OpenClaw EnterpriseDOCSGitHub

PluginDriver feature matrix

This page preserves the 2026-09-17 historical source snapshot below. Its always/never/auto vocabulary and unsupported-policy statuses do not describe the current API. For current authoring controls, read Agent plugin policy, bundled Driver mappings, or the selected Driver's GET /installation capabilities. For current hosted discovery, see Create Agent plugins.

The local docs preview adds filters and expandable evidence to this historical table. GitHub shows the generated table with pinned source/test links. Both use the same snapshot data. No live runtime was exercised for that review. The testing guide distinguishes older runtime results from the current verification gap.

PluginDriver feature matrix

Reviewed 2026-09-17 at baseline c4ecf32727aef09a6b4caeec16870bf391f7a505.

The status filter matches either Driver cell. Test links identify repository coverage; source support is not live-runtime proof.

8 rows

CapabilityScopeocc-plugin (embedded OpenClaw)codex-plugin (dedicated Codex)
DiscoveryLIST/QUERY pluginsDiscover available plugins through the controller catalog and HTTP inventory.

Whether OCC and API clients can list available plugins. Agent reads show saved selections; they do not query the available catalog.

Reference

docs/reference/drivers/plugin.md:23-48

Partial

Internal listCatalog returns the bundled Diffs catalog. No HTTP plugin inventory or catalog-query endpoint is exposed.

Source

apps/controller/src/drivers/plugin/index.ts:144-147, docs/reference/drivers/plugin.md:44-48

Test coverage

tests/conformance/plugin-driver.test.mjs:151-162

Live proof: unknown/not run

Partial

Internal listCatalog requires paired codexExecutable/codexHome and a ChatGPT-backed profile. No HTTP plugin inventory or catalog-query endpoint is exposed.

Source

apps/controller/src/drivers/plugin/index.ts:150-178, docs/reference/drivers/plugin.md:44-48

Test coverage

tests/conformance/plugin-driver.test.mjs:212-268

Live proof: unknown/not run

Policyapproval mode: alwaysRun without a plugin approval prompt.

Request plugin calls without asking for approval. Other platform permissions and workload restrictions still apply.

Reference

docs/reference/drivers/plugin.md:83-93

Supported

Enable the selected plugin without a plugin approval step; other native restrictions still apply.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:415-437

Test coverage

tests/conformance/plugin-driver.test.mjs:165-181

Live proof: unknown/not run

Partial

Native app mode approve plus bridge allow_destructive_actions=true; explicit auto_review is rejected.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:271-290, apps/controller/src/drivers/plugin/runtime-translator.ts:306-315, apps/controller/src/drivers/plugin/runtime-translator.ts:365-384

Test coverage

tests/conformance/plugin-driver.test.mjs:351-365

Live proof: unknown/not run

Policyapproval mode: autoUse native automatic approval semantics.

Let the native runtime decide when approval is needed. This does not mean approve every call automatically.

Reference

docs/reference/drivers/plugin.md:83-93

Unsupported

No equivalent generic native OpenClaw plugin approval control; startup rejects auto.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:416-421

Test coverage

tests/conformance/plugin-driver.test.mjs:184-193

Live proof: unknown/not run

Supported

Supported app-only selections use native auto approval and bridge allow_destructive_actions=auto.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:306-315, apps/controller/src/drivers/plugin/runtime-translator.ts:365-384

Test coverage

tests/conformance/plugin-driver.test.mjs:283-325

Live proof: unknown/not run

Policyapproval mode: neverBlock selected-plugin execution.

Prevent the Agent from executing the selected plugin, even if the package remains installed.

