{"id":"0d9ad24a-ffb7-4792-bfdc-cbe503cbdfa9","entityType":"agent","slug":"clawhub-science-prof-robot-autoskill","name":"autoskill","canonicalUrl":"https://www.xpersona.co/agent/clawhub-science-prof-robot-autoskill","canonicalPath":"/agent/clawhub-science-prof-robot-autoskill","generatedAt":"2026-10-11T14:13:16.153Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T10:11:35.491Z","emptyReason":null},"description":"Intelligent skill router. Analyzes the current problem statement and context, scores all available skills for applicability, and recommends the most relevant... Skill: autoskill Owner: science-prof-robot Summary: Intelligent skill router. Analyzes the current problem statement and context, scores all available skills for applicability, and recommends the most relevant... Tags: latest:1.1.1 Version history: v1.1.1 | 2026-05-09T18:11:14.070Z | user ClawScan security review fixes: mandatory confirmation for all runs, expanded high-risk registry, heuristic detection, and removed","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17df8jczacx272nn3y0q0szt985d6cz:autoskill","sourceUrl":"https://clawhub.ai/science-prof-robot/autoskill","homepage":"https://clawhub.ai/science-prof-robot/skills/autoskill","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/science-prof-robot/autoskill","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/science-prof-robot/skills/autoskill","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Intelligent skill router. Analyzes the current problem statement and context, scores all available skills for applicability, and recommends the most relevant..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:11:35.491Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:11:35.491Z","emptyReason":null},"stars":null,"forks":null,"downloads":1091,"packageName":null,"latestVersion":"1.1.1","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:11:35.430Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T10:11:35.491Z","lastCrawledAt":"2026-10-11T10:11:35.430Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T10:11:35.430Z","lastVerifiedAt":null,"highlights":[{"version":"1.1.1","createdAt":"2026-05-09T18:11:14.070Z","changelog":"ClawScan security review fixes: mandatory confirmation for all runs, expanded high-risk registry, heuristic detection, and removed auto-apply exceptions.","fileCount":4,"zipByteSize":8941},{"version":"1.1.0","createdAt":"2026-05-09T14:24:13.201Z","changelog":"Security hardening: high-risk gate, execution preview, provenance metadata — addresses ClawScan findings","fileCount":3,"zipByteSize":7067},{"version":"1.0.1","createdAt":"2026-05-09T14:08:42.573Z","changelog":"Improved README with full pipeline explanation and design principles","fileCount":3,"zipByteSize":5877},{"version":"1.0.0","createdAt":"2026-05-09T14:05:39.488Z","changelog":"Initial release — intelligent skill router for Claude Code","fileCount":3,"zipByteSize":5877}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17df8jczacx272nn3y0q0szt985d6cz:autoskill","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T14:13:16.150Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-science-prof-robot-autoskill/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T10:11:35.491Z","emptyReason":null},"readme":"Skill: autoskill\n\nOwner: science-prof-robot\n\nSummary: Intelligent skill router. Analyzes the current problem statement and context, scores all available skills for applicability, and recommends the most relevant...\n\nTags: latest:1.1.1\n\nVersion history:\n\nv1.1.1 | 2026-05-09T18:11:14.070Z | user\n\nClawScan security review fixes: mandatory confirmation for all runs, expanded high-risk registry, heuristic detection, and removed auto-apply exceptions.\n\nv1.1.0 | 2026-05-09T14:24:13.201Z | user\n\nSecurity hardening: high-risk gate, execution preview, provenance metadata — addresses ClawScan findings\n\nv1.0.1 | 2026-05-09T14:08:42.573Z | user\n\nImproved README with full pipeline explanation and design principles\n\nv1.0.0 | 2026-05-09T14:05:39.488Z | user\n\nInitial release — intelligent skill router for Claude Code\n\nArchive index:\n\nArchive v1.1.1: 4 files, 8941 bytes\n\nFiles: install.sh (1220b), skill-card.md (2005b), SKILL.md (16808b), _meta.json (128b)\n\nFile v1.1.1:SKILL.md\n\n---\nname: autoskill\npreamble-tier: 2\nversion: 1.1.1\nauthor: Science-Prof-Robot\nhomepage: https://github.com/Science-Prof-Robot/autoskill\nlicense: MIT\ndescription: |\n  Intelligent skill router. Analyzes the current problem statement and context,\n  scores all available skills for applicability, and recommends the most relevant\n  ones in priority order. **No skill is ever invoked without your explicit approval.**\n\n  Use when you want Claude to automatically identify and recommend the right\n  skills without manually choosing them. Great for complex tasks where the right set\n  of skills is non-obvious.\n\n  Invocation:\n    /autoskill [problem description]\n    /autoskill (uses current conversation context if no args given)\n\n  Examples:\n    /autoskill fix the login bug that crashes on empty password\n    /autoskill add unit tests for the payment module\n    /autoskill review my PR before I merge\n    /autoskill (running with no args analyzes the current conversation)\nallowed-tools:\n  - Bash\n  - Read\n  - Glob\n  - Grep\n  - AskUserQuestion\n  - Skill\n---\n\n## Preamble (run first)\n\nThe commands below inspect local git state and detect the project language from\nconfig files. They do not modify anything, send data externally, or run project\ncode. They are safe to run in any local workspace.