35# Coding Agent
36
37Use for background feature builds, PR reviews, large refactors, and issue-to-PR loops. Do not use for simple edits, read-only lookup, ACP thread-bound work, or any run inside ~/.openclaw, $OPENCLAW_STATE_DIR, or active OpenClaw state dirs.
38
39## Hard rules
40
41- Always launch with background:true.
42- Codex and OpenCode: use pty:true.
43- Codex: never inherit ambient CODEX_HOME or the default ~/.codex. Use a
44 separately authenticated coding-agent home and scope it to each Codex command.
45- Claude Code: no PTY; use claude --permission-mode bypassPermissions --print.
46- Capture a real notification route before spawning.
47- Worker must send completion/failure via openclaw message send.
48- Do not rely on heartbeat, system events, or notify-on-exit.
49- Monitor with process; do not kill slow workers without cause.
50- If user asked for a specific agent, use that agent.
51- If worker fails/hangs, respawn or ask; do not silently hand-code instead.
52- Never checkout branches or run background coding agents in ~/Projects/openclaw; use an isolated checkout.
53- Classify the source ref as trusted or untrusted before any checkout or worktree creation. Never materialize a contributor-controlled ref outside the repository's approved untrusted-PR sandbox/review workflow, and never launch a permission-bypassed worker in it.
54- For tasks that modify a Git-backed project, prepare and verify the Git worktree before launch, then include the exact Git preparation block below in the worker prompt.
55
56## Mandatory Git preparation
57
58Before launching Codex, Claude Code, or OpenCode for work that modifies a Git-backed project:
59
601. Establish the intended target repository, then select its canonical remote. Prefer upstream when it exists and matches that target; otherwise verify origin. Resolve the selected remote's default branch dynamically. Determine the target base from an explicit task branch or authoritative existing-PR metadata; for other shared branches, prove the configured/tracked base or ask. Use the canonical default only for new work with no other specified base. Stop if the repository, remote, or target base cannot be proven.
612. Classify the source ref as trusted or untrusted before any checkout or worktree creation. For contributor-controlled refs, use the repository's approved untrusted-PR sandbox/review workflow, which must own ref materialization inside the sandbox, or stop. The remaining steps and launch forms are for trusted refs only.
623. For trusted new work, run git fetch --prune <canonical> immediately before creating a new isolated worktree and branch from <canonical>/<targetBaseBranch>.
634. For trusted new work, verify the worktree's initial HEAD equals the fetched target-base SHA. Record the canonical remote, canonical default branch, target base branch, base SHA, worktree path, and branch.
645. For a trusted existing PR or shared branch, fetch the canonical target base and source branch immediately before creating an isolated worktree from the fetched source branch. Record that source ref and starting SHA, report its divergence from the refreshed target base, and do not automatically rebase, merge, reset, force-push, or otherwise rewrite shared history.
656. Launch the worker in the isolated worktree, never the primary checkout. For OpenClaw, the primary checkout under ~/Projects/openclaw remains forbidden.
66
67For tasks that modify a Git-backed project, append this block to the worker prompt with real values:
68
69```text
70Git preparation (mandatory before edits):
71- canonical remote: <canonicalRemote>
72- canonical default branch: <canonicalDefaultBranch>
73- target base branch: <targetBaseBranch>
74- fetched target base SHA: <targetBaseSha>
75- preparation mode: <new work | existing PR/shared branch>
76- checkout trust: trusted
77- prepared source ref: <canonicalRemote/targetBaseBranch | fetched trusted source ref>
78- prepared start SHA: <preparedStartSha>
79- isolated worktree: <worktreePath>
80- working branch: <branch>
81- preparation receipt: <new work: git fetch --prune <canonicalRemote> ran immediately before creation from <canonicalRemote>/<targetBaseBranch> | existing branch: the canonical target base and trusted source ref were fetched immediately before the worktree was created from <preparedSourceRef> at <preparedStartSha>>
82
83Before editing, verify the current directory is the isolated worktree and its initial HEAD equals <preparedStartSha>. For new work, that SHA must equal <targetBaseSha>. Never edit the primary checkout. For existing PR/shared-branch work, report divergence and do not rebase, merge, reset, force-push, or otherwise rewrite shared history unless explicitly asked.
84Immediately before the final push or PR for newly authored work, run git fetch --prune <canonicalRemote> and git merge-base --is-ancestor <canonicalRemote>/<targetBaseBranch> HEAD. If the ancestry check fails, update the new branch onto the latest target base, rerun the relevant proof, and only then push without force. For existing PR/shared-branch work, report a failed ancestry check and follow the repository workflow without rewriting the branch.
85```
86
87For trusted refs, the launcher must create and verify the worktree before starting the editing worker; do not delegate worktree creation to that worker. The approved untrusted-PR workflow must instead own checkout and worktree materialization inside its sandbox. Never start a worker in ~/Projects/openclaw. Read-only tasks and non-project scratch work do not require the Git preparation block.
