agentCLAWHUBUnverified

ponytail-audit

Quality audit of the whole repo: bugs, security, real load, missing tests, speed, and what to delete. Most important first. Skill: ponytail-audit Owner: dietrichgebert Summary: Quality audit of the whole repo: bugs, security, real load, missing tests, speed, and what to delete. Most important first. Tags: latest:5.1.0 Version history: v5.1.0 | 2026-10-08T16:20:51.115Z | auto - Expanded scope: now audits for bugs, security risks, load handling, missing tests, speed, and unnecessary code, not just over-engineering. - Output reorganized: sta

OpenClaw

Rank

62

Safety

84

Downloads

1.8k

Updated

Oct 10, 2026

Version

5.1.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.8K downloadsadoption · observed Oct 10, 2026
Latest release
5.1.0release · observed Oct 8, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17beee6vfcnpy9kq5vh15rzzh88rnca:ponytail-audit
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-dietrichgebert-ponytail-audit/snapshot"

Documentation

CLAWHUB

44,249 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

---
name: ponytail-audit
description: "Quality audit of the whole repo: bugs, security, real load, missing tests, speed, and what to delete. Most important first."
homepage: https://github.com/DietrichGebert/ponytail
license: MIT
---

Audit the whole repo like the senior developer who just inherited it and
will be paged when it breaks. Order of importance: correct, safe, holds under
load, tested, fast, lean. Lean still matters: every extra line must be read,
tested and fixed later. This is a report the user asked for, so give it in full.

## 1. Map first

- Audit what the user names: a folder, a package, or the whole repo.
  Nothing named: the whole repo.
- Read the README, the deploy and build config, the dependency list, the
  entry points (main, routes, handlers, jobs, CLI commands) and the tests.
- Find the expected load: one person running a script, or many users and
  processes at once. Judge scale against that, and say which load you assumed.
- Trace the main flows end to end: where data comes in, what is stored,
  what goes out. Read those paths fully: input from users, money, auth,
  data writes, background jobs, anything shared between processes.
- Big repo: go deep where a mistake costs the most, not file by file. Say
  which parts you did not read.

## 2. Look for

1. **Bug:** wrong result, crash, missed edge case (empty, zero, last item,
   rounding, time zones), callers that disagree with what a function returns,
   the same rule applied differently in two places.
2. **Risk:** security holes (injection, weak randomness, secrets in code,
   missing checks on input from users), data loss (errors swallowed, writes
   in the wrong order, no transaction).
3. **Scale:** fine for one user, wrong for many: check-then-write races, the
   same work done by every process, memory or lists that only grow, a query
   per item, O(n^2) on big input, per-process state that must be shared.
4. **Missing test:** risky logic (a branch, a parser, money, security, data
   writes) with no test that fails when it breaks. One good test, not coverage.
5. **Speed:** big slowdowns are problems. Small wins (work repeated in a hot
   loop) are suggestions; some software counts every millisecond.
6. **Lean:** code that should not exist or should be smaller.
   - delete: dead code, unused options, flags and config, speculative features
   - reuse: two helpers doing the same thing (keep one, name the path)
   - stdlib / native: the standard library or platform already does it;
     a dependency doing what a few lines or the platform can do
   - yagni: interface with one implementation, factory with one product,
     wrapper that only passes calls through
   - merge: near-copies that must change together
   - split: one function or class doing several unrelated jobs, so it is
     hard to read or test. Split by job, never by line count, and never into
     helpers that exist only to make a function shorter.

## 3. Check before you report

- Every finding needs a conc

_meta.json

{
  "ownerId": "kn75jhs1s4186aj57w94eykzm188rxj8",
  "slug": "ponytail-audit",
  "version": "5.1.0",
  "publishedAt": 1791476451115
}

skill-card.md

## Description:

Quality audit of the whole repo: bugs, security, real load, missing tests, speed, and what to delete. Most important first.

This skill is ready for commercial/non-commercial use.

## Publisher:

[dietrichgebert](https://clawhub.ai/user/dietrichgebert)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and engineers use this skill to review a repository or named folder for concrete bugs, security and data-loss risks, load issues, missing tests, performance problems, and unnecessary code.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The audit requires access to repository contents, which may include sensitive material.

Mitigation: Use it only on repositories the agent is authorized to read, and limit the requested scope when appropriate.

Risk: A read-only review can miss problems in code that was not inspected.

Mitigation: Check the report's 'Not checked' section and confirm important findings before making changes.

## Reference(s):

- [Skill homepage](https://github.com/DietrichGebert/ponytail)

## Skill Output:

**Output Type(s):** [Analysis, Guidance]

**Output Format:** [Markdown]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Read-only, prioritized audit report with up to 20 numbered findings, concrete cases and suggested fixes; notes what was not checked.]

## Skill Version(s):

5.1.0 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 12h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/dietrichgebert/skills/ponytail-audit",
      "sourceUrl": "https://clawhub.ai/dietrichgebert/skills/ponytail-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:17:34.408Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-dietrichgebert-ponytail-audit/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-dietrichgebert-ponytail-audit/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:17:34.408Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.8K downloads",
      "href": "https://clawhub.ai/dietrichgebert/ponytail-audit",
      "sourceUrl": "https://clawhub.ai/dietrichgebert/ponytail-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T02:17:34.408Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "5.1.0",
      "href": "https://clawhub.ai/dietrichgebert/ponytail-audit",
      "sourceUrl": "https://clawhub.ai/dietrichgebert/ponytail-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-08T16:20:51.115Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-dietrichgebert-ponytail-audit/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-dietrichgebert-ponytail-audit/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 5.1.0",
      "description": "- Expanded scope: now audits for bugs, security risks, load handling, missing tests, speed, and unnecessary code, not just over-engineering. - Output reorganized: starts with a repo summary; findings grouped by priority (must fix, should fix, nice to have); each finding includes what, why, fix, and impact if skipped. - Stronger focus on real-world use: considers expected load, completeness of audit, and requires concrete cases for findings. - More practical: recommends the smallest effective fix; prefers deletion and avoids unnecessary complexity. - Lean audit tags (delete, stdlib, native, reuse, yagni, shrink) now folded into a wider quality review rather than the sole focus. - Removes skill-card.md; documentation now centered in SKILL.md.",
      "href": "https://clawhub.ai/dietrichgebert/ponytail-audit",
      "sourceUrl": "https://clawhub.ai/dietrichgebert/ponytail-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-08T16:20:51.115Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to ponytail-audit and adjacent AI workflows.