\n\n```bash\n_BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo \"no-git\")\necho \"BRANCH: $_BRANCH\"\n_LANG_SIGNALS=\"\"\n[ -f package.json ] && _LANG_SIGNALS=\"$_LANG_SIGNALS typescript,javascript\"\n[ -f requirements.txt ] || [ -f pyproject.toml ] || [ -f setup.py ] && _LANG_SIGNALS=\"$_LANG_SIGNALS python\"\n[ -f Cargo.toml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS rust\"\n[ -f go.mod ] && _LANG_SIGNALS=\"$_LANG_SIGNALS go\"\n[ -f pom.xml ] || [ -f build.gradle ] && _LANG_SIGNALS=\"$_LANG_SIGNALS java\"\n[ -f pubspec.yaml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS dart,flutter\"\nls *.csproj 2>/dev/null | head -1 | grep -q . && _LANG_SIGNALS=\"$_LANG_SIGNALS csharp\"\necho \"LANG_SIGNALS:${_LANG_SIGNALS:-unknown}\"\n_GIT_CHANGES=$(git status --short 2>/dev/null | head -20 || echo \"\")\necho \"GIT_CHANGES: $(echo \"$_GIT_CHANGES\" | wc -l | tr -d ' ') files\"\necho \"CHANGED_EXTS: $(echo \"$_GIT_CHANGES\" | grep -oE '\\.[a-zA-Z]+$' | sort -u | tr '\\n' ',' 2>/dev/null || echo 'none')\"\n```\n\n## High-Risk Skill Registry\n\nThe following skills perform irreversible, externally-visible, or broadly-scoped\nactions. They are **always treated as SUGGEST-tier** — they will never be\nrecommended for automatic inclusion and always require individual user\nconfirmation before running.\n\n```\nHIGH_RISK_SKILLS = [\n  # Deployment / release / CI\n  ship, land-and-deploy, canary, deploy, setup-deploy, prp-pr, deployment-patterns,\n\n  # Payment / billing / money\n  customer-billing-ops, finance-billing-ops, agent-payment-x402,\n\n  # Database mutations\n  database-migrations,\n\n  # External communications / public posts\n  github-ops, x-api, email-ops, messages-ops, unified-notifications-ops,\n  crosspost, content-writer,\n\n  # Account / enterprise / credential operations\n  enterprise-agent-ops, investor-outreach, cso, security-bounty-hunter,\n\n  # Broad shell / file system access\n  careful, guard, safety-guard,\n]\n```\n\n**Additional heuristic:** Any skill whose description contains keywords such as\n\"deploy\", \"payment\", \"billing\", \"money\", \"purchase\", \"credential\", \"account\",\n\"external message\", \"post to\", \"send email\", \"database migration\",\n\"DROP TABLE\", \"rm -rf\", \"force-push\", or \"broad shell\" is also treated as\nhigh-risk even if it is not in the fixed list above.\n\nWhen scoring (Phase 3), check each candidate against this registry and the\nheuristic. If it matches, force its tier to SUGGEST and add a `[HIGH-RISK]`\nlabel in the scoring table, regardless of its numeric score.\n\n## Phase 1 — Problem Extraction\n\n**Goal:** Build a structured context profile from the arguments and project state.\n\n**Input:** `$ARGUMENTS` — the user's problem description. If empty, synthesize from the current conversation: look at the most recent user messages, any error output, open files, or recent tool calls visible in context.\n\n**Build the context profile by answering these questions:**\n\n1. **Problem statement** — What is the user trying to accomplish? (1-2 sentences, concrete)\n2. **Action intent** — What category of work is this?\n   - `create` — building something new (feature, file, component, test)\n   - `fix` — repairing broken behavior (bug, error, crash, regression)\n   - `review` — evaluating quality (code review, security audit, PR check)\n   - `deploy` — shipping or releasing (push, merge, publish, CI)\n   - `document` — writing or updating docs\n   - `refactor` — improving structure without changing behavior\n   - `test` — adding or improving test coverage\n   - `analyze` — understanding or investigating something\n   - `design` — UI/UX or architecture planning\n   - `optimize` — improving performance\n3. **Language/stack** — From the preamble `LANG_SIGNALS` and `CHANGED_EXTS`\n4. **Domain tags** — Select all that apply from: `frontend`, `backend`, `database`, `security`, `testing`, `deployment`, `performance`, `documentation`, `architecture`, `mobile`, `api`, `infrastructure`, `data`\n5. **Keywords** — Extract 5-10 specific nouns and verbs from the problem statement (e.g., \"authentication\", \"token\", \"crash\", \"refactor\", \"test coverage\")\n\nPrint the context profile in this format before proceeding:\n```\nCONTEXT PROFILE\n───────────────\nProblem:  [1-2 sentences]\nIntent:   [action intent]\nStack:    [languages/frameworks]\nDomains:  [comma-separated domain tags]\nKeywords: [comma-separated keywords]\n```\n\n## Phase 2 — Skill Inventory Scan\n\n**Goal:** Build a candidate list from the available skills.\n\nThe full skill list is already loaded in your context (from the system-reminder's \"The following skills are available\" section). You do NOT need to read files — use the in-context list directly.\n\n**Steps:**\n\n1. From the system-reminder skill list, extract every skill's name and description.