--- name: tide-watch description: Proactive session capacity monitoring and management for OpenClaw. Prevents context window lockups by warning at configurable thresholds (75%, 85%, 90%, 95%), automatically backing up sessions before resets, and managing session resumption prompts. Use when working on long-running projects, managing multiple conversation channels (Discord, Telegram, webchat), or preventing lost work from full context windows. Includes CLI tools for capacity checks, cross-session dashboards, archive management, and session resumption. Supports any model or provider. author: Chris Giddings homepage: https://github.com/chrisagiddings/openclaw-tide-watch repository: https://github.com/chrisagiddings/openclaw-tide-watch metadata: {"openclaw":{"emoji":"🌊","version":"1.3.6","disable-model-invocation":false,"capabilities":["session-monitoring","capacity-warnings","session-backup","session-resumption","multi-agent-support","auto-detection","file-operations-local"],"requires":{"bins":[],"anyBins":["node"],"config":["~/.openclaw/agents/main/sessions/"],"env":{"optional":["OPENCLAW_SESSION_ID"],"notes":"OPENCLAW_SESSION_ID is optional for auto-detection in CLI mode (v1.3.4+). Not required for Directives-Only mode."}},"install":[{"id":"npm","kind":"node","package":".","command":"npm link","bins":["tide-watch"],"label":"Install tide-watch CLI (requires Node.js 14+, optional for Directives-Only mode)"}],"credentials":{"required":false,"types":[],"notes":"No external credentials required. Operates on local OpenClaw session files only."}}} --- # Tide Watch 🌊 Proactive session capacity monitoring for OpenClaw. ## ⚠️ Security & Architecture Notice **Tide Watch is a HYBRID SKILL with two operational modes:** ### Mode 1: Directives-Only (Recommended for Most Users) **Description:** AGENTS.md and HEARTBEAT.md directives only **Code Execution:** **NONE** - Uses OpenClaw's built-in tools only (no CLI installation) **File Access:** Reads OpenClaw session files via agent's built-in tools **Installation:** Copy template directives to workspace config files **Security:** Lowest risk - no code installation or execution required **What it does:** - ✅ Monitors session capacity via `session_status` tool - ✅ Warns at thresholds (75%, 85%, 90%, 95%) - ✅ Auto-loads resumption prompts on session reset - ✅ All operations through OpenClaw's native tools ### Mode 2: CLI Tools (Optional) **Description:** Node.js command-line tools for manual management **Code Execution:** **YES** - Executable JavaScript code **File Access:** Direct read/write to `~/.openclaw/agents/main/sessions/` **Installation:** `git clone` + `npm link` (requires Node.js) **Security:** Moderate risk - requires code inspection before install **What it does:** - CLI commands: `tide-watch status`, `tide-watch dashboard`, etc. - Manual capacity checks - Session archive management - Resumption prompt editing (⚠️ see CVE-2026-001 below) ### Mode Comparison | Feature | Directives-Only | CLI Tools | |---------|-----------------|-----------| | **Node.js required?** | ❌ No | ✅ Yes (14+) | | **Installation** | Copy templates | `npm link` | | **Code execution** | ❌ None | ✅ JavaScript | | **File access** | Via built-in tools | Direct filesystem | | **Security risk** | Lowest | Moderate | | **Use case** | Passive monitoring | Active management | **Choose Directives-Only if:** You only need capacity warnings and resumption prompts. **Choose CLI Tools if:** You need manual session management, archiving, or dashboard views. ### 🚨 CRITICAL SECURITY NOTICE: CVE-2026-001 **Vulnerability:** Shell injection in `editResumePrompt` function **Affected Version:** v1.0.0 ONLY **Current Version:** v1.0.1 (PATCHED) **Severity:** HIGH (CVSS 7.8) **Status:** ✅ FIXED **Summary:** v1.0.0 contained a shell injection vulnerability in the CLI's `resume-prompt edit` command. An attacker who could control the `--session` parameter could execute arbitrary commands. **This has been fixed in v1.0.1** by replacing `execSync` with `spawnSync`. **If you installed v1.0.0:** **Update immediately** to v1.0.1. **Full disclosure:** See [SECURITY-ADVISORY-CVE-2026-001.md](./SECURITY-ADVISORY-CVE-2026-001.md) ### Security Best Practices **For Directives-Only Mode (Safest):** 1. ✅ Copy AGENTS.md.template and HEARTBEAT.md.template to workspace 2. ✅ No code installation required 3. ✅ No npm dependencies 4. ✅ Lowest security surface **For CLI Tools Mode (If Needed):** 1. ⚠️ **Verify version 1.0.1 or later** (`tide-watch --version`) 2. ⚠️ **Inspect code before installing:** - Review `lib/capacity.js` and `lib/resumption.js` - Check `package.json` for install hooks (should have none) - Run `npm test` to verify behavior (113 tests) 3. ⚠️ **Only use UUID session IDs** with `--session` flag 4. ⚠️ **Avoid untrusted input** to CLI commands 5. ⚠️ **Review backups location** (`~/.openclaw/agents/main/sessions/archive/`) **Operation Types:** **Read-Only Operations** (✅ Safe, no modifications): - `tide-watch status` - Check current session count - `tide-watch check --session ` - View specific session capacity - `tide-watch check --current` - Auto-detect and check current session (v1.3.4+) - `tide-watch dashboard` - Visual capacity overview - `tide-watch dashboard --watch` - Live updating dashboard - `tide-watch dashboard --raw-size` - Show full precision token counts (v1.3.2+) - `tide-watch report` - List sessions above threshold - `tide-watch resume-prompt show --session ` - View resumption prompt **Modifying Operations** (⚠️ Moves/creates files): - `tide-watch archive --older-than