diff --git a/AGENTS.md b/AGENTS.md
index 44b0149fd..f1be79e42 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -1,7 +1,25 @@
-# Repository Guidelines
+# CLAUDE.md
+
+This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
+
- Repo: https://github.com/moltbot/moltbot
- GitHub issues/comments/PR comments: use literal multiline strings or `-F - <<'EOF'` (or $'...') for real newlines; never embed "\\n".
+## Architecture Overview
+
+Moltbot is a local-first personal AI assistant that bridges messaging channels to AI agents.
+
+**Message flow:** Inbound message (WhatsApp, Telegram, Slack, etc.) → Gateway WebSocket server (`src/gateway/server.ts`) → Channel plugin routes message → Pi agent runtime (`src/agents/pi-embedded-runner.ts`) executes tools (browser, bash, canvas, etc.) via gateway RPC → Final reply sent back through channel's outbound adapter.
+
+**Key subsystems:**
+- **Gateway** (`src/gateway/`): WebSocket control plane. Hosts sessions, routes messages, serves the Control UI, and exposes RPC methods for agent tool calls. Config is YAML-based (`~/.clawdbot/config.yaml`), hot-reloaded via chokidar.
+- **Agents** (`src/agents/`): Pi agent runtime. Manages LLM provider config, auth profiles, tool definitions, sandbox execution, and skill loading. Sessions are isolated per-agent/group as JSONL files under `~/.clawdbot/sessions/`.
+- **Channel plugins** (`src/channels/plugins/`): Unified `ChannelPlugin` interface with `inbound` (receive) and `outbound` (send) adapters. Core channels live in `src/` (discord, telegram, slack, signal, imessage, web/WhatsApp). Extension channels live in `extensions/*` as workspace packages.
+- **Dependency injection** (`src/cli/deps.ts`): `createDefaultDeps()` wires all channel send functions and services. Used throughout for testability.
+- **Plugin registry** (`src/plugins/runtime.ts`): Channels and extensions are runtime-registered (not statically imported). Access via `getActivePluginRegistry()`.
+
+**Apps:** macOS menu bar (SwiftUI, `apps/macos/`), iOS (`apps/ios/`), Android (Kotlin, `apps/android/`), shared Swift code in `apps/shared/MoltbotKit/`.
+
## Project Structure & Module Organization
- Source code: `src/` (CLI wiring in `src/cli`, commands in `src/commands`, web provider in `src/provider-web.ts`, infra in `src/infra`, media pipeline in `src/media`).
- Tests: colocated `*.test.ts`.
@@ -47,6 +65,7 @@
- Type-check/build: `pnpm build` (tsc)
- Lint/format: `pnpm lint` (oxlint), `pnpm format` (oxfmt)
- Tests: `pnpm test` (vitest); coverage: `pnpm test:coverage`
+- Run a single test file: `pnpm test -- src/path/to/file.test.ts`
## Coding Style & Naming Conventions
- Language: TypeScript (ESM). Prefer strict typing; avoid `any`.
diff --git a/README.md b/README.md
index ec970bb5b..85c58a239 100644
--- a/README.md
+++ b/README.md
@@ -1,7 +1,7 @@
# 🦞 Moltbot — Personal AI Assistant
-
+
@@ -52,6 +52,8 @@ moltbot onboard --install-daemon
The wizard installs the Gateway daemon (launchd/systemd user service) so it stays running.
Legacy note: `clawdbot` remains available as a compatibility shim.
+
+
## Quick start (TL;DR)
Runtime: **Node ≥22**.
diff --git a/docs/automation/cron-jobs.md b/docs/automation/cron-jobs.md
index b117ba827..46787670b 100644
--- a/docs/automation/cron-jobs.md
+++ b/docs/automation/cron-jobs.md
@@ -15,6 +15,8 @@ the right time, and can optionally deliver output back to a chat.
If you want *“run this every morning”* or *“poke the agent in 20 minutes”*,
cron is the mechanism.
+
+
## TL;DR
- Cron runs **inside the Gateway** (not inside the model).
- Jobs persist under `~/.clawdbot/cron/` so restarts don’t lose schedules.
diff --git a/docs/automation/webhook.md b/docs/automation/webhook.md
index 81565bd41..22a484b40 100644
--- a/docs/automation/webhook.md
+++ b/docs/automation/webhook.md
@@ -9,6 +9,8 @@ read_when:
Gateway can expose a small HTTP webhook endpoint for external triggers.
