agentCLAWHUBUnverified

Skill Audit & Publish

Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.

OpenClaw

Rank

62

Safety

84

Downloads

2.0k

Updated

Oct 9, 2026

Version

1.5.9

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2K downloadsadoption · observed Oct 9, 2026
Latest release
1.5.9release · observed Sep 20, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17672gh0nx9qr7sjp84kz7xen83jv7v:skill-audit-publish
  1. Install using `clawhub skill install s17672gh0nx9qr7sjp84kz7xen83jv7v:skill-audit-publish` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/haiyangchenbj/skill-audit-publish before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/snapshot"

Documentation

CLAWHUB

150,837 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: "Skill Audit & Publish"
slug: skill-audit-publish
displayName: "Skill Audit & Publish"
description: "Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'."
version: "1.5.9"
allowed-tools: execute_command, read_file, file_read, write_to_file, file_write, env, network
metadata:
  openclaw:
    permissions:
      - "network: api.github.com — used only by the bundled sync helper when explicitly invoked"
      - "credentials: GITHUB_TOKEN / GITHUB_PAT environment variables — read at runtime, never stored or logged"
      - "network: api.skillhub.cn — used only by the stage 5b SkillHub upload when the user approves publishing"
      - "credentials: the local SkillHub credential file (~/.skillhub/credentials.json, field user.token) read only during stage 5b to authenticate the upload — held in memory for that single request, never embedded in the skill, logged, or shipped in any package"
    tags:
      - skill-publishing
      - pre-publish-audit
      - pii-sanitization
      - secret-scanning
      - skill-lifecycle
      - content-governance
      - developer-tools
      - publishing-workflow
      - audit-checklist
---

# Skill Audit & Publish

A five-stage pipeline that takes a local OpenClaw skill and ships a sanitized, verified release to ClawHub. The publish command is the last step, not the first — every earlier step is designed to keep private data and irreversible mistakes out of the public record.

**The single most important rule:** never modify the user's original files. Work in a separate publish folder; only after explicit approval move anything to the live registry.

---

## When to use

Trigger this skill when the user says or implies any of:

- "Publish this skill to ClawHub" / "I want to publish to ClawHub" / "ship it to clawhub"
- "How do I publish a skill" / "What's the ClawHub publish command" / "clawhub publish syntax"
- "Sanitize my skill before publishing" / "remove personal info" / "audit for PII"
- "Check for secrets / API keys / tokens before I publish"
- "Make a publish-ready version of this skill"
- "I want to share this skill publicly" / "publish a skill without leaking my data"
- "clawhub publish" / "clawhub publish command" / 

README.md

# Skill Publish

Audit, clean, and publish agent skills to ClawHub and GitHub. Works with any SKILL.md-based skill in the OpenClaw ecosystem.

Complements `skill-design-guide` (design-time) with publish-time workflow.

**Version**: v1.5.7 (2026-09-16)

> ⚠️ **Publish has external side effects.** `audit` mode is read-only. `publish` mode
> transmits the cleaned skill contents to ClawHub and GitHub (public services). The bundled
> sync helper only creates or updates files — it never deletes anything from your repos or
> your machine, and it never modifies your local files. Publishing runs only after an audit
> and your explicit confirmation of the file list, target repos, and version. Treat
> everything you publish as publicly visible.

## Modes

| Mode | Command | Description |
|------|---------|-------------|
| **Audit** | "audit skill" | Read-only scan — reports issues, changes nothing, transmits nothing |
| **Publish** | "publish skill" | After audit + confirmation: clean (in a temp copy) → push to ClawHub/GitHub → verify |

## What It Checks

1. **Personal data** — share counts, cost basis, account values, personal names
2. **Frontmatter** — description length, language, version numbers in name
3. **Content** — internal dev notes, references sections, version history
4. **Language** — English SKILL.md body, bilingual READMEs
5. **Files** — ticker-specific scripts, meta-documents, outdated files

## Quick Start

```bash
# Audit a skill directory
"audit skill ~/.workbuddy/skills/my-skill"

# Publish to ClawHub + GitHub
"publish skill ~/.workbuddy/skills/[email protected]"
```

## Bundled Scripts

`scripts/sync_skill_to_github.js` — optional helper that mirrors a publish folder to a GitHub repo via the Contents API.

- Token: read from `GITHUB_TOKEN` / `GITHUB_PAT` env vars only; exits with an error if unset. Never embedded, read from files, or logged. (The SkillHub upload stage reads a separate credential from a local file — declared in the skill's frontmatter permissions; it does not involve this helper.)
- Network: talks to `api.github.com` only. Creates/updates files (PUT); **never deletes** anything.
- Fully parameterized: `--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`. No hardcoded paths or usernames.

```bash
node scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill
```

## License

MIT

_meta.json

{
  "ownerId": "kn70yg6zwmkftx4939qrs89awx82rr9a",
  "slug": "skill-audit-publish",
  "version": "1.5.9",
  "publishedAt": 1789883389948
}

references/publish-rules.md

# Publish Rules for ClawHub & GitHub

> Full rule reference loaded by the `skill-publish` workflow. Do not embed this in SKILL.md.

---

## 1. Frontmatter Requirements

| Field | Rule | Why |
|-------|------|-----|
| `name` | Pure English slug, **no version number**. e.g. `invassistant` not `invassistant-v2` | ClawHub display name; version belongs in changelog |
| `description` | ≤3 sentences, English only. No version numbers, stock tickers, keyword lists, or changelogs | ClawHub card + search summary |
| `metadata.openclaw.tags` | 5-10 English tags | ClawHub category system |
| `metadata.openclaw.requires.bins` | Declare required binaries (e.g. `python3`) | ClawHub security analysis |

**Bad**:
```yaml
description: |
  个人投资组合管理框架 v2.1.1(执行简化版)。覆盖 A 股、港股、美股。
  新增 §7.4 模式 D...
  触发关键词:检查持仓, COST, LLY...
```

**Good**:
```yaml
description: >
  Multi-asset investment portfolio management framework.
  A/B/C-class differentiated rules, 7 red-line risk controls.
  Covers US, A-share, and HK stocks.
```

## 2. Content Cleanup

### Must Remove
- `## 详细参考` / `## References` section (lists internal file paths — meaningless to users)
- Unreleased versions in version history (e.g. "v3.0 planned 2027")
- Internal dev notes ("审计清理版", "next 6-12 months: no new rules")
- Ticker-specific entry scripts (e.g. `check_tsla_entry.py`) — exposes personal holdings
- Meta-documents not part of the skill (e.g. `SKILL_PUBLISH_RULES.md`)

### Version History
- Only published versions (available on ClawHub)
- One sentence per version
- Max 5 rows

## 3. Language

These are **ClawHub discoverability conventions, not hard requirements**. Recommend them
and flag deviations in the audit report, but respect the user's intended primary language
and never delete or reject valid content solely on language grounds.

| File | Recommended language |
|------|----------|
| `SKILL.md` | English body + optional Chinese intro paragraph at end |
| `README.md` | English |
| `README_zh.md` | Chinese (mirror of English README) |
| `CONTRIBUTING.md` | English |
| All `references/*.md` | English |

## 4. File Separation: Local vs Published

Files that stay **local only** (never push to GitHub or ClawHub):
- Ticker-specific scripts (`check_tsla_entry.py`, `check_detail.py`, etc.)
- Personal config files (`*-config.json` with real credentials)
- Meta-documents (`SKILL_PUBLISH_RULES.md`)
- Session-specific notes or logs
- `.git/` directory

Files that go to **both platforms**:
- `SKILL.md`, `README.md`, `README_zh.md`
- `CONTRIBUTING.md`, `LICENSE`, `requirements.txt`
- `references/` (all `.md`)
- `scripts/` (only generic, reusable engines)

Files for **ClawHub only** (not GitHub):
- `_meta.json`

## 5. Publish Mechanics

### ClawHub
```bash
clawhub publish <clean-dir> --slug <slug> --version <semver> --changelog "<one-liner>"
```
- Requires prior `clawhub login --token <token>` (persists to session)
- Version must not already exist on ClawHub
- If overriding `latest` tag, version number must be hig

references/skillhub-publish.md

# Publishing to SkillHub (stage 5b)

> Loaded by stage 5 of the pipeline. Kept out of the skill file on purpose — the skill file stays a routing surface; operational detail lives here.

SkillHub is the third platform in the unified-version rule. **There is no maintained CLI for it.** A helper named `skills_store_cli.py` used to exist and no longer ships anywhere on a typical machine — do not spend time searching for it. Build the request directly.

---

## Endpoint

```
POST https://api.skillhub.cn/api/v1/community/skills/publish
```

## Auth

Bearer token from `~/.skillhub/credentials.json` → **`user.token`**.
The file has no top-level `token` key; reading `d["token"]` yields null and produces a misleading 401/403.

## Request — multipart/form-data

**Part 1** — field `payload`, `Content-Type: application/json`:

```json
{
  "slug": "my-skill",
  "displayName": "My Skill",
  "version": "1.2.3",
  "description": "one-line English summary",
  "changelog": "what changed",
  "category": "",
  "subCategories": [],
  "source": "community",
  "tags": ["tag-a", "tag-b"]
}
```

**Parts 2..n** — one per file:

- field name **must be `files`** (`file` and `files[]` are wrong)
- `filename` = repo-relative path with forward slashes, e.g. `references/guardian-patterns.md`
- `Content-Type: text/markdown`

## Response

| Code | Meaning |
|---|---|
| **201** | accepted — body carries `ok:true`, `version`, `fileCount`, `skillId`, `fingerprint`, and `pending` review/scan statuses |
| 400 | frontmatter or payload validation failed |
| 409 | slug tombstoned, or version already exists → bump and retry. **Never delete a `source=community` skill to force a republish** — the slug becomes an unrecoverable tombstone |
| 429 | consecutive publishes rate-limited → wait ~90s (a single 90 s backoff has been the reliable fix in practice; 20 s retries can fail repeatedly) |
| 503 | transient → wait ~20s and retry once |

## Constraints

- **No read API.** Every `GET` under `/api/v1/community/skills/*` returns 405, including `/mine`, `/list`, and `/rankings`, with or without a Bearer token. You cannot verify remotely whether a skill is already on SkillHub. Use side evidence instead: `clawhub inspect <slug> --versions` plus the existence of the GitHub mirror repo.
- **Stricter frontmatter than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files retrieved via `clawhub install` often lose the leading `---` in ClawHub storage — backfill it before publishing.
- **`LICENSE` is rejected.** Publish from a staging copy that excludes it.
- **Version must match ClawHub and GitHub exactly.** No platform-local version numbers.

## Ordering inside stage 5

1. ClawHub publish (async — settle with `inspect --json` → `latestVersion.version`)
2. **SkillHub publish (this file)**
3. GitHub sync from the staging dir (never from an install dir)
4. Install-check against ClawHub

Skipping step 2 is the most common way the three-platform version rule breaks: the skill l
Github ReposUpdated 6h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/haiyangchenbj/skills/skill-audit-publish",
      "sourceUrl": "https://clawhub.ai/haiyangchenbj/skills/skill-audit-publish",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:15:43.181Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:15:43.181Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2K downloads",
      "href": "https://clawhub.ai/haiyangchenbj/skill-audit-publish",
      "sourceUrl": "https://clawhub.ai/haiyangchenbj/skill-audit-publish",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:15:43.181Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.5.9",
      "href": "https://clawhub.ai/haiyangchenbj/skill-audit-publish",
      "sourceUrl": "https://clawhub.ai/haiyangchenbj/skill-audit-publish",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-20T05:49:49.948Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.5.9",
      "description": "LP1 fix: SkillHub upload stage (5b) declared in frontmatter permissions (api.skillhub.cn network + local credential-file read) and allowed-tools env/network tokens; stage-5b auth disclosure added to the body; absolute credential claims scoped to the sync helper to remove self-contradiction; SkillHub 429 backoff corrected from ~60s to ~90s (field-verified).",
      "href": "https://clawhub.ai/haiyangchenbj/skill-audit-publish",
      "sourceUrl": "https://clawhub.ai/haiyangchenbj/skill-audit-publish",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-20T05:49:49.948Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to Skill Audit & Publish and adjacent AI workflows.