agentCLAWHUBUnverified

Mapick

Mapick — Skill recommendation & privacy protection for OpenClaw. Scans your local skills, suggests what you're missing, and keeps other skills from seeing yo... Skill: Mapick Owner: sunlleyevan Summary: Mapick — Skill recommendation & privacy protection for OpenClaw. Scans your local skills, suggests what you're missing, and keeps other skills from seeing yo... Tags: latest:1.0.28 Version history: v1.0.28 | 2026-05-08T09:17:11.267Z | user Fixed - backup:restore: fix validateSkillId check (was returning early for valid IDs) - flows.md: persona report now requires explicit use

OpenClaw

Rank

62

Safety

84

Downloads

1.2k

Updated

Oct 11, 2026

Version

1.0.28

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.2K downloadsadoption · observed Oct 11, 2026
Latest release
1.0.28release · observed May 8, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s171btjf6zqjt0e2ccnyk45ras83p6n8:mapick
  1. Node.js workspace detected. Install dependencies securely: run `npm ci --ignore-scripts` to prevent post-install lifecycle triggers from running arbitrary code, then selectively audit the dependency tree.
  2. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  3. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sunlleyevan-mapick/snapshot"

Documentation

CLAWHUB

160,000 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: mapick
description: Mapick — Skill recommendation & privacy protection for OpenClaw. Scans your local skills, suggests what you're missing, and keeps other skills from seeing your sensitive data.
metadata: { "openclaw": { "emoji": "🔍", "requires": { "bins": ["node"], "node": ">=22.14" }, "permissions": { "network": ["api.mapick.ai"], "file_read": ["~/.openclaw/skills/","~/.openclaw/workspace/skills/","~/.mapick/logs/","~/.mapick/cache/","/tmp/mapick-report-"], "file_write": ["~/.openclaw/skills/","~/.openclaw/workspace/skills/","~/.mapick/","/tmp/mapick-report-"] } } }
---

# Mapick

Priority: **recommendation = privacy > persona > safety score > cleanup > everything else.**

## Global rules

- Output reference below is English — render in the user's conversation language.
- Match every intent trigger in ANY language. Trigger lists are illustrative, not allow-lists.
- Every `node scripts/shell.js <subcommand>` runs the Mapick Node entrypoint. Node.js (>=22.14) required.
- Shell responses are single-line JSON. Parse it; never dump raw JSON to the user. Paraphrase errors.
- For slash commands, never narrate internal preparation. Do not tell the user
  you are reading SKILL.md, loading reference files, checking handlers, or
  deciding which tool to call. Run the command and render only the final
  user-facing result.
- **Use the literal command names registered in `scripts/shell.js` HANDLERS — do not abbreviate or invent shorthand.** Right: `privacy consent-decline`, `privacy consent-agree`, `recommend:track`, `clean:track`, `update:check`, `notify:plan`. Wrong: `privacy decline`, `privacy agree`, `recommend track`, `update check`. If a command appears to be missing, surface the error code as-is (`unknown_command`) — do not silently substitute a similar-looking command (e.g. don't fall through to `summary` because `status` "looked wrong").

Detailed rendering, multi-step flows, error templates, and lifecycle rules live in `reference/`. Load on demand.

---

## 1. Recommend / Search

### Intent: recommend
Triggers: recommend, suggest, find skill, what should I install, what am I missing.
Command: `node scripts/shell.js recommend [limit]` · cached 24h, force refresh with explicit limit.

### Intent: search
Triggers: search, find, look for, anything for X.
Command: `node scripts/shell.js search <keyword> [limit]`

### Intent: intent (P1 — local gap detection)
Triggers: user says they want to do something but don't have a skill for it ("I need to scrape data", "can I deploy to k8s", "有没有做代码审查的", "帮我读 PDF"). Also triggered by tool failures / missing capability in the current workflow.
Command: `node scripts/shell.js intent <natural language description>`

**How it works (privacy-first):**
1. You detect the gap from the user's natural language.
2. Call `intent "他们的原话"` — Mapick extracts keywords **locally**.
3. Only the extracted keywords are sent to the backend for search.
4. The user's full message never leaves the machine.

**Rendering:**
- 

README.md

# Mapick

The Skill manager for OpenClaw. Recommends what you're missing, cleans
what you don't use, blocks what's unsafe — without reading your project
code or chat history.

```
openclaw skills install mapick
```

After install, talk to your agent in any language. Mapick auto-detects intent.

| Say | What you get |
| --- | --- |
| `recommend` | Personalized recommendations based on what you've already installed |
| `clean` · `zombies` | List of skills idle 30+ days, one reply to remove |
| `search <keyword>` | Live ClawHub search with safety grades |
| `is X safe?` · `security X` | Per-skill safety report; Grade-C skills surface safer alternatives |
| `analyze me` · `report` | Developer persona based on your usage pattern |
| `bundle` | Curated skill packs for a workflow (e.g. `fullstack-dev`) |

## Privacy at a glance

**Consent-first.** Mapick asks for network consent **before** any remote call.
On first use of `recommend`, `search`, `bundle`, `security`, or `report`, the
skill prompts you to choose:

- **Allow & remember** — all future calls proceed without prompting
- **This time only** — one call, then ask again
- **Local only** — no remote calls; local features only (`status`, `diagnose`, `scan`, `clean`)

Without explicit consent, no data is sent to api.mapick.ai. Local commands
work offline.

**If you prefer opt-in**: run `/mapick privacy consent-decline` to block all
remote calls client-side. Commands like `recommend`, `search`, and `security`
will return `disabled_in_local_mode` until you run `/mapick privacy consent-agree`
to enable.

**Sent**: anonymous device fingerprint (16-char hash of `hostname|os|home`) + Skill IDs you act on + timestamps.

**Never sent**: chat content, arbitrary local file contents, API tokens, credentials, Skill source, environment variables.

**One thing that does upload to api.mapick.ai**: persona-share. Only when you
**explicitly confirm** "share my persona" after seeing the report, Mapick
uploads a generated `/tmp/mapick-report-<id>.html` after fail-closed redaction.
The skill shows the full report locally first, then asks for confirmation
before any upload. Retained 30 days at `mapick.ai/s/{shareId}`. Refuses upload
if redaction is unavailable or disabled.

Three opt-outs, one command each:

- `/mapick privacy consent-decline` — block all remote calls client-side
- `/mapick privacy delete-all --confirm` — wipe local state + backend records
- `/mapick privacy log` — show every outbound HTTP request from Mapick (endpoint, field names, status, duration; never values)

## What it touches

| Permission | Scope (declared in SKILL.md frontmatter, enforced in code) |
| --- | --- |
| Network | `api.mapick.ai` only — endpoint allowlist refuses any other URL |
| File read | `~/.openclaw/skills/` and `~/.openclaw/workspace/skills/` — scans every installed Skill's `SKILL.md` frontmatter to know what's there |
| File write | `~/.openclaw/workspace/skills/mapick/CONFIG.md`, `~/.openclaw/skills/mapick/trash/`, `~/.mapic

_meta.json

{
  "ownerId": "kn7746w2qh2emy9q8vftnqzwsd81wxsb",
  "slug": "mapick",
  "version": "1.0.28",
  "publishedAt": 1778231831267
}

scripts/package.json

{
  "type": "commonjs"
}

prompts/persona-production.md

# Mapick Persona Report — Production Prompt v1.0

> V1 PR-12 delivery. This is the contract the AI uses to turn
> `GET /report/persona` output into a single self-contained HTML document
> uploaded via `share <reportId> <htmlFile>`.
>
> **Do not translate this file** — it is consumed verbatim by the AI.

---

You are generating a personalized developer persona report for a Mapick user.

The output is a SINGLE self-contained HTML document that will be stored for
30 days at `mapick.ai/s/{shareId}` and viewed by the user and people they share
it with (social media preview etc.).

## Input variables

- `primaryPersona` — one of 10 IDs:
  `3am_committer` / `install_first_ask_later` / `pr_approval_hoarder` /
  `the_paranoid` / `openclaw_lifer` / `just_in_case_club` /
  `tldr_generator` / `serial_uninstaller` / `openclaw_maximalist` / `fresh_meat`
- `shadowPersona` — same enum, secondary persona (may be null)
- `dataProfile` — `{ daysUsed, conversationsCount, wordsProduced, codeReviewsCount,
   reportsGeneratedCount, activeHoursStart, activeHoursEnd, installedSkillsCount,
   activeSkillsCount, percentileRank, topSkills: [...] }`
- `locale` — `en` / `zh` / `de` / `ja` / `ko` / `es` / `pt` / `fr` / ...

## Output constraints (STRICT — consistent rendering across LLMs)

1. **Exactly ONE `<!DOCTYPE html>` block** — no preamble, no explanation, no
   trailing text. The entire response is valid HTML.
2. **HTML `<head>` must contain** (in this order):
   - `<meta charset="UTF-8">`
   - `<meta property="og:title" content="...">`
   - `<meta property="og:description" content="...">`
   - `<meta property="og:image" content="https://mapick.ai/public/og-{primaryPersona}.png">`
   - `<meta property="og:url" content="https://mapick.ai/s/{shareId}">` (the AI leaves `{shareId}` as a placeholder; backend `/share/upload` replaces it after shareId is minted)
   - `<meta property="og:type" content="website">`
   - `<meta name="twitter:card" content="summary_large_image">`
   - `<meta name="mapick:shareText" content="<localized share text>">`
   - `<meta name="mapick:personaName" content="<localized primary persona name>">`
3. **Body structure** (required `<div>` IDs for future automation):
   - `<div id="persona-header">` — persona name + emoji + matchScore %
   - `<div id="shadow-persona">` — shadow persona line (omit if null)
   - `<div id="data-highlights">` — 3-5 key numbers from `dataProfile`
   - `<div id="top-skills">` — top 3 skills list
   - `<div id="share-cta">` — "Generate yours →" button linking to `https://mapick.ai`
4. **CSS**: inline only (`<style>` in `<head>`). No external `<link>` except
   `mapick.ai`. No CSS-in-JS. No Tailwind class names assuming CDN.
5. **Two display modes** via `.screenshot-mode` CSS class on `<body>`:
   - default (browse): standard web card, max-width 640px
   - `.screenshot-mode`: 1200×630 optimized for og:image snapshot
6. **Size**: total HTML < 200KB (enforced server-side; going over returns 413).
7. **Localization**: all user-f
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/sunlleyevan/skills/mapick",
      "sourceUrl": "https://clawhub.ai/sunlleyevan/skills/mapick",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T00:11:13.973Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-sunlleyevan-mapick/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sunlleyevan-mapick/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T00:11:13.973Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.2K downloads",
      "href": "https://clawhub.ai/sunlleyevan/mapick",
      "sourceUrl": "https://clawhub.ai/sunlleyevan/mapick",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T00:11:13.973Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.0.28",
      "href": "https://clawhub.ai/sunlleyevan/mapick",
      "sourceUrl": "https://clawhub.ai/sunlleyevan/mapick",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-08T09:17:11.267Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-sunlleyevan-mapick/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sunlleyevan-mapick/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.0.28",
      "description": "### Fixed - backup:restore: fix validateSkillId check (was returning early for valid IDs) - flows.md: persona report now requires explicit user confirmation before share - CLAWHUB.md: clarify persona upload requires explicit confirmation - Addresses ClawScan Findings #1, #3, #6",
      "href": "https://clawhub.ai/sunlleyevan/mapick",
      "sourceUrl": "https://clawhub.ai/sunlleyevan/mapick",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-08T09:17:11.267Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to Mapick and adjacent AI workflows.