+
+
## Enable
```json5
diff --git a/docs/broadcast-groups.md b/docs/broadcast-groups.md
index d5e6b3ea0..7ebe6db80 100644
--- a/docs/broadcast-groups.md
+++ b/docs/broadcast-groups.md
@@ -17,6 +17,8 @@ Broadcast Groups enable multiple agents to process and respond to the same messa
Current scope: **WhatsApp only** (web channel).
+
+
Broadcast groups are evaluated after channel allowlists and group activation rules. In WhatsApp groups, this means broadcasts happen when Moltbot would normally reply (for example: on mention, depending on your group settings).
## Use Cases
diff --git a/docs/concepts/agent-loop.md b/docs/concepts/agent-loop.md
index 65572e4ed..e123cb18c 100644
--- a/docs/concepts/agent-loop.md
+++ b/docs/concepts/agent-loop.md
@@ -13,6 +13,8 @@ In Moltbot, a loop is a single, serialized run per session that emits lifecycle
as the model thinks, calls tools, and streams output. This doc explains how that authentic loop is
wired end-to-end.
+
+
## Entry points
- Gateway RPC: `agent` and `agent.wait`.
- CLI: `agent` command.
@@ -80,6 +82,8 @@ These run inside the agent loop or gateway pipeline:
See [Plugins](/plugin#plugin-hooks) for the hook API and registration details.
+
+
## Streaming + partial replies
- Assistant deltas are streamed from pi-agent-core and emitted as `assistant` events.
- Block streaming can emit partial replies either on `text_end` or `message_end`.
diff --git a/docs/concepts/agent-workspace.md b/docs/concepts/agent-workspace.md
index ace2ad4eb..3997e7f95 100644
--- a/docs/concepts/agent-workspace.md
+++ b/docs/concepts/agent-workspace.md
@@ -9,6 +9,8 @@ read_when:
The workspace is the agent's home. It is the only working directory used for
file tools and for workspace context. Keep it private and treat it as memory.
+
+
This is separate from `~/.clawdbot/`, which stores config, credentials, and
sessions.
diff --git a/docs/concepts/architecture.md b/docs/concepts/architecture.md
index e31becb34..95f66a2cd 100644
--- a/docs/concepts/architecture.md
+++ b/docs/concepts/architecture.md
@@ -21,6 +21,8 @@ Last updated: 2026-01-22
## Components and flows
+
+
### Gateway (daemon)
- Maintains provider connections.
- Exposes a typed WS API (requests, responses, server‑push events).
diff --git a/docs/concepts/channel-routing.md b/docs/concepts/channel-routing.md
index a6ecf9465..9dc857043 100644
--- a/docs/concepts/channel-routing.md
+++ b/docs/concepts/channel-routing.md
@@ -51,6 +51,8 @@ Routing picks **one agent** for each inbound message:
The matched agent determines which workspace and session store are used.
+
+
## Broadcast groups (run multiple agents)
Broadcast groups let you run **multiple agents** for the same peer **when Moltbot would normally reply** (for example: in WhatsApp groups, after mention/activation gating).
@@ -69,6 +71,8 @@ Config:
See: [Broadcast Groups](/broadcast-groups).
+
+
## Config overview
- `agents.list`: named agent definitions (workspace, model, etc.).
diff --git a/docs/concepts/compaction.md b/docs/concepts/compaction.md
index a01d35991..c70ee1ad9 100644
--- a/docs/concepts/compaction.md
+++ b/docs/concepts/compaction.md
@@ -8,6 +8,8 @@ read_when:
Every model has a **context window** (max tokens it can see). Long-running chats accumulate messages and tool results; once the window is tight, Moltbot **compacts** older history to stay within limits.
+
+
## What compaction is
Compaction **summarizes older conversation** into a compact summary entry and keeps recent messages intact. The summary is stored in the session history, so future requests use:
- The compaction summary
diff --git a/docs/concepts/memory.md b/docs/concepts/memory.md
index f2bca461a..9f831e974 100644
--- a/docs/concepts/memory.md
+++ b/docs/concepts/memory.md
@@ -9,6 +9,8 @@ read_when:
Moltbot memory is **plain Markdown in the agent workspace**. The files are the
source of truth; the model only "remembers" what gets written to disk.