\n\n2. Group skills by domain bucket:\n\n| Bucket | Skill name patterns to look for |\n|--------|--------------------------------|\n| `testing` | tdd, test, pytest, jest, coverage, e2e, playwright, spec |\n| `security` | security, auth, vulnerability, owasp, bounty, pentest |\n| `code-quality` | review, lint, simplify, refactor, clean, style, standards |\n| `deployment` | ship, deploy, land, canary, pm2, docker, ci, cd |\n| `frontend` | frontend, ui, design, figma, css, react, vue, html, animation |\n| `backend` | backend, api, rest, graphql, server, express, fastapi, spring |\n| `database` | database, sql, postgres, clickhouse, migration, schema |\n| `documentation` | docs, readme, update-docs, codemaps, openapi |\n| `planning` | plan, autoplan, blueprint, office-hours, architect, prp |\n| `performance` | performance, optimize, bundle, lighthouse, profil |\n| `infrastructure` | kubernetes, terraform, aws, cloud, gstack, mcp |\n| `mobile` | flutter, android, ios, kotlin, swift, react-native |\n| `meta` | checkpoint, learn, memory, session, instinct, hookify |\n\n3. Build a flat candidate list: every skill that appears in at least one domain bucket relevant to the context profile's `Domain tags`.\n\nPrint the candidate count: `Found N candidate skills in relevant buckets.`\n\n## Phase 3 — Relevance Scoring\n\n**Goal:** Score every candidate skill and decide what to recommend, suggest, or skip.\n\nFor each candidate skill, score 0–100 using this rubric:\n\n| Criterion | Weight | How to evaluate |\n|-----------|--------|-----------------|\n| **Intent match** | 35% | Does the skill's purpose directly match the context profile's `action intent`? Exact match = 35, close match = 20, weak match = 10, no match = 0 |\n| **Domain match** | 30% | How many of the context profile's `domain tags` appear in this skill's description or bucket? Each match adds ~10 points up to 30 |\n| **Keyword overlap** | 20% | How many of the context profile's `keywords` appear (roughly) in the skill name or description? Each match adds ~4 points up to 20 |\n| **Stack match** | 15% | Does the skill explicitly target the detected language/framework? Match = 15, stack-agnostic = 10, mismatch = 0 |\n\n**Thresholds:**\n- **≥ 70** → RECOMMENDED (high confidence — included in the proposed plan)\n- **40–69** → SUGGEST (borderline — presented to user for optional inclusion)\n- **< 40** → Skip silently\n\n**High-risk override:** If a skill appears in the HIGH_RISK_SKILLS registry or matches\nthe heuristic above, force it to SUGGEST tier and mark it `[HIGH-RISK]` in the table,\nregardless of its numeric score.\n\n**Constraint: max 5 RECOMMENDED skills per invocation.** If more than 5 score ≥70, take the top 5 by score.\n\nPrint the scoring table (show only skills scoring ≥ 30):\n\n```\nSKILL SCORING\n─────────────────────────────────────────────────────────────────\nSkill                  Score  Tier             Reason\n─────────────────────── ─────  ──────────────   ─────────────────────\ntdd-workflow           88     RECOMMENDED      intent=create, domain=testing, keyword=test\nsecurity-review        82     RECOMMENDED      intent=fix, domain=security, keyword=auth\ntypescript-reviewer    75     RECOMMENDED      stack=typescript, domain=code-quality\ncode-review            72     RECOMMENDED      intent=review match\ndatabase-reviewer      55     SUGGEST          domain=database, weak intent match\nship                   71     SUGGEST [HIGH-RISK]  score≥70 but forced to SUGGEST — deployment skill\nseo                    8      SKIP             no frontend/content signals\n─────────────────────────────────────────────────────────────────\nRECOMMENDED: N skills | SUGGEST: M skills (K high-risk) | SKIP: K skills\n```\n\n## Phase 4 — Execution Preview and Mandatory Confirmation\n\n**This phase ALWAYS runs before any skill is invoked.** There are no exceptions.\nEven a single RECOMMENDED skill requires explicit user confirmation.\n\n### Step 4a — Show the execution plan\n\nPrint the full proposed run as a preview. Do not invoke anything yet:\n\n```\nEXECUTION PLAN\n──────────────────────────────────────────────────\n #  Skill                Tier        Score  Why\n──  ─────────────────── ──────────  ─────  ─────────────────────────\n 1  security-review      RECOMMENDED 88     fix intent + security domain\n 2  investigate          RECOMMENDED 82     fix intent + keyword=crash\n 3  typescript-reviewer  RECOMMENDED 75     stack=typescript\n 4  code-review          RECOMMENDED 72     review intent match\n 5  ship                 HIGH-RISK   71     deployment — requires confirmation\n──────────────────────────────────────────────────\n```\n\n### Step 4b — Mandatory confirmation gate\n\nUse **AskUserQuestion** for EVERY run. Do not skip this step.\n\nFormat the question as follows:\n\n> **autoskill recommends [N] skills for: \"[problem statement]\"**\n>\n> These skills will run **only after you confirm** below:\n>\n> **Recommended (score ≥70):**\n> - `skill-name` — [reason it applies]\n> - `skill-name` — [reason it applies]\n>\n> **Also applicable — want any of these?**\n> - `skill-name` [SUGGEST] — [reason it might apply]\n> - `skill-name` [HIGH-RISK] — [why it needs confirmation]\n>\n> **Actions:**\n> - Type the names of any suggested/high-risk skills you want to add\n> - Type \"none\" to run only the recommended skills\n> - Type \"cancel\" to stop and do nothing\n\nIf the user replies \"cancel\" or selects no skills and there are no recommended\nskills, abort and report BLOCKED.\n\nAdd any user-selected skills to the execution queue before continuing.\n\n## Phase 5 — Skill Execution\n\n**Goal:** Apply each queued skill in order.\n\n**Execution order:**\n1. RECOMMENDED skills sorted by score descending\n2. User-approved SUGGEST / HIGH-RISK skills appended at the end\n\n**For each skill in the queue:**\n\n1. Print: `→ Applying \\`[skill-name]\\` (score: [N]) — [one-line reason]`\n2. Invoke: `Skill(skill=\"[skill-name]\", args=\"[relevant portion of the original problem statement]\")`\n3. Wait for the skill to complete before starting the next one\n4. Note the outcome (completed / blocked / needs-context)\n\n**If a skill returns BLOCKED or NEEDS_CONTEXT:** note it in the audit table and continue to the next skill. Do not abort the entire queue for one blocked skill.