The Always-On Agent
Module 3b ran the agent when you sent a message. Heartbeats and cron jobs can start unattended work, and an agent can delegate work to a sub-agent. Skills supply reusable instructions to a running agent. Each run still uses the agent loop and OpenShell sandbox; the session, instructions, and trigger determine what runs. You will install a skill and observe a cron-fired write.
How triggers choose context and instructions
Every mechanism on this page is described by the same three knobs:
- The session sets whose context a run inherits.
- The directive supplies instructions, through a file or a scheduled message.
- The trigger decides when a run starts.
The table shows the course configuration. Use the same three fields to classify other trigger types; OpenClaw also exposes additional session modes.
| Name | Session | Directive lives in | Trigger |
|---|---|---|---|
| Skill (run below) | reuses the caller's | workspace/skills/<name>/SKILL.md | explicit skill request in this exercise; automatic selection is a separate check |
| Heartbeat (concept only) | main session here | HEARTBEAT.md | gateway timer, ~30 min by default |
| Cron (run below) | isolated here; fresh per fire | payload.message in the scheduled job | one-shot scheduled time in this exercise |
| Sub-agent (concept only) | fresh, parent holds the handle | task instructions supplied by the parent | parent agent decides mid-turn |
Step 1 · Read a skill and its runbook
Install a practice directory containing SKILL.md with name/description frontmatter and a bundled runbook. Readback verifies both files. Then a fresh conversation explicitly reads the skill and retrieves a reference from the runbook. Inspect its tool events and proposed action before judging whether it followed the instructions. This tests explicit skill use; automatic selection requires a separate discovery test.
Same runtime as Kickstart. You are driving the same OpenClaw agent you connected on the Kickstart page.
Step 2 · Inspect your running agent
Scheduled jobs live on the gateway rather than behind an HTTP REST route, so the
same WebSocket connection the Control UI uses is also where you list and manage them
through the cron methods cron.list cron.add and
cron.remove. A cron job lets an always-on agent act with no human in
the loop because scheduled work fires on its own timer. The course runtime creates
an isolated session for this demonstration. OpenClaw can instead bind scheduled work
to another supported session mode when continuity is more important than isolation.
The cell installs one uniquely named job and waits up to three minutes for a successful scheduled run. The one-shot job requests automatic deletion after its run, which also limits work if the page closes. The cell verifies a new file reference and removes its owned job, including on failure or Stop. Keep the page open until cleanup finishes. If cleanup fails, retain the logged job ID and use the removal cell. The evidence file remains for inspection.
A successful run history entry and matching new file establish that the schedule triggered the write without a new chat message at firing time.
Where to take this
Public Hermes repository exposes the same broad capability categories: reusable skills, persistent memory, scheduled work, and a messaging gateway. Its implementation and defaults differ from OpenClaw, so compare the security boundary and session behavior rather than assuming that matching feature names imply matching risk controls.
Any harness that can write reusable instructions, schedule work, and accept remote messages can persist a compromised directive beyond one conversation. Module 4 separates those application controls from the sandbox controls that bound filesystem, process, and network access.
default: deny when no allow rule matches. Those application controls decide who
may talk to the agent. An operating-system sandbox separately bounds what its tools can reach.
These references describe different ways to preserve reusable code, execution state, or instructions:
- Wang et al., Voyager (2023). The research origin, demonstrated in a Minecraft agent.
- LangGraph Persistence. Checkpointed graphs as save-and-resume.
- Anthropic, Agent Skills. The production skill-folder layout.
References
- Wang et al., Voyager: An Open-Ended Embodied Agent (2023). The skill-library / memoised-trajectory mechanic this page builds on, demonstrated in a Minecraft agent.
- Park et al., Generative Agents (2023). Multi-day autonomous-agent simulation; the reflection and memory-consolidation patterns an always-on loop reuses.
- Anthropic, Agent Skills. The skill-folder layout used by this page's
skills/<name>/SKILL.mdfixture. - LangGraph, Persistence (checkpointers). Checkpointed graphs as the same save-and-resume primitive in a different production shape.
- Hermes Agent. Agent application with self-improving skills, persistent memory, cron, and a messaging gateway; NVIDIA's DGX Spark playbooks list Hermes and NemoClaw as separate setup paths.
- OpenClaw, Automation & Tasks. Current session and trigger semantics for cron, heartbeat, hooks, and background tasks.
- Hermes Agent, Security. Pairing and allowlist behavior for messaging-gateway callers.
- cron(8). The canonical reference for the scheduling primitive the cron drop-in borrows.
Comprehensive list at Going Further · References.
Try it · trigger a skill in conversation
Copy the installed SKILL.md path from Step 1 and ask the agent to read it for a new practice incident. Compare the proposal with the runbook and inspect its tool events. To test automatic selection separately, omit the path and check whether the agent reads the skill.
That is the same machinery a heartbeat or a cron fire would use, only driven by your own message instead of by a timer.