File Transfer (OpenClaw)
390,823 starsCore built-in OpenClaw plugin (@openclaw/file-transfer): fetch, list and write files on paired nodes via dedicated node commands — base64 over node.invoke bypasses bash stdout truncation for binaries up to 16 MB; dir_fetch pulls a whole directory tree, dotfiles and hidden directories included.
- First published:2026-04-30
- data as of:
- 2026-09-30
Host
On paired nodes, within policy-allowed paths: read (whole trees including dotfiles), list and write files — binaries up to 16 MB transfer intact. The docs state policy checks every descendant path of a dir_fetch and one denied entry rejects the whole transfer; path identity, symlink, archive-size and extraction limits also apply.
It operates on OpenClaw's proprietary node pairing and node.invoke command channel (official reference page: contract tools, CLI surface openclaw file-transfer), and its file policy and approvals (the approvals-migrate flow) are OpenClaw Gateway mechanisms. Without OpenClaw's node fabric, this plugin has nothing to attach to.
Risk
This is a channel that puts files onto other machines: an injected agent can write scripts or configs onto your other devices (planting executable content there), or pull whole sensitive trees back and exfiltrate them through other tools. Legacy permissive grants are deliberately frozen after upgrade and require interactive re-approval — the design itself tells you these permissions deserve a line-by-line look.
Install prompt
此插件隨 OpenClaw 核心 npm 包內建(官方 inventory 標記 included in OpenClaw),無需另行安裝;使用前需先在 OpenClaw 完成節點配對,並按官方 File transfers 文件設定檔案傳輸政策與審批。從舊版升級的話,官方要求先執行審批遷移流程重新確認既有權限。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.