{"id":"62e8756f-72a7-4b83-a075-84260b25968a","entityType":"agent","slug":"clawhub-haiyangchenbj-skill-audit-publish","name":"Skill Audit & Publish","canonicalUrl":"https://www.xpersona.co/agent/clawhub-haiyangchenbj-skill-audit-publish","canonicalPath":"/agent/clawhub-haiyangchenbj-skill-audit-publish","generatedAt":"2026-10-10T02:05:03.336Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:15:43.181Z","emptyReason":null},"description":"Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17672gh0nx9qr7sjp84kz7xen83jv7v:skill-audit-publish","sourceUrl":"https://clawhub.ai/haiyangchenbj/skill-audit-publish","homepage":"https://clawhub.ai/haiyangchenbj/skills/skill-audit-publish","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/haiyangchenbj/skill-audit-publish","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/haiyangchenbj/skills/skill-audit-publish","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":66,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Skill Audit & Publish technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:15:43.181Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:15:43.181Z","emptyReason":null},"stars":null,"forks":null,"downloads":1987,"packageName":null,"latestVersion":"1.5.9","tractionLabel":"2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:15:43.151Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T21:15:43.181Z","lastCrawledAt":"2026-10-09T21:15:43.151Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T21:15:43.151Z","lastVerifiedAt":null,"highlights":[{"version":"1.5.9","createdAt":"2026-09-20T05:49:49.948Z","changelog":"LP1 fix: SkillHub upload stage (5b) declared in frontmatter permissions (api.skillhub.cn network + local credential-file read) and allowed-tools env/network tokens; stage-5b auth disclosure added to the body; absolute credential claims scoped to the sync helper to remove self-contradiction; SkillHub 429 backoff corrected from ~60s to ~90s (field-verified).","fileCount":11,"zipByteSize":26870},{"version":"1.5.8","createdAt":"2026-09-18T04:10:26.399Z","changelog":"Add stage 5b: SkillHub publish. The pipeline covered ClawHub and GitHub only, which silently broke the unified three-platform version rule. New references/skillhub-publish.md holds the endpoint, multipart request shape, response codes, and the no-read-API caveat; the skill file gains a short routing section and the description now names all three platforms.","fileCount":11,"zipByteSize":26133},{"version":"1.5.7","createdAt":"2026-09-16T05:57:32.671Z","changelog":"AE1 experiment: removed skill-file self-reference and script-name literals from SKILL.md to test scanner coverage findings; zero unpinned-runner mentions (RP1); optional zh-summary now requires explicit user consent (SQP-3); allowed-tools declared (LP3); credential comment rewritten (PE3). Fail-closed path containment unchanged.","fileCount":10,"zipByteSize":24033},{"version":"1.5.6","createdAt":"2026-09-16T05:07:56.831Z","changelog":"Scanner-hardening per clawscan findings: sync helper now enforces fail-closed path containment (absolute paths, .. components, symlinked segments, and escapes rejected before any read or upload); sanitize.md Chinese-summary add-on converted to explicit consent gate and patch-track approval no longer optional; pinned/locally-installed clawhub CLI recommended over unpinned npx (supply-chain); skill-card risk mitigation aligned with enforced behavior; version bump","fileCount":10,"zipByteSize":23832},{"version":"1.5.5","createdAt":"2026-09-10T04:28:25.968Z","changelog":"Restore correct display name (1.5.4 submit derived it from the staging folder name); no functional changes","fileCount":10,"zipByteSize":22646},{"version":"1.5.4","createdAt":"2026-09-10T02:57:28.120Z","changelog":"Fix misleading error text in bundled sync helper (credentials are sourced from environment variables only, never from files)","fileCount":10,"zipByteSize":22565},{"version":"1.5.3","createdAt":"2026-09-09T02:40:06.861Z","changelog":"Align README external-side-effect notice with actual behavior: sync helper is upsert-only, nothing is ever deleted","fileCount":10,"zipByteSize":22633},{"version":"1.5.2","createdAt":"2026-09-08T08:25:04.678Z","changelog":"Fix scanner findings: remove token-file fallback (env-var only), replace internal GitHub playbook with generic upsert-only guidance, declare permissions in manifest","fileCount":10,"zipByteSize":22597}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17672gh0nx9qr7sjp84kz7xen83jv7v:skill-audit-publish","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17672gh0nx9qr7sjp84kz7xen83jv7v:skill-audit-publish` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/haiyangchenbj/skill-audit-publish before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T02:05:03.332Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-haiyangchenbj-skill-audit-publish/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:15:43.181Z","emptyReason":null},"readme":"Skill: Skill Audit & Publish\n\nOwner: haiyangchenbj\n\nSummary: Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.\n\nTags: latest:1.5.9\n\nVersion history:\n\nv1.5.9 | 2026-09-20T05:49:49.948Z | user\n\nLP1 fix: SkillHub upload stage (5b) declared in frontmatter permissions (api.skillhub.cn network + local credential-file read) and allowed-tools env/network tokens; stage-5b auth disclosure added to the body; absolute credential claims scoped to the sync helper to remove self-contradiction; SkillHub 429 backoff corrected from ~60s to ~90s (field-verified).\n\nv1.5.8 | 2026-09-18T04:10:26.399Z | user\n\nAdd stage 5b: SkillHub publish. The pipeline covered ClawHub and GitHub only, which silently broke the unified three-platform version rule. New references/skillhub-publish.md holds the endpoint, multipart request shape, response codes, and the no-read-API caveat; the skill file gains a short routing section and the description now names all three platforms.\n\nv1.5.7 | 2026-09-16T05:57:32.671Z | user\n\nAE1 experiment: removed skill-file self-reference and script-name literals from SKILL.md to test scanner coverage findings; zero unpinned-runner mentions (RP1); optional zh-summary now requires explicit user consent (SQP-3); allowed-tools declared (LP3); credential comment rewritten (PE3). Fail-closed path containment unchanged.\n\nv1.5.6 | 2026-09-16T05:07:56.831Z | user\n\nScanner-hardening per clawscan findings: sync helper now enforces fail-closed path containment (absolute paths, .. components, symlinked segments, and escapes rejected before any read or upload); sanitize.md Chinese-summary add-on converted to explicit consent gate and patch-track approval no longer optional; pinned/locally-installed clawhub CLI recommended over unpinned npx (supply-chain); skill-card risk mitigation aligned with enforced behavior; version bump\n\nv1.5.5 | 2026-09-10T04:28:25.968Z | user\n\nRestore correct display name (1.5.4 submit derived it from the staging folder name); no functional changes\n\nv1.5.4 | 2026-09-10T02:57:28.120Z | user\n\nFix misleading error text in bundled sync helper (credentials are sourced from environment variables only, never from files)\n\nv1.5.3 | 2026-09-09T02:40:06.861Z | user\n\nAlign README external-side-effect notice with actual behavior: sync helper is upsert-only, nothing is ever deleted\n\nv1.5.2 | 2026-09-08T08:25:04.678Z | user\n\nFix scanner findings: remove token-file fallback (env-var only), replace internal GitHub playbook with generic upsert-only guidance, declare permissions in manifest\n\nv1.5.1 | 2026-09-08T06:42:46.401Z | user\n\nSecurity hardening: bundled GitHub sync script now fully parameterized (env-var token, CLI owner/dir, no hardcoded paths or usernames); bundled-script side effects disclosed in description, SKILL.md, and READMEs\n\nv1.5.0 | 2026-09-08T02:41:09.022Z | user\n\nAdd Critical rules: unified three-platform versioning (max+0.0.1), phantom-occupied version numbers, SkillHub strict frontmatter validation, skill-card removal, GitHub sync from publish staging dir\n\nv1.4.0 | 2026-08-24T05:06:13.773Z | user\n\nAdd Release Type Gate: new-skill vs content-update vs patch pipeline strictness; mandatory slug-collision pre-check and structure completeness for new skills; frozen-skill list (social-persona-profiling)\n\nv1.3.0 | 2026-08-14T05:48:39.242Z | user\n\nAdd Step 5 rollback strategy to sanitize.md: when fixes increase findings, rollback frontmatter to last-passing version + retain body scope fixes. Real example from social-persona-profiling 1.0.4->1.0.11.\n\nv1.2.1 | 2026-08-14T05:36:44.736Z | user\n\nAdd Chinese trigger keywords to description for skillhub search discoverability\n\nv1.2.0 | 2026-08-14T04:07:08.543Z | user\n\nAdd post-publish finding diagnosis section to sanitize.md: L1/L2/L3 layer framework for SkillSpector findings, anti-patterns (no reflexive disclaimers, no version-bump loops), and stop-fixing criteria\n\nv1.1.6 | 2026-08-07T07:39:48.196Z | auto\n\n- Bumped version to 1.1.6.\n- No functional or documentation changes; only the version number in SKILL.md was updated.\n\nv1.1.5 | 2026-08-07T07:38:34.515Z | auto\n\n- Version bump to 1.1.5.\n- Added Chinese documentation: README_zh.md.\n- Removed skill-card.md from the skill package.\n- Updated SKILL.md and _meta.json with current version and minor clarifications.\n\nv1.1.4 | 2026-08-07T06:42:01.484Z | auto\n\nVersion 1.1.4\n\n- Added a Chinese-language description (description_zh) to SKILL.md for improved GEO/LLM retrieval.\n- Removed the skill-card.md reference file from the repository.\n- Updated version number and metadata in SKILL.md and _meta.json.\n- No changes to functionality or workflow.\n\nv1.1.3 | 2026-08-02T16:14:25.575Z | user\n\nAdd two publish guardrails: (8) --slug must be passed explicitly because clawhub publish derives slug from the publish-folder name (silent wrong/duplicate-slug bugs otherwise); (9) detect and flatten slug/slug/ nested source folders from clawhub install, assert flat root + correct slug in Verify.\n\nv1.1.2 | 2026-08-01T10:20:06.460Z | user\n\nRemove incorrect fork-of attribution (content is original, not derived); rephrase comparison FAQ vs plain clawhub publish; publisher haiyangchenbj\n\nv1.1.1 | 2026-08-01T10:12:53.203Z | user\n\nPromote GEO rewrite to latest (1.1.1); 5-stage pipeline, FAQ, 中文摘要; fork-of ivangdavila/skill-publish\n\nv1.1.0 | 2026-08-01T10:10:53.617Z | user\n\nRename from workbuddy-skill-publish; GEO rewrite: 5-stage pipeline (Sanitize/Transform/Verify/Publish/Install-check), FAQ, 中文摘要; fork-of ivangdavila/skill-publish\n\nv1.0.3 | 2026-07-31T09:23:23.810Z | user\n\nSync local 1.0.3: Windows node.exe path fix + safe-delete fail-closed notes; no new feature\n\nv1.0.2 | 2026-07-15T03:44:22.385Z | user\n\nSecurity hardening from SkillSpector audit: fix Step 7 local-file contradiction (fixes now written only to temp copy), add explicit external side-effect + confirmation warnings, scope GitHub PAT to minimum, soften English-first from mandate to platform default.\n\nv1.0.1 | 2026-06-06T06:09:36.142Z | user\n\nv1.0.1: de-emphasize WorkBuddy branding, general-purpose agent skill publish\n\nv1.0.0 | 2026-06-06T06:02:17.272Z | user\n\nv1.0.0: Initial release. Audit and publish WorkBuddy skills to ClawHub & GitHub.\n\nArchive index:\n\nArchive v1.5.9: 11 files, 26870 bytes\n\nFiles: _meta.json (138b), README_zh.md (2172b), README.md (2414b), references/publish-rules.md (4568b), references/skillhub-publish.md (3151b), sanitize.md (7622b), scripts/sync_skill_to_github.js (7169b), skill-card.md (2825b), SKILL.md (20637b), transform.md (1870b), verify.md (1876b)\n\nFile v1.5.9:SKILL.md\n\n---\nname: \"Skill Audit & Publish\"\nslug: skill-audit-publish\ndisplayName: \"Skill Audit & Publish\"\ndescription: \"Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.\"\nversion: \"1.5.9\"\nallowed-tools: execute_command, read_file, file_read, write_to_file, file_write, env, network\nmetadata:\n  openclaw:\n    permissions:\n      - \"network: api.github.com — used only by the bundled sync helper when explicitly invoked\"\n      - \"credentials: GITHUB_TOKEN / GITHUB_PAT environment variables — read at runtime, never stored or logged\"\n      - \"network: api.skillhub.cn — used only by the stage 5b SkillHub upload when the user approves publishing\"\n      - \"credentials: the local SkillHub credential file (~/.skillhub/credentials.json, field user.token) read only during stage 5b to authenticate the upload — held in memory for that single request, never embedded in the skill, logged, or shipped in any package\"\n    tags:\n      - skill-publishing\n      - pre-publish-audit\n      - pii-sanitization\n      - secret-scanning\n      - skill-lifecycle\n      - content-governance\n      - developer-tools\n      - publishing-workflow\n      - audit-checklist\n---\n\n# Skill Audit & Publish\n\nA five-stage pipeline that takes a local OpenClaw skill and ships a sanitized, verified release to ClawHub. The publish command is the last step, not the first — every earlier step is designed to keep private data and irreversible mistakes out of the public record.\n\n**The single most important rule:** never modify the user's original files. Work in a separate publish folder; only after explicit approval move anything to the live registry.\n\n---\n\n## When to use\n\nTrigger this skill when the user says or implies any of:\n\n- \"Publish this skill to ClawHub\" / \"I want to publish to ClawHub\" / \"ship it to clawhub\"\n- \"How do I publish a skill\" / \"What's the ClawHub publish command\" / \"clawhub publish syntax\"\n- \"Sanitize my skill before publishing\" / \"remove personal info\" / \"audit for PII\"\n- \"Check for secrets / API keys / tokens before I publish\"\n- \"Make a publish-ready version of this skill\"\n- \"I want to share this skill publicly\" / \"publish a skill without leaking my data\"\n- \"clawhub publish\" / \"clawhub publish command\" / \"openclaw publish\"\n- \"Pre-publish checklist\" / \"what should I check before publishing\"\n\n**Do NOT trigger** for: editing skill content (use the skill's own skill), reading a skill from ClawHub, listing installed skills, or any non-publish operation.\n\n---\n\n## What this skill produces\n\nA `publish-folder/` with:\n- **The skill file** (rewritten frontmatter: `name`, `description`, `version`, GEO-optimized)\n- `FILES.txt` (manifest of what will ship)\n- Auxiliaries: `sanitize.md`, `transform.md`, `verify.md`\n- `_meta.json` (slug, version, publishedAt)\n- An **approval message** summarizing slug / name / version / files / sanitization status — held until the user explicitly approves.\n\nNothing leaves the local publish folder until the user replies \"yes / publish / go\".\n\n---\n\n## The 5-stage pipeline\n\n| Stage | Output | Gate |\n|---|---|---|\n| 1. **Understand** | One-paragraph summary of what the skill does, who it's for, what to keep / cut | User confirms the summary |\n| 2. **Transform** | Re-structured skill file (frontmatter + body) + extracted auxiliaries | Diff shown to user |\n| 3. **Sanitize (the audit)** | `sanitize.md` checklist run: PII / credentials / model-specific refs / internal paths / dangerous patterns; each item marked `removed` / `genericized` / `kept-with-reason` | User reviews every kept-with-reason item |\n| 4. **Verify** | Approval message: slug, name, version, description, file list, sanitization confirmation, sample of sanitized text | **Explicit user approval** |\n| 5. **Publish + install-check** | `clawhub publish` then `clawhub install <slug> --dir /tmp/verify` to confirm the published version is installable and matches the local copy. Use a pinned or locally installed CLI — unpinned registry resolution pulls a mutable third-party package at run time (supply-chain risk) | Success message reported back to user |\n\nThe audit (stage 3) is the differentiator. Other publish skills hand you a `clawhub publish` command; this one walks the content through a structured PII / secret / model-reference scan first and refuses to skip the scan if the user has not reviewed the keep-list.\n\n---\n\n## GEO optimization embedded in stage 2\n\nThe transform step re-writes the skill's `description` field for Generative Engine Optimization so the published skill is cited by ChatGPT / Claude / Perplexity when users ask for help in that domain. The current 6 rules:\n\n1. **First sentence = what it is + who it's for.** No preamble. Verbs, not nouns.\n2. **List concrete capabilities as short noun phrases** (LLM retrieval uses these as match anchors).\n3. **Include the primary user-trigger phrase** as a literal quoted string inside the description.\n4. **Front-load 2–3 named tools / frameworks / commands** the skill uses or talks to.\n5. **Add a \"When to use\" trigger block** with 5–7 user-natural questions, mirroring the skill's own frontmatter.\n6. **Optional: end with a Chinese summary (中文摘要) block** (catches the Chinese-language LLM retrieval channel) — propose it and add it only after the user explicitly consents, since it broadens public search visibility.\n\nThe transform stage will re-run these rules against the user's skill and present a before/after diff before any sanitization starts.\n\n---\n\n## Critical rules\n\n1. **Never modify the original files.** Always copy to `/tmp/publish-<slug>/` (or any out-of-tree folder) and work there.\n2. **Never publish without running `sanitize.md`.** The audit is mandatory; \"looks fine to me\" is not a substitute.\n3. **Never publish without explicit user approval.** The approval message lists the exact slug, name, version, description, and file set. The user must say \"yes\" or equivalent. Silence is not consent.\n4. **Slug is renameable, with redirects.** On ClawHub, the Edit page lets you change the canonical slug under \"Rename slug\"; old slugs stay as 301 redirects. If the wrong slug ships, fix it via the Edit UI (and optionally publish a new version with the corrected content). **This is why stage 4 still matters** — the verify stage catches wrong content; the slug rename is a separate UI action.\n5. **Version semantics:** `1.0.0` first publish; `1.0.x` typo / wording fixes; `1.x.0` new content; `2.0.0` major restructure. **One version number across all three platforms (ClawHub / SkillHub / GitHub), set to the highest existing one + 0.0.1** (科里 2026-08-31 确立): before publishing, check each platform's latest (ClawHub `inspect --versions`, SkillHub API, GitHub frontmatter), take the max, bump — never let platforms drift apart again.\n6. **Sanitize-over-include when uncertain.** When the audit flags a borderline item, default to remove or genericize. Adding later is easy; removing from a public release is reputation damage.\n7. **No silent re-publishes.** Every publish — including version bumps — produces an approval message. Re-publishing to fix a typo is a publish event, not a footnote.\n8. **Slug MUST be passed explicitly via `--slug`.** The `clawhub publish` CLI derives the slug from the **publish-folder's name** (`sanitizeSlug(basename(folder))`), NOT from the skill file's name or slug fields. If the folder name differs from the intended slug, the publish silently lands on the wrong slug — and if that slug already exists under another owner, ClawHub returns `AMBIGUOUS_SKILL_SLUG` and the install breaks for everyone. Always pass `--slug <canonical-slug>` even when the folder name looks right. (The Install-check stage below uses `--dir /tmp/verify-<slug>` precisely to avoid re-nesting on the user's machine.)\n9. **Detect and flatten nested source folders before publishing.** `clawhub install <slug> --dir .` wraps the downloaded skill in a slug-named subfolder, producing a `slug/slug/` double-nested layout on disk (the skill file ends up two levels deep). Before publishing, resolve the skill file to the **inner** folder; never publish from the outer wrapper. In the Verify stage, assert the skill file sits at the publish-root (not nested one level down) and that `slug` equals the intended canonical slug.\n10. **Version numbers can be phantom-occupied.** When a platform version was published as \"add missing files only\" (the skill file untouched), the platform Latest leads the `version:` field inside the skill file (e.g. platform 1.1.3 / file says 1.1.1). Before any patch publish, run `clawhub inspect <slug> --versions` and target **platform Latest + 0.0.1** — never trust the version field inside the file. Same on SkillHub: \"version already exists\" on publish = phantom occupation; bump again.\n11. **SkillHub publish has stricter frontmatter validation than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files downloaded via `clawhub install` often miss the leading `---` (stripped in ClawHub storage) and `slug`/`displayName` — backfill them before SkillHub publish. Consecutive SkillHub publishes trigger 429 rate limits; wait ~90s between publishes (a single 90 s backoff has been the reliable fix in practice; 20 s retries can fail repeatedly).