+
+
Memory search tools are provided by the active memory plugin (default:
`memory-core`). Disable memory plugins with `plugins.slots.memory = "none"`.
diff --git a/docs/concepts/messages.md b/docs/concepts/messages.md
index 34ecc4c5b..b329648c2 100644
--- a/docs/concepts/messages.md
+++ b/docs/concepts/messages.md
@@ -20,6 +20,8 @@ Inbound message
-> outbound replies (channel limits + chunking)
```
+
+
Key knobs live in configuration:
- `messages.*` for prefixes, queueing, and group behavior.
- `agents.defaults.*` for block streaming and chunking defaults.
diff --git a/docs/concepts/model-failover.md b/docs/concepts/model-failover.md
index 9c2de352c..ee2b72896 100644
--- a/docs/concepts/model-failover.md
+++ b/docs/concepts/model-failover.md
@@ -13,6 +13,8 @@ Moltbot handles failures in two stages:
This doc explains the runtime rules and the data that backs them.
+
+
## Auth storage (keys + OAuth)
Moltbot uses **auth profiles** for both API keys and OAuth tokens.
diff --git a/docs/concepts/multi-agent.md b/docs/concepts/multi-agent.md
index a36bc3113..64abd49b8 100644
--- a/docs/concepts/multi-agent.md
+++ b/docs/concepts/multi-agent.md
@@ -9,7 +9,9 @@ status: active
Goal: multiple *isolated* agents (separate workspace + `agentDir` + sessions), plus multiple channel accounts (e.g. two WhatsApps) in one running Gateway. Inbound is routed to an agent via bindings.
-## What is “one agent”?
+
+
+## What is "one agent"?
An **agent** is a fully scoped brain with its own:
diff --git a/docs/concepts/queue.md b/docs/concepts/queue.md
index ca498d66b..a0420aad6 100644
--- a/docs/concepts/queue.md
+++ b/docs/concepts/queue.md
@@ -7,6 +7,8 @@ read_when:
We serialize inbound auto-reply runs (all channels) through a tiny in-process queue to prevent multiple agent runs from colliding, while still allowing safe parallelism across sessions.
+
+
## Why
- Auto-reply runs can be expensive (LLM calls) and can collide when multiple inbound messages arrive close together.
- Serializing avoids competing for shared resources (session files, logs, CLI stdin) and reduces the chance of upstream rate limits.
@@ -27,6 +29,8 @@ Inbound messages can steer the current run, wait for a followup turn, or do both
- `interrupt` (legacy): abort the active run for that session, then run the newest message.
- `queue` (legacy alias): same as `steer`.
+
+
Steer-backlog means you can get a followup response after the steered run, so
streaming surfaces can look like duplicates. Prefer `collect`/`steer` if you want
one response per inbound message.
diff --git a/docs/concepts/session.md b/docs/concepts/session.md
index b15b1a1ea..56733afc3 100644
--- a/docs/concepts/session.md
+++ b/docs/concepts/session.md
@@ -7,6 +7,8 @@ read_when:
Moltbot treats **one direct-chat session per agent** as primary. Direct chats collapse to `agent::` (default `main`), while group/channel chats get their own keys. `session.mainKey` is honored.
+
+
Use `session.dmScope` to control how **direct messages** are grouped:
- `main` (default): all DMs share the main session for continuity.
- `per-peer`: isolate by sender id across channels.
diff --git a/docs/concepts/streaming.md b/docs/concepts/streaming.md
index ecb149005..1cd9b1daf 100644
--- a/docs/concepts/streaming.md
+++ b/docs/concepts/streaming.md
@@ -13,6 +13,8 @@ Moltbot has two separate “streaming” layers:
There is **no real token streaming** to external channel messages today. Telegram draft streaming is the only partial-stream surface.
+
+
## Block streaming (channel messages)
Block streaming sends assistant output in coarse chunks as it becomes available.
diff --git a/docs/gateway/index.md b/docs/gateway/index.md
index 8c5be0fa8..68793df29 100644
--- a/docs/gateway/index.md
+++ b/docs/gateway/index.md
@@ -9,6 +9,9 @@ Last updated: 2025-12-09
## What it is
- The always-on process that owns the single Baileys/Telegram connection and the control/event plane.