88
89## Notification block
90
91Append this shape to every worker prompt with real values:
92
93```text
94Notification route:
95- channel: <notifyChannel>
96- target: <notifyTarget>
97- account: <notifyAccount or omit>
98- reply_to: <notifyReplyTo or omit>
99- thread_id: <notifyThreadId or omit>
100
101When finished, send exactly one completion or failure message using:
102openclaw message send --channel <channel> --target '<target>' --message '<brief result>'
103Add --account, --reply-to, or --thread-id only when present above.
104Do not use openclaw system event or heartbeat.
105```
106
107If no trustworthy route exists, say completion auto-notify is unavailable.
108
109## Launch forms
110
111Write the worker prompt to a temp file first. This avoids shell quoting bugs when the required notification block contains quotes or newlines.
112
113```bash
114PROMPT=$(mktemp -t openclaw-worker-prompt.XXXXXX)
115cat >"$PROMPT" <<'EOF'
116Task.
117<mandatory Git preparation block>
118<notification block>
119EOF
120printf 'prompt file: %s\n' "$PROMPT"
121```
122
123Use $PROMPT when launching from the same shell/session. If using a separate tool call, substitute the printed path. The launch forms below are for trusted checkouts only; untrusted contributor refs require the repository's approved sandbox/review workflow.
124
125Before the first Codex worker on a host, prepare a dedicated auth home in the
126foreground. Do not copy auth.json or other credentials from ambient
127~/.codex; authorize this home separately. Codex scopes both file and keyring
128credentials by CODEX_HOME.
129
130```bash
131CODEX_WORKER_HOME="$HOME/.codex-coding-agent"
132mkdir -p "$CODEX_WORKER_HOME"
133if ! env -u CODEX_API_KEY -u CODEX_ACCESS_TOKEN -u OPENAI_API_KEY \
134 CODEX_HOME="$CODEX_WORKER_HOME" codex login status >/dev/null 2>&1; then
135 printf 'Codex coding-agent login required for %s\n' "$CODEX_WORKER_HOME"
136 env -u CODEX_API_KEY -u CODEX_ACCESS_TOKEN -u OPENAI_API_KEY \
137 CODEX_HOME="$CODEX_WORKER_HOME" codex login --device-auth
138fi
139printf 'Codex worker home: %s\n' "$CODEX_WORKER_HOME"
140```
141
142The login is an interactive foreground setup step, not a background worker.
143The launch command repeats the fixed, quoted home and removes ambient Codex and
144OpenAI auth overrides. Never export the worker home into the OpenClaw Gateway
145environment.
146
147Codex:
148
149```bash
150bash pty:true background:true workdir:/path/isolated-worktree command:"env -u CODEX_API_KEY -u CODEX_ACCESS_TOKEN -u OPENAI_API_KEY CODEX_HOME=\"$HOME/.codex-coding-agent\" codex exec - < \"$PROMPT\""
151```
152
153Claude Code:
154
155```bash
156bash background:true workdir:/path/isolated-worktree command:"claude --permission-mode bypassPermissions --print < \"$PROMPT\""
157```
158
159OpenCode:
160
161```bash
162bash pty:true background:true workdir:/path/isolated-worktree command:"opencode run < \"$PROMPT\""
163```
164
165## Long issue-to-PR work
166
1671. Create/reuse a GitHub issue as durable spec.
1682. Include issue URL, repo, canonical remote/default branch, target base branch/SHA, isolated worktree, working branch, expected PR, proof, and notification route.
1693. Include the mandatory Git preparation block, then tell the worker to implement, test, run review until no accepted actionable findings, and open the PR.
1704. Return issue URL and sessionId immediately.
1715. Monitor with process; cancel through Task Registry if mirrored there.
172
173## Scratch Codex
174
175Codex needs a trusted git repo. This throwaway scaffold is not project work and has no canonical remote, so the Git preparation block does not apply:
176
177```bash
178SCRATCH=$(mktemp -d)
179git -C "$SCRATCH" init
180PROMPT=$(mktemp -t openclaw-worker-prompt.XXXXXX)
181cat >"$PROMPT" <<'EOF'
182Build X.
183<notification block>
184EOF
185printf 'prompt file: %s\n' "$PROMPT"
186bash pty:true background:true workdir:$SCRATCH command:"env -u CODEX_API_KEY -u CODEX_ACCESS_TOKEN -u OPENAI_API_KEY CODEX_HOME=\"$HOME/.codex-coding-agent\" codex exec - < \"$PROMPT\""
187```
188
189## Process actions
190
191- list: running/recent sessions.
192- poll: status.
193- log: output.
194- submit: send input + Enter.
195- write: raw stdin.
196- paste: paste text.
197- kill: terminate.
198
199## Status to user
200
201- Say what started, where, and sessionId.
202- Update only on milestone, worker question, error, user action needed, or finish.
203- If killed, say why.
204