\n12. **Delete `skill-card.md` from install-sourced publish folders.** ClawHub generates it and refuses publishes containing it. Publish with explicit `--slug/--name/--version/--changelog` (the CLI reads version from frontmatter when flags are absent, and phantom-occupied versions fail late).\n13. **On Windows, pass Windows paths to `clawhub publish` / `clawhub install`.** Under Git Bash a `/c/Users/...` path fails with `Error: Path must be a folder`; the same command with `C:\\Users\\...` succeeds. This is not a permissions or install problem — retry with the Windows form before concluding anything else. (Verified 2026-09-11.)\n14. **`inspect`'s table view is cached; `--json` is authoritative.** After a publish the table can keep showing the previous `Latest` for several minutes. Read `inspect <slug> --json` → `latestVersion.version` and `skill.tags.latest` instead. Do not re-publish because the table looks stale, and do not poll with long sleeps — one JSON read settles it. (Verified 2026-09-11.)\n15. **GitHub mirror sync must push from the publish staging dir (`pub-*`), never from an install-sourced dir.** An install dir holds whatever the registry had (possibly a phantom-occupied old `version:` field without your patch), while the staging dir is the exact content you verified. Upsert-only: contents-API pushes add/update files but never delete removed ones — audit the repo file list after major restructures.\n16. **Use a pinned or locally installed `clawhub` CLI, never an unpinned one-shot runner.** Executing a CLI straight from the registry without a pinned version downloads the latest third-party package at run time — a supply-chain risk for a command that reads your token and uploads content. Install once (`npm i -g clawhub`) and invoke the reviewed local binary; if a one-shot run is truly unavoidable, pin the exact package version.\n\n---\n\n## Bundled scripts (external side effects, disclosed)\n\n**Bundled sync helper (see the bundled scripts/ directory)** — optional helper that mirrors a publish folder to a GitHub repo via the GitHub Contents API (PAT auth). Behavior, explicitly:\n\n- **Reads a token from the environment only.** Requires the `GITHUB_TOKEN` / `GITHUB_PAT` environment variable; exits with an error if unset. No token is embedded in the skill, read from files, transmitted anywhere except api.github.com, or logged. (The stage 5b SkillHub upload reads a different credential from a local file — declared separately in the frontmatter permissions; it does not involve this helper.)\n- **Writes to GitHub only.** All network traffic goes to `api.github.com`. It creates or updates files (Contents API PUT) in the repo you name via `--owner` / `--repo`.\n- **Never deletes.** Upsert-only: files present on GitHub but absent from the local file list are left untouched; remote deletion must be done manually.\n- **Fully parameterized.** Owner, repo, local directory, branch, commit message, and file list all come from CLI flags (`--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`) — no hardcoded user names or machine paths.\n- **Path containment (fail-closed).** Every `--files` entry must resolve inside the local directory: absolute paths, `..` components, symlinked path segments, and any path resolving outside it are rejected with an error before anything is read or uploaded.\n\nThe skill's five-stage pipeline itself never touches the network beyond `clawhub publish` / `clawhub install` and the stage 5b SkillHub upload; the sync script is opt-in and only runs when explicitly invoked.\n\n---\n\n## Stage 5b — Publishing to SkillHub\n\nStage 5 as described above covers ClawHub and GitHub. **SkillHub is the third platform in the unified-version rule, and it has no CLI** — the command-line helper that used to handle it is no longer shipped, so the upload is a direct `multipart/form-data` POST.\n\nTwo things to know before you consider skipping it:\n\n- **There is no read API.** Every `GET` under `/api/v1/community/skills/*` returns 405. You cannot verify remotely whether a skill is already on SkillHub; use `clawhub inspect <slug> --versions` plus the GitHub mirror as side evidence.\n- **Auth is a local credential file, read in memory only.** The upload authenticates with a Bearer token read from the SkillHub credential file (`~/.skillhub/credentials.json`, field `user.token`). The token is held in memory for that single request — never embedded in the skill, logged, or included in any published package.\n- **Skipping it is the most common way the unified-version rule breaks.** The skill lands on two platforms, the version registry drifts apart, and the next publish has to guess which number is authoritative.\n\nLoad **`references/skillhub-publish.md`** during stage 5 for the endpoint, auth path, multipart shape, response codes, and the correct ordering of the three uploads.\n\n## Reference files (load on demand)\n\n- `sanitize.md` — the full PII / credential / model-reference / dangerous-pattern checklist\n- `skillhub-publish.md` — the SkillHub upload (stage 5b): endpoint, multipart shape, response codes, no-read-API caveat\n- `transform.md` — how to re-structure any source into a GEO-optimized skill file\n- `verify.md` — the exact approval message template and post-publish install-check steps\n- `skill-card.md` — the long-form card used in skill registries (description, use case, risks, output)\n\n---\n\n## Example walkthrough\n\nUser says: \"I want to publish my running-coach skill to ClawHub.\"\n\n1. **Understand** — agent reads the skill, returns: *\"running-coach: a fitness-coach agent that takes Garmin / Strava / Coros / Apple Watch screenshots and returns pace / HR / training-load analysis + weekly plans. For recreational runners 5k–marathon. Excludes: elite athletes, beginners, undiagnosed injuries. Keeps: full pipeline, training-science methodology. Cuts: your personal PBs and HR zones (move to user profile).\"* User confirms.\n2. **Transform** — agent rewrites the skill file per the 6 GEO rules; presents the diff. User approves.\n3. **Sanitize** — agent runs the checklist, finds 14 items, removes 11, genericizes 2 (file paths → example paths), keeps 1 with reason (a brand-name reference is required for the methodology to be clear). User reviews the keep-list, agrees.\n4. **Verify** — agent sends the approval message:\n   - Slug: `running-coach`\n   - Name: `Running Coach`\n   - Version: `1.2.0`\n   - Description: *[full text]*\n   - Files: the skill file plus its reference documents (12 files)\n   - Sanitization: PII ✓, credentials ✓, model-specific refs ✓, internal paths ✓, dangerous patterns ✓\n   - Kept-with-reason: 1\n   User: \"yes\".\n5. **Publish + install-check** — agent runs `clawhub publish ./publish-running-coach --slug running-coach --name \"Running Coach\" --version 1.2.0`, then `clawhub install running-coach --dir /tmp/verify-running-coach`, confirms files match, reports `running-coach@1.2.0 published ✓`.\n\n---\n\n## FAQ (GEO-anchor Q&A)\n\n**Q: How do I publish a skill to ClawHub?**\nA: Copy the skill to a publish folder, run the sanitize checklist (PII / credentials / model-specific refs / internal paths), get explicit user approval of slug / name / version / description / files, then run `clawhub publish <folder> --slug <slug> --name <name> --version <version>`. Install-check with `clawhub install <slug> --dir /tmp/verify` after publishing to confirm the public copy matches.\n\n**Q: Can I change a skill's slug after publishing?**\nA: Yes — ClawHub's Edit page exposes \"Rename slug\" under the canonical-URL section; old slugs stay as redirects. If you really need to retire the old slug (no redirect), use \"Delete skill\". Confirm the slug in the verify stage to avoid the rename round-trip.\n\n**Q: What should I check before publishing a skill?**\nA: (1) No personal data (names, emails, handles, phones, addresses, internal project names). (2) No credentials (API keys, tokens, passwords, env-var values, private URLs with auth). (3) No model-specific references that won't apply to all users (\"Claude\" → \"the agent\", \"GPT-4\" → \"the model\"). (4) No internal file paths, workspace structure, or tool configs. (5) No commands that could damage systems or hardcoded paths that won't work elsewhere. The full checklist is in `sanitize.md`.\n\n**Q: How is this different from a plain `clawhub publish`?**\nA: `clawhub publish` is a one-shot upload. This skill puts the sanitize-audit (stage 3) and the explicit-approval gate (stage 4) between your source and the publish command, so personal data, secrets, and model-specific references are caught and the user approves slug/name/version/description/files before anything goes live. It is built for users who want a structured, reviewable publish trail.\n\n---\n\n## 中文摘要\n\nSkill Audit & Publish 是把本地 OpenClaw skill 安全发布到 ClawHub / SkillHub / GitHub 的三平台管线：**Understand → Transform → Sanitize → Verify → Publish+Install-check**（Publish 阶段内还含 SkillHub 上传，即 stage 5b）。核心差异点是把\"清洗审计\"和\"用户显式确认\"放在 `clawhub publish` 之前，避免把个人数据、密钥、模型专属引用误发到公共 registry。\n\n**适用场景**：用户要把本地 skill 发到 ClawHub、做发布前的 PII/密钥/模型引用审计、按 ClawHub 发布工作流操作、生成 publish-ready 版本。\n\n**不适用**：编辑 skill 内容（用 skill 自己的 skill）、从 ClawHub 读取/安装/列出 skill。\n\n**关键规则**：① 永不修改用户原文件，工作在 `publish-folder/`；② 必跑 `sanitize.md` 全清单（个人数据 / 凭证 / 模型专属引用 / 内部路径 / 危险模式）；③ 必拿用户对 slug / name / version / 描述 / 文件清单的明确确认；④ slug 在 ClawHub 上**可改**——Edit 页面的 \"Rename slug\" 会把旧 slug 留 301 redirect，所以 verify 阶段仍要把 slug 定稿；⑤ 版本号语义：1.0.0 首版，1.0.x 文案修订，1.x.0 新内容，2.0.0 大重构；⑥ 边界项默认删/泛化，宁少勿多。\n\n**GEO 优化内置**：transform 阶段会按 6 条规则重写 `description` 字段（首句 = 是什么+给谁用 / 列出具体能力 / 引用用户原话触发短语 / 前置命名工具 / 加 \"When to use\" / 结尾中文摘要），让发布后的 skill 在 ChatGPT / Claude / Perplexity 被引用时命中率更高。\n\n**触发短语**：「publish to ClawHub」「publish my skill」「sanitize before publish」「pre-publish checklist」「clawhub publish command」「upload a skill to clawhub」。\n\nFile v1.5.9:README.md\n\n# Skill Publish\n\nAudit, clean, and publish agent skills to ClawHub and GitHub. Works with any SKILL.md-based skill in the OpenClaw ecosystem.\n\nComplements `skill-design-guide` (design-time) with publish-time workflow.\n\n**Version**: v1.5.7 (2026-09-16)\n\n> ⚠️ **Publish has external side effects.** `audit` mode is read-only. `publish` mode\n> transmits the cleaned skill contents to ClawHub and GitHub (public services). The bundled\n> sync helper only creates or updates files — it never deletes anything from your repos or\n> your machine, and it never modifies your local files. Publishing runs only after an audit\n> and your explicit confirmation of the file list, target repos, and version. Treat\n> everything you publish as publicly visible.\n\n## Modes\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| **Audit** | \"audit skill\" | Read-only scan — reports issues, changes nothing, transmits nothing |\n| **Publish** | \"publish skill\" | After audit + confirmation: clean (in a temp copy) → push to ClawHub/GitHub → verify |\n\n## What It Checks\n\n1. **Personal data** — share counts, cost basis, account values, personal names\n2. **Frontmatter** — description length, language, version numbers in name\n3. **Content** — internal dev notes, references sections, version history\n4. **Language** — English SKILL.md body, bilingual READMEs\n5. **Files** — ticker-specific scripts, meta-documents, outdated files\n\n## Quick Start\n\n```bash\n# Audit a skill directory\n\"audit skill ~/.workbuddy/skills/my-skill\"\n\n# Publish to ClawHub + GitHub\n\"publish skill ~/.workbuddy/skills/my-skill@1.2.0\"\n```\n\n## Bundled Scripts\n\n`scripts/sync_skill_to_github.js` — optional helper that mirrors a publish folder to a GitHub repo via the Contents API.\n\n- Token: read from `GITHUB_TOKEN` / `GITHUB_PAT` env vars only; exits with an error if unset. Never embedded, read from files, or logged. (The SkillHub upload stage reads a separate credential from a local file — declared in the skill's frontmatter permissions; it does not involve this helper.)\n- Network: talks to `api.github.com` only. Creates/updates files (PUT); **never deletes** anything.\n- Fully parameterized: `--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`. No hardcoded paths or usernames.\n\n```bash\nnode scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill\n```\n\n## License\n\nMIT\n\nFile v1.5.9:_meta.json\n\n{\n  \"ownerId\": \"kn70yg6zwmkftx4939qrs89awx82rr9a\",\n  \"slug\": \"skill-audit-publish\",\n  \"version\": \"1.5.9\",\n  \"publishedAt\": 1789883389948\n}\n\nFile v1.5.9:references/publish-rules.md\n\n# Publish Rules for ClawHub & GitHub\n\n> Full rule reference loaded by the `skill-publish` workflow. Do not embed this in SKILL.md.\n\n---\n\n## 1. Frontmatter Requirements\n\n| Field | Rule | Why |\n|-------|------|-----|\n| `name` | Pure English slug, **no version number**. e.g. `invassistant` not `invassistant-v2` | ClawHub display name; version belongs in changelog |\n| `description` | ≤3 sentences, English only. No version numbers, stock tickers, keyword lists, or changelogs | ClawHub card + search summary |\n| `metadata.openclaw.tags` | 5-10 English tags | ClawHub category system |\n| `metadata.openclaw.requires.bins` | Declare required binaries (e.g. `python3`) | ClawHub security analysis |\n\n**Bad**:\n```yaml\ndescription: |\n  个人投资组合管理框架 v2.1.1（执行简化版）。覆盖 A 股、港股、美股。\n  新增 §7.4 模式 D...\n  触发关键词：检查持仓, COST, LLY...\n```\n\n**Good**:\n```yaml\ndescription: >\n  Multi-asset investment portfolio management framework.\n  A/B/C-class differentiated rules, 7 red-line risk controls.\n  Covers US, A-share, and HK stocks.\n```\n\n## 2. Content Cleanup\n\n### Must Remove\n- `## 详细参考` / `## References` section (lists internal file paths — meaningless to users)\n- Unreleased versions in version history (e.g. \"v3.0 planned 2027\")\n- Internal dev notes (\"审计清理版\", \"next 6-12 months: no new rules\")\n- Ticker-specific entry scripts (e.g. `check_tsla_entry.py`) — exposes personal holdings\n- Meta-documents not part of the skill (e.g. `SKILL_PUBLISH_RULES.md`)\n\n### Version History\n- Only published versions (available on ClawHub)\n- One sentence per version\n- Max 5 rows\n\n## 3. Language\n\nThese are **ClawHub discoverability conventions, not hard requirements**. Recommend them\nand flag deviations in the audit report, but respect the user's intended primary language\nand never delete or reject valid content solely on language grounds.\n\n| File | Recommended language |\n|------|----------|\n| `SKILL.md` | English body + optional Chinese intro paragraph at end |\n| `README.md` | English |\n| `README_zh.md` | Chinese (mirror of English README) |\n| `CONTRIBUTING.md` | English |\n| All `references/*.md` | English |\n\n## 4. File Separation: Local vs Published\n\nFiles that stay **local only** (never push to GitHub or ClawHub):\n- Ticker-specific scripts (`check_tsla_entry.py`, `check_detail.py`, etc.)\n- Personal config files (`*-config.json` with real credentials)\n- Meta-documents (`SKILL_PUBLISH_RULES.md`)\n- Session-specific notes or logs\n- `.git/` directory\n\nFiles that go to **both platforms**:\n- `SKILL.md`, `README.md`, `README_zh.md`\n- `CONTRIBUTING.md`, `LICENSE`, `requirements.txt`\n- `references/` (all `.md`)\n- `scripts/` (only generic, reusable engines)\n\nFiles for **ClawHub only** (not GitHub):\n- `_meta.json`\n\n## 5. Publish Mechanics\n\n### ClawHub\n```bash\nclawhub publish <clean-dir> --slug <slug> --version <semver> --changelog \"<one-liner>\"\n```\n- Requires prior `clawhub login --token <token>` (persists to session)\n- Version must not already exist on ClawHub\n- If overriding `latest` tag, version number must be higher than current latest\n\n### GitHub\nAuthenticate with a PAT from your environment: set `GITHUB_TOKEN` (or `GITHUB_PAT`) before syncing. Never hardcode a token or a token-file path inside the skill.\n\n- **Create the repo manually first** (github.com/new, or `POST /user/repos` with your own token outside this skill).\n- **Sync files with the bundled helper** `scripts/sync_skill_to_github.js` — it only creates or updates files via the Contents API (upsert-only). It has **no delete capability**; removing a file from the repo is a manual action in the GitHub web UI.\n- Prefer a small Node.js `https.request` script over `curl` in Git Bash (avoids pipe/TLS quirks).\n\n### Optimal strategy\n1. Create clean temp directory (copy whitelisted files only)\n2. Publish to ClawHub from temp dir (avoids leaking local files)\n3. Push individual files to GitHub via API\n4. Delete temp dir\n5. Verify both platforms\n\n## 6. Post-Publish Verification\n\n```\n[ ] clawhub inspect shows correct latest version + English description\n[ ] ClawHub card description is English, ≤3 sentences\n[ ] ClawHub display name has no version number\n[ ] Version history shows only published versions (≤5)\n[ ] SKILL.md has no \"详细参考/References\" section\n[ ] SKILL.md has no internal dev notes\n[ ] README.md + README_zh.md both exist, versions match\n[ ] GitHub repo has no ticker-specific scripts\n[ ] GitHub repo has no personal config files\n[ ] GitHub commit message matches changelog\n```\n\nFile v1.5.9:references/skillhub-publish.md\n\n# Publishing to SkillHub (stage 5b)\n\n> Loaded by stage 5 of the pipeline. Kept out of the skill file on purpose — the skill file stays a routing surface; operational detail lives here.\n\nSkillHub is the third platform in the unified-version rule. **There is no maintained CLI for it.** A helper named `skills_store_cli.py` used to exist and no longer ships anywhere on a typical machine — do not spend time searching for it. Build the request directly.\n\n---\n\n## Endpoint\n\n```\nPOST https://api.skillhub.cn/api/v1/community/skills/publish\n```\n\n## Auth\n\nBearer token from `~/.skillhub/credentials.json` → **`user.token`**.\nThe file has no top-level `token` key; reading `d[\"token\"]` yields null and produces a misleading 401/403.\n\n## Request — multipart/form-data\n\n**Part 1** — field `payload`, `Content-Type: application/json`:\n\n```json\n{\n  \"slug\": \"my-skill\",\n  \"displayName\": \"My Skill\",\n  \"version\": \"1.2.3\",\n  \"description\": \"one-line English summary\",\n  \"changelog\": \"what changed\",\n  \"category\": \"\",\n  \"subCategories\": [],\n  \"source\": \"community\",\n  \"tags\": [\"tag-a\", \"tag-b\"]\n}\n```\n\n**Parts 2..n** — one per file:\n\n- field name **must be `files`** (`file` and `files[]` are wrong)\n- `filename` = repo-relative path with forward slashes, e.g. `references/guardian-patterns.md`\n- `Content-Type: text/markdown`\n\n## Response\n\n| Code | Meaning |\n|---|---|\n| **201** | accepted — body carries `ok:true`, `version`, `fileCount`, `skillId`, `fingerprint`, and `pending` review/scan statuses |\n| 400 | frontmatter or payload validation failed |\n| 409 | slug tombstoned, or version already exists → bump and retry. **Never delete a `source=community` skill to force a republish** — the slug becomes an unrecoverable tombstone |\n| 429 | consecutive publishes rate-limited → wait ~90s (a single 90 s backoff has been the reliable fix in practice; 20 s retries can fail repeatedly) |\n| 503 | transient → wait ~20s and retry once |\n\n## Constraints\n\n- **No read API.** Every `GET` under `/api/v1/community/skills/*` returns 405, including `/mine`, `/list`, and `/rankings`, with or without a Bearer token. You cannot verify remotely whether a skill is already on SkillHub. Use side evidence instead: `clawhub inspect <slug> --versions` plus the existence of the GitHub mirror repo.\n- **Stricter frontmatter than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files retrieved via `clawhub install` often lose the leading `---` in ClawHub storage — backfill it before publishing.\n- **`LICENSE` is rejected.** Publish from a staging copy that excludes it.\n- **Version must match ClawHub and GitHub exactly.** No platform-local version numbers.\n\n## Ordering inside stage 5\n\n1. ClawHub publish (async — settle with `inspect --json` → `latestVersion.version`)\n2. **SkillHub publish (this file)**\n3. GitHub sync from the staging dir (never from an install dir)\n4. Install-check against ClawHub\n\nSkipping step 2 is the most common way the three-platform version rule breaks: the skill lands on two platforms, the version registry drifts apart, and the next publish has to guess which number is authoritative.\n\nFile v1.5.9:README_zh.md\n\n# Skill Publish\n\n审计、清理并发布 Agent Skill 到 ClawHub 和 GitHub。适用于 OpenClaw 生态中任何基于 SKILL.md 的 skill。\n\n与 `skill-design-guide`（设计阶段）配合。\n\n**版本**: v1.5.7（2026-09-16）\n\n> ⚠️ **发布模式有外部副作用。** 审计模式为只读。发布模式会把清理后的 skill 内容传输到\n> ClawHub 和 GitHub（公开服务）。捆绑的同步脚本只创建或更新文件——从不删除你的仓库或本机的\n> 任何内容，也不修改本地文件。发布仅在完成审计并经你明确确认文件清单、目标仓库和版本后执行。\n> 凡发布的内容都应视为公开可见。