permission-vending-machineMulti-channel approval system for AI agent permissions. GATES sensitive operations (file deletion, git force-push) behind human approval. Notifies via iMessa...
Install via ClawdBot CLI:
clawdbot install tylerdotai/permission-vending-machineGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
sudo mvCalls external URL not in known-safe list
https://github.com/tylerdotai/permission-vending-machine.gitUses known external API (expected, informational)
slack.comGenerated May 22, 2026
A developer uses an AI agent to prune old code, delete temporary files, and force-push refactored branches. PVM ensures each destructive action is approved via iMessage or Discord before execution, preventing accidental data loss.
IT operations deploy AI agents to clean up logs, rotate backups, and remove obsolete files on production servers. PVM gates deletion commands, sending approval requests to the admin on-call via email or SMS.
A social media platform uses AI to flag and remove inappropriate content. PVM requires human approval before AI can delete posts or user data, ensuring compliance with content policies.
In a law firm, AI assists in archiving and deleting old case files. PVM notifies the managing partner via email for approval before any file is permanently removed from the cloud storage.
Sell annual licenses to companies that want to integrate PVM into their AI toolchain, offering priority support and custom channel integrations.
Charge per approval transaction or per active grant, ideal for SaaS platforms that embed PVM for end customers.
Offer the core PVM as open-source (free), with premium features like advanced audit logs, SSO, and dedicated channel bridges available via paid plan.
💬 Integration Tip
Start by configuring one approval channel (e.g., email) and using the CLI for manual tests before automating with the daemon.
Scored May 22, 2026
AI Analysis
The skill's core purpose is security-enhancing by gating destructive operations behind human approval, and its external API usage (Slack, Discord, email, etc.) is consistent with its stated multi-channel notification system. However, it requires users to configure sensitive credentials (IMAP passwords, API keys) in a local config file, creating a potential attack surface if the host system is compromised, but no evidence of hidden malicious instructions or data exfiltration exists.
Audited Apr 17, 2026 · audit v1.0
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.
Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentic...