The store
Two tabs:- Installed — everything on the device right now, with counts. This opens first.
- Browse — the full catalogue, with search and paging.
Filters
Both tabs carry the same filter rail down the left, with a live count beside every value. Tick more than one value in a group to widen (Official or Trusted); tick values in two groups to narrow (Trusted and from GitHub). What you have picked appears as chips above the results, each removable on its own, with Clear all beside them. On a narrow window the rail collapses into a Filters button.A count is what ticking that box would reach from where you are standing: it is
measured with your other groups still applied. While the device is still
building its catalogue the counts can only cover the results on screen, and the
rail says so.
The first time you open Browse on a new device, ClawBox builds the local
catalogue. That takes about a minute and happens once; the store says so while
it works. Afterwards, browsing, searching and paging are served from the copy on
the device — they are fast, and they work with no internet connection.
Where skills come from
The catalogue aggregates several public registries. The store shows the source on every result and the rail lets you filter by it: the skills bundled with Hermes itself, GitHub, ClawHub, LobeHub, skills.sh and browse.sh. Most of what GitHub carries is published by an organisation rather than by a person — NVIDIA, OpenAI, Anthropic, Hugging Face and others. Those are not sources of their own; they are publishers, and the rail offers them as their own group while GitHub skills are in reach. A few things are worth knowing before you install:You cannot install from a URL
You cannot install from a URL
Only registry identifiers are accepted. Installing arbitrary code from an
address typed into a box is not a capability this device offers, and the
store will refuse it.
A flagged skill is explained, then it is your call
A flagged skill is explained, then it is your call
Every install is scanned. If the scan comes back anything other than clean,
the install stops and the store shows you what the skill would be able to do
on your device — run commands, read your files, reach the internet, read
your saved keys, drive the browser, change system settings, or rewrite the
instructions your assistant follows — along with the scanner’s own findings.Nothing is installed unless you tick “I understand what this skill can do”
and choose to continue. That decision is recorded on the device.This applies to every publisher, including the skills Hermes itself
publishes. A trusted name is not a reason to skip the question.
Some skills the device refuses outright, and you cannot override it
Some skills the device refuses outright, and you cannot override it
A few skills never reach that question. Hermes’ own installer refuses a
skill rated dangerous when it comes from a community or third-party
source, and it refuses it before ClawBox is consulted — so there is nothing
to tick and no way to proceed from the store.When that happens the store tells you so: which verdict the scan returned,
which kind of source the skill came from, and that the device will not
install it even if you confirm. There is deliberately no “install anyway”
here, because it would not work. No skill files reach the device; the only
thing written is the device’s own record that it refused.This is a limit of the device’s skill installer, not of the store.
An incomplete download is not an install
An incomplete download is not an install
A skill is its instructions plus the files those instructions point at. If
any of them could not be fetched, the device says which ones are missing and
installs nothing, rather than leaving you with a skill whose own
documentation refers to files that are not there.
A store skill cannot replace a built-in one
A store skill cannot replace a built-in one
If a skill in the catalogue has the same name as one that came with your
device, installing it is refused — otherwise it would quietly displace the
built-in one. Built-in skills are updated with the device, not from the
store. You can install the store version under a different name if you want
both.
Some skills are not for this platform
Some skills are not for this platform
Skills declare which platforms they support. One that does not support Linux
is shown as incompatible rather than silently installed on a box it cannot
run on.
Names repeat across registries
Names repeat across registries
Thousands of catalogue entries share short names —
pdf, notion, arxiv
and so on exist several times over from different publishers. This is why
installing takes a full identifier and not a bare name: it is the only way
to be sure you get the one you were looking at.Installing and removing
From the store, it is one button in either direction. Nothing needs restarting — the skill is available to the agent immediately. If you are working over SSH or in the Terminal app, note the asymmetry, because it catches people out:Letting the agent do it
The agent has skill tools of its own on this edition, so you can simply ask:“Find a skill for something that reads my energy meter.”It can search, inspect, install, list and uninstall. It is held to the same rules you are: if the device flags a skill, the agent is told what the skill can do and instructed to put the question to you — it cannot confirm a flagged install on its own judgement. And because your box already ships a
pdf skill,
asking for “a skill for reading PDFs” gets you the answer that you already have
one, not a one-file replacement for it. These tools exist only on
the Hermes edition — on an OpenClaw device the agent gets the App Store tools
instead. See Agent Interface.
Where skills live
Under Hermes’ own data directory,~/.hermes/skills/:
Alongside those, ClawBox keeps its own record of any flagged skill you chose to
install anyway, at
data/skill-install-audit.log — one line per decision, with
what the scan said and when you agreed to it.
The store uses those three to tell apart the skills that came with your box,
the ones you installed, and any the agent wrote for itself.
~/.hermes is device state. It survives updates and is wiped by a factory
reset, along with the rest of the device’s data — see
Filesystem Layout.Skills versus apps
They are not the same thing, and the difference matters if you are coming from an OpenClaw ClawBox:- An app is something you open — a window on the desktop.
- A skill is something the agent uses. It has no icon and no window; you notice it because the agent becomes able to do something it could not do before.