\n\n## 模式\n\n| 模式 | 触发词 | 说明 |\n|------|--------|------|\n| **审计** | \"检查发布\" / \"audit skill\" | 只读扫描，报告问题，不改动文件、不传输任何内容 |\n| **发布** | \"发布 skill\" / \"publish skill\" | 审计并经确认后：在临时副本中清理 → 推送到 ClawHub/GitHub → 验证 |\n\n## 检查项\n\n1. **个人数据** — 持仓数量、成本价、账户金额、个人姓名\n2. **Frontmatter** — 描述长度、语言、名称中的版本号\n3. **内容** — 内部开发备注、参考章节、版本历史\n4. **语言** — SKILL.md 英文主体、README 中英双语\n5. **文件** — 个股脚本、元文档、过期文件\n\n## 快速开始\n\n```\n# 审计一个 skill 目录\n\"检查发布 ~/.workbuddy/skills/my-skill\"\n\n# 发布到 ClawHub + GitHub\n\"发布 skill ~/.workbuddy/skills/my-skill@1.2.0\"\n```\n\n## 捆绑脚本\n\n`scripts/sync_skill_to_github.js` — 可选辅助脚本，把 publish 目录镜像同步到 GitHub 仓库（Contents API）。\n\n- Token：仅从 `GITHUB_TOKEN` / `GITHUB_PAT` 环境变量读取，未设置时报错退出。不内置、不读文件、不打印日志。\n- 网络：仅访问 `api.github.com`。只创建/更新文件（PUT），**从不删除**远端文件。\n- 全参数化：`--owner`、`--repo`、`--dir`、`--message`、`--branch`、`--files`。无硬编码路径或用户名。\n\n```bash\nnode scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill\n```\n\n## License\n\nMIT\n\nFile v1.5.9:sanitize.md\n\n**Run this BEFORE any publish.** Public skills are permanent.\n\n## Release Type Gate (run first)\n\nBefore starting, classify the release — the pipeline strictness differs:\n\n| Type | Definition | Required stages |\n|---|---|---|\n| **New skill publish** | Slug not yet on ClawHub | **Full 5 stages**: Understand → Transform → Sanitize → Verify (user approval message) → Publish + Install-check |\n| **Content update** | New references / new sections / scope change | Sanitize → Verify (user approval) → Publish |\n| **Patch (wording / metadata)** | Description tweak, frontmatter fix, version bump only | Sanitize → Publish (user approval is still required — show the diff or content before publishing) |\n\n**New-skill extra checks (mandatory):**\n1. `clawhub inspect <slug>` — must return \"Skill not found\" (not AMBIGUOUS) before publish. A slug collision creates an unfixable ghost record.\n2. Structure completeness per skill-design-guide: Hard Rules, Failure Handling, Output Format, steps tagged `[Deterministic]`/`[LLM]`.\n3. Optional discoverability add-on: a Chinese summary + trigger keywords can be appended to the description (skillhub search indexes description only, not description_zh). This broadens public search visibility beyond what the user may expect — ask the user and proceed only after explicit consent. Never add these by default.\n\n**Frozen skills (do not update unless necessary):**\n- `social-persona-profiling` — any update risks re-triggering SkillSpector alerts (its third-party-profiling capability sits on the policy line). If an update is unavoidable, keep frontmatter minimal and change body only.\n\n## Personal Data\n\nRemove or genericize:\n- [ ] Names (your name, team members, company)\n- [ ] Email addresses\n- [ ] Usernames, handles, IDs\n- [ ] Phone numbers\n- [ ] Addresses, locations\n- [ ] URLs to private resources\n- [ ] Internal project names\n- [ ] Client/customer references\n\n## Credentials & Secrets\n\n**NEVER include:**\n- [ ] API keys, tokens, passwords\n- [ ] Environment variable VALUES (names are ok)\n- [ ] Private URLs with auth params\n- [ ] Database connection strings\n- [ ] SSH keys, certificates\n\n## Model-Specific References\n\nRemove references to specific models that won't apply to all users:\n- [ ] \"Claude\" → \"the agent\" or \"the model\"\n- [ ] \"GPT\" → generic term\n- [ ] Specific model versions\n- [ ] Provider-specific features\n\n## Internal References\n\nRemove:\n- [ ] References to your specific file paths\n- [ ] Your workspace structure\n- [ ] Your tool configurations\n- [ ] Internal documentation links\n- [ ] Team-specific workflows\n\n## Dangerous Patterns\n\nCheck for:\n- [ ] Commands that could damage systems\n- [ ] Patterns that encourage unsafe behavior\n- [ ] Hardcoded paths that won't work elsewhere\n- [ ] Assumptions about user's environment\n\n## Genericize Examples\n\nReplace specific with generic:\n- `~/my-company/project` → `~/projects/example`\n- `john@company.com` → `user@example.com`\n- `api.mycompany.com` → `api.example.com`\n- Internal tool names → generic descriptions\n\n## Final Check\n\nBefore publishing, read entire skill asking:\n- \"Would I be comfortable if this were public forever?\"\n- \"Could this expose anything about me/my company?\"\n- \"Would this work for someone with zero context about me?\"\n\n## If Unsure\n\n**Ask the user:**\n> \"I found [X] which might be personal/internal. Should I remove, genericize, or keep it?\"\n\nBetter to ask than to publish something private.\n\n## Post-publish Finding Diagnosis (if SkillSpector or similar scanner reports findings)\n\nWhen a security/policy scanner reports findings AFTER publish, diagnose the finding's layer before fixing. **Do not reflexively add disclaimers or narrow triggers — that often makes things worse.**\n\n### Step 1: Read the \"Finding\" text\n\nFindings quote specific lines. Identify what the scanner actually objects to:\n- Is it quoting **frontmatter** (trigger keywords, description text)? → L1\n- Is it quoting **body steps** but the issue is wording mismatch with description? → L2\n- Is it quoting **body steps** and the issue is the capability itself (e.g. \"actionable interpersonal advice\", \"third-party profiling\", \"consequential decision automation\")? → L3\n\n### Step 2: Match to layer\n\n| Layer | Signal | Fix approach |\n|---|---|---|\n| **L1 Surface** | Finding quotes frontmatter trigger keywords or description phrasing | Narrow trigger words, add data preconditions, move hidden-style content to separate fields |\n| **L2 Behavior mismatch** | Finding quotes body steps, but the root cause is description saying one thing while body does another | Align description to match actual body behavior (or change body to match description) |\n| **L3 Scope** | Finding quotes body steps and the issue is the skill's core capability itself | This is a design decision, not a wording fix. Ask the user: keep the capability and accept the finding, or restructure the skill's scope? |\n\n### Step 3: Anti-patterns\n\n- **Do not add \"NOT a decision-support system\" disclaimers to fix L3 findings.** The scanner reads the body, not just the disclaimer. If the body provides actionable guidance, a disclaimer creates a *new* mismatch (L2).\n- **Do not reflexively narrow trigger keywords for L2/L3 findings.** Narrow triggers only fixes L1. If the finding quotes body steps, trigger wording is not the issue.\n- **Do not bump versions repeatedly trying to fix the same finding.** If the same finding persists after 2 patch attempts, the issue is L3 (scope), not L1 (wording). Stop and escalate to the user with the scope-level tradeoff.\n\n### Step 4: When to stop fixing\n\nIf ClawHub moderation shows `CLEAN` but SkillSpector (or similar third-party scanner) still reports findings, **the skill is already live and installable**. SkillSpector findings are informational — they do not block ClawHub moderation. Ask the user whether to:\n1. Accept the findings (skill is live, moderation is CLEAN)\n2. Continue fixing (only worthwhile if findings indicate real risk to users)\n\n### Step 5: Rollback strategy (when fixes make things worse)\n\nIf 2+ patch attempts have been made and findings are **increasing** (new findings appeared that weren't in the original version), the fixes themselves are the problem. Each added field (trigger keywords, read_when, not_for, disclaimers, Chinese triggers) gives the scanner **more surface to analyze** and **more patterns to match against**.\n\n**Rollback procedure:**\n1. Identify the last version that passed SkillSpector cleanly (or had the fewest findings)\n2. Take that version's **frontmatter** (description, read_when, not_for — all of it)\n3. Take the current version's **body** (if a scope-level fix like Step 8 rename was already made, keep it — it's a real improvement)\n4. Publish as a new version with changelog: \"Rollback frontmatter to [version] original; retain [version] scope fix\"\n5. **Do not re-add** trigger keywords, Chinese triggers, NOT disclaimers, read_when narrowing, or not_for items — these are what triggered the new findings\n\n**Key insight:** A clean, minimal frontmatter (just name + description + version) has the **smallest attack surface**. Every additional field is a potential finding. If a skill passed at version X, the fastest path to passing again is to return to X's frontmatter, not to add more guards.\n\n**Real example (social-persona-profiling):**\n- 1.0.4: passed SkillSpector (no findings)\n- 1.0.5-1.0.10: added trigger keywords, read_when, not_for, disclaimers, Chinese triggers → findings **increased** to 10+\n- 1.0.11: rolled back frontmatter to 1.0.4 original + retained 1.0.8 body scope fix → **passed**\n\nFile v1.5.9:skill-card.md\n\n## Description:\n\nSkill Audit & Publish guides agents through an audit-first workflow for sanitizing, verifying, and publishing OpenClaw skills to ClawHub, SkillHub, and GitHub with explicit approval before external side effects.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[haiyangchenbj](https://clawhub.ai/user/haiyangchenbj)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and skill maintainers use this skill to prepare SKILL.md-based OpenClaw skills for public release. It helps audit for personal data and credentials, stage a publish-ready folder, confirm exact release metadata, and publish only after explicit approval.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Publishing can make skill files publicly visible, including accidental personal data, credentials, or internal references.\n\nMitigation: Run the sanitize checklist, review the exact file list and diff, and require explicit approval before publishing.\n\nRisk: The workflow may use GitHub credentials from GITHUB_TOKEN or GITHUB_PAT and a SkillHub token from ~/.skillhub/credentials.json for authenticated uploads.\n\nMitigation: Use deliberately scoped credentials, keep tokens outside published files, and confirm the destination platforms and repositories before any command runs.\n\nRisk: The GitHub sync helper creates or updates files but does not delete remote files that were removed from a release.\n\nMitigation: After major restructures, audit the remote repository file list and remove obsolete files manually.\n\nRisk: SkillHub has no read API and version drift across ClawHub, SkillHub, and GitHub can make later releases harder to verify.\n\nMitigation: Keep one version across all platforms and use ClawHub inspect output plus the GitHub mirror as side evidence.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/haiyangchenbj/skills/skill-audit-publish)\n- [README](README.md)\n- [Sanitize checklist](sanitize.md)\n- [Publish rules](references/publish-rules.md)\n- [SkillHub publish procedure](references/skillhub-publish.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with command snippets and generated publish-folder files]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May propose external publish and sync commands only after audit, verification, and explicit user approval.]\n\n## Skill Version(s):\n\n1.5.9 (source: server release metadata and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.5.9:transform.md\n\nReference — how to convert any knowledge into proper skill structure.\n\n## Source Types\n\n### Already a Skill\n- Copy to separate publish folder\n- Run sanitization\n- Verify structure meets standards\n\n### Instructions in Files\n- Read and understand the full process\n- Extract core actionable instructions\n- Remove personal context, keep universal value\n- Structure into SKILL.md + auxiliaries\n\n### Knowledge You've Developed\n- Document what you know about the topic\n- Focus on WHAT TO DO, not explanations\n- Include the non-obvious parts\n- Ask user to confirm you captured it correctly\n\n### User's Request to Share Something\n- Ask: \"What specifically should this skill help others do?\"\n- Ask: \"What do you do that others might not know?\"\n- Condense their workflow into reusable instructions\n\n## Transformation Rules\n\n### Keep\n- Actionable instructions\n- Non-obvious insights\n- Useful patterns\n- Practical examples (genericized)\n\n### Remove\n- Personal context\n- Explanations of basics\n- Verbose descriptions\n- Meta-commentary\n\n### Restructure\n- SKILL.md: Core instructions only (30-50 lines ideal)\n- Auxiliary files: Details, references, patterns\n- Progressive disclosure: Load details only when needed\n\n## Standard Structure\n\n```\npublish-folder/\n├── SKILL.md          ← Core instructions\n├── FILES.txt         ← List of files to publish\n└── [topic].md        ← Supporting details\n```\n\n## When Unsure What to Include\n\n**Default: Include it.** Easier for user to remove than to add later.\n\nMark uncertain sections:\n> \"I included [X] — let me know if this should be removed or modified.\"\n\n## Verify Understanding\n\nBefore finalizing, confirm with user:\n1. \"Here's what I understood as the core value: [summary]\"\n2. \"I'm including these sections: [list]\"\n3. \"I'm excluding: [list with reasons]\"\n4. \"Any changes before I prepare the publish version?\"\n\nFile v1.5.9:verify.md\n\n**Never publish without completing this process.**\n\n## Create Publish Folder\n\nWork in a SEPARATE folder, never modify originals:\n```\n/tmp/publish-[slug]/\n├── SKILL.md\n├── FILES.txt\n└── [auxiliaries]\n```\n\n## Verification Message\n\nBefore publishing, send user a verification with:\n\n### Required Information\n- **Slug:** exact slug to use\n- **Name:** exact display name\n- **Version:** version number\n- **Description:** exact description text\n- **Files:** complete list of files to publish\n\n### Content Summary\n- Brief summary of what the skill does\n- Key sections/topics covered\n- Any notable inclusions or exclusions\n\n### Sanitization Confirmation\n- \"Checked for personal data: ✓\"\n- \"Checked for credentials: ✓\"\n- \"Checked for model-specific references: ✓\"\n- Note any items that were removed/genericized\n\n## Wait for Approval\n\n**Do not proceed without explicit approval.**\n\nUser should confirm:\n- Slug is correct\n- Name is correct\n- Description is correct\n- Content looks right\n- Ready to publish\n\n## Publish Command\n\nOnly after approval:\n```bash\nclawhub publish <folder> \\\n  --slug \"<slug>\" \\\n  --name \"<name>\" \\\n  --version \"<version>\"\n```\n\n## Post-Publish Verification\n\nAfter publishing:\n1. Confirm success message\n2. Optionally install to verify: `clawhub install <slug> --dir /tmp/verify`\n3. Report to user: \"Published [slug]@[version]\"\n\n## If Something Goes Wrong\n\n- Wrong slug? Use ClawHub Edit page → \"Rename slug\" (old slugs stay as redirects). Then publish a new version with the corrected content if needed.\n- Wrong content? Publish new version with fix.\n- Exposed private data? Publish sanitized version ASAP, rename or delete the old listing, contact support if needed.\n\n## Version Guidelines\n\n- `1.0.0` — First publish\n- `1.0.1` — Small fixes (typos, clarifications)\n- `1.1.0` — New content/features\n- `2.0.0` — Major restructure\n\nArchive v1.5.8: 11 files, 26133 bytes\n\nFiles: _meta.json (138b), README_zh.md (2172b), README.md (2254b), references/publish-rules.md (4568b), references/skillhub-publish.md (3055b), sanitize.md (7622b), scripts/sync_skill_to_github.js (7169b), skill-card.md (2178b), SKILL.md (19616b), transform.md (1870b), verify.md (1876b)\n\nFile v1.5.8:SKILL.md\n\n---\nname: \"Skill Audit & Publish\"\nslug: skill-audit-publish\ndisplayName: \"Skill Audit & Publish\"\ndescription: \"Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.\"\nversion: \"1.5.8\"\nallowed-tools: execute_command, read_file, file_read, write_to_file, file_write\nmetadata:\n  openclaw:\n    permissions:\n      - \"network: api.github.com — used only by the bundled sync helper when explicitly invoked\"\n      - \"credentials: GITHUB_TOKEN / GITHUB_PAT environment variables — read at runtime, never stored or logged\"\n    tags:\n      - skill-publishing\n      - pre-publish-audit\n      - pii-sanitization\n      - secret-scanning\n      - skill-lifecycle\n      - content-governance\n      - developer-tools\n      - publishing-workflow\n      - audit-checklist\n---\n\n# Skill Audit & Publish\n\nA five-stage pipeline that takes a local OpenClaw skill and ships a sanitized, verified release to ClawHub. The publish command is the last step, not the first — every earlier step is designed to keep private data and irreversible mistakes out of the public record.\n\n**The single most important rule:** never modify the user's original files. Work in a separate publish folder; only after explicit approval move anything to the live registry.\n\n---\n\n## When to use\n\nTrigger this skill when the user says or implies any of:\n\n- \"Publish this skill to ClawHub\" / \"I want to publish to ClawHub\" / \"ship it to clawhub\"\n- \"How do I publish a skill\" / \"What's the ClawHub publish command\" / \"clawhub publish syntax\"\n- \"Sanitize my skill before publishing\" / \"remove personal info\" / \"audit for PII\"\n- \"Check for secrets / API keys / tokens before I publish\"\n- \"Make a publish-ready version of this skill\"\n- \"I want to share this skill publicly\" / \"publish a skill without leaking my data\"\n- \"clawhub publish\" / \"clawhub publish command\" / \"openclaw publish\"\n- \"Pre-publish checklist\" / \"what should I check before publishing\"\n\n**Do NOT trigger** for: editing skill content (use the skill's own skill), reading a skill from ClawHub, listing installed skills, or any non-publish operation.\n\n---\n\n## What this skill produces\n\nA `publish-folder/` with:\n- **The skill file** (rewritten frontmatter: `name`, `description`, `version`, GEO-optimized)\n- `FILES.txt` (manifest of what will ship)\n- Auxiliaries: `sanitize.md`, `transform.md`, `verify.md`\n- `_meta.json` (slug, version, publishedAt)\n- An **approval message** summarizing slug / name / version / files / sanitization status — held until the user explicitly approves.\n\nNothing leaves the local publish folder until the user replies \"yes / publish / go\".\n\n---\n\n## The 5-stage pipeline\n\n| Stage | Output | Gate |\n|---|---|---|\n| 1. **Understand** | One-paragraph summary of what the skill does, who it's for, what to keep / cut | User confirms the summary |\n| 2. **Transform** | Re-structured skill file (frontmatter + body) + extracted auxiliaries | Diff shown to user |\n| 3. **Sanitize (the audit)** | `sanitize.md` checklist run: PII / credentials / model-specific refs / internal paths / dangerous patterns; each item marked `removed` / `genericized` / `kept-with-reason` | User reviews every kept-with-reason item |\n| 4. **Verify** | Approval message: slug, name, version, description, file list, sanitization confirmation, sample of sanitized text | **Explicit user approval** |\n| 5. **Publish + install-check** | `clawhub publish` then `clawhub install <slug> --dir /tmp/verify` to confirm the published version is installable and matches the local copy. Use a pinned or locally installed CLI — unpinned registry resolution pulls a mutable third-party package at run time (supply-chain risk) | Success message reported back to user |\n\nThe audit (stage 3) is the differentiator. Other publish skills hand you a `clawhub publish` command; this one walks the content through a structured PII / secret / model-reference scan first and refuses to skip the scan if the user has not reviewed the keep-list.\n\n---\n\n## GEO optimization embedded in stage 2\n\nThe transform step re-writes the skill's `description` field for Generative Engine Optimization so the published skill is cited by ChatGPT / Claude / Perplexity when users ask for help in that domain. The current 6 rules:\n\n1. **First sentence = what it is + who it's for.** No preamble. Verbs, not nouns.\n2. **List concrete capabilities as short noun phrases** (LLM retrieval uses these as match anchors).\n3. **Include the primary user-trigger phrase** as a literal quoted string inside the description.\n4. **Front-load 2–3 named tools / frameworks / commands** the skill uses or talks to.\n5. **Add a \"When to use\" trigger block** with 5–7 user-natural questions, mirroring the skill's own frontmatter.\n6. **Optional: end with a Chinese summary (中文摘要) block** (catches the Chinese-language LLM retrieval channel) — propose it and add it only after the user explicitly consents, since it broadens public search visibility.\n\nThe transform stage will re-run these rules against the user's skill and present a before/after diff before any sanitization starts.\n\n---\n\n## Critical rules\n\n1. **Never modify the original files.** Always copy to `/tmp/publish-<slug>/` (or any out-of-tree folder) and work there.\n2. **Never publish without running `sanitize.md`.** The audit is mandatory; \"looks fine to me\" is not a substitute.\n3. **Never publish without explicit user approval.** The approval message lists the exact slug, name, version, description, and file set. The user must say \"yes\" or equivalent. Silence is not consent.\n4. **Slug is renameable, with redirects.** On ClawHub, the Edit page lets you change the canonical slug under \"Rename slug\"; old slugs stay as 301 redirects. If the wrong slug ships, fix it via the Edit UI (and optionally publish a new version with the corrected content). **This is why stage 4 still matters** — the verify stage catches wrong content; the slug rename is a separate UI action.\n5. **Version semantics:** `1.0.0` first publish; `1.0.x` typo / wording fixes; `1.x.0` new content; `2.0.0` major restructure. **One version number across all three platforms (ClawHub / SkillHub / GitHub), set to the highest existing one + 0.0.1** (科里 2026-08-31 确立): before publishing, check each platform's latest (ClawHub `inspect --versions`, SkillHub API, GitHub frontmatter), take the max, bump — never let platforms drift apart again.\n6. **Sanitize-over-include when uncertain.** When the audit flags a borderline item, default to remove or genericize. Adding later is easy; removing from a public release is reputation damage.\n7. **No silent re-publishes.** Every publish — including version bumps — produces an approval message. Re-publishing to fix a typo is a publish event, not a footnote.\n8. **Slug MUST be passed explicitly via `--slug`.** The `clawhub publish` CLI derives the slug from the **publish-folder's name** (`sanitizeSlug(basename(folder))`), NOT from the skill file's name or slug fields. If the folder name differs from the intended slug, the publish silently lands on the wrong slug — and if that slug already exists under another owner, ClawHub returns `AMBIGUOUS_SKILL_SLUG` and the install breaks for everyone. Always pass `--slug <canonical-slug>` even when the folder name looks right. (The Install-check stage below uses `--dir /tmp/verify-<slug>` precisely to avoid re-nesting on the user's machine.)\n9. **Detect and flatten nested source folders before publishing.** `clawhub install <slug> --dir .` wraps the downloaded skill in a slug-named subfolder, producing a `slug/slug/` double-nested layout on disk (the skill file ends up two levels deep). Before publishing, resolve the skill file to the **inner** folder; never publish from the outer wrapper. In the Verify stage, assert the skill file sits at the publish-root (not nested one level down) and that `slug` equals the intended canonical slug.\n10. **Version numbers can be phantom-occupied.** When a platform version was published as \"add missing files only\" (the skill file untouched), the platform Latest leads the `version:` field inside the skill file (e.g. platform 1.1.3 / file says 1.1.1). Before any patch publish, run `clawhub inspect <slug> --versions` and target **platform Latest + 0.0.1** — never trust the version field inside the file. Same on SkillHub: \"version already exists\" on publish = phantom occupation; bump again.\n11. **SkillHub publish has stricter frontmatter validation than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files downloaded via `clawhub install` often miss the leading `---` (stripped in ClawHub storage) and `slug`/`displayName` — backfill them before SkillHub publish. Consecutive SkillHub publishes trigger 429 rate limits; wait ~60s between publishes.\n12. **Delete `skill-card.md` from install-sourced publish folders.** ClawHub generates it and refuses publishes containing it. Publish with explicit `--slug/--name/--version/--changelog` (the CLI reads version from frontmatter when flags are absent, and phantom-occupied versions fail late).\n13. **On Windows, pass Windows paths to `clawhub publish` / `clawhub install`.** Under Git Bash a `/c/Users/...` path fails with `Error: Path must be a folder`; the same command with `C:\\Users\\...` succeeds. This is not a permissions or install problem — retry with the Windows form before concluding anything else. (Verified 2026-09-11.)\n14. **`inspect`'s table view is cached; `--json` is authoritative.** After a publish the table can keep showing the previous `Latest` for several minutes. Read `inspect <slug> --json` → `latestVersion.version` and `skill.tags.latest` instead. Do not re-publish because the table looks stale, and do not poll with long sleeps — one JSON read settles it. (Verified 2026-09-11.)\n15. **GitHub mirror sync must push from the publish staging dir (`pub-*`), never from an install-sourced dir.** An install dir holds whatever the registry had (possibly a phantom-occupied old `version:` field without your patch), while the staging dir is the exact content you verified. Upsert-only: contents-API pushes add/update files but never delete removed ones — audit the repo file list after major restructures.\n16. **Use a pinned or locally installed `clawhub` CLI, never an unpinned one-shot runner.** Executing a CLI straight from the registry without a pinned version downloads the latest third-party package at run time — a supply-chain risk for a command that reads your token and uploads content. Install once (`npm i -g clawhub`) and invoke the reviewed local binary; if a one-shot run is truly unavoidable, pin the exact package version.\n\n---\n\n## Bundled scripts (external side effects, disclosed)\n\n**Bundled sync helper (see the bundled scripts/ directory)** — optional helper that mirrors a publish folder to a GitHub repo via the GitHub Contents API (PAT auth). Behavior, explicitly:\n\n- **Reads a token from the environment only.** Requires the `GITHUB_TOKEN` / `GITHUB_PAT` environment variable; exits with an error if unset. No token is embedded in the skill, read from files, transmitted anywhere except api.github.com, or logged.\n- **Writes to GitHub only.** All network traffic goes to `api.github.com`. It creates or updates files (Contents API PUT) in the repo you name via `--owner` / `--repo`.\n- **Never deletes.** Upsert-only: files present on GitHub but absent from the local file list are left untouched; remote deletion must be done manually.\n- **Fully parameterized.** Owner, repo, local directory, branch, commit message, and file list all come from CLI flags (`--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`) — no hardcoded user names or machine paths.\n- **Path containment (fail-closed).** Every `--files` entry must resolve inside the local directory: absolute paths, `..` components, symlinked path segments, and any path resolving outside it are rejected with an error before anything is read or uploaded.\n\nThe skill's five-stage pipeline itself never touches the network beyond `clawhub publish` / `clawhub install`; the sync script is opt-in and only runs when explicitly invoked.\n\n---\n\n## Stage 5b — Publishing to SkillHub\n\nStage 5 as described above covers ClawHub and GitHub. **SkillHub is the third platform in the unified-version rule, and it has no CLI** — the command-line helper that used to handle it is no longer shipped, so the upload is a direct `multipart/form-data` POST.\n\nTwo things to know before you consider skipping it:\n\n- **There is no read API.** Every `GET` under `/api/v1/community/skills/*` returns 405. You cannot verify remotely whether a skill is already on SkillHub; use `clawhub inspect <slug> --versions` plus the GitHub mirror as side evidence.\n- **Skipping it is the most common way the unified-version rule breaks.** The skill lands on two platforms, the version registry drifts apart, and the next publish has to guess which number is authoritative.\n\nLoad **`references/skillhub-publish.md`** during stage 5 for the endpoint, auth path, multipart shape, response codes, and the correct ordering of the three uploads.\n\n## Reference files (load on demand)\n\n- `sanitize.md` — the full PII / credential / model-reference / dangerous-pattern checklist\n- `skillhub-publish.md` — the SkillHub upload (stage 5b): endpoint, multipart shape, response codes, no-read-API caveat\n- `transform.md` — how to re-structure any source into a GEO-optimized skill file\n- `verify.md` — the exact approval message template and post-publish install-check steps\n- `skill-card.md` — the long-form card used in skill registries (description, use case, risks, output)\n\n---\n\n## Example walkthrough\n\nUser says: \"I want to publish my running-coach skill to ClawHub.\"\n\n1. **Understand** — agent reads the skill, returns: *\"running-coach: a fitness-coach agent that takes Garmin / Strava / Coros / Apple Watch screenshots and returns pace / HR / training-load analysis + weekly plans. For recreational runners 5k–marathon. Excludes: elite athletes, beginners, undiagnosed injuries. Keeps: full pipeline, training-science methodology. Cuts: your personal PBs and HR zones (move to user profile).\"* User confirms.\n2. **Transform** — agent rewrites the skill file per the 6 GEO rules; presents the diff. User approves.\n3. **Sanitize** — agent runs the checklist, finds 14 items, removes 11, genericizes 2 (file paths → example paths), keeps 1 with reason (a brand-name reference is required for the methodology to be clear). User reviews the keep-list, agrees.\n4. **Verify** — agent sends the approval message:\n   - Slug: `running-coach`\n   - Name: `Running Coach`\n   - Version: `1.2.0`\n   - Description: *[full text]*\n   - Files: the skill file plus its reference documents (12 files)\n   - Sanitization: PII ✓, credentials ✓, model-specific refs ✓, internal paths ✓, dangerous patterns ✓\n   - Kept-with-reason: 1\n   User: \"yes\".\n5. **Publish + install-check** — agent runs `clawhub publish ./publish-running-coach --slug running-coach --name \"Running Coach\" --version 1.2.0`, then `clawhub install running-coach --dir /tmp/verify-running-coach`, confirms files match, reports `running-coach@1.2.0 published ✓`.\n\n---\n\n## FAQ (GEO-anchor Q&A)\n\n**Q: How do I publish a skill to ClawHub?**\nA: Copy the skill to a publish folder, run the sanitize checklist (PII / credentials / model-specific refs / internal paths), get explicit user approval of slug / name / version / description / files, then run `clawhub publish <folder> --slug <slug> --name <name> --version <version>`. Install-check with `clawhub install <slug> --dir /tmp/verify` after publishing to confirm the public copy matches.\n\n**Q: Can I change a skill's slug after publishing?**\nA: Yes — ClawHub's Edit page exposes \"Rename slug\" under the canonical-URL section; old slugs stay as redirects. If you really need to retire the old slug (no redirect), use \"Delete skill\". Confirm the slug in the verify stage to avoid the rename round-trip.\n\n**Q: What should I check before publishing a skill?**\nA: (1) No personal data (names, emails, handles, phones, addresses, internal project names). (2) No credentials (API keys, tokens, passwords, env-var values, private URLs with auth). (3) No model-specific references that won't apply to all users (\"Claude\" → \"the agent\", \"GPT-4\" → \"the model\"). (4) No internal file paths, workspace structure, or tool configs. (5) No commands that could damage systems or hardcoded paths that won't work elsewhere. The full checklist is in `sanitize.md`.\n\n**Q: How is this different from a plain `clawhub publish`?**\nA: `clawhub publish` is a one-shot upload. This skill puts the sanitize-audit (stage 3) and the explicit-approval gate (stage 4) between your source and the publish command, so personal data, secrets, and model-specific references are caught and the user approves slug/name/version/description/files before anything goes live. It is built for users who want a structured, reviewable publish trail.\n\n---\n\n## 中文摘要\n\nSkill Audit & Publish 是把本地 OpenClaw skill 安全发布到 ClawHub / SkillHub / GitHub 的三平台管线：**Understand → Transform → Sanitize → Verify → Publish+Install-check**（Publish 阶段内还含 SkillHub 上传，即 stage 5b）。核心差异点是把\"清洗审计\"和\"用户显式确认\"放在 `clawhub publish` 之前，避免把个人数据、密钥、模型专属引用误发到公共 registry。\n\n**适用场景**：用户要把本地 skill 发到 ClawHub、做发布前的 PII/密钥/模型引用审计、按 ClawHub 发布工作流操作、生成 publish-ready 版本。\n\n**不适用**：编辑 skill 内容（用 skill 自己的 skill）、从 ClawHub 读取/安装/列出 skill。\n\n**关键规则**：① 永不修改用户原文件，工作在 `publish-folder/`；② 必跑 `sanitize.md` 全清单（个人数据 / 凭证 / 模型专属引用 / 内部路径 / 危险模式）；③ 必拿用户对 slug / name / version / 描述 / 文件清单的明确确认；④ slug 在 ClawHub 上**可改**——Edit 页面的 \"Rename slug\" 会把旧 slug 留 301 redirect，所以 verify 阶段仍要把 slug 定稿；⑤ 版本号语义：1.0.0 首版，1.0.x 文案修订，1.x.0 新内容，2.0.0 大重构；⑥ 边界项默认删/泛化，宁少勿多。\n\n**GEO 优化内置**：transform 阶段会按 6 条规则重写 `description` 字段（首句 = 是什么+给谁用 / 列出具体能力 / 引用用户原话触发短语 / 前置命名工具 / 加 \"When to use\" / 结尾中文摘要），让发布后的 skill 在 ChatGPT / Claude / Perplexity 被引用时命中率更高。\n\n**触发短语**：「publish to ClawHub」「publish my skill」「sanitize before publish」「pre-publish checklist」「clawhub publish command」「upload a skill to clawhub」。\n\nFile v1.5.8:README.md\n\n# Skill Publish\n\nAudit, clean, and publish agent skills to ClawHub and GitHub. Works with any SKILL.md-based skill in the OpenClaw ecosystem.\n\nComplements `skill-design-guide` (design-time) with publish-time workflow.\n\n**Version**: v1.5.7 (2026-09-16)\n\n> ⚠️ **Publish has external side effects.** `audit` mode is read-only. `publish` mode\n> transmits the cleaned skill contents to ClawHub and GitHub (public services). The bundled\n> sync helper only creates or updates files — it never deletes anything from your repos or\n> your machine, and it never modifies your local files. Publishing runs only after an audit\n> and your explicit confirmation of the file list, target repos, and version. Treat\n> everything you publish as publicly visible.\n\n## Modes\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| **Audit** | \"audit skill\" | Read-only scan — reports issues, changes nothing, transmits nothing |\n| **Publish** | \"publish skill\" | After audit + confirmation: clean (in a temp copy) → push to ClawHub/GitHub → verify |\n\n## What It Checks\n\n1. **Personal data** — share counts, cost basis, account values, personal names\n2. **Frontmatter** — description length, language, version numbers in name\n3. **Content** — internal dev notes, references sections, version history\n4. **Language** — English SKILL.md body, bilingual READMEs\n5. **Files** — ticker-specific scripts, meta-documents, outdated files\n\n## Quick Start\n\n```bash\n# Audit a skill directory\n\"audit skill ~/.workbuddy/skills/my-skill\"\n\n# Publish to ClawHub + GitHub\n\"publish skill ~/.workbuddy/skills/my-skill@1.2.0\"\n```\n\n## Bundled Scripts\n\n`scripts/sync_skill_to_github.js` — optional helper that mirrors a publish folder to a GitHub repo via the Contents API.\n\n- Token: read from `GITHUB_TOKEN` / `GITHUB_PAT` env vars only; exits with an error if unset. Never embedded, read from files, or logged.\n- Network: talks to `api.github.com` only. Creates/updates files (PUT); **never deletes** anything.\n- Fully parameterized: `--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`. No hardcoded paths or usernames.\n\n```bash\nnode scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill\n```\n\n## License\n\nMIT\n\nFile v1.5.8:_meta.json\n\n{\n  \"ownerId\": \"kn70yg6zwmkftx4939qrs89awx82rr9a\",\n  \"slug\": \"skill-audit-publish\",\n  \"version\": \"1.5.8\",\n  \"publishedAt\": 1789704626399\n}\n\nFile v1.5.8:references/publish-rules.md\n\n# Publish Rules for ClawHub & GitHub\n\n> Full rule reference loaded by the `skill-publish` workflow. Do not embed this in SKILL.md.\n\n---\n\n## 1. Frontmatter Requirements\n\n| Field | Rule | Why |\n|-------|------|-----|\n| `name` | Pure English slug, **no version number**. e.g. `invassistant` not `invassistant-v2` | ClawHub display name; version belongs in changelog |\n| `description` | ≤3 sentences, English only. No version numbers, stock tickers, keyword lists, or changelogs | ClawHub card + search summary |\n| `metadata.openclaw.tags` | 5-10 English tags | ClawHub category system |\n| `metadata.openclaw.requires.bins` | Declare required binaries (e.g. `python3`) | ClawHub security analysis |\n\n**Bad**:\n```yaml\ndescription: |\n  个人投资组合管理框架 v2.1.1（执行简化版）。覆盖 A 股、港股、美股。\n  新增 §7.4 模式 D...\n  触发关键词：检查持仓, COST, LLY...\n```\n\n**Good**:\n```yaml\ndescription: >\n  Multi-asset investment portfolio management framework.\n  A/B/C-class differentiated rules, 7 red-line risk controls.\n  Covers US, A-share, and HK stocks.\n```\n\n## 2. Content Cleanup\n\n### Must Remove\n- `## 详细参考` / `## References` section (lists internal file paths — meaningless to users)\n- Unreleased versions in version history (e.g. \"v3.0 planned 2027\")\n- Internal dev notes (\"审计清理版\", \"next 6-12 months: no new rules\")\n- Ticker-specific entry scripts (e.g. `check_tsla_entry.py`) — exposes personal holdings\n- Meta-documents not part of the skill (e.g. `SKILL_PUBLISH_RULES.md`)\n\n### Version History\n- Only published versions (available on ClawHub)\n- One sentence per version\n- Max 5 rows\n\n## 3. Language\n\nThese are **ClawHub discoverability conventions, not hard requirements**. Recommend them\nand flag deviations in the audit report, but respect the user's intended primary language\nand never delete or reject valid content solely on language grounds.\n\n| File | Recommended language |\n|------|----------|\n| `SKILL.md` | English body + optional Chinese intro paragraph at end |\n| `README.md` | English |\n| `README_zh.md` | Chinese (mirror of English README) |\n| `CONTRIBUTING.md` | English |\n| All `references/*.md` | English |\n\n## 4. File Separation: Local vs Published\n\nFiles that stay **local only** (never push to GitHub or ClawHub):\n- Ticker-specific scripts (`check_tsla_entry.py`, `check_detail.py`, etc.)\n- Personal config files (`*-config.json` with real credentials)\n- Meta-documents (`SKILL_PUBLISH_RULES.md`)\n- Session-specific notes or logs\n- `.git/` directory\n\nFiles that go to **both platforms**:\n- `SKILL.md`, `README.md`, `README_zh.md`\n- `CONTRIBUTING.md`, `LICENSE`, `requirements.txt`\n- `references/` (all `.md`)\n- `scripts/` (only generic, reusable engines)\n\nFiles for **ClawHub only** (not GitHub):\n- `_meta.json`\n\n## 5. Publish Mechanics\n\n### ClawHub\n```bash\nclawhub publish <clean-dir> --slug <slug> --version <semver> --changelog \"<one-liner>\"\n```\n- Requires prior `clawhub login --token <token>` (persists to session)\n- Version must not already exist on ClawHub\n- If overriding `latest` tag, version number must be higher than current latest\n\n### GitHub\nAuthenticate with a PAT from your environment: set `GITHUB_TOKEN` (or `GITHUB_PAT`) before syncing. Never hardcode a token or a token-file path inside the skill.\n\n- **Create the repo manually first** (github.com/new, or `POST /user/repos` with your own token outside this skill).\n- **Sync files with the bundled helper** `scripts/sync_skill_to_github.js` — it only creates or updates files via the Contents API (upsert-only). It has **no delete capability**; removing a file from the repo is a manual action in the GitHub web UI.\n- Prefer a small Node.js `https.request` script over `curl` in Git Bash (avoids pipe/TLS quirks).\n\n### Optimal strategy\n1. Create clean temp directory (copy whitelisted files only)\n2. Publish to ClawHub from temp dir (avoids leaking local files)\n3. Push individual files to GitHub via API\n4. Delete temp dir\n5. Verify both platforms\n\n## 6. Post-Publish Verification\n\n```\n[ ] clawhub inspect shows correct latest version + English description\n[ ] ClawHub card description is English, ≤3 sentences\n[ ] ClawHub display name has no version number\n[ ] Version history shows only published versions (≤5)\n[ ] SKILL.md has no \"详细参考/References\" section\n[ ] SKILL.md has no internal dev notes\n[ ] README.md + README_zh.md both exist, versions match\n[ ] GitHub repo has no ticker-specific scripts\n[ ] GitHub repo has no personal config files\n[ ] GitHub commit message matches changelog\n```\n\nFile v1.5.8:references/skillhub-publish.md\n\n# Publishing to SkillHub (stage 5b)\n\n> Loaded by stage 5 of the pipeline. Kept out of the skill file on purpose — the skill file stays a routing surface; operational detail lives here.\n\nSkillHub is the third platform in the unified-version rule. **There is no maintained CLI for it.** A helper named `skills_store_cli.py` used to exist and no longer ships anywhere on a typical machine — do not spend time searching for it. Build the request directly.\n\n---\n\n## Endpoint\n\n```\nPOST https://api.skillhub.cn/api/v1/community/skills/publish\n```\n\n## Auth\n\nBearer token from `~/.skillhub/credentials.json` → **`user.token`**.\nThe file has no top-level `token` key; reading `d[\"token\"]` yields null and produces a misleading 401/403.\n\n## Request — multipart/form-data\n\n**Part 1** — field `payload`, `Content-Type: application/json`:\n\n```json\n{\n  \"slug\": \"my-skill\",\n  \"displayName\": \"My Skill\",\n  \"version\": \"1.2.3\",\n  \"description\": \"one-line English summary\",\n  \"changelog\": \"what changed\",\n  \"category\": \"\",\n  \"subCategories\": [],\n  \"source\": \"community\",\n  \"tags\": [\"tag-a\", \"tag-b\"]\n}\n```\n\n**Parts 2..n** — one per file:\n\n- field name **must be `files`** (`file` and `files[]` are wrong)\n- `filename` = repo-relative path with forward slashes, e.g. `references/guardian-patterns.md`\n- `Content-Type: text/markdown`\n\n## Response\n\n| Code | Meaning |\n|---|---|\n| **201** | accepted — body carries `ok:true`, `version`, `fileCount`, `skillId`, `fingerprint`, and `pending` review/scan statuses |\n| 400 | frontmatter or payload validation failed |\n| 409 | slug tombstoned, or version already exists → bump and retry. **Never delete a `source=community` skill to force a republish** — the slug becomes an unrecoverable tombstone |\n| 429 | consecutive publishes rate-limited → wait ~60s |\n| 503 | transient → wait ~20s and retry once |\n\n## Constraints\n\n- **No read API.** Every `GET` under `/api/v1/community/skills/*` returns 405, including `/mine`, `/list`, and `/rankings`, with or without a Bearer token. You cannot verify remotely whether a skill is already on SkillHub. Use side evidence instead: `clawhub inspect <slug> --versions` plus the existence of the GitHub mirror repo.\n- **Stricter frontmatter than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files retrieved via `clawhub install` often lose the leading `---` in ClawHub storage — backfill it before publishing.\n- **`LICENSE` is rejected.** Publish from a staging copy that excludes it.\n- **Version must match ClawHub and GitHub exactly.** No platform-local version numbers.\n\n## Ordering inside stage 5\n\n1. ClawHub publish (async — settle with `inspect --json` → `latestVersion.version`)\n2. **SkillHub publish (this file)**\n3. GitHub sync from the staging dir (never from an install dir)\n4. Install-check against ClawHub\n\nSkipping step 2 is the most common way the three-platform version rule breaks: the skill lands on two platforms, the version registry drifts apart, and the next publish has to guess which number is authoritative.\n\nFile v1.5.8:README_zh.md\n\n# Skill Publish\n\n审计、清理并发布 Agent Skill 到 ClawHub 和 GitHub。适用于 OpenClaw 生态中任何基于 SKILL.md 的 skill。\n\n与 `skill-design-guide`（设计阶段）配合。\n\n**版本**: v1.5.7（2026-09-16）\n\n> ⚠️ **发布模式有外部副作用。** 审计模式为只读。发布模式会把清理后的 skill 内容传输到\n> ClawHub 和 GitHub（公开服务）。捆绑的同步脚本只创建或更新文件——从不删除你的仓库或本机的\n> 任何内容，也不修改本地文件。发布仅在完成审计并经你明确确认文件清单、目标仓库和版本后执行。\n> 凡发布的内容都应视为公开可见。\n\n## 模式\n\n| 模式 | 触发词 | 说明 |\n|------|--------|------|\n| **审计** | \"检查发布\" / \"audit skill\" | 只读扫描，报告问题，不改动文件、不传输任何内容 |\n| **发布** | \"发布 skill\" / \"publish skill\" | 审计并经确认后：在临时副本中清理 → 推送到 ClawHub/GitHub → 验证 |\n\n## 检查项\n\n1. **个人数据** — 持仓数量、成本价、账户金额、个人姓名\n2. **Frontmatter** — 描述长度、语言、名称中的版本号\n3. **内容** — 内部开发备注、参考章节、版本历史\n4. **语言** — SKILL.md 英文主体、README 中英双语\n5. **文件** — 个股脚本、元文档、过期文件\n\n## 快速开始\n\n```\n# 审计一个 skill 目录\n\"检查发布 ~/.workbuddy/skills/my-skill\"\n\n# 发布到 ClawHub + GitHub\n\"发布 skill ~/.workbuddy/skills/my-skill@1.2.0\"\n```\n\n## 捆绑脚本\n\n`scripts/sync_skill_to_github.js` — 可选辅助脚本，把 publish 目录镜像同步到 GitHub 仓库（Contents API）。\n\n- Token：仅从 `GITHUB_TOKEN` / `GITHUB_PAT` 环境变量读取，未设置时报错退出。不内置、不读文件、不打印日志。\n- 网络：仅访问 `api.github.com`。只创建/更新文件（PUT），**从不删除**远端文件。\n- 全参数化：`--owner`、`--repo`、`--dir`、`--message`、`--branch`、`--files`。无硬编码路径或用户名。\n\n```bash\nnode scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill\n```\n\n## License\n\nMIT\n\nFile v1.5.8:sanitize.md\n\n**Run this BEFORE any publish.** Public skills are permanent.\n\n## Release Type Gate (run first)\n\nBefore starting, classify the release — the pipeline strictness differs:\n\n| Type | Definition | Required stages |\n|---|---|---|\n| **New skill publish** | Slug not yet on ClawHub | **Full 5 stages**: Understand → Transform → Sanitize → Verify (user approval message) → Publish + Install-check |\n| **Content update** | New references / new sections / scope change | Sanitize → Verify (user approval) → Publish |\n| **Patch (wording / metadata)** | Description tweak, frontmatter fix, version bump only | Sanitize → Publish (user approval is still required — show the diff or content before publishing) |\n\n**New-skill extra checks (mandatory):**\n1. `clawhub inspect <slug>` — must return \"Skill not found\" (not AMBIGUOUS) before publish. A slug collision creates an unfixable ghost record.\n2. Structure completeness per skill-design-guide: Hard Rules, Failure Handling, Output Format, steps tagged `[Deterministic]`/`[LLM]`.\n3. Optional discoverability add-on: a Chinese summary + trigger keywords can be appended to the description (skillhub search indexes description only, not description_zh). This broadens public search visibility beyond what the user may expect — ask the user and proceed only after explicit consent. Never add these by default.\n\n**Frozen skills (do not update unless necessary):**\n- `social-persona-profiling` — any update risks re-triggering SkillSpector alerts (its third-party-profiling capability sits on the policy line). If an update is unavoidable, keep frontmatter minimal and change body only.\n\n## Personal Data\n\nRemove or genericize:\n- [ ] Names (your name, team members, company)\n- [ ] Email addresses\n- [ ] Usernames, handles, IDs\n- [ ] Phone numbers\n- [ ] Addresses, locations\n- [ ] URLs to private resources\n- [ ] Internal project names\n- [ ] Client/customer references\n\n## Credentials & Secrets\n\n**NEVER include:**\n- [ ] API keys, tokens, passwords\n- [ ] Environment variable VALUES (names are ok)\n- [ ] Private URLs with auth params\n- [ ] Database connection strings\n- [ ] SSH keys, certificates\n\n## Model-Specific References\n\nRemove references to specific models that won't apply to all users:\n- [ ] \"Claude\" → \"the agent\" or \"the model\"\n- [ ] \"GPT\" → generic term\n- [ ] Specific model versions\n- [ ] Provider-specific features\n\n## Internal References\n\nRemove:\n- [ ] References to your specific file paths\n- [ ] Your workspace structure\n- [ ] Your tool configurations\n- [ ] Internal documentation links\n- [ ] Team-specific workflows\n\n## Dangerous Patterns\n\nCheck for:\n- [ ] Commands that could damage systems\n- [ ] Patterns that encourage unsafe behavior\n- [ ] Hardcoded paths that won't work elsewhere\n- [ ] Assumptions about user's environment\n\n## Genericize Examples\n\nReplace specific with generic:\n- `~/my-company/project` → `~/projects/example`\n- `john@company.com` → `user@example.com`\n- `api.mycompany.com` → `api.example.com`\n- Internal tool names → generic descriptions\n\n## Final Check\n\nBefore publishing, read entire skill asking:\n- \"Would I be comfortable if this were public forever?\"\n- \"Could this expose anything about me/my company?\"\n- \"Would this work for someone with zero context about me?\"\n\n## If Unsure\n\n**Ask the user:**\n> \"I found [X] which might be personal/internal. Should I remove, genericize, or keep it?\"\n\nBetter to ask than to publish something private.\n\n## Post-publish Finding Diagnosis (if SkillSpector or similar scanner reports findings)\n\nWhen a security/policy scanner reports findings AFTER publish, diagnose the finding's layer before fixing. **Do not reflexively add disclaimers or narrow triggers — that often makes things worse.**\n\n### Step 1: Read the \"Finding\" text\n\nFindings quote specific lines. Identify what the scanner actually objects to:\n- Is it quoting **frontmatter** (trigger keywords, description text)? → L1\n- Is it quoting **body steps** but the issue is wording mismatch with description? → L2\n- Is it quoting **body steps** and the issue is the capability itself (e.g. \"actionable interpersonal advice\", \"third-party profiling\", \"consequential decision automation\")? → L3\n\n### Step 2: Match to layer\n\n| Layer | Signal | Fix approach |\n|---|---|---|\n| **L1 Surface** | Finding quotes frontmatter trigger keywords or description phrasing | Narrow trigger words, add data preconditions, move hidden-style content to separate fields |\n| **L2 Behavior mismatch** | Finding quotes body steps, but the root cause is description saying one thing while body does another | Align description to match actual body behavior (or change body to match description) |\n| **L3 Scope** | Finding quotes body steps and the issue is the skill's core capability itself | This is a design decision, not a wording fix. Ask the user: keep the capability and accept the finding, or restructure the skill's scope? |\n\n### Step 3: Anti-patterns\n\n- **Do not add \"NOT a decision-support system\" disclaimers to fix L3 findings.** The scanner reads the body, not just the disclaimer. If the body provides actionable guidance, a disclaimer creates a *new* mismatch (L2).\n- **Do not reflexively narrow trigger keywords for L2/L3 findings.** Narrow triggers only fixes L1. If the finding quotes body steps, trigger wording is not the issue.\n- **Do not bump versions repeatedly trying to fix the same finding.** If the same finding persists after 2 patch attempts, the issue is L3 (scope), not L1 (wording). Stop and escalate to the user with the scope-level tradeoff.\n\n### Step 4: When to stop fixing\n\nIf ClawHub moderation shows `CLEAN` but SkillSpector (or similar third-party scanner) still reports findings, **the skill is already live and installable**. SkillSpector findings are informational — they do not block ClawHub moderation. Ask the user whether to:\n1. Accept the findings (skill is live, moderation is CLEAN)\n2. Continue fixing (only worthwhile if findings indicate real risk to users)\n\n### Step 5: Rollback strategy (when fixes make things worse)\n\nIf 2+ patch attempts have been made and findings are **increasing** (new findings appeared that weren't in the original version), the fixes themselves are the problem. Each added field (trigger keywords, read_when, not_for, disclaimers, Chinese triggers) gives the scanner **more surface to analyze** and **more patterns to match against**.\n\n**Rollback procedure:**\n1. Identify the last version that passed SkillSpector cleanly (or had the fewest findings)\n2. Take that version's **frontmatter** (description, read_when, not_for — all of it)\n3. Take the current version's **body** (if a scope-level fix like Step 8 rename was already made, keep it — it's a real improvement)\n4. Publish as a new version with changelog: \"Rollback frontmatter to [version] original; retain [version] scope fix\"\n5. **Do not re-add** trigger keywords, Chinese triggers, NOT disclaimers, read_when narrowing, or not_for items — these are what triggered the new findings\n\n**Key insight:** A clean, minimal frontmatter (just name + description + version) has the **smallest attack surface**. Every additional field is a potential finding. If a skill passed at version X, the fastest path to passing again is to return to X's frontmatter, not to add more guards.\n\n**Real example (social-persona-profiling):**\n- 1.0.4: passed SkillSpector (no findings)\n- 1.0.5-1.0.10: added trigger keywords, read_when, not_for, disclaimers, Chinese triggers → findings **increased** to 10+\n- 1.0.11: rolled back frontmatter to 1.0.4 original + retained 1.0.8 body scope fix → **passed**\n\nFile v1.5.8:skill-card.md\n\n## Description:\n\nSkill Audit & Publish is an audit-first workflow that helps agents sanitize, verify, and publish OpenClaw skills to ClawHub, SkillHub, and GitHub with explicit user approval before irreversible publishing steps.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[haiyangchenbj](https://clawhub.ai/user/haiyangchenbj)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and skill publishers use this skill to prepare publish-ready OpenClaw skills by transforming content, checking for personal data, credentials, model-specific references, internal paths, and dangerous patterns, then publishing only after explicit approval.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Publishing mode can upload public artifacts using local publishing credentials.\n\nMitigation: Confirm the exact file list, target destinations, and version before publishing; use narrowly scoped credentials.\n\nRisk: SkillHub publishing may use credentials from ~/.skillhub/credentials.json.\n\nMitigation: Do not grant access to that credential file unless intentionally publishing to SkillHub with that account.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/haiyangchenbj/skills/skill-audit-publish)\n- [Publish rules](references/publish-rules.md)\n- [SkillHub publish reference](references/skillhub-publish.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, file manifests, approval text, and optional JavaScript helper commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces local publish-folder artifacts and publishing instructions; public uploads require user approval and appropriate local credentials.]\n\n## Skill Version(s):\n\n1.5.8 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.5.8:transform.md\n\nReference — how to convert any knowledge into proper skill structure.\n\n## Source Types\n\n### Already a Skill\n- Copy to separate publish folder\n- Run sanitization\n- Verify structure meets standards\n\n### Instructions in Files\n- Read and understand the full process\n- Extract core actionable instructions\n- Remove personal context, keep universal value\n- Structure into SKILL.md + auxiliaries\n\n### Knowledge You've Developed\n- Document what you know about the topic\n- Focus on WHAT TO DO, not explanations\n- Include the non-obvious parts\n- Ask user to confirm you captured it correctly\n\n### User's Request to Share Something\n- Ask: \"What specifically should this skill help others do?\"\n- Ask: \"What do you do that others might not know?\"\n- Condense their workflow into reusable instructions\n\n## Transformation Rules\n\n### Keep\n- Actionable instructions\n- Non-obvious insights\n- Useful patterns\n- Practical examples (genericized)\n\n### Remove\n- Personal context\n- Explanations of basics\n- Verbose descriptions\n- Meta-commentary\n\n### Restructure\n- SKILL.md: Core instructions only (30-50 lines ideal)\n- Auxiliary files: Details, references, patterns\n- Progressive disclosure: Load details only when needed\n\n## Standard Structure\n\n```\npublish-folder/\n├── SKILL.md          ← Core instructions\n├── FILES.txt         ← List of files to publish\n└── [topic].md        ← Supporting details\n```\n\n## When Unsure What to Include\n\n**Default: Include it.** Easier for user to remove than to add later.\n\nMark uncertain sections:\n> \"I included [X] — let me know if this should be removed or modified.\"\n\n## Verify Understanding\n\nBefore finalizing, confirm with user:\n1. \"Here's what I understood as the core value: [summary]\"\n2. \"I'm including these sections: [list]\"\n3. \"I'm excluding: [list with reasons]\"\n4. \"Any changes before I prepare the publish version?\"\n\nFile v1.5.8:verify.md\n\n**Never publish without completing this process.**\n\n## Create Publish Folder\n\nWork in a SEPARATE folder, never modify originals:\n```\n/tmp/publish-[slug]/\n├── SKILL.md\n├── FILES.txt\n└── [auxiliaries]\n```\n\n## Verification Message\n\nBefore publishing, send user a verification with:\n\n### Required Information\n- **Slug:** exact slug to use\n- **Name:** exact display name\n- **Version:** version number\n- **Description:** exact description text\n- **Files:** complete list of files to publish\n\n### Content Summary\n- Brief summary of what the skill does\n- Key sections/topics covered\n- Any notable inclusions or exclusions\n\n### Sanitization Confirmation\n- \"Checked for personal data: ✓\"\n- \"Checked for credentials: ✓\"\n- \"Checked for model-specific references: ✓\"\n- Note any items that were removed/genericized\n\n## Wait for Approval\n\n**Do not proceed without explicit approval.**\n\nUser should confirm:\n- Slug is correct\n- Name is correct\n- Description is correct\n- Content looks right\n- Ready to publish\n\n## Publish Command\n\nOnly after approval:\n```bash\nclawhub publish <folder> \\\n  --slug \"<slug>\" \\\n  --name \"<name>\" \\\n  --version \"<version>\"\n```\n\n## Post-Publish Verification\n\nAfter publishing:\n1. Confirm success message\n2. Optionally install to verify: `clawhub install <slug> --dir /tmp/verify`\n3. Report to user: \"Published [slug]@[version]\"\n\n## If Something Goes Wrong\n\n- Wrong slug? Use ClawHub Edit page → \"Rename slug\" (old slugs stay as redirects). Then publish a new version with the corrected content if needed.\n- Wrong content? Publish new version with fix.\n- Exposed private data? Publish sanitized version ASAP, rename or delete the old listing, contact support if needed.\n\n## Version Guidelines\n\n- `1.0.0` — First publish\n- `1.0.1` — Small fixes (typos, clarifications)\n- `1.1.0` — New content/features\n- `2.0.0` — Major restructure\n\nArchive v1.5.7: 10 files, 24033 bytes\n\nFiles: README_zh.md (2172b), README.md (2254b), references/publish-rules.md (4568b), sanitize.md (7622b), scripts/sync_skill_to_github.js (7169b), skill-card.md (2655b), SKILL.md (18423b), transform.md (1870b), verify.md (1876b), _meta.json (138b)\n\nFile v1.5.7:SKILL.md\n\n---\nname: \"Skill Audit & Publish\"\nslug: skill-audit-publish\ndisplayName: \"Skill Audit & Publish\"\ndescription: \"Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.\"\nversion: \"1.5.7\"\nallowed-tools: execute_command, read_file, file_read, write_to_file, file_write\nmetadata:\n  openclaw:\n    permissions:\n      - \"network: api.github.com — used only by the bundled sync helper when explicitly invoked\"\n      - \"credentials: GITHUB_TOKEN / GITHUB_PAT environment variables — read at runtime, never stored or logged\"\n    tags:\n      - skill-publishing\n      - pre-publish-audit\n      - pii-sanitization\n      - secret-scanning\n      - skill-lifecycle\n      - content-governance\n      - developer-tools\n      - publishing-workflow\n      - audit-checklist\n---\n\n# Skill Audit & Publish\n\nA five-stage pipeline that takes a local OpenClaw skill and ships a sanitized, verified release to ClawHub. The publish command is the last step, not the first — every earlier step is designed to keep private data and irreversible mistakes out of the public record.\n\n**The single most important rule:** never modify the user's original files. Work in a separate publish folder; only after explicit approval move anything to the live registry.\n\n---\n\n## When to use\n\nTrigger this skill when the user says or implies any of:\n\n- \"Publish this skill to ClawHub\" / \"I want to publish to ClawHub\" / \"ship it to clawhub\"\n- \"How do I publish a skill\" / \"What's the ClawHub publish command\" / \"clawhub publish syntax\"\n- \"Sanitize my skill before publishing\" / \"remove personal info\" / \"audit for PII\"\n- \"Check for secrets / API keys / tokens before I publish\"\n- \"Make a publish-ready version of this skill\"\n- \"I want to share this skill publicly\" / \"publish a skill without leaking my data\"\n- \"clawhub publish\" / \"clawhub publish command\" / \"openclaw publish\"\n- \"Pre-publish checklist\" / \"what should I check before publishing\"\n\n**Do NOT trigger** for: editing skill content (use the skill's own skill), reading a skill from ClawHub, listing installed skills, or any non-publish operation.\n\n---\n\n## What this skill produces\n\nA `publish-folder/` with:\n- **The skill file** (rewritten frontmatter: `name`, `description`, `version`, GEO-optimized)\n- `FILES.txt` (manifest of what will ship)\n- Auxiliaries: `sanitize.md`, `transform.md`, `verify.md`\n- `_meta.json` (slug, version, publishedAt)\n- An **approval message** summarizing slug / name / version / files / sanitization status — held until the user explicitly approves.\n\nNothing leaves the local publish folder until the user replies \"yes / publish / go\".\n\n---\n\n## The 5-stage pipeline\n\n| Stage | Output | Gate |\n|---|---|---|\n| 1. **Understand** | One-paragraph summary of what the skill does, who it's for, what to keep / cut | User confirms the summary |\n| 2. **Transform** | Re-structured skill file (frontmatter + body) + extracted auxiliaries | Diff shown to user |\n| 3. **Sanitize (the audit)** | `sanitize.md` checklist run: PII / credentials / model-specific refs / internal paths / dangerous patterns; each item marked `removed` / `genericized` / `kept-with-reason` | User reviews every kept-with-reason item |\n| 4. **Verify** | Approval message: slug, name, version, description, file list, sanitization confirmation, sample of sanitized text | **Explicit user approval** |\n| 5. **Publish + install-check** | `clawhub publish` then `clawhub install <slug> --dir /tmp/verify` to confirm the published version is installable and matches the local copy. Use a pinned or locally installed CLI — unpinned registry resolution pulls a mutable third-party package at run time (supply-chain risk) | Success message reported back to user |\n\nThe audit (stage 3) is the differentiator. Other publish skills hand you a `clawhub publish` command; this one walks the content through a structured PII / secret / model-reference scan first and refuses to skip the scan if the user has not reviewed the keep-list.\n\n---\n\n## GEO optimization embedded in stage 2\n\nThe transform step re-writes the skill's `description` field for Generative Engine Optimization so the published skill is cited by ChatGPT / Claude / Perplexity when users ask for help in that domain. The current 6 rules:\n\n1. **First sentence = what it is + who it's for.** No preamble. Verbs, not nouns.\n2. **List concrete capabilities as short noun phrases** (LLM retrieval uses these as match anchors).\n3. **Include the primary user-trigger phrase** as a literal quoted string inside the description.\n4. **Front-load 2–3 named tools / frameworks / commands** the skill uses or talks to.\n5. **Add a \"When to use\" trigger block** with 5–7 user-natural questions, mirroring the skill's own frontmatter.\n6. **Optional: end with a Chinese summary (中文摘要) block** (catches the Chinese-language LLM retrieval channel) — propose it and add it only after the user explicitly consents, since it broadens public search visibility.\n\nThe transform stage will re-run these rules against the user's skill and present a before/after diff before any sanitization starts.\n\n---\n\n## Critical rules\n\n1. **Never modify the original files.** Always copy to `/tmp/publish-<slug>/` (or any out-of-tree folder) and work there.\n2. **Never publish without running `sanitize.md`.** The audit is mandatory; \"looks fine to me\" is not a substitute.\n3. **Never publish without explicit user approval.** The approval message lists the exact slug, name, version, description, and file set. The user must say \"yes\" or equivalent. Silence is not consent.\n4. **Slug is renameable, with redirects.** On ClawHub, the Edit page lets you change the canonical slug under \"Rename slug\"; old slugs stay as 301 redirects. If the wrong slug ships, fix it via the Edit UI (and optionally publish a new version with the corrected content). **This is why stage 4 still matters** — the verify stage catches wrong content; the slug rename is a separate UI action.\n5. **Version semantics:** `1.0.0` first publish; `1.0.x` typo / wording fixes; `1.x.0` new content; `2.0.0` major restructure. **One version number across all three platforms (ClawHub / SkillHub / GitHub), set to the highest existing one + 0.0.1** (科里 2026-08-31 确立): before publishing, check each platform's latest (ClawHub `inspect --versions`, SkillHub API, GitHub frontmatter), take the max, bump — never let platforms drift apart again.\n6. **Sanitize-over-include when uncertain.** When the audit flags a borderline item, default to remove or genericize. Adding later is easy; removing from a public release is reputation damage.\n7. **No silent re-publishes.** Every publish — including version bumps — produces an approval message. Re-publishing to fix a typo is a publish event, not a footnote.\n8. **Slug MUST be passed explicitly via `--slug`.** The `clawhub publish` CLI derives the slug from the **publish-folder's name** (`sanitizeSlug(basename(folder))`), NOT from the skill file's name or slug fields. If the folder name differs from the intended slug, the publish silently lands on the wrong slug — and if that slug already exists under another owner, ClawHub returns `AMBIGUOUS_SKILL_SLUG` and the install breaks for everyone. Always pass `--slug <canonical-slug>` even when the folder name looks right. (The Install-check stage below uses `--dir /tmp/verify-<slug>` precisely to avoid re-nesting on the user's machine.)\n9. **Detect and flatten nested source folders before publishing.** `clawhub install <slug> --dir .` wraps the downloaded skill in a slug-named subfolder, producing a `slug/slug/` double-nested layout on disk (the skill file ends up two levels deep). Before publishing, resolve the skill file to the **inner** folder; never publish from the outer wrapper. In the Verify stage, assert the skill file sits at the publish-root (not nested one level down) and that `slug` equals the intended canonical slug.\n10. **Version numbers can be phantom-occupied.** When a platform version was published as \"add missing files only\" (the skill file untouched), the platform Latest leads the `version:` field inside the skill file (e.g. platform 1.1.3 / file says 1.1.1). Before any patch publish, run `clawhub inspect <slug> --versions` and target **platform Latest + 0.0.1** — never trust the version field inside the file. Same on SkillHub: \"version already exists\" on publish = phantom occupation; bump again.\n11. **SkillHub publish has stricter frontmatter validation than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files downloaded via `clawhub install` often miss the leading `---` (stripped in ClawHub storage) and `slug`/`displayName` — backfill them before SkillHub publish. Consecutive SkillHub publishes trigger 429 rate limits; wait ~60s between publishes.\n12. **Delete `skill-card.md` from install-sourced publish folders.** ClawHub generates it and refuses publishes containing it. Publish with explicit `--slug/--name/--version/--changelog` (the CLI reads version from frontmatter when flags are absent, and phantom-occupied versions fail late).\n13. **On Windows, pass Windows paths to `clawhub publish` / `clawhub install`.** Under Git Bash a `/c/Users/...` path fails with `Error: Path must be a folder`; the same command with `C:\\Users\\...` succeeds. This is not a permissions or install problem — retry with the Windows form before concluding anything else. (Verified 2026-09-11.)\n14. **`inspect`'s table view is cached; `--json` is authoritative.** After a publish the table can keep showing the previous `Latest` for several minutes. Read `inspect <slug> --json` → `latestVersion.version` and `skill.tags.latest` instead. Do not re-publish because the table looks stale, and do not poll with long sleeps — one JSON read settles it. (Verified 2026-09-11.)\n15. **GitHub mirror sync must push from the publish staging dir (`pub-*`), never from an install-sourced dir.** An install dir holds whatever the registry had (possibly a phantom-occupied old `version:` field without your patch), while the staging dir is the exact content you verified. Upsert-only: contents-API pushes add/update files but never delete removed ones — audit the repo file list after major restructures.\n16. **Use a pinned or locally installed `clawhub` CLI, never an unpinned one-shot runner.** Executing a CLI straight from the registry without a pinned version downloads the latest third-party package at run time — a supply-chain risk for a command that reads your token and uploads content. Install once (`npm i -g clawhub`) and invoke the reviewed local binary; if a one-shot run is truly unavoidable, pin the exact package version.\n\n---\n\n## Bundled scripts (external side effects, disclosed)\n\n**Bundled sync helper (see the bundled scripts/ directory)** — optional helper that mirrors a publish folder to a GitHub repo via the GitHub Contents API (PAT auth). Behavior, explicitly:\n\n- **Reads a token from the environment only.** Requires the `GITHUB_TOKEN` / `GITHUB_PAT` environment variable; exits with an error if unset. No token is embedded in the skill, read from files, transmitted anywhere except api.github.com, or logged.\n- **Writes to GitHub only.** All network traffic goes to `api.github.com`. It creates or updates files (Contents API PUT) in the repo you name via `--owner` / `--repo`.\n- **Never deletes.** Upsert-only: files present on GitHub but absent from the local file list are left untouched; remote deletion must be done manually.\n- **Fully parameterized.** Owner, repo, local directory, branch, commit message, and file list all come from CLI flags (`--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`) — no hardcoded user names or machine paths.\n- **Path containment (fail-closed).** Every `--files` entry must resolve inside the local directory: absolute paths, `..` components, symlinked path segments, and any path resolving outside it are rejected with an error before anything is read or uploaded.\n\nThe skill's five-stage pipeline itself never touches the network beyond `clawhub publish` / `clawhub install`; the sync script is opt-in and only runs when explicitly invoked.\n\n---\n\n## Reference files (load on demand)\n\n- `sanitize.md` — the full PII / credential / model-reference / dangerous-pattern checklist\n- `transform.md` — how to re-structure any source into a GEO-optimized skill file\n- `verify.md` — the exact approval message template and post-publish install-check steps\n- `skill-card.md` — the long-form card used in skill registries (description, use case, risks, output)\n\n---\n\n## Example walkthrough\n\nUser says: \"I want to publish my running-coach skill to ClawHub.\"\n\n1. **Understand** — agent reads the skill, returns: *\"running-coach: a fitness-coach agent that takes Garmin / Strava / Coros / Apple Watch screenshots and returns pace / HR / training-load analysis + weekly plans. For recreational runners 5k–marathon. Excludes: elite athletes, beginners, undiagnosed injuries. Keeps: full pipeline, training-science methodology. Cuts: your personal PBs and HR zones (move to user profile).\"* User confirms.\n2. **Transform** — agent rewrites the skill file per the 6 GEO rules; presents the diff. User approves.\n3. **Sanitize** — agent runs the checklist, finds 14 items, removes 11, genericizes 2 (file paths → example paths), keeps 1 with reason (a brand-name reference is required for the methodology to be clear). User reviews the keep-list, agrees.\n4. **Verify** — agent sends the approval message:\n   - Slug: `running-coach`\n   - Name: `Running Coach`\n   - Version: `1.2.0`\n   - Description: *[full text]*\n   - Files: the skill file plus its reference documents (12 files)\n   - Sanitization: PII ✓, credentials ✓, model-specific refs ✓, internal paths ✓, dangerous patterns ✓\n   - Kept-with-reason: 1\n   User: \"yes\".\n5. **Publish + install-check** — agent runs `clawhub publish ./publish-running-coach --slug running-coach --name \"Running Coach\" --version 1.2.0`, then `clawhub install running-coach --dir /tmp/verify-running-coach`, confirms files match, reports `running-coach@1.2.0 published ✓`.\n\n---\n\n## FAQ (GEO-anchor Q&A)\n\n**Q: How do I publish a skill to ClawHub?**\nA: Copy the skill to a publish folder, run the sanitize checklist (PII / credentials / model-specific refs / internal paths), get explicit user approval of slug / name / version / description / files, then run `clawhub publish <folder> --slug <slug> --name <name> --version <version>`. Install-check with `clawhub install <slug> --dir /tmp/verify` after publishing to confirm the public copy matches.\n\n**Q: Can I change a skill's slug after publishing?**\nA: Yes — ClawHub's Edit page exposes \"Rename slug\" under the canonical-URL section; old slugs stay as redirects. If you really need to retire the old slug (no redirect), use \"Delete skill\". Confirm the slug in the verify stage to avoid the rename round-trip.\n\n**Q: What should I check before publishing a skill?**\nA: (1) No personal data (names, emails, handles, phones, addresses, internal project names). (2) No credentials (API keys, tokens, passwords, env-var values, private URLs with auth). (3) No model-specific references that won't apply to all users (\"Claude\" → \"the agent\", \"GPT-4\" → \"the model\"). (4) No internal file paths, workspace structure, or tool configs. (5) No commands that could damage systems or hardcoded paths that won't work elsewhere. The full checklist is in `sanitize.md`.\n\n**Q: How is this different from a plain `clawhub publish`?**\nA: `clawhub publish` is a one-shot upload. This skill puts the sanitize-audit (stage 3) and the explicit-approval gate (stage 4) between your source and the publish command, so personal data, secrets, and model-specific references are caught and the user approves slug/name/version/description/files before anything goes live. It is built for users who want a structured, reviewable publish trail.\n\n---\n\n## 中文摘要\n\nSkill Audit & Publish 是把本地 OpenClaw skill 安全发布到 ClawHub 的五阶段管线：**Understand → Transform → Sanitize → Verify → Publish+Install-check**。核心差异点是把\"清洗审计\"和\"用户显式确认\"放在 `clawhub publish` 之前，避免把个人数据、密钥、模型专属引用误发到公共 registry。\n\n**适用场景**：用户要把本地 skill 发到 ClawHub、做发布前的 PII/密钥/模型引用审计、按 ClawHub 发布工作流操作、生成 publish-ready 版本。\n\n**不适用**：编辑 skill 内容（用 skill 自己的 skill）、从 ClawHub 读取/安装/列出 skill。\n\n**关键规则**：① 永不修改用户原文件，工作在 `publish-folder/`；② 必跑 `sanitize.md` 全清单（个人数据 / 凭证 / 模型专属引用 / 内部路径 / 危险模式）；③ 必拿用户对 slug / name / version / 描述 / 文件清单的明确确认；④ slug 在 ClawHub 上**可改**——Edit 页面的 \"Rename slug\" 会把旧 slug 留 301 redirect，所以 verify 阶段仍要把 slug 定稿；⑤ 版本号语义：1.0.0 首版，1.0.x 文案修订，1.x.0 新内容，2.0.0 大重构；⑥ 边界项默认删/泛化，宁少勿多。\n\n**GEO 优化内置**：transform 阶段会按 6 条规则重写 `description` 字段（首句 = 是什么+给谁用 / 列出具体能力 / 引用用户原话触发短语 / 前置命名工具 / 加 \"When to use\" / 结尾中文摘要），让发布后的 skill 在 ChatGPT / Claude / Perplexity 被引用时命中率更高。\n\n**触发短语**：「publish to ClawHub」「publish my skill」「sanitize before publish」「pre-publish checklist」「clawhub publish command」「upload a skill to clawhub」。\n\nFile v1.5.7:README.md\n\n# Skill Publish\n\nAudit, clean, and publish agent skills to ClawHub and GitHub. Works with any SKILL.md-based skill in the OpenClaw ecosystem.\n\nComplements `skill-design-guide` (design-time) with publish-time workflow.\n\n**Version**: v1.5.7 (2026-09-16)\n\n> ⚠️ **Publish has external side effects.** `audit` mode is read-only. `publish` mode\n> transmits the cleaned skill contents to ClawHub and GitHub (public services). The bundled\n> sync helper only creates or updates files — it never deletes anything from your repos or\n> your machine, and it never modifies your local files. Publishing runs only after an audit\n> and your explicit confirmation of the file list, target repos, and version. Treat\n> everything you publish as publicly visible.\n\n## Modes\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| **Audit** | \"audit skill\" | Read-only scan — reports issues, changes nothing, transmits nothing |\n| **Publish** | \"publish skill\" | After audit + confirmation: clean (in a temp copy) → push to ClawHub/GitHub → verify |\n\n## What It Checks\n\n1. **Personal data** — share counts, cost basis, account values, personal names\n2. **Frontmatter** — description length, language, version numbers in name\n3. **Content** — internal dev notes, references sections, version history\n4. **Language** — English SKILL.md body, bilingual READMEs\n5. **Files** — ticker-specific scripts, meta-documents, outdated files\n\n## Quick Start\n\n```bash\n# Audit a skill directory\n\"audit skill ~/.workbuddy/skills/my-skill\"\n\n# Publish to ClawHub + GitHub\n\"publish skill ~/.workbuddy/skills/my-skill@1.2.0\"\n```\n\n## Bundled Scripts\n\n`scripts/sync_skill_to_github.js` — optional helper that mirrors a publish folder to a GitHub repo via the Contents API.\n\n- Token: read from `GITHUB_TOKEN` / `GITHUB_PAT` env vars only; exits with an error if unset. Never embedded, read from files, or logged.\n- Network: talks to `api.github.com` only. Creates/updates files (PUT); **never deletes** anything.\n- Fully parameterized: `--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`. No hardcoded paths or usernames.\n\n```bash\nnode scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill\n```\n\n## License\n\nMIT\n\nFile v1.5.7:_meta.json\n\n{\n  \"ownerId\": \"kn70yg6zwmkftx4939qrs89awx82rr9a\",\n  \"slug\": \"skill-audit-publish\",\n  \"version\": \"1.5.7\",\n  \"publishedAt\": 1789538252671\n}\n\nFile v1.5.7:references/publish-rules.md\n\n# Publish Rules for ClawHub & GitHub\n\n> Full rule reference loaded by the `skill-publish` workflow. Do not embed this in SKILL.md.\n\n---\n\n## 1. Frontmatter Requirements\n\n| Field | Rule | Why |\n|-------|------|-----|\n| `name` | Pure English slug, **no version number**. e.g. `invassistant` not `invassistant-v2` | ClawHub display name; version belongs in changelog |\n| `description` | ≤3 sentences, English only. No version numbers, stock tickers, keyword lists, or changelogs | ClawHub card + search summary |\n| `metadata.openclaw.tags` | 5-10 English tags | ClawHub category system |\n| `metadata.openclaw.requires.bins` | Declare required binaries (e.g. `python3`) | ClawHub security analysis |\n\n**Bad**:\n```yaml\ndescription: |\n  个人投资组合管理框架 v2.1.1（执行简化版）。覆盖 A 股、港股、美股。\n  新增 §7.4 模式 D...\n  触发关键词：检查持仓, COST, LLY...\n```\n\n**Good**:\n```yaml\ndescription: >\n  Multi-asset investment portfolio management framework.\n  A/B/C-class differentiated rules, 7 red-line risk controls.\n  Covers US, A-share, and HK stocks.\n```\n\n## 2. Content Cleanup\n\n### Must Remove\n- `## 详细参考` / `## References` section (lists internal file paths — meaningless to users)\n- Unreleased versions in version history (e.g. \"v3.0 planned 2027\")\n- Internal dev notes (\"审计清理版\", \"next 6-12 months: no new rules\")\n- Ticker-specific entry scripts (e.g. `check_tsla_entry.py`) — exposes personal holdings\n- Meta-documents not part of the skill (e.g. `SKILL_PUBLISH_RULES.md`)\n\n### Version History\n- Only published versions (available on ClawHub)\n- One sentence per version\n- Max 5 rows\n\n## 3. Language\n\nThese are **ClawHub discoverability conventions, not hard requirements**. Recommend them\nand flag deviations in the audit report, but respect the user's intended primary language\nand never delete or reject valid content solely on language grounds.\n\n| File | Recommended language |\n|------|----------|\n| `SKILL.md` | English body + optional Chinese intro paragraph at end |\n| `README.md` | English |\n| `README_zh.md` | Chinese (mirror of English README) |\n| `CONTRIBUTING.md` | English |\n| All `references/*.md` | English |\n\n## 4. File Separation: Local vs Published\n\nFiles that stay **local only** (never push to GitHub or ClawHub):\n- Ticker-specific scripts (`check_tsla_entry.py`, `check_detail.py`, etc.)\n- Personal config files (`*-config.json` with real credentials)\n- Meta-documents (`SKILL_PUBLISH_RULES.md`)\n- Session-specific notes or logs\n- `.git/` directory\n\nFiles that go to **both platforms**:\n- `SKILL.md`, `README.md`, `README_zh.md`\n- `CONTRIBUTING.md`, `LICENSE`, `requirements.txt`\n- `references/` (all `.md`)\n- `scripts/` (only generic, reusable engines)\n\nFiles for **ClawHub only** (not GitHub):\n- `_meta.json`\n\n## 5. Publish Mechanics\n\n### ClawHub\n```bash\nclawhub publish <clean-dir> --slug <slug> --version <semver> --changelog \"<one-liner>\"\n```\n- Requires prior `clawhub login --token <token>` (persists to session)\n- Version must not already exist on ClawHub\n- If overriding `latest` tag, version number must be higher than current latest\n\n### GitHub\nAuthenticate with a PAT from your environment: set `GITHUB_TOKEN` (or `GITHUB_PAT`) before syncing. Never hardcode a token or a token-file path inside the skill.\n\n- **Create the repo manually first** (github.com/new, or `POST /user/repos` with your own token outside this skill).\n- **Sync files with the bundled helper** `scripts/sync_skill_to_github.js` — it only creates or updates files via the Contents API (upsert-only). It has **no delete capability**; removing a file from the repo is a manual action in the GitHub web UI.\n- Prefer a small Node.js `https.request` script over `curl` in Git Bash (avoids pipe/TLS quirks).\n\n### Optimal strategy\n1. Create clean temp directory (copy whitelisted files only)\n2. Publish to ClawHub from temp dir (avoids leaking local files)\n3. Push individual files to GitHub via API\n4. Delete temp dir\n5. Verify both platforms\n\n## 6. Post-Publish Verification\n\n```\n[ ] clawhub inspect shows correct latest version + English description\n[ ] ClawHub card description is English, ≤3 sentences\n[ ] ClawHub display name has no version number\n[ ] Version history shows only published versions (≤5)\n[ ] SKILL.md has no \"详细参考/References\" section\n[ ] SKILL.md has no internal dev notes\n[ ] README.md + README_zh.md both exist, versions match\n[ ] GitHub repo has no ticker-specific scripts\n[ ] GitHub repo has no personal config files\n[ ] GitHub commit message matches changelog\n```\n\nFile v1.5.7:README_zh.md\n\n# Skill Publish\n\n审计、清理并发布 Agent Skill 到 ClawHub 和 GitHub。适用于 OpenClaw 生态中任何基于 SKILL.md 的 skill。\n\n与 `skill-design-guide`（设计阶段）配合。\n\n**版本**: v1.5.7（2026-09-16）\n\n> ⚠️ **发布模式有外部副作用。** 审计模式为只读。发布模式会把清理后的 skill 内容传输到\n> ClawHub 和 GitHub（公开服务）。捆绑的同步脚本只创建或更新文件——从不删除你的仓库或本机的\n> 任何内容，也不修改本地文件。发布仅在完成审计并经你明确确认文件清单、目标仓库和版本后执行。\n> 凡发布的内容都应视为公开可见。\n\n## 模式\n\n| 模式 | 触发词 | 说明 |\n|------|--------|------|\n| **审计** | \"检查发布\" / \"audit skill\" | 只读扫描，报告问题，不改动文件、不传输任何内容 |\n| **发布** | \"发布 skill\" / \"publish skill\" | 审计并经确认后：在临时副本中清理 → 推送到 ClawHub/GitHub → 验证 |\n\n## 检查项\n\n1. **个人数据** — 持仓数量、成本价、账户金额、个人姓名\n2. **Frontmatter** — 描述长度、语言、名称中的版本号\n3. **内容** — 内部开发备注、参考章节、版本历史\n4. **语言** — SKILL.md 英文主体、README 中英双语\n5. **文件** — 个股脚本、元文档、过期文件\n\n## 快速开始\n\n```\n# 审计一个 skill 目录\n\"检查发布 ~/.workbuddy/skills/my-skill\"\n\n# 发布到 ClawHub + GitHub\n\"发布 skill ~/.workbuddy/skills/my-skill@1.2.0\"\n```\n\n## 捆绑脚本\n\n`scripts/sync_skill_to_github.js` — 可选辅助脚本，把 publish 目录镜像同步到 GitHub 仓库（Contents API）。\n\n- Token：仅从 `GITHUB_TOKEN` / `GITHUB_PAT` 环境变量读取，未设置时报错退出。不内置、不读文件、不打印日志。\n- 网络：仅访问 `api.github.com`。只创建/更新文件（PUT），**从不删除**远端文件。\n- 全参数化：`--owner`、`--repo`、`--dir`、`--message`、`--branch`、`--files`。无硬编码路径或用户名。\n\n```bash\nnode scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill\n```\n\n## License\n\nMIT\n\nFile v1.5.7:sanitize.md\n\n**Run this BEFORE any publish.** Public skills are permanent.\n\n## Release Type Gate (run first)\n\nBefore starting, classify the release — the pipeline strictness differs:\n\n| Type | Definition | Required stages |\n|---|---|---|\n| **New skill publish** | Slug not yet on ClawHub | **Full 5 stages**: Understand → Transform → Sanitize → Verify (user approval message) → Publish + Install-check |\n| **Content update** | New references / new sections / scope change | Sanitize → Verify (user approval) → Publish |\n| **Patch (wording / metadata)** | Description tweak, frontmatter fix, version bump only | Sanitize → Publish (user approval is still required — show the diff or content before publishing) |\n\n**New-skill extra checks (mandatory):**\n1. `clawhub inspect <slug>` — must return \"Skill not found\" (not AMBIGUOUS) before publish. A slug collision creates an unfixable ghost record.\n2. Structure completeness per skill-design-guide: Hard Rules, Failure Handling, Output Format, steps tagged `[Deterministic]`/`[LLM]`.\n3. Optional discoverability add-on: a Chinese summary + trigger keywords can be appended to the description (skillhub search indexes description only, not description_zh). This broadens public search visibility beyond what the user may expect — ask the user and proceed only after explicit consent. Never add these by default.\n\n**Frozen skills (do not update unless necessary):**\n- `social-persona-profiling` — any update risks re-triggering SkillSpector alerts (its third-party-profiling capability sits on the policy line). If an update is unavoidable, keep frontmatter minimal and change body only.\n\n## Personal Data\n\nRemove or genericize:\n- [ ] Names (your name, team members, company)\n- [ ] Email addresses\n- [ ] Usernames, handles, IDs\n- [ ] Phone numbers\n- [ ] Addresses, locations\n- [ ] URLs to private resources\n- [ ] Internal project names\n- [ ] Client/customer references\n\n## Credentials & Secrets\n\n**NEVER include:**\n- [ ] API keys, tokens, passwords\n- [ ] Environment variable VALUES (names are ok)\n- [ ] Private URLs with auth params\n- [ ] Database connection strings\n- [ ] SSH keys, certificates\n\n## Model-Specific References\n\nRemove references to specific models that won't apply to all users:\n- [ ] \"Claude\" → \"the agent\" or \"the model\"\n- [ ] \"GPT\" → generic term\n- [ ] Specific model versions\n- [ ] Provider-specific features\n\n## Internal References\n\nRemove:\n- [ ] References to your specific file paths\n- [ ] Your workspace structure\n- [ ] Your tool configurations\n- [ ] Internal documentation links\n- [ ] Team-specific workflows\n\n## Dangerous Patterns\n\nCheck for:\n- [ ] Commands that could damage systems\n- [ ] Patterns that encourage unsafe behavior\n- [ ] Hardcoded paths that won't work elsewhere\n- [ ] Assumptions about user's environment\n\n## Genericize Examples\n\nReplace specific with generic:\n- `~/my-company/project` → `~/projects/example`\n- `john@company.com` → `user@example.com`\n- `api.mycompany.com` → `api.example.com`\n- Internal tool names → generic descriptions\n\n## Final Check\n\nBefore publishing, read entire skill asking:\n- \"Would I be comfortable if this were public forever?\"\n- \"Could this expose anything about me/my company?\"\n- \"Would this work for someone with zero context about me?\"\n\n## If Unsure\n\n**Ask the user:**\n> \"I found [X] which might be personal/internal. Should I remove, genericize, or keep it?\"\n\nBetter to ask than to publish something private.\n\n## Post-publish Finding Diagnosis (if SkillSpector or similar scanner reports findings)\n\nWhen a security/policy scanner reports findings AFTER publish, diagnose the finding's layer before fixing. **Do not reflexively add disclaimers or narrow triggers — that often makes things worse.**\n\n### Step 1: Read the \"Finding\" text\n\nFindings quote specific lines. Identify what the scanner actually objects to:\n- Is it quoting **frontmatter** (trigger keywords, description text)? → L1\n- Is it quoting **body steps** but the issue is wording mismatch with description? → L2\n- Is it quoting **body steps** and the issue is the capability itself (e.g. \"actionable interpersonal advice\", \"third-party profiling\", \"consequential decision automation\")? → L3\n\n### Step 2: Match to layer\n\n| Layer | Signal | Fix approach |\n|---|---|---|\n| **L1 Surface** | Finding quotes frontmatter trigger keywords or description phrasing | Narrow trigger words, add data preconditions, move hidden-style content to separate fields |\n| **L2 Behavior mismatch** | Finding quotes body steps, but the root cause is description saying one thing while body does another | Align description to match actual body behavior (or change body to match description) |\n| **L3 Scope** | Finding quotes body steps and the issue is the skill's core capability itself | This is a design decision, not a wording fix. Ask the user: keep the capability and accept the finding, or restructure the skill's scope? |\n\n### Step 3: Anti-patterns\n\n- **Do not add \"NOT a decision-support system\" disclaimers to fix L3 findings.** The scanner reads the body, not just the disclaimer. If the body provides actionable guidance, a disclaimer creates a *new* mismatch (L2).\n- **Do not reflexively narrow trigger keywords for L2/L3 findings.** Narrow triggers only fixes L1. If the finding quotes body steps, trigger wording is not the issue.\n- **Do not bump versions repeatedly trying to fix the same finding.** If the same finding persists after 2 patch attempts, the issue is L3 (scope), not L1 (wording). Stop and escalate to the user with the scope-level tradeoff.\n\n### Step 4: When to stop fixing\n\nIf ClawHub moderation shows `CLEAN` but SkillSpector (or similar third-party scanner) still reports findings, **the skill is already live and installable**. SkillSpector findings are informational — they do not block ClawHub moderation. Ask the user whether to:\n1. Accept the findings (skill is live, moderation is CLEAN)\n2. Continue fixing (only worthwhile if findings indicate real risk to users)\n\n### Step 5: Rollback strategy (when fixes make things worse)\n\nIf 2+ patch attempts have been made and findings are **increasing** (new findings appeared that weren't in the original version), the fixes themselves are the problem. Each added field (trigger keywords, read_when, not_for, disclaimers, Chinese triggers) gives the scanner **more surface to analyze** and **more patterns to match against**.\n\n**Rollback procedure:**\n1. Identify the last version that passed SkillSpector cleanly (or had the fewest findings)\n2. Take that version's **frontmatter** (description, read_when, not_for — all of it)\n3. Take the current version's **body** (if a scope-level fix like Step 8 rename was already made, keep it — it's a real improvement)\n4. Publish as a new version with changelog: \"Rollback frontmatter to [version] original; retain [version] scope fix\"\n5. **Do not re-add** trigger keywords, Chinese triggers, NOT disclaimers, read_when narrowing, or not_for items — these are what triggered the new findings\n\n**Key insight:** A clean, minimal frontmatter (just name + description + version) has the **smallest attack surface**. Every additional field is a potential finding. If a skill passed at version X, the fastest path to passing again is to return to X's frontmatter, not to add more guards.\n\n**Real example (social-persona-profiling):**\n- 1.0.4: passed SkillSpector (no findings)\n- 1.0.5-1.0.10: added trigger keywords, read_when, not_for, disclaimers, Chinese triggers → findings **increased** to 10+\n- 1.0.11: rolled back frontmatter to 1.0.4 original + retained 1.0.8 body scope fix → **passed**\n\nFile v1.5.7:skill-card.md\n\n## Description:\n\nSkill Audit & Publish guides agents through auditing, sanitizing, verifying, publishing, and install-checking OpenClaw skills for ClawHub releases, with optional GitHub synchronization.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[haiyangchenbj](https://clawhub.ai/user/haiyangchenbj)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and skill maintainers use this skill to prepare OpenClaw skills for ClawHub publication by staging a publish folder, auditing for private data or credentials, checking metadata and versioning, requiring approval, and verifying installation after publish.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Publishing can expose skill contents publicly and may be difficult to undo cleanly.\n\nMitigation: Review the exact file list, target slug, version, destination, and sanitized content before approving any publish action.\n\nRisk: Credentials could be exposed if tokens are passed or stored carelessly.\n\nMitigation: Use narrowly scoped GitHub tokens through environment variables only, and avoid command-line token arguments or token files.\n\nRisk: Using a mutable one-shot ClawHub CLI runner can introduce supply-chain risk.\n\nMitigation: Use a pinned or locally installed ClawHub CLI version where possible before running publish or install-check commands.\n\nRisk: The optional GitHub sync helper only creates or updates files, so removed local files can remain in the remote repository.\n\nMitigation: Audit the remote repository file list after major restructures and remove stale files manually when needed.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/haiyangchenbj/skills/skill-audit-publish)\n- [Publish Rules for ClawHub & GitHub](artifact/references/publish-rules.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with shell commands, file manifests, rewritten skill files, audit checklists, and optional JavaScript sync commands.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Generates local publish folders and approval messages; optional GitHub sync helper creates or updates files only and does not delete remote files.]\n\n## Skill Version(s):\n\n1.5.7 (source: evidence.json release metadata and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.5.7:transform.md\n\nReference — how to convert any knowledge into proper skill structure.\n\n## Source Types\n\n### Already a Skill\n- Copy to separate publish folder\n- Run sanitization\n- Verify structure meets standards\n\n### Instructions in Files\n- Read and understand the full process\n- Extract core actionable instructions\n- Remove personal context, keep universal value\n- Structure into SKILL.md + auxiliaries\n\n### Knowledge You've Developed\n- Document what you know about the topic\n- Focus on WHAT TO DO, not explanations\n- Include the non-obvious parts\n- Ask user to confirm you captured it correctly\n\n### User's Request to Share Something\n- Ask: \"What specifically should this skill help others do?\"\n- Ask: \"What do you do that others might not know?\"\n- Condense their workflow into reusable instructions\n\n## Transformation Rules\n\n### Keep\n- Actionable instructions\n- Non-obvious insights\n- Useful patterns\n- Practical examples (genericized)\n\n### Remove\n- Personal context\n- Explanations of basics\n- Verbose descriptions\n- Meta-commentary\n\n### Restructure\n- SKILL.md: Core instructions only (30-50 lines ideal)\n- Auxiliary files: Details, references, patterns\n- Progressive disclosure: Load details only when needed\n\n## Standard Structure\n\n```\npublish-folder/\n├── SKILL.md          ← Core instructions\n├── FILES.txt         ← List of files to publish\n└── [topic].md        ← Supporting details\n```\n\n## When Unsure What to Include\n\n**Default: Include it.** Easier for user to remove than to add later.\n\nMark uncertain sections:\n> \"I included [X] — let me know if this should be removed or modified.\"\n\n## Verify Understanding\n\nBefore finalizing, confirm with user:\n1. \"Here's what I understood as the core value: [summary]\"\n2. \"I'm including these sections: [list]\"\n3. \"I'm excluding: [list with reasons]\"\n4. \"Any changes before I prepare the publish version?\"\n\nFile v1.5.7:verify.md\n\n**Never publish without completing this process.**\n\n## Create Publish Folder\n\nWork in a SEPARATE folder, never modify originals:\n```\n/tmp/publish-[slug]/\n├── SKILL.md\n├── FILES.txt\n└── [auxiliaries]\n```\n\n## Verification Message\n\nBefore publishing, send user a verification with:\n\n### Required Information\n- **Slug:** exact slug to use\n- **Name:** exact display name\n- **Version:** version number\n- **Description:** exact description text\n- **Files:** complete list of files to publish\n\n### Content Summary\n- Brief summary of what the skill does\n- Key sections/topics covered\n- Any notable inclusions or exclusions\n\n### Sanitization Confirmation\n- \"Checked for personal data: ✓\"\n- \"Checked for credentials: ✓\"\n- \"Checked for model-specific references: ✓\"\n- Note any items that were removed/genericized\n\n## Wait for Approval\n\n**Do not proceed without explicit approval.**\n\nUser should confirm:\n- Slug is correct\n- Name is correct\n- Description is correct\n- Content looks right\n- Ready to publish\n\n## Publish Command\n\nOnly after approval:\n```bash\nclawhub publish <folder> \\\n  --slug \"<slug>\" \\\n  --name \"<name>\" \\\n  --version \"<version>\"\n```\n\n## Post-Publish Verification\n\nAfter publishing:\n1. Confirm success message\n2. Optionally install to verify: `clawhub install <slug> --dir /tmp/verify`\n3. Report to user: \"Published [slug]@[version]\"\n\n## If Something Goes Wrong\n\n- Wrong slug? Use ClawHub Edit page → \"Rename slug\" (old slugs stay as redirects). Then publish a new version with the corrected content if needed.\n- Wrong content? Publish new version with fix.\n- Exposed private data? Publish sanitized version ASAP, rename or delete the old listing, contact support if needed.\n\n## Version Guidelines\n\n- `1.0.0` — First publish\n- `1.0.1` — Small fixes (typos, clarifications)\n- `1.1.0` — New content/features\n- `2.0.0` — Major restructure\n\nArchive v1.5.6: 10 files, 23832 bytes\n\nFiles: README_zh.md (2172b), README.md (2254b), references/publish-rules.md (4568b), sanitize.md (7622b), scripts/sync_skill_to_github.js (7106b), skill-card.md (2529b), SKILL.md (18031b), transform.md (1870b), verify.md (1884b), _meta.json (138b)\n\nFile v1.5.6:SKILL.md\n\n---\nname: \"Skill Audit & Publish\"\nslug: skill-audit-publish\ndisplayName: \"Skill Audit & Publish\"\ndescription: \"Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. Bundled helper script: scripts/sync_skill_to_github.js mirrors a publish folder to a GitHub repo via the GitHub Contents API using a user-supplied token (GITHUB_TOKEN/GITHUB_PAT env var); it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.\"\nversion: \"1.5.6\"\nmetadata:\n  openclaw:\n    permissions:\n      - \"network: api.github.com — used only by the bundled sync helper when explicitly invoked\"\n      - \"credentials: GITHUB_TOKEN / GITHUB_PAT environment variables — read at runtime, never stored or logged\"\n    tags:\n      - skill-publishing\n      - pre-publish-audit\n      - pii-sanitization\n      - secret-scanning\n      - skill-lifecycle\n      - content-governance\n      - developer-tools\n      - publishing-workflow\n      - audit-checklist\n---\n\n# Skill Audit & Publish\n\nA five-stage pipeline that takes a local OpenClaw skill and ships a sanitized, verified release to ClawHub. The publish command is the last step, not the first — every earlier step is designed to keep private data and irreversible mistakes out of the public record.\n\n**The single most important rule:** never modify the user's original files. Work in a separate publish folder; only after explicit approval move anything to the live registry.\n\n---\n\n## When to use\n\nTrigger this skill when the user says or implies any of:\n\n- \"Publish this skill to ClawHub\" / \"I want to publish to ClawHub\" / \"ship it to clawhub\"\n- \"How do I publish a skill\" / \"What's the ClawHub publish command\" / \"clawhub publish syntax\"\n- \"Sanitize my skill before publishing\" / \"remove personal info\" / \"audit for PII\"\n- \"Check for secrets / API keys / tokens before I publish\"\n- \"Make a publish-ready version of this skill\"\n- \"I want to share this skill publicly\" / \"publish a skill without leaking my data\"\n- \"clawhub publish\" / \"npx clawhub publish\" / \"openclaw publish\"\n- \"Pre-publish checklist\" / \"what should I check before publishing\"\n\n**Do NOT trigger** for: editing skill content (use the skill's own skill), reading a skill from ClawHub, listing installed skills, or any non-publish operation.\n\n---\n\n## What this skill produces\n\nA `publish-folder/` with:\n- `SKILL.md` (rewritten frontmatter: `name`, `description`, `version`, GEO-optimized)\n- `FILES.txt` (manifest of what will ship)\n- Auxiliaries: `sanitize.md`, `transform.md`, `verify.md`\n- `_meta.json` (slug, version, publishedAt)\n- An **approval message** summarizing slug / name / version / files / sanitization status — held until the user explicitly approves.\n\nNothing leaves the local publish folder until the user replies \"yes / publish / go\".\n\n---\n\n## The 5-stage pipeline\n\n| Stage | Output | Gate |\n|---|---|---|\n| 1. **Understand** | One-paragraph summary of what the skill does, who it's for, what to keep / cut | User confirms the summary |\n| 2. **Transform** | Re-structured `SKILL.md` (frontmatter + body) + extracted auxiliaries | Diff shown to user |\n| 3. **Sanitize (the audit)** | `sanitize.md` checklist run: PII / credentials / model-specific refs / internal paths / dangerous patterns; each item marked `removed` / `genericized` / `kept-with-reason` | User reviews every kept-with-reason item |\n| 4. **Verify** | Approval message: slug, name, version, description, file list, sanitization confirmation, sample of sanitized text | **Explicit user approval** |\n| 5. **Publish + install-check** | `clawhub publish` then `clawhub install <slug> --dir /tmp/verify` to confirm the published version is installable and matches the local copy. Use a pinned or locally installed CLI — unpinned `npx clawhub` resolves a mutable third-party package at run time (supply-chain risk) | Success message reported back to user |\n\nThe audit (stage 3) is the differentiator. Other publish skills hand you a `clawhub publish` command; this one walks the content through a structured PII / secret / model-reference scan first and refuses to skip the scan if the user has not reviewed the keep-list.\n\n---\n\n## GEO optimization embedded in stage 2\n\nThe transform step re-writes the skill's `description` field for Generative Engine Optimization so the published skill is cited by ChatGPT / Claude / Perplexity when users ask for help in that domain. The current 6 rules:\n\n1. **First sentence = what it is + who it's for.** No preamble. Verbs, not nouns.\n2. **List concrete capabilities as short noun phrases** (LLM retrieval uses these as match anchors).\n3. **Include the primary user-trigger phrase** as a literal quoted string inside the description.\n4. **Front-load 2–3 named tools / frameworks / commands** the skill uses or talks to.\n5. **Add a \"When to use\" trigger block** with 5–7 user-natural questions, mirroring the skill's own frontmatter.\n6. **End with a 中文摘要** block (catches the Chinese-language LLM retrieval channel).\n\nThe transform stage will re-run these rules against the user's skill and present a before/after diff before any sanitization starts.\n\n---\n\n## Critical rules\n\n1. **Never modify the original files.** Always copy to `/tmp/publish-<slug>/` (or any out-of-tree folder) and work there.\n2. **Never publish without running `sanitize.md`.** The audit is mandatory; \"looks fine to me\" is not a substitute.\n3. **Never publish without explicit user approval.** The approval message lists the exact slug, name, version, description, and file set. The user must say \"yes\" or equivalent. Silence is not consent.\n4. **Slug is renameable, with redirects.** On ClawHub, the Edit page lets you change the canonical slug under \"Rename slug\"; old slugs stay as 301 redirects. If the wrong slug ships, fix it via the Edit UI (and optionally publish a new version with the corrected content). **This is why stage 4 still matters** — the verify stage catches wrong content; the slug rename is a separate UI action.\n5. **Version semantics:** `1.0.0` first publish; `1.0.x` typo / wording fixes; `1.x.0` new content; `2.0.0` major restructure. **One version number across all three platforms (ClawHub / SkillHub / GitHub), set to the highest existing one + 0.0.1** (科里 2026-08-31 确立): before publishing, check each platform's latest (ClawHub `inspect --versions`, SkillHub API, GitHub frontmatter), take the max, bump — never let platforms drift apart again.\n6. **Sanitize-over-include when uncertain.** When the audit flags a borderline item, default to remove or genericize. Adding later is easy; removing from a public release is reputation damage.\n7. **No silent re-publishes.** Every publish — including version bumps — produces an approval message. Re-publishing to fix a typo is a publish event, not a footnote.\n8. **Slug MUST be passed explicitly via `--slug`.** The `clawhub publish` CLI derives the slug from the **publish-folder's name** (`sanitizeSlug(basename(folder))`), NOT from `SKILL.md`'s `name` or `metadata.openclaw.slug`. If the folder name differs from the intended slug, the publish silently lands on the wrong slug — and if that slug already exists under another owner, ClawHub returns `AMBIGUOUS_SKILL_SLUG` and the install breaks for everyone. Always pass `--slug <canonical-slug>` even when the folder name looks right. (The Install-check stage below uses `--dir /tmp/verify-<slug>` precisely to avoid re-nesting on the user's machine.)\n9. **Detect and flatten nested source folders before publishing.** `clawhub install <slug> --dir .` wraps the downloaded skill in a slug-named subfolder, producing `slug/slug/SKILL.md` nesting on disk. Before publishing, resolve `SKILL.md` to the **inner** folder; never publish from the outer wrapper. In the Verify stage, assert `SKILL.md` sits at the publish-root (not nested one level down) and that `slug` equals the intended canonical slug.\n10. **Version numbers can be phantom-occupied.** When a platform version was published as \"add missing files only\" (SKILL.md untouched), the platform Latest leads the `version:` field inside SKILL.md (e.g. platform 1.1.3 / file says 1.1.1). Before any patch publish, run `clawhub inspect <slug> --versions` and target **platform Latest + 0.0.1** — never trust the version field inside the file. Same on SkillHub: \"version already exists\" on publish = phantom occupation; bump again.\n11. **SkillHub publish has stricter frontmatter validation than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files downloaded via `clawhub install` often miss the leading `---` (stripped in ClawHub storage) and `slug`/`displayName` — backfill them before SkillHub publish. Consecutive SkillHub publishes trigger 429 rate limits; wait ~60s between publishes.\n12. **Delete `skill-card.md` from install-sourced publish folders.** ClawHub generates it and refuses publishes containing it. Publish with explicit `--slug/--name/--version/--changelog` (the CLI reads version from frontmatter when flags are absent, and phantom-occupied versions fail late).\n13. **On Windows, pass Windows paths to `clawhub publish` / `clawhub install`.** Under Git Bash a `/c/Users/...` path fails with `Error: Path must be a folder`; the same command with `C:\\Users\\...` succeeds. This is not a permissions or install problem — retry with the Windows form before concluding anything else. (Verified 2026-09-11.)\n14. **`inspect`'s table view is cached; `--json` is authoritative.** After a publish the table can keep showing the previous `Latest` for several minutes. Read `inspect <slug> --json` → `latestVersion.version` and `skill.tags.latest` instead. Do not re-publish because the table looks stale, and do not poll with long sleeps — one JSON read settles it. (Verified 2026-09-11.)\n15. **GitHub mirror sync must push from the publish staging dir (`pub-*`), never from an install-sourced dir.** An install dir holds whatever the registry had (possibly a phantom-occupied old `version:` field without your patch), while the staging dir is the exact content you verified. Upsert-only: contents-API pushes add/update files but never delete removed ones — audit the repo file list after major restructures.\n16. **Use a pinned or locally installed `clawhub` CLI, not unpinned `npx clawhub`.** Unpinned `npx` resolves the latest third-party package at run time — a supply-chain risk for a command that reads your token and uploads content. Install once (`npm i -g clawhub`) and invoke the reviewed local binary, or pin the version (`npx clawhub@<version>`).\n\n---\n\n## Bundled scripts (external side effects, disclosed)\n\n`scripts/sync_skill_to_github.js` — optional helper that mirrors a publish folder to a GitHub repo via the GitHub Contents API (PAT auth). Behavior, explicitly:\n\n- **Reads a token from the environment only.** Requires the `GITHUB_TOKEN` / `GITHUB_PAT` environment variable; exits with an error if unset. No token is embedded in the skill, read from files, transmitted anywhere except api.github.com, or logged.\n- **Writes to GitHub only.** All network traffic goes to `api.github.com`. It creates or updates files (Contents API PUT) in the repo you name via `--owner` / `--repo`.\n- **Never deletes.** Upsert-only: files present on GitHub but absent from the local file list are left untouched; remote deletion must be done manually.\n- **Fully parameterized.** Owner, repo, local directory, branch, commit message, and file list all come \n\nArchive v1.5.5: 10 files, 22646 bytes\n\nFiles: _meta.json (138b), README_zh.md (2172b), README.md (2254b), references/publish-rules.md (4568b), sanitize.md (7397b), scripts/sync_skill_to_github.js (5801b), skill-card.md (2520b), SKILL.md (16581b), transform.md (1870b), verify.md (1884b)\n\nArchive v1.5.4: 10 files, 22565 bytes\n\nFiles: _meta.json (138b), README_zh.md (2172b), README.md (2254b), references/publish-rules.md (4568b), sanitize.md (7397b), scripts/sync_skill_to_github.js (5801b), skill-card.md (2302b), SKILL.md (16581b), transform.md (1870b), verify.md (1884b)\n\nArchive v1.5.3: 10 files, 22633 bytes\n\nFiles: _meta.json (138b), README_zh.md (2172b), README.md (2254b), references/publish-rules.md (4568b), sanitize.md (7397b), scripts/sync_skill_to_github.js (5741b), skill-card.md (2502b), SKILL.md (16581b), transform.md (1870b), verify.md (1884b)\n\nArchive v1.5.2: 10 files, 22597 bytes\n\nFiles: _meta.json (138b), README_zh.md (2129b), README.md (2174b), references/publish-rules.md (4568b), sanitize.md (7397b), scripts/sync_skill_to_github.js (5741b), skill-card.md (2545b), SKILL.md (16581b), transform.md (1870b), verify.md (1884b)\n\nArchive v1.5.1: 10 files, 22828 bytes\n\nFiles: _meta.json (138b), README_zh.md (2150b), README.md (2184b), references/publish-rules.md (4861b), sanitize.md (7397b), scripts/sync_skill_to_github.js (5942b), skill-card.md (2593b), SKILL.md (16355b), transform.md (1870b), verify.md (1884b)\n\nArchive v1.5.0: 10 files, 20602 bytes\n\nFiles: _meta.json (138b), README_zh.md (1503b), README.md (1560b), references/publish-rules.md (4861b), sanitize.md (7397b), scripts/sync_skill_to_github.js (3676b), skill-card.md (2371b), SKILL.md (14896b), transform.md (1870b), verify.md (1884b)","readmeExcerpt":"Skill: Skill Audit & Publish Owner: haiyangchenbj Summary: Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# Audit a skill directory\n\"audit skill ~/.workbuddy/skills/my-skill\"\n\n# Publish to ClawHub + GitHub\n\"publish skill ~/.workbuddy/skills/my-skill@1.2.0\""},{"language":"bash","snippet":"node scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill"},{"language":"yaml","snippet":"description: |\n  个人投资组合管理框架 v2.1.1（执行简化版）。覆盖 A 股、港股、美股。\n  新增 §7.4 模式 D...\n  触发关键词：检查持仓, COST, LLY..."},{"language":"yaml","snippet":"description: >\n  Multi-asset investment portfolio management framework.\n  A/B/C-class differentiated rules, 7 red-line risk controls.\n  Covers US, A-share, and HK stocks."},{"language":"bash","snippet":"clawhub publish <clean-dir> --slug <slug> --version <semver> --changelog \"<one-liner>\""},{"language":"text","snippet":"[ ] clawhub inspect shows correct latest version + English description\n[ ] ClawHub card description is English, ≤3 sentences\n[ ] ClawHub display name has no version number\n[ ] Version history shows only published versions (≤5)\n[ ] SKILL.md has no \"详细参考/References\" section\n[ ] SKILL.md has no internal dev notes\n[ ] README.md + README_zh.md both exist, versions match\n[ ] GitHub repo has no ticker-specific scripts\n[ ] GitHub repo has no personal config files\n[ ] GitHub commit message matches changelog"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: \"Skill Audit & Publish\"\nslug: skill-audit-publish\ndisplayName: \"Skill Audit & Publish\"\ndescription: \"Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a publish folder to a GitHub repo via the GitHub Contents API using environment-provided credentials only; it only creates or updates files and never deletes anything. Trigger phrases: 'publish to ClawHub', 'publish my skill', 'sanitize before publish', 'pre-publish checklist', 'clawhub publish command', 'upload a skill to clawhub'.\"\nversion: \"1.5.9\"\nallowed-tools: execute_command, read_file, file_read, write_to_file, file_write, env, network\nmetadata:\n  openclaw:\n    permissions:\n      - \"network: api.github.com — used only by the bundled sync helper when explicitly invoked\"\n      - \"credentials: GITHUB_TOKEN / GITHUB_PAT environment variables — read at runtime, never stored or logged\"\n      - \"network: api.skillhub.cn — used only by the stage 5b SkillHub upload when the user approves publishing\"\n      - \"credentials: the local SkillHub credential file (~/.skillhub/credentials.json, field user.token) read only during stage 5b to authenticate the upload — held in memory for that single request, never embedded in the skill, logged, or shipped in any package\"\n    tags:\n      - skill-publishing\n      - pre-publish-audit\n      - pii-sanitization\n      - secret-scanning\n      - skill-lifecycle\n      - content-governance\n      - developer-tools\n      - publishing-workflow\n      - audit-checklist\n---\n\n# Skill Audit & Publish\n\nA five-stage pipeline that takes a local OpenClaw skill and ships a sanitized, verified release to ClawHub. The publish command is the last step, not the first — every earlier step is designed to keep private data and irreversible mistakes out of the public record.\n\n**The single most important rule:** never modify the user's original files. Work in a separate publish folder; only after explicit approval move anything to the live registry.\n\n---\n\n## When to use\n\nTrigger this skill when the user says or implies any of:\n\n- \"Publish this skill to ClawHub\" / \"I want to publish to ClawHub\" / \"ship it to clawhub\"\n- \"How do I publish a skill\" / \"What's the ClawHub publish command\" / \"clawhub publish syntax\"\n- \"Sanitize my skill before publishing\" / \"remove personal info\" / \"audit for PII\"\n- \"Check for secrets / API keys / tokens before I publish\"\n- \"Make a publish-ready version of this skill\"\n- \"I want to share this skill publicly\" / \"publish a skill without leaking my data\"\n- \"clawhub publish\" / \"clawhub publish command\" / "},{"path":"README.md","content":"# Skill Publish\n\nAudit, clean, and publish agent skills to ClawHub and GitHub. Works with any SKILL.md-based skill in the OpenClaw ecosystem.\n\nComplements `skill-design-guide` (design-time) with publish-time workflow.\n\n**Version**: v1.5.7 (2026-09-16)\n\n> ⚠️ **Publish has external side effects.** `audit` mode is read-only. `publish` mode\n> transmits the cleaned skill contents to ClawHub and GitHub (public services). The bundled\n> sync helper only creates or updates files — it never deletes anything from your repos or\n> your machine, and it never modifies your local files. Publishing runs only after an audit\n> and your explicit confirmation of the file list, target repos, and version. Treat\n> everything you publish as publicly visible.\n\n## Modes\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| **Audit** | \"audit skill\" | Read-only scan — reports issues, changes nothing, transmits nothing |\n| **Publish** | \"publish skill\" | After audit + confirmation: clean (in a temp copy) → push to ClawHub/GitHub → verify |\n\n## What It Checks\n\n1. **Personal data** — share counts, cost basis, account values, personal names\n2. **Frontmatter** — description length, language, version numbers in name\n3. **Content** — internal dev notes, references sections, version history\n4. **Language** — English SKILL.md body, bilingual READMEs\n5. **Files** — ticker-specific scripts, meta-documents, outdated files\n\n## Quick Start\n\n```bash\n# Audit a skill directory\n\"audit skill ~/.workbuddy/skills/my-skill\"\n\n# Publish to ClawHub + GitHub\n\"publish skill ~/.workbuddy/skills/my-skill@1.2.0\"\n```\n\n## Bundled Scripts\n\n`scripts/sync_skill_to_github.js` — optional helper that mirrors a publish folder to a GitHub repo via the Contents API.\n\n- Token: read from `GITHUB_TOKEN` / `GITHUB_PAT` env vars only; exits with an error if unset. Never embedded, read from files, or logged. (The SkillHub upload stage reads a separate credential from a local file — declared in the skill's frontmatter permissions; it does not involve this helper.)\n- Network: talks to `api.github.com` only. Creates/updates files (PUT); **never deletes** anything.\n- Fully parameterized: `--owner`, `--repo`, `--dir`, `--message`, `--branch`, `--files`. No hardcoded paths or usernames.\n\n```bash\nnode scripts/sync_skill_to_github.js --owner <you> --repo <skill-repo> --dir ./publish-my-skill\n```\n\n## License\n\nMIT"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn70yg6zwmkftx4939qrs89awx82rr9a\",\n  \"slug\": \"skill-audit-publish\",\n  \"version\": \"1.5.9\",\n  \"publishedAt\": 1789883389948\n}"},{"path":"references/publish-rules.md","content":"# Publish Rules for ClawHub & GitHub\n\n> Full rule reference loaded by the `skill-publish` workflow. Do not embed this in SKILL.md.\n\n---\n\n## 1. Frontmatter Requirements\n\n| Field | Rule | Why |\n|-------|------|-----|\n| `name` | Pure English slug, **no version number**. e.g. `invassistant` not `invassistant-v2` | ClawHub display name; version belongs in changelog |\n| `description` | ≤3 sentences, English only. No version numbers, stock tickers, keyword lists, or changelogs | ClawHub card + search summary |\n| `metadata.openclaw.tags` | 5-10 English tags | ClawHub category system |\n| `metadata.openclaw.requires.bins` | Declare required binaries (e.g. `python3`) | ClawHub security analysis |\n\n**Bad**:\n```yaml\ndescription: |\n  个人投资组合管理框架 v2.1.1（执行简化版）。覆盖 A 股、港股、美股。\n  新增 §7.4 模式 D...\n  触发关键词：检查持仓, COST, LLY...\n```\n\n**Good**:\n```yaml\ndescription: >\n  Multi-asset investment portfolio management framework.\n  A/B/C-class differentiated rules, 7 red-line risk controls.\n  Covers US, A-share, and HK stocks.\n```\n\n## 2. Content Cleanup\n\n### Must Remove\n- `## 详细参考` / `## References` section (lists internal file paths — meaningless to users)\n- Unreleased versions in version history (e.g. \"v3.0 planned 2027\")\n- Internal dev notes (\"审计清理版\", \"next 6-12 months: no new rules\")\n- Ticker-specific entry scripts (e.g. `check_tsla_entry.py`) — exposes personal holdings\n- Meta-documents not part of the skill (e.g. `SKILL_PUBLISH_RULES.md`)\n\n### Version History\n- Only published versions (available on ClawHub)\n- One sentence per version\n- Max 5 rows\n\n## 3. Language\n\nThese are **ClawHub discoverability conventions, not hard requirements**. Recommend them\nand flag deviations in the audit report, but respect the user's intended primary language\nand never delete or reject valid content solely on language grounds.\n\n| File | Recommended language |\n|------|----------|\n| `SKILL.md` | English body + optional Chinese intro paragraph at end |\n| `README.md` | English |\n| `README_zh.md` | Chinese (mirror of English README) |\n| `CONTRIBUTING.md` | English |\n| All `references/*.md` | English |\n\n## 4. File Separation: Local vs Published\n\nFiles that stay **local only** (never push to GitHub or ClawHub):\n- Ticker-specific scripts (`check_tsla_entry.py`, `check_detail.py`, etc.)\n- Personal config files (`*-config.json` with real credentials)\n- Meta-documents (`SKILL_PUBLISH_RULES.md`)\n- Session-specific notes or logs\n- `.git/` directory\n\nFiles that go to **both platforms**:\n- `SKILL.md`, `README.md`, `README_zh.md`\n- `CONTRIBUTING.md`, `LICENSE`, `requirements.txt`\n- `references/` (all `.md`)\n- `scripts/` (only generic, reusable engines)\n\nFiles for **ClawHub only** (not GitHub):\n- `_meta.json`\n\n## 5. Publish Mechanics\n\n### ClawHub\n```bash\nclawhub publish <clean-dir> --slug <slug> --version <semver> --changelog \"<one-liner>\"\n```\n- Requires prior `clawhub login --token <token>` (persists to session)\n- Version must not already exist on ClawHub\n- If overriding `latest` tag, version number must be hig"},{"path":"references/skillhub-publish.md","content":"# Publishing to SkillHub (stage 5b)\n\n> Loaded by stage 5 of the pipeline. Kept out of the skill file on purpose — the skill file stays a routing surface; operational detail lives here.\n\nSkillHub is the third platform in the unified-version rule. **There is no maintained CLI for it.** A helper named `skills_store_cli.py` used to exist and no longer ships anywhere on a typical machine — do not spend time searching for it. Build the request directly.\n\n---\n\n## Endpoint\n\n```\nPOST https://api.skillhub.cn/api/v1/community/skills/publish\n```\n\n## Auth\n\nBearer token from `~/.skillhub/credentials.json` → **`user.token`**.\nThe file has no top-level `token` key; reading `d[\"token\"]` yields null and produces a misleading 401/403.\n\n## Request — multipart/form-data\n\n**Part 1** — field `payload`, `Content-Type: application/json`:\n\n```json\n{\n  \"slug\": \"my-skill\",\n  \"displayName\": \"My Skill\",\n  \"version\": \"1.2.3\",\n  \"description\": \"one-line English summary\",\n  \"changelog\": \"what changed\",\n  \"category\": \"\",\n  \"subCategories\": [],\n  \"source\": \"community\",\n  \"tags\": [\"tag-a\", \"tag-b\"]\n}\n```\n\n**Parts 2..n** — one per file:\n\n- field name **must be `files`** (`file` and `files[]` are wrong)\n- `filename` = repo-relative path with forward slashes, e.g. `references/guardian-patterns.md`\n- `Content-Type: text/markdown`\n\n## Response\n\n| Code | Meaning |\n|---|---|\n| **201** | accepted — body carries `ok:true`, `version`, `fileCount`, `skillId`, `fingerprint`, and `pending` review/scan statuses |\n| 400 | frontmatter or payload validation failed |\n| 409 | slug tombstoned, or version already exists → bump and retry. **Never delete a `source=community` skill to force a republish** — the slug becomes an unrecoverable tombstone |\n| 429 | consecutive publishes rate-limited → wait ~90s (a single 90 s backoff has been the reliable fix in practice; 20 s retries can fail repeatedly) |\n| 503 | transient → wait ~20s and retry once |\n\n## Constraints\n\n- **No read API.** Every `GET` under `/api/v1/community/skills/*` returns 405, including `/mine`, `/list`, and `/rankings`, with or without a Bearer token. You cannot verify remotely whether a skill is already on SkillHub. Use side evidence instead: `clawhub inspect <slug> --versions` plus the existence of the GitHub mirror repo.\n- **Stricter frontmatter than ClawHub.** Required: leading `---` delimiter, `slug`, `displayName`, `version`. Files retrieved via `clawhub install` often lose the leading `---` in ClawHub storage — backfill it before publishing.\n- **`LICENSE` is rejected.** Publish from a staging copy that excludes it.\n- **Version must match ClawHub and GitHub exactly.** No platform-local version numbers.\n\n## Ordering inside stage 5\n\n1. ClawHub publish (async — settle with `inspect --json` → `latestVersion.version`)\n2. **SkillHub publish (this file)**\n3. GitHub sync from the staging dir (never from an install dir)\n4. Install-check against ClawHub\n\nSkipping step 2 is the most common way the three-platform version rule breaks: the skill l"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2185,"uniquenessScore":41,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:15:43.181Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:15:43.181Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T02:05:03.336Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}