+
+
+
- Replaces the legacy `gateway` command. CLI entry point: `moltbot gateway`.
- Runs until stopped; exits non-zero on fatal errors so the supervisor restarts it.
@@ -22,6 +25,8 @@ moltbot gateway --force
# dev loop (auto-reload on TS changes):
pnpm gateway:watch
```
+
+
- Config hot reload watches `~/.clawdbot/moltbot.json` (or `CLAWDBOT_CONFIG_PATH`).
- Default mode: `gateway.reload.mode="hybrid"` (hot-apply safe changes, restart on critical).
- Hot reload uses in-process restart via **SIGUSR1** when needed.
diff --git a/docs/gateway/protocol.md b/docs/gateway/protocol.md
index 66136bd8a..03bf59cd8 100644
--- a/docs/gateway/protocol.md
+++ b/docs/gateway/protocol.md
@@ -18,6 +18,8 @@ handshake time.
- WebSocket, text frames with JSON payloads.
- First frame **must** be a `connect` request.
+
+
## Handshake (connect)
Gateway → Client (pre-connect challenge):
diff --git a/docs/gateway/security/index.md b/docs/gateway/security/index.md
index a5d841c18..1c3fde0d3 100644
--- a/docs/gateway/security/index.md
+++ b/docs/gateway/security/index.md
@@ -5,6 +5,8 @@ read_when:
---
# Security 🔒
+
+
## Quick check: `moltbot security audit` (formerly `clawdbot security audit`)
See also: [Formal Verification (Security Models)](/security/formal-verification/)
@@ -35,6 +37,8 @@ Moltbot is both a product and an experiment: you’re wiring frontier-model beha
Start with the smallest access that still works, then widen it as you gain confidence.
+
+
### What the audit checks (high level)
- **Inbound access** (DM policies, group policies, allowlists): can strangers trigger the bot?
diff --git a/docs/images/diagrams/01-architecture.png b/docs/images/diagrams/01-architecture.png
new file mode 100644
index 000000000..df88113d5
Binary files /dev/null and b/docs/images/diagrams/01-architecture.png differ
diff --git a/docs/images/diagrams/02-agent-loop.png b/docs/images/diagrams/02-agent-loop.png
new file mode 100644
index 000000000..c0e7356ab
Binary files /dev/null and b/docs/images/diagrams/02-agent-loop.png differ
diff --git a/docs/images/diagrams/03-message-flow.png b/docs/images/diagrams/03-message-flow.png
new file mode 100644
index 000000000..346d33a4b
Binary files /dev/null and b/docs/images/diagrams/03-message-flow.png differ
diff --git a/docs/images/diagrams/04-ws-protocol.png b/docs/images/diagrams/04-ws-protocol.png
new file mode 100644
index 000000000..c73d123ac
Binary files /dev/null and b/docs/images/diagrams/04-ws-protocol.png differ
diff --git a/docs/images/diagrams/05-channel-routing.png b/docs/images/diagrams/05-channel-routing.png
new file mode 100644
index 000000000..be129bebf
Binary files /dev/null and b/docs/images/diagrams/05-channel-routing.png differ
diff --git a/docs/images/diagrams/06-multi-agent.png b/docs/images/diagrams/06-multi-agent.png
new file mode 100644
index 000000000..f9976979b
Binary files /dev/null and b/docs/images/diagrams/06-multi-agent.png differ
diff --git a/docs/images/diagrams/07-queue-lanes.png b/docs/images/diagrams/07-queue-lanes.png
new file mode 100644
index 000000000..4d096a10b
Binary files /dev/null and b/docs/images/diagrams/07-queue-lanes.png differ
diff --git a/docs/images/diagrams/08-queue-modes.png b/docs/images/diagrams/08-queue-modes.png
new file mode 100644
index 000000000..41047ab18
Binary files /dev/null and b/docs/images/diagrams/08-queue-modes.png differ
diff --git a/docs/images/diagrams/09-cron-jobs.png b/docs/images/diagrams/09-cron-jobs.png
new file mode 100644
index 000000000..959700792
Binary files /dev/null and b/docs/images/diagrams/09-cron-jobs.png differ
diff --git a/docs/images/diagrams/10-webhook.png b/docs/images/diagrams/10-webhook.png
new file mode 100644
index 000000000..f7417c37b
Binary files /dev/null and b/docs/images/diagrams/10-webhook.png differ
diff --git a/docs/images/diagrams/11-compaction.png b/docs/images/diagrams/11-compaction.png
new file mode 100644
index 000000000..44a065591
Binary files /dev/null and b/docs/images/diagrams/11-compaction.png differ
diff --git a/docs/images/diagrams/12-memory.png b/docs/images/diagrams/12-memory.png
new file mode 100644
index 000000000..d7ad4ea85
Binary files /dev/null and b/docs/images/diagrams/12-memory.png differ
diff --git a/docs/images/diagrams/13-streaming.png b/docs/images/diagrams/13-streaming.png
new file mode 100644
index 000000000..16cb442a0
Binary files /dev/null and b/docs/images/diagrams/13-streaming.png differ
diff --git a/docs/images/diagrams/14-broadcast.png b/docs/images/diagrams/14-broadcast.png
new file mode 100644
index 000000000..ba4102e22
Binary files /dev/null and b/docs/images/diagrams/14-broadcast.png differ
diff --git a/docs/images/diagrams/15-security.png b/docs/images/diagrams/15-security.png
new file mode 100644
index 000000000..9c7e47978
Binary files /dev/null and b/docs/images/diagrams/15-security.png differ
diff --git a/docs/images/diagrams/16-pairing.png b/docs/images/diagrams/16-pairing.png
new file mode 100644
index 000000000..1241fb603
Binary files /dev/null and b/docs/images/diagrams/16-pairing.png differ
diff --git a/docs/images/diagrams/17-model-failover.png b/docs/images/diagrams/17-model-failover.png
new file mode 100644
index 000000000..d643ff7c4
Binary files /dev/null and b/docs/images/diagrams/17-model-failover.png differ
diff --git a/docs/images/diagrams/18-tool-groups.png b/docs/images/diagrams/18-tool-groups.png
new file mode 100644
index 000000000..21cb3b340
Binary files /dev/null and b/docs/images/diagrams/18-tool-groups.png differ
diff --git a/docs/images/diagrams/19-plugin-discovery.png b/docs/images/diagrams/19-plugin-discovery.png
new file mode 100644
index 000000000..4874f7650
Binary files /dev/null and b/docs/images/diagrams/19-plugin-discovery.png differ
diff --git a/docs/images/diagrams/20-plugin-hooks.png b/docs/images/diagrams/20-plugin-hooks.png
new file mode 100644
index 000000000..efa3a4663
Binary files /dev/null and b/docs/images/diagrams/20-plugin-hooks.png differ
diff --git a/docs/images/diagrams/21-browser.png b/docs/images/diagrams/21-browser.png
new file mode 100644
index 000000000..0551a038e
Binary files /dev/null and b/docs/images/diagrams/21-browser.png differ
diff --git a/docs/images/diagrams/22-onboarding.png b/docs/images/diagrams/22-onboarding.png
new file mode 100644
index 000000000..26c57d20c
Binary files /dev/null and b/docs/images/diagrams/22-onboarding.png differ
diff --git a/docs/images/diagrams/23-gateway-lifecycle.png b/docs/images/diagrams/23-gateway-lifecycle.png
new file mode 100644
index 000000000..b7067eced
Binary files /dev/null and b/docs/images/diagrams/23-gateway-lifecycle.png differ
diff --git a/docs/images/diagrams/24-hot-reload.png b/docs/images/diagrams/24-hot-reload.png
new file mode 100644
index 000000000..d7af741cb
Binary files /dev/null and b/docs/images/diagrams/24-hot-reload.png differ
diff --git a/docs/images/diagrams/25-install.png b/docs/images/diagrams/25-install.png
new file mode 100644
index 000000000..c65e66560
Binary files /dev/null and b/docs/images/diagrams/25-install.png differ
diff --git a/docs/images/diagrams/26-workspace.png b/docs/images/diagrams/26-workspace.png
new file mode 100644
index 000000000..4c9828ee2
Binary files /dev/null and b/docs/images/diagrams/26-workspace.png differ
diff --git a/docs/images/diagrams/27-readme-architecture.png b/docs/images/diagrams/27-readme-architecture.png
new file mode 100644
index 000000000..79489fc0e
Binary files /dev/null and b/docs/images/diagrams/27-readme-architecture.png differ
diff --git a/docs/images/diagrams/28-session-lifecycle.png b/docs/images/diagrams/28-session-lifecycle.png
new file mode 100644
index 000000000..81d76e9e8
Binary files /dev/null and b/docs/images/diagrams/28-session-lifecycle.png differ
diff --git a/docs/images/diagrams/29-broadcast-vs-normal.png b/docs/images/diagrams/29-broadcast-vs-normal.png
new file mode 100644
index 000000000..a6ba1e312
Binary files /dev/null and b/docs/images/diagrams/29-broadcast-vs-normal.png differ
diff --git a/docs/images/diagrams/30-hero-banner.png b/docs/images/diagrams/30-hero-banner.png
new file mode 100644
index 000000000..c25d86849
Binary files /dev/null and b/docs/images/diagrams/30-hero-banner.png differ
diff --git a/docs/images/diagrams/31-security-threat-model.png b/docs/images/diagrams/31-security-threat-model.png
new file mode 100644
index 000000000..06f7b3133
Binary files /dev/null and b/docs/images/diagrams/31-security-threat-model.png differ
diff --git a/docs/images/diagrams/32-getting-started-timeline.png b/docs/images/diagrams/32-getting-started-timeline.png
new file mode 100644
index 000000000..b37243d97
Binary files /dev/null and b/docs/images/diagrams/32-getting-started-timeline.png differ
diff --git a/docs/install/index.md b/docs/install/index.md
index 8c6943589..eb4e6c2c6 100644
--- a/docs/install/index.md
+++ b/docs/install/index.md
@@ -9,6 +9,8 @@ read_when:
Use the installer unless you have a reason not to. It sets up the CLI and runs onboarding.
+
+
## Quick install (recommended)
```bash
diff --git a/docs/plugin.md b/docs/plugin.md
index 1b5a20608..18a5220be 100644
--- a/docs/plugin.md
+++ b/docs/plugin.md
@@ -112,6 +112,8 @@ manifest.
If multiple plugins resolve to the same id, the first match in the order above
wins and lower-precedence copies are ignored.
+
+
### Package packs
A plugin directory may include a `package.json` with `moltbot.extensions`:
diff --git a/docs/start/getting-started.md b/docs/start/getting-started.md
index 239b29966..1a057a6bb 100644
--- a/docs/start/getting-started.md
+++ b/docs/start/getting-started.md
@@ -7,8 +7,12 @@ read_when:
# Getting Started
+
+
Goal: go from **zero** → **first working chat** (with sane defaults) as quickly as possible.
+
+
Fastest chat: open the Control UI (no channel setup needed). Run `moltbot dashboard`
and chat in the browser, or open `http://127.0.0.1:18789/` on the gateway host.
Docs: [Dashboard](/web/dashboard) and [Control UI](/web/control-ui).
diff --git a/docs/start/pairing.md b/docs/start/pairing.md
index cb679bfb5..d35e89fa9 100644
--- a/docs/start/pairing.md
+++ b/docs/start/pairing.md
@@ -14,6 +14,8 @@ It is used in two places:
1) **DM pairing** (who is allowed to talk to the bot)
2) **Node pairing** (which devices/nodes are allowed to join the gateway network)
+
+
Security context: [Security](/gateway/security)
## 1) DM pairing (inbound chat access)
diff --git a/docs/tools/browser.md b/docs/tools/browser.md
index 084c36bf3..eb60375d3 100644
--- a/docs/tools/browser.md
+++ b/docs/tools/browser.md
@@ -321,6 +321,8 @@ High-level flow:
This design keeps the agent on a stable, deterministic interface while letting
you swap local/remote browsers and profiles.
+
+
## CLI quick reference
All commands accept `--browser-profile ` to target a specific profile.
diff --git a/docs/tools/index.md b/docs/tools/index.md
index 7c2274fb4..0bfa6c686 100644
--- a/docs/tools/index.md
+++ b/docs/tools/index.md
@@ -11,6 +11,8 @@ Moltbot exposes **first-class agent tools** for browser, canvas, nodes, and cron
These replace the old `moltbot-*` skills: the tools are typed, no shelling,
and the agent should rely on them directly.
+
+
## Disabling tools
You can globally allow/deny tools via `tools.allow` / `tools.deny` in `moltbot.json`