\n\n**If NO skills score ≥40:**\n\nDo not silently do nothing. Instead use AskUserQuestion:\n\n> No skills scored above the applicability threshold for: \"[problem statement]\"\n>\n> This usually means the request is best handled directly (not via a specialized skill),\n> or the problem description needs more context.\n>\n> Options:\n> A) Let me handle this directly without a skill\n> B) Tell me more about what you need (I'll re-score)\n> C) Show me all available skills so I can pick manually\n\n## Phase 6 — Decision Audit Report\n\nAfter all skills have run (or been skipped), print the final report:\n\n```markdown\n## autoskill Run Complete\n\n**Problem:** [problem statement]\n**Intent:** [action intent] | **Stack:** [stack] | **Domains:** [domains]\n\n| Skill | Score | Tier | Applied | Outcome | Reason |\n|-------|-------|------|---------|---------|--------|\n| tdd-workflow | 88 | RECOMMENDED | ✅ | completed | create intent + testing domain |\n| security-review | 82 | RECOMMENDED | ✅ | completed | fix intent + security domain |\n| ship | 71 | HIGH-RISK | ⏸ User | skipped | user declined |\n| database-reviewer | 55 | SUGGEST | ⏸ User | completed | user approved |\n| seo | 8 | SKIP | ❌ | — | no frontend signals |\n\n**Summary:** [N] skills applied, [M] skipped, [K] blocked.\n```\n\n## Completion Status Protocol\n\nReport final status as one of:\n- **DONE** — All queued skills completed successfully\n- **DONE_WITH_CONCERNS** — Completed, but one or more skills returned BLOCKED or NEEDS_CONTEXT\n- **BLOCKED** — Could not determine applicable skills, all skills failed, or user cancelled\n- **NEEDS_CONTEXT** — Problem statement too vague to score skills reliably\n\n## Design Constraints\n\n- **Never bulk-read skill files.** The system-reminder list is sufficient for scoring. Only read a specific SKILL.md file if you need to understand invocation details for an edge case.\n- **Never hardcode skill assumptions.** Always derive the candidate list from the live system-reminder. New skills added to the system are automatically included.\n- **Mandatory confirmation for every run.** No skill is ever invoked without the user first seeing the execution plan and explicitly confirming or selecting which skills to run. There are no single-skip exceptions.\n- **High-risk skills always require individual confirmation.** Skills that deploy, send messages, modify data, charge accounts, or access broad shell/file scope are never automatically included — they are always presented as optional and marked `[HIGH-RISK]`.\n- **Heuristic + registry for high-risk detection.** The fixed HIGH_RISK_SKILLS list is supplemented by a keyword heuristic so newly added skills with dangerous descriptions are caught even if the registry has not been updated.\n- **Show the plan before executing.** The execution preview in Phase 4 ensures the user always sees what will run before any skill is invoked.\n- **Graceful degradation.** If the Skill tool is unavailable, print the scored table and explain which skills the user should invoke manually.\n- **Max 5 recommended skills.** Prevents runaway chaining on broad problem statements.\n- **Sequential execution.** Skills run one at a time, in score order. Never parallel — each skill may change project state that the next skill depends on.\n\n## Safety Notice\n\n`autoskill` is a meta-skill that recommends and routes to other skills. It does not\nperform any file modifications, deployments, or external communications itself.\nHowever, the skills it recommends may do so. Because of this:\n\n1. **Always review the execution plan** before confirming.\n2. **Remove any skill you do not want** by selecting only the ones you trust.\n3. **Be especially cautious with [HIGH-RISK] skills** — they are marked for a reason.\n4. **If you are unsure, choose \"cancel\"** — autoskill will stop and you can proceed manually.\n\nFile v1.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn77vxcwht8y7b07j822fsk0a985da95\",\n  \"slug\": \"autoskill\",\n  \"version\": \"1.1.1\",\n  \"publishedAt\": 1778350274070\n}\n\nFile v1.1.1:skill-card.md\n\n## Description:\n\nIntelligent skill router that analyzes the current problem statement and context, scores available skills for applicability, and recommends the most relevant ones in priority order.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[science-prof-robot](https://clawhub.ai/user/science-prof-robot)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use Autoskill to identify applicable agent skills for a task, review a scored execution plan, and explicitly approve which skills may run.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Approved downstream skills may perform file, network, or external-service actions outside Autoskill's own behavior.\n\nMitigation: Review the execution plan before approval, decline high-risk skills that are not needed, and cancel when the proposed queue is broader than intended.\n\nRisk: Skill recommendations could route work to an unsuitable or overly broad skill.\n\nMitigation: Use the scored table and mandatory confirmation step to select only the skills that match the task.