Skip to main content
Clawboo is open-source software under the MIT License. This page summarizes that license, the notable third-party code that ships inside the published package, and the upstream content the marketplace catalog is adapted from. The repository’s two canonical files are the source of truth:
  • LICENSE: the MIT license text and copyright holder.
  • THIRD_PARTY_NOTICES.md: the full per-dependency license table and the verbatim upstream license texts.
This page is a reading guide to those files, not a replacement for them. When in doubt, the two files above govern.

At a glance

Clawboo’s own license: MIT

The repository’s LICENSE is the standard MIT License, Copyright (c) 2026 Sanreds. It grants permission to use, copy, modify, merge, publish, distribute, sublicense, and sell copies, with the usual “AS IS”, no-warranty disclaimer, on the condition that the copyright notice and permission notice are retained in copies or substantial portions. The only npm-published artifact is the clawboo CLI package (apps/cli/package.json), whose license field is MIT. Everything you install with npm install -g clawboo (or npx clawboo to try it without installing) ships under that license. See The CLI for what the package contains and Deployment for how it boots.
Every workspace library under packages/ is named @clawboo/* and marked private: true. None of them publish to npm independently; they are bundled into the CLI’s dist/server.js and dist/ui/ at assembly time. So “the published software” is exactly the one clawboo package, under MIT. See the package overview.

Bundled third-party dependencies

The code listed below ships inside the published clawboo package. Most of it is bundled (inlined) at build time into the server bundle (dist/server.js) and the dashboard UI (dist/ui/), so it does not appear as separate entries in the installed package’s node_modules; a few packages (better-sqlite3, ws, pino) are declared runtime dependencies and carry their own license texts in node_modules. For the inlined packages, the aggregated notices ship in THIRD_PARTY_NOTICES.md (included in the package as dist/THIRD_PARTY_NOTICES.md), which is also the authoritative table; the summary here highlights the licenses you most need to know about. A few notes on the non-MIT licenses, restated from THIRD_PARTY_NOTICES.md:
  • Apache-2.0 (openai, drizzle-orm): used under the terms of the Apache License, Version 2.0.
  • EPL-2.0 (elkjs): the graph-layout backend is used under the Eclipse Public License, Version 2.0. It is bundled unmodified; its source is available on npm and at the upstream repository linked in the notices file.
  • CC0-1.0 (simple-icons): the brand-mark paths are CC0-1.0, but the brand logos themselves remain the property of their respective owners. Clawboo renders provider and runtime marks from simple-icons where one exists, and uses original lettermark tiles otherwise (it never reproduces a logo simple-icons does not carry).
Development-only dependencies (Playwright, MSW, Vitest, Turbo, tsup, ESLint, jest-axe, axe-core) are used to build and test Clawboo and are not shipped in the npm package. Their licenses are listed in the notices file.

Bundled content: the marketplace catalog

The marketplace ships 436 agents and 85 teams across nineteen packs (see the marketplace catalog reference for the full breakdown). Most of the agent content is adapted from seventeen upstream repositories, sixteen MIT-licensed and one Apache-2.0, each pinned by commit SHA so the provenance is reproducible. The catalog is hand-maintained JSON under the repository’s catalog/ folder: there is no generator, and every entry is reviewed like any other file. Each pack carries its own NOTICE.md alongside the summary here. Every pack records its upstream repository and pinned commit in its manifest’s provenance block, and most adapted entries additionally carry an origin.url linking back to the exact upstream file at that commit, for example:
Entries are adapted, not verbatim: they were pruned, renamed, re-described, and re-formatted by the Clawboo maintainers, and each stores the whole edited instruction body (never a summary) in its IDENTITY.md document. The upstream license texts are reproduced in THIRD_PARTY_NOTICES.md, each alongside a note recording those modifications.
The two first-party packs, the 15 built-in agents and the 35 life-and-home agents, are content authored in this repo. They carry no external attribution and no origin.url. The founder-sprint pack also ships under the clawboo publisher folder, but it is adapted rather than first-party: it carries the garrytan/gstack provenance and its own NOTICE.md.
The 44 curated skills in the marketplace’s Skills tab are first-party annotations, except that the process taught by 14 of them is adapted from obra/superpowers (MIT, pinned at b36e0829c6d0140e93cfef2ca599b1b07d4a7797). No upstream prose, structure, or example ships in Clawboo. Four packs additionally declare skills of their own, 27 in total, which agents reference through the merged registry; those declarations are covered by the same pack notices as the agents that use them.

Runtime acknowledgements

Clawboo coordinates other open-source AI agent runtimes as peer teammates. Each runs on its own terms under its own license; Clawboo does not vendor their code; the adapters drive each runtime’s own CLI/SDK contract over MCP. The acknowledgements section of THIRD_PARTY_NOTICES.md credits:
  • OpenClaw: the Gateway-driven connected substrate.
  • Hermes (hermes-agent), Claude Code (Anthropic Claude Agent SDK), and Codex (OpenAI Codex CLI): the wrapped-one-shot runtimes.
It also credits prior art in the agent-orchestration space (Paperclip, vibe-kanban, and Nous Research’s hermes-paperclip-adapter) as design inspiration.

See also

Last modified on September 2, 2026