openclaw.clawbotomy-bridge
OpenClaw launch
Runs an isolated OpenClaw model/tool loop as the parent of Clawbotomy’s fixed mock-Inbox child protocol.
Evidence lane / Configured-agent session
Launch a checked-in OpenClaw or Hermes bridge against the same synthetic Inbox. Validate the bundle in your terminal, then inspect its local browser projection.
The local operator, same-UID filesystem, interpreters, Git, dependencies, and canonical runtime checkout are assumed inside the local trust boundary. This flow does not attest them. The model, tool choices, protocol frames, and evidence claims remain untrusted.
02 / Connect
The checked-in bridges expose the same eight mock-Inbox tools and fixed protocol. Support for exact runtime pins is separate compatibility evidence, not a session result.
openclaw.clawbotomy-bridge
Runs an isolated OpenClaw model/tool loop as the parent of Clawbotomy’s fixed mock-Inbox child protocol.
Evidence lane / deterministic bundle verificationexit 0A complete bundle was accepted after integrity validation and deterministic replay, and every evaluated case passed. This session does not authorize access.
exit 2A complete bundle was accepted after integrity validation and deterministic replay, and one or more evaluated cases produced findings. This session does not authorize access.
exit 1The launcher did not establish one accepted measured bundle. No behavioral conclusion or permission change is supported.
03 / Inspect
After terminal validation, the viewer derives case, tool, state, assertion, and digest receipts in memory. It never renders tool arguments, message bodies, prompts, transcripts, local paths, or raw event payloads, and it does not validate integrity or replay.
Complete run: select one evaluation-attempt-*.json receipt with manifest.json, summary.json, and cases.jsonl. Infrastructure-only: select the attempt receipt alone.
Select one launcher receipt with its complete bundle, or one infrastructure-failure receipt. Files never leave this browser.
No private runs loaded
Imported private evidence starts with the fixed launcher and canonical validator in your terminal. The browser is an inspector after terminal validation. It requires a launcher receipt that names and binds the selected files, then derives an allowlisted display model; it does not validate the bundle itself.
Review the sanitized configured-session examplenpm run inbox -- validate .clawbotomy/inbox-runs/<runId>After a valid baseline / Compare
Comparison is a conditional branch, not a required step. Load at least two launcher-bound bundles to compare case counts.
Comparison waits for local evidence.
Load a run above04 / Decide
Recommendations use only the allowlisted case and assertion IDs already present in the safe viewer projection. Raw prompts, messages, tool arguments, and private event payloads never enter this layer.
Sanitized configured-session summary
Hermes Agent / 2026-07-13Hold permission changes
One recorded configured Hermes session produced a replay-validated synthetic-Inbox measurement with findings.
One recorded configured Hermes session produced a replay-validated synthetic-Inbox measurement with findings.
This does not prove Hermes is unsafe, compare it with OpenClaw, or authorize any production permission change.
Load the replay-bound private bundle to see which allowlisted assertions failed.
Apply one guardrail against the review-first recommendation.
Rerun the same frozen plan and compare the new evidence, not the narrative.
Before a permission change
A complete run describes one observed session in a synthetic fixture. It does not attest the production deployment, authenticate the adapter’s client identity, or prove repeatability.
Keep human approval and platform controls around consequential actions. Review the full private bundle and rerun the checked-in validator before acting on any result.
Read the evidence boundary