Reference

docs/reference/drivers/plugin.md:83-93

Supported

Disable the selected plugin; its package remains installed.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:407-445

Test coverage

tests/conformance/plugin-driver.test.mjs:179-181

Live proof: unknown/not run

Supported

No selected native app entry and bridge disabled; install identity remains and installation still runs.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:344-404, apps/controller/src/drivers/plugin/runtime-translator.ts:306-315, apps/controller/src/drivers/plugin/runtime-translator.ts:365-384

Test coverage

tests/conformance/plugin-driver.test.mjs:379-389

Live proof: unknown/not run

Policyapproval mode: prompt_humanReview every plugin call using a human user.

Display label for approvalMode: prompt with approvalsReviewer: user. The request asks for review before every call; this label is not an API enum value.

Reference

docs/reference/drivers/plugin.md:83-111, docs/reference/agent-plugins.md:93-106

Unsupported

Every-call prompting and explicit reviewer selection are unsupported; startup rejects this policy.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:415-425

Test coverage

tests/conformance/plugin-driver.test.mjs:184-193

Live proof: unknown/not run

Unsupported

Startup rejects prompt, including with user. Reviewer selection is available with supported auto policy, but does not force review of every call.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:271-280, apps/controller/src/drivers/plugin/runtime-translator.ts:365-384

Test coverage

tests/conformance/plugin-driver.test.mjs:392-404

Live proof: unknown/not run

Policyapproval mode: prompt_auto_reviewReview every plugin call using the native automatic reviewer.

Display label for approvalMode: prompt with approvalsReviewer: auto_review. The request asks for review before every call; this label is not an API enum value.

Reference

docs/reference/drivers/plugin.md:83-111, docs/reference/agent-plugins.md:93-106

Unsupported

Every-call prompting and explicit reviewer selection are unsupported; startup rejects this policy.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:415-425

Test coverage

tests/conformance/plugin-driver.test.mjs:184-193

Live proof: unknown/not run

Unsupported

Startup rejects prompt, including with auto_review. Reviewer selection is available with supported auto policy, but does not force review of every call.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:271-280, apps/controller/src/drivers/plugin/runtime-translator.ts:365-384

Test coverage

tests/conformance/plugin-driver.test.mjs:392-404

Live proof: unknown/not run

PolicyDestructive-action and write overridesOverride write/destructive-action policy.

Set different approval rules for write operations or destructive actions across a plugin. Enforcement needs reliable action classifications.

Reference

docs/reference/drivers/plugin.md:85-111

Unsupported

Both destructiveActions and writes are rejected at startup.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:423-425

Test coverage

tests/conformance/plugin-driver.test.mjs:184-193

Live proof: unknown/not run

Unsupported

Category overrides are rejected; reliable tool metadata is unavailable.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:130-136

Test coverage

tests/conformance/plugin-driver.test.mjs:392-404

Live proof: unknown/not run

PolicyPer-tool enablement and approval overridesOverride individual tool policy.

Enable, disable, or set approval rules for individual tools inside a plugin, instead of using only the plugin-wide policy.

Reference

docs/reference/drivers/plugin.md:85-111

Unsupported

Any tools map is rejected at startup; catalog tools is null.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:423-457

Test coverage

tests/conformance/plugin-driver.test.mjs:184-193

Live proof: unknown/not run

Unsupported

Any tools map is rejected; curated catalog projection reports tools:null.

Source

apps/controller/src/drivers/plugin/runtime-translator.ts:130-136

Test coverage

tests/conformance/plugin-driver.test.mjs:392-404

Live proof: unknown/not run

Update this snapshot

Edit docs/assets/plugin-driver-matrix.json after reading the current reference, implementation, and focused tests. Set baseline to the reviewed full commit, update reviewedAt, and verify each source range at that commit. Keep native enforcement separate from API acceptance and preserve proof limitations.

From the repository root, regenerate and validate:

sh
node scripts/generate-plugin-matrix.mjsnode scripts/generate-plugin-matrix.mjs --checkpnpm docs:checkpnpm docs:build

Follow local preview to open /reference/drivers/plugin-matrix/. Contributor test and runtime prerequisites remain in the plugin testing guide.

Search documentation