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/science-prof-robot/skills/autoskill)\n- [Project homepage](https://github.com/Science-Prof-Robot/autoskill)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown with scored recommendations, execution previews, confirmation prompts, and audit tables]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires explicit user confirmation before invoking recommended, suggested, or high-risk downstream skills.]\n\n## Skill Version(s):\n\n1.1.1 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.1.0: 3 files, 7067 bytes\n\nFiles: install.sh (1220b), SKILL.md (14859b), _meta.json (128b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: autoskill\npreamble-tier: 2\nversion: 1.1.0\nauthor: Science-Prof-Robot\nhomepage: https://github.com/Science-Prof-Robot/autoskill\nlicense: MIT\ndescription: |\n  Intelligent skill router. Analyzes the current problem statement and context,\n  scores all available skills for applicability, and automatically invokes the\n  most relevant ones in priority order.\n\n  Use when you want Claude to automatically identify and apply the right skills\n  without manually choosing them. Great for complex tasks where the right set\n  of skills is non-obvious.\n\n  Invocation:\n    /autoskill [problem description]\n    /autoskill (uses current conversation context if no args given)\n\n  Examples:\n    /autoskill fix the login bug that crashes on empty password\n    /autoskill add unit tests for the payment module\n    /autoskill review my PR before I merge\n    /autoskill (running with no args analyzes the current conversation)\nallowed-tools:\n  - Bash\n  - Read\n  - Glob\n  - Grep\n  - AskUserQuestion\n  - Skill\n---\n\n## Preamble (run first)\n\nThe commands below inspect local git state and detect the project language from\nconfig files. They do not modify anything, send data externally, or run project\ncode. They are safe to run in any local workspace.\n\n```bash\n_BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo \"no-git\")\necho \"BRANCH: $_BRANCH\"\n_LANG_SIGNALS=\"\"\n[ -f package.json ] && _LANG_SIGNALS=\"$_LANG_SIGNALS typescript,javascript\"\n[ -f requirements.txt ] || [ -f pyproject.toml ] || [ -f setup.py ] && _LANG_SIGNALS=\"$_LANG_SIGNALS python\"\n[ -f Cargo.toml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS rust\"\n[ -f go.mod ] && _LANG_SIGNALS=\"$_LANG_SIGNALS go\"\n[ -f pom.xml ] || [ -f build.gradle ] && _LANG_SIGNALS=\"$_LANG_SIGNALS java\"\n[ -f pubspec.yaml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS dart,flutter\"\nls *.csproj 2>/dev/null | head -1 | grep -q . && _LANG_SIGNALS=\"$_LANG_SIGNALS csharp\"\necho \"LANG_SIGNALS:${_LANG_SIGNALS:-unknown}\"\n_GIT_CHANGES=$(git status --short 2>/dev/null | head -20 || echo \"\")\necho \"GIT_CHANGES: $(echo \"$_GIT_CHANGES\" | wc -l | tr -d ' ') files\"\necho \"CHANGED_EXTS: $(echo \"$_GIT_CHANGES\" | grep -oE '\\.[a-zA-Z]+$' | sort -u | tr '\\n' ',' 2>/dev/null || echo 'none')\"\n```\n\n## High-Risk Skill Registry\n\nThe following skills perform irreversible or externally-visible actions (deploys,\npayments, account changes, external messages, data mutations). They are **always\ntreated as SUGGEST-tier regardless of their score** — they will never auto-apply\nand always require explicit user confirmation before running.\n\n```\nHIGH_RISK_SKILLS = [\n  # Deployment / release\n  ship, land-and-deploy, canary, deploy, setup-deploy, prp-pr,\n\n  # Payment / billing\n  customer-billing-ops, finance-billing-ops, agent-payment-x402,\n\n  # Data mutations\n  database-migrations,\n\n  # External communications\n  github-ops, x-api, email-ops, messages-ops, unified-notifications-ops,\n\n  # Account / enterprise operations\n  enterprise-agent-ops, investor-outreach,\n]\n```\n\nWhen scoring (Phase 3), check each candidate against this list. If it matches,\nforce its tier to SUGGEST and add a `[HIGH-RISK]` label in the scoring table,\nregardless of its numeric score.\n\n## Phase 1 — Problem Extraction\n\n**Goal:** Build a structured context profile from the arguments and project state.\n\n**Input:** `$ARGUMENTS` — the user's problem description. If empty, synthesize from the current conversation: look at the most recent user messages, any error output, open files, or recent tool calls visible in context.\n\n**Build the context profile by answering these questions:**\n\n1. **Problem statement** — What is the user trying to accomplish? (1-2 sentences, concrete)\n2. **Action intent** — What category of work is this?\n   - `create` — building something new (feature, file, component, test)\n   - `fix` — repairing broken behavior (bug, error, crash, regression)\n   - `review` — evaluating quality (code review, security audit, PR check)\n   - `deploy` — shipping or releasing (push, merge, publish, CI)\n   - `document` — writing or updating docs\n   - `refactor` — improving structure without changing behavior\n   - `test` — adding or improving test coverage\n   - `analyze` — understanding or investigating something\n   - `design` — UI/UX or architecture planning\n   - `optimize` — improving performance\n3. **Language/stack** — From the preamble `LANG_SIGNALS` and `CHANGED_EXTS`\n4. **Domain tags** — Select all that apply from: `frontend`, `backend`, `database`, `security`, `testing`, `deployment`, `performance`, `documentation`, `architecture`, `mobile`, `api`, `infrastructure`, `data`\n5. **Keywords** — Extract 5-10 specific nouns and verbs from the problem statement (e.g., \"authentication\", \"token\", \"crash\", \"refactor\", \"test coverage\")\n\nPrint the context profile in this format before proceeding:\n```\nCONTEXT PROFILE\n───────────────\nProblem:  [1-2 sentences]\nIntent:   [action intent]\nStack:    [languages/frameworks]\nDomains:  [comma-separated domain tags]\nKeywords: [comma-separated keywords]\n```\n\n## Phase 2 — Skill Inventory Scan\n\n**Goal:** Build a candidate list from the available skills.\n\nThe full skill list is already loaded in your context (from the system-reminder's \"The following skills are available\" section). You do NOT need to read files — use the in-context list directly.\n\n**Steps:**\n\n1. From the system-reminder skill list, extract every skill's name and description.\n\n2. Group skills by domain bucket:\n\n| Bucket | Skill name patterns to look for |\n|--------|--------------------------------|\n| `testing` | tdd, test, pytest, jest, coverage, e2e, playwright, spec |\n| `security` | security, auth, vulnerability, owasp, bounty, pentest |\n| `code-quality` | review, lint, simplify, refactor, clean, style, standards |\n| `deployment` | ship, deploy, land, canary, pm2, docker, ci, cd |\n| `frontend` | frontend, ui, design, figma, css, react, vue, html, animation |\n| `backend` | backend, api, rest, graphql, server, express, fastapi, spring |\n| `database` | database, sql, postgres, clickhouse, migration, schema |\n| `documentation` | docs, readme, update-docs, codemaps, openapi |\n| `planning` | plan, autoplan, blueprint, office-hours, architect, prp |\n| `performance` | performance, optimize, bundle, lighthouse, profil |\n| `infrastructure` | kubernetes, terraform, aws, cloud, gstack, mcp |\n| `mobile` | flutter, android, ios, kotlin, swift, react-native |\n| `meta` | checkpoint, learn, memory, session, instinct, hookify |\n\n3. Build a flat candidate list: every skill that appears in at least one domain bucket relevant to the context profile's `Domain tags`.\n\nPrint the candidate count: `Found N candidate skills in relevant buckets.`\n\n## Phase 3 — Relevance Scoring\n\n**Goal:** Score every candidate skill and decide what to apply, suggest, or skip.\n\nFor each candidate skill, score 0–100 using this rubric:\n\n| Criterion | Weight | How to evaluate |\n|-----------|--------|-----------------|\n| **Intent match** | 35% | Does the skill's purpose directly match the context profile's `action intent`? Exact match = 35, close match = 20, weak match = 10, no match = 0 |\n| **Domain match** | 30% | How many of the context profile's `domain tags` appear in this skill's description or bucket? Each match adds ~10 points up to 30 |\n| **Keyword overlap** | 20% | How many of the context profile's `keywords` appear (roughly) in the skill name or description? Each match adds ~4 points up to 20 |\n| **Stack match** | 15% | Does the skill explicitly target the detected language/framework? Match = 15, stack-agnostic = 10, mismatch = 0 |\n\n**Thresholds:**\n- **≥ 70** → Auto-apply (includes in the execution queue without asking)\n- **40–69** → Suggest (present to user in a batch question)\n- **< 40** → Skip silently\n\n**High-risk override:** If a skill appears in the HIGH_RISK_SKILLS registry above,\nforce it to SUGGEST tier and mark it `[HIGH-RISK]` in the table, regardless of score.\n\n**Constraint: max 5 auto-apply skills per invocation.** If more than 5 score ≥70, take the top 5 by score.\n\nPrint the scoring table (show only skills scoring ≥ 30):\n\n```\nSKILL SCORING\n─────────────────────────────────────────────────────────────────\nSkill                  Score  Tier             Reason\n─────────────────────── ─────  ──────────────   ─────────────────────\ntdd-workflow           88     AUTO-APPLY       intent=create, domain=testing, keyword=test\nsecurity-review        82     AUTO-APPLY       intent=fix, domain=security, keyword=auth\ntypescript-reviewer    75     AUTO-APPLY       stack=typescript, domain=code-quality\ncode-review            72     AUTO-APPLY       intent=review match\ndatabase-reviewer      55     SUGGEST          domain=database, weak intent match\nship                   71     SUGGEST [HIGH-RISK]  score≥70 but forced to SUGGEST — deployment skill\nseo                    8      SKIP             no frontend/content signals\n─────────────────────────────────────────────────────────────────\nAUTO-APPLY: N skills | SUGGEST: M skills (K high-risk) | SKIP: K skills\n```\n\n## Phase 4 — Execution Preview and User Confirmation\n\n**This phase always runs before any skill is invoked**, even if there are no SUGGEST-tier skills.\n\n### Step 4a — Show the execution plan\n\nPrint the full proposed run as a preview. Do not invoke anything yet:\n\n```\nEXECUTION PLAN\n──────────────────────────────────────────────────\n #  Skill                Tier        Score  Why\n──  ─────────────────── ──────────  ─────  ─────────────────────────\n 1  security-review      AUTO        88     fix intent + security domain\n 2  investigate          AUTO        82     fix intent + keyword=crash\n 3  typescript-reviewer  AUTO        75     stack=typescript\n 4  code-review          AUTO        72     review intent match\n 5  ship                 HIGH-RISK   71     deployment — requires confirmation\n──────────────────────────────────────────────────\n```\n\n### Step 4b — Confirmation gate\n\n**If the plan contains only 1 AUTO-APPLY skill and no SUGGEST or HIGH-RISK skills:**\nSkip the confirmation question and proceed directly to Phase 5.\n\n**In all other cases**, use **AskUserQuestion** with this format:\n\n> **autoskill is ready to run [N] skills.**\n>\n> Auto-applying: [list — these will run without further prompts]\n> Needs your approval:\n> - `skill-name` [SUGGEST] — [reason it might apply]\n> - `skill-name` [HIGH-RISK] — [why it needs confirmation]\n>\n> Which of the suggested/high-risk skills do you want to include?\n> (Select any, \"all\", or \"none\" — auto-apply skills will run regardless)\n\nAdd any user-selected skills to the execution queue before continuing.\n\n## Phase 5 — Skill Execution\n\n**Goal:** Apply each queued skill in order.\n\n**Execution order:**\n1. AUTO-APPLY skills sorted by score descending\n2. User-approved SUGGEST / HIGH-RISK skills appended at the end\n\n**For each skill in the queue:**\n\n1. Print: `→ Applying \\`[skill-name]\\` (score: [N]) — [one-line reason]`\n2. Invoke: `Skill(skill=\"[skill-name]\", args=\"[relevant portion of the original problem statement]\")`\n3. Wait for the skill to complete before starting the next one\n4. Note the outcome (completed / blocked / needs-context)\n\n**If a skill returns BLOCKED or NEEDS_CONTEXT:** note it in the audit table and continue to the next skill. Do not abort the entire queue for one blocked skill.\n\n**If NO skills score ≥40:**\n\nDo not silently do nothing. Instead use AskUserQuestion:\n\n> No skills scored above the applicability threshold for: \"[problem statement]\"\n>\n> This usually means the request is best handled directly (not via a specialized skill),\n> or the problem description needs more context.\n>\n> Options:\n> A) Let me handle this directly without a skill\n> B) Tell me more about what you need (I'll re-score)\n> C) Show me all available skills so I can pick manually\n\n## Phase 6 — Decision Audit Report\n\nAfter all skills have run (or been skipped), print the final report:\n\n```markdown\n## autoskill Run Complete\n\n**Problem:** [problem statement]\n**Intent:** [action intent] | **Stack:** [stack] | **Domains:** [domains]\n\n| Skill | Score | Tier | Applied | Outcome | Reason |\n|-------|-------|------|---------|---------|--------|\n| tdd-workflow | 88 | AUTO | ✅ | completed | create intent + testing domain |\n| security-review | 82 | AUTO | ✅ | completed | fix intent + security domain |\n| ship | 71 | HIGH-RISK | ⏸ User | skipped | user declined |\n| database-reviewer | 55 | SUGGEST | ⏸ User | completed | user approved |\n| seo | 8 | SKIP | ❌ | — | no frontend signals |\n\n**Summary:** [N] skills applied, [M] skipped, [K] blocked.\n```\n\n## Completion Status Protocol\n\nReport final status as one of:\n- **DONE** — All queued skills completed successfully\n- **DONE_WITH_CONCERNS** — Completed, but one or more skills returned BLOCKED or NEEDS_CONTEXT\n- **BLOCKED** — Could not determine applicable skills or all skills failed\n- **NEEDS_CONTEXT** — Problem statement too vague to score skills reliably\n\n## Design Constraints\n\n- **Never bulk-read skill files.** The system-reminder list is sufficient for scoring. Only read a specific SKILL.md file if you need to understand invocation details for an edge case.\n- **Never hardcode skill assumptions.** Always derive the candidate list from the live system-reminder. New skills added to the system are automatically included.\n- **High-risk skills always require confirmation.** Skills that deploy, send messages, modify data, or charge accounts are never auto-applied — they are always presented for explicit user approval.\n- **Show the plan before executing.** The execution preview in Phase 4 ensures the user always sees what will run before any skill is invoked (except for single-skill low-risk runs).\n- **Graceful degradation.** If the Skill tool is unavailable, print the scored table and explain which skills the user should invoke manually.\n- **Max 5 auto-applied skills.** Prevents runaway chaining on broad problem statements.\n- **Sequential execution.** Skills run one at a time, in score order. Never parallel — each skill may change project state that the next skill depends on.\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn77vxcwht8y7b07j822fsk0a985da95\",\n  \"slug\": \"autoskill\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1778336653201\n}\n\nArchive v1.0.1: 3 files, 5877 bytes\n\nFiles: install.sh (1119b), SKILL.md (11545b), _meta.json (128b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: autoskill\npreamble-tier: 2\nversion: 1.0.0\ndescription: |\n  Intelligent skill router. Analyzes the current problem statement and context,\n  scores all available skills for applicability, and automatically invokes the\n  most relevant ones in priority order.\n\n  Use when you want Claude to automatically identify and apply the right skills\n  without manually choosing them. Great for complex tasks where the right set\n  of skills is non-obvious.\n\n  Invocation:\n    /autoskill [problem description]\n    /autoskill (uses current conversation context if no args given)\n\n  Examples:\n    /autoskill fix the login bug that crashes on empty password\n    /autoskill add unit tests for the payment module\n    /autoskill review my PR before I merge\n    /autoskill (running with no args analyzes the current conversation)\nallowed-tools:\n  - Bash\n  - Read\n  - Glob\n  - Grep\n  - AskUserQuestion\n  - Skill\n---\n\n## Preamble (run first)\n\n```bash\n_BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo \"no-git\")\necho \"BRANCH: $_BRANCH\"\n_LANG_SIGNALS=\"\"\n[ -f package.json ] && _LANG_SIGNALS=\"$_LANG_SIGNALS typescript,javascript\"\n[ -f requirements.txt ] || [ -f pyproject.toml ] || [ -f setup.py ] && _LANG_SIGNALS=\"$_LANG_SIGNALS python\"\n[ -f Cargo.toml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS rust\"\n[ -f go.mod ] && _LANG_SIGNALS=\"$_LANG_SIGNALS go\"\n[ -f pom.xml ] || [ -f build.gradle ] && _LANG_SIGNALS=\"$_LANG_SIGNALS java\"\n[ -f pubspec.yaml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS dart,flutter\"\nls *.csproj 2>/dev/null | head -1 | grep -q . && _LANG_SIGNALS=\"$_LANG_SIGNALS csharp\"\necho \"LANG_SIGNALS:${_LANG_SIGNALS:-unknown}\"\n_GIT_CHANGES=$(git status --short 2>/dev/null | head -20 || echo \"\")\necho \"GIT_CHANGES: $(echo \"$_GIT_CHANGES\" | wc -l | tr -d ' ') files\"\necho \"CHANGED_EXTS: $(echo \"$_GIT_CHANGES\" | grep -oE '\\.[a-zA-Z]+$' | sort -u | tr '\\n' ',' 2>/dev/null || echo 'none')\"\n```\n\n## Phase 1 — Problem Extraction\n\n**Goal:** Build a structured context profile from the arguments and project state.\n\n**Input:** `$ARGUMENTS` — the user's problem description. If empty, synthesize from the current conversation: look at the most recent user messages, any error output, open files, or recent tool calls visible in context.\n\n**Build the context profile by answering these questions:**\n\n1. **Problem statement** — What is the user trying to accomplish? (1-2 sentences, concrete)\n2. **Action intent** — What category of work is this?\n   - `create` — building something new (feature, file, component, test)\n   - `fix` — repairing broken behavior (bug, error, crash, regression)\n   - `review` — evaluating quality (code review, security audit, PR check)\n   - `deploy` — shipping or releasing (push, merge, publish, CI)\n   - `document` — writing or updating docs\n   - `refactor` — improving structure without changing behavior\n   - `test` — adding or improving test coverage\n   - `analyze` — understanding or investigating something\n   - `design` — UI/UX or architecture planning\n   - `optimize` — improving performance\n3. **Language/stack** — From the preamble `LANG_SIGNALS` and `CHANGED_EXTS`\n4. **Domain tags** — Select all that apply from: `frontend`, `backend`, `database`, `security`, `testing`, `deployment`, `performance`, `documentation`, `architecture`, `mobile`, `api`, `infrastructure`, `data`\n5. **Keywords** — Extract 5-10 specific nouns and verbs from the problem statement (e.g., \"authentication\", \"token\", \"crash\", \"refactor\", \"test coverage\")\n\nPrint the context profile in this format before proceeding:\n```\nCONTEXT PROFILE\n───────────────\nProblem:  [1-2 sentences]\nIntent:   [action intent]\nStack:    [languages/frameworks]\nDomains:  [comma-separated domain tags]\nKeywords: [comma-separated keywords]\n```\n\n## Phase 2 — Skill Inventory Scan\n\n**Goal:** Build a candidate list from the available skills.\n\nThe full skill list is already loaded in your context (from the system-reminder's \"The following skills are available\" section). You do NOT need to read files — use the in-context list directly.\n\n**Steps:**\n\n1. From the system-reminder skill list, extract every skill's name and description.\n\n2. Group skills by domain bucket:\n\n| Bucket | Skill name patterns to look for |\n|--------|--------------------------------|\n| `testing` | tdd, test, pytest, jest, coverage, e2e, playwright, spec |\n| `security` | security, auth, vulnerability, owasp, bounty, pentest |\n| `code-quality` | review, lint, simplify, refactor, clean, style, standards |\n| `deployment` | ship, deploy, land, canary, pm2, docker, ci, cd |\n| `frontend` | frontend, ui, design, figma, css, react, vue, html, animation |\n| `backend` | backend, api, rest, graphql, server, express, fastapi, spring |\n| `database` | database, sql, postgres, clickhouse, migration, schema |\n| `documentation` | docs, readme, update-docs, codemaps, openapi |\n| `planning` | plan, autoplan, blueprint, office-hours, architect, prp |\n| `performance` | performance, optimize, bundle, lighthouse, profil |\n| `infrastructure` | kubernetes, terraform, aws, cloud, gstack, mcp |\n| `mobile` | flutter, android, ios, kotlin, swift, react-native |\n| `meta` | checkpoint, learn, memory, session, instinct, hookify |\n\n3. Build a flat candidate list: every skill that appears in at least one domain bucket relevant to the context profile's `Domain tags`.\n\nPrint the candidate count: `Found N candidate skills in relevant buckets.`\n\n## Phase 3 — Relevance Scoring\n\n**Goal:** Score every candidate skill and decide what to apply, suggest, or skip.\n\nFor each candidate skill, score 0–100 using this rubric:\n\n| Criterion | Weight | How to evaluate |\n|-----------|--------|-----------------|\n| **Intent match** | 35% | Does the skill's purpose directly match the context profile's `action intent`? Exact match = 35, close match = 20, weak match = 10, no match = 0 |\n| **Domain match** | 30% | How many of the context profile's `domain tags` appear in this skill's description or bucket? Each match adds ~10 points up to 30 |\n| **Keyword overlap** | 20% | How many of the context profile's `keywords` appear (roughly) in the skill name or description? Each match adds ~4 points up to 20 |\n| **Stack match** | 15% | Does the skill explicitly target the detected language/framework? Match = 15, stack-agnostic = 10, mismatch = 0 |\n\n**Thresholds:**\n- **≥ 70** → Auto-apply (includes in the execution queue without asking)\n- **40–69** → Suggest (present to user in a batch question)\n- **< 40** → Skip silently\n\n**Constraint: max 5 auto-apply skills per invocation.** If more than 5 score ≥70, take the top 5 by score.\n\nPrint the scoring table (show only skills scoring ≥ 30):\n\n```\nSKILL SCORING\n