggle to the settings page in ~/myapp"

How It Works

SoulFlow connects to your local OpenClaw gateway via WebSocket and runs each workflow step as an isolated agent session. A dedicated soulflow-worker agent is auto-created with minimal context — no memory bleed from your main agent.

Each step:

  1. Gets a fresh session (no context bloat)
  2. Receives the task + output from previous steps
  3. Has full tool access (read, write, edit, exec, browser)
  4. Must complete its work and report results

Auto-notifications (v1.1.0+): When workflows complete, SoulFlow automatically notifies the main agent session with results. No need to manually check status.

Example Workflows (Included)

These are examples to show what's possible. Build your own for any domain.

security-audit

Scan → Prioritize → Fix → Verify Development example: Reads your source files, identifies vulnerabilities by severity, applies fixes, then verifies them.

bug-fix

Triage → Fix → Verify Development example: Investigates the root cause by reading code, applies the fix, then verifies it didn't introduce regressions.

feature-dev

Plan → Implement → Review Development example: Architects the implementation plan, writes the code, then reviews for quality and correctness.

Want content workflows? Research pipelines? Deploy automation? Create your own .workflow.json — see Custom Workflows below.

Commands

node soulflow.js run <workflow> "<task>"    # Run a workflow
node soulflow.js list                       # List available workflows
node soulflow.js runs                       # List past runs
node soulflow.js status [run-id]            # Check run status
node soulflow.js test                       # Test gateway connection

Natural Language (via your agent)

The agent knows how to invoke SoulFlow for you. Just describe what you want:

Security audits:

  • "Audit my app for security issues"
  • "Check ~/myapp for vulnerabilities"
  • "Scan the codebase for security problems"

Bug fixes:

  • "Fix this bug: login fails when..."
  • "There's a problem with the payment flow"
  • "Users are seeing 500 errors when they..."

Features:

  • "Build a referral system"
  • "Add dark mode to the settings page"
  • "Implement OAuth login with Google"

How it works:

  1. You tell your agent what you need
  2. Your agent reads this SKILL.md
  3. Agent invokes node soulflow.js run <workflow> "<task>"
  4. SoulFlow runs the workflow and reports back

Pattern matching: The agent matches your message to workflows:

  • Security audit → keywords: "audit", "security", "scan", "vulnerabilit"
  • Bug fix → keywords: "fix", "bug", "broken", "not working", "error"
  • Feature dev → keywords: "build", "add", "implement", "create", "feature"

No workflow matches? Agent will ask which workflow you want or suggest creating a custom one.

Custom Workflows

You can create workflows for ANY task. Define them in JSON and place in the workflows/ directory.

Creating via Chat

Tell your agent:

"Create a SoulFlow workflow for [your use case]"

Examples:

  • "Create a workflow for content publishing: research topic → draft article → edit → publish to blog"
  • "Create a workflow for deployment: run tests → build → deploy → verify health checks → rollback if failed"
  • "Create a workflow for weekly reports: gather metrics → analyze trends → generate summary → send email"

Your agent will:

  1. Design the workflow steps
  2. Write the .workflow.json file to workflows/
  3. Show you how to run it

Manual Creation

Create a .workflow.json file in the workflows/ directory:

{
  "id": "my-workflow",
  "name": "My Custom Workflow",
  "version": 1,
  "description": "What this workflow does",
  "steps": [
    {
      "id": "step1",
      "name": "First Step",
      "input": "Do this thing: {{task}}",
      "expects": "STATUS: done",
      "maxRetries": 1
    },
    {
      "id": "step2",
      "name": "Second Step",
      "input": "Now do this based on step 1:\
\
{{step1_output}}\
\
Original task: {{task}}",
      "expects": "STATUS: done",
      "maxRetries": 1
    }
  ]
}

Variables

  • {{task}} — The user's original task description
  • {{stepid_output}} — Full output from a previous step (e.g. {{scan_output}})
  • Any KEY: value lines in step output become variables (e.g. ROOT_CAUSE: ...{{root_cause}})

Prompt Tips

For best results, write prompts that:

  • Explicitly tell the agent to use tools: "Use read to examine the file", "Use edit to apply the fix"
  • Say "Do NOT just describe — actually do it"
  • End with "When done, end with: STATUS: done"

Architecture

  • Zero dependencies — Pure Node.js 22 (native WebSocket)
  • Gateway-native — Connects via WebSocket with challenge-response auth
  • Session isolation — Each step in a fresh session
  • Dedicated worker — Auto-creates soulflow-worker agent with minimal brain files
  • JSON state — Run history saved to ~/.openclaw/workspace/.soulflow/runs/
  • 10-minute timeout per step (configurable)

Requirements

  • OpenClaw 2026.2.x or later
  • Node.js 22+ (for native WebSocket)
  • Gateway with token auth configured

Security & Permissions

What SoulFlow does to your OpenClaw instance:

  1. Reads your gateway config (~/.openclaw/openclaw.json) to obtain the authentication token needed to connect via WebSocket
  2. Modifies your gateway config (~/.openclaw/openclaw.json) via config.patch to register the soulflow-worker agent
  3. Creates a dedicated worker agent (soulflow-worker) with minimal brain files (SOUL.md only, no memory/history)
  4. Copies authProfiles from existing agents — Worker inherits credentials for external services (GitHub, cloud providers, etc.) that your other agents use
  5. Grants the worker full tool access (read, write, edit, exec, browser) — this is required for workflows to actually perform tasks
  6. Writes run state to ~/.openclaw/workspace/.soulflow/runs/ as JSON files

Why these permissions are needed:

  • Config read/write: Required to authenticate with the gateway and register the worker agent (same as openclaw CLI tool)
  • Agent creation: Each workflow step runs in an isolated session to prevent context bleed
  • authProfiles inheritance: Allows workflows to interact with external services (e.g., git push, cloud API calls) using your existing credentials
  • Full tools: Workflows need real capabilities (e.g., security-audit reads files, bug-fix edits code, deploy-pipeline pushes to git)
  • Filesystem write: Stores workflow history and allows workflows to create/modify files

Security considerations:

  • Worker agent has NO access to your main agent's memory or history
  • Worker DOES inherit your external service credentials (authProfiles) — can access GitHub, cloud APIs, etc.
  • Workflows run with YOUR permissions (same as running commands yourself)
  • Malicious workflows could read/modify files, run commands, or access external services
  • Only install SoulFlow if you trust the skill author (review code on GitHub first)
  • Only run workflows you trust — custom workflows from untrusted sources could exfiltrate data or misuse credentials
  • Run SoulFlow in isolated/sandboxed environments if processing untrusted workflows

Recommended practices:

  • Review built-in workflows before first use (especially security-audit and bug-fix)
  • Inspect custom .workflow.json files before running
  • Review GitHub repo (https://github.com/0xtommythomas-dev/soulflow) before installation
  • Run on non-production OpenClaw instances when testing new workflows
  • Back up important files before running workflows that modify code
  • Use BYOK (bring your own keys) mode if you want isolated credentials per workflow
  • Monitor ~/.openclaw/workspace/.soulflow/runs/ for workflow execution logs

For Agents: How to Invoke SoulFlow

When the user requests a workflow (security audit, bug fix, feature build, etc.), you should:

  1. Identify the workflow by matching keywords:

- Security audit: "audit", "security", "scan", "vulnerabilit" - Bug fix: "fix", "bug", "broken", "not working", "error" - Feature dev: "build", "add", "implement", "create", "feature" - Custom: check workflows/*.workflow.json for other options

  1. Extract the task description — the user's description of what they want done
  1. Invoke SoulFlow using exec:
   cd /root/.openclaw/workspace/soulflow && node soulflow.js run <workflow> "<task>"
  1. Monitor the run — SoulFlow will output the run ID, then show progress as each step completes
  1. Report results — When complete, relay the final status to the user

Example:

User: "Run a security audit on ~/myapp"
You: [exec] cd /root/.openclaw/workspace/soulflow && node soulflow.js run security-audit "Audit ~/myapp for vulnerabilities"

Creating workflows for users: If the user asks you to create a custom workflow:

  1. Design the workflow steps based on their requirements
  2. Write a .workflow.json file to /root/.openclaw/workspace/soulflow/workflows/
  3. Show them how to run it

See CONTRIBUTING.md for workflow design best practices.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

76.01%
按下载量换算7,647

安全审计

VirusTotal

可疑

ClawScan

可疑

Static analysis

未展示

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills