GuidesGetting started

OpenClaw plugins vs skills: code, instructions, and the trust line

Skills are markdown; plugins are code running inside your Gateway — and most channels are plugins. The allowlist mechanics, and what that startup warning means.

August 1, 2026The Everpod team
The short answer

Plugins are code that extends OpenClaw — new channels, model providers, tools, even voice calling. Skills are markdown instructions that teach the agent workflows using tools it already has. The practical difference: a skill is a document; a plugin runs inside your Gateway process with everything that implies — which is why OpenClaw’s docs say to treat plugin installs like running code.

Tool, skill, or plugin?

OpenClaw’s capability model has three layers, and the docs draw the lines cleanly. A tool is a typed function the model can call — exec, browser, message. A skill is a SKILL.md instruction pack loaded into the prompt — right when the agent has the tools but needs the recipe. A plugin is for everything with actual machinery: code, credentials, lifecycle hooks, packaging. Plugins can register new tools, add channels, wire in model providers, and even ship skills of their own — the browser plugin, for instance, bundles a browser-automation skill alongside the code.

You’re probably already running several

The fact that reframes the whole topic: of OpenClaw’s roughly two dozen chat channels, only two ship in the core install — Telegram and the built-in WebChat. Everything else — Discord, Slack, Signal, WhatsApp, iMessage, Matrix, Microsoft Teams, and the rest — is an official plugin, installed with one command (openclaw plugins install @openclaw/discord). There’s a voice-calling plugin that places and answers real phone calls through Twilio-class providers. So “should I use plugins?” is usually moot; the real question is which ones you’ve granted, and on whose authority.

The trust dials that matter

Plugins install from several sources — ClawHub (clawhub:), npm, git, or a local path — and OpenClaw ships real controls for deciding what actually loads:

Why the caution is proportionate

A skill you regret is a document you delete. A plugin runs in-process with the Gateway — the docs’ phrase is “treat them as trusted code” — meaning a malicious one could reach whatever the Gateway reaches: config, credentials, session history, the filesystem. ClawHub runs automated checks on published plugins and gates publishing, which raises the floor without making the decision for you. The operating rule we’d put on a sticky note: install channels and capabilities from official sources freely; treat everything else with the same paranoia you’d give a shell script from a stranger — because mechanically, that’s what it is.

Don’t want to run it yourself?

Everpod hosts OpenClaw for you: a secure, private, always-on cloud computer of your agent’s own — set up, secured, and backed up, with its software kept up to date and $10 of model usage included every month. Nothing to configure, no surprise bills — just say hello.

Request early access
$29/mo · $10 model usage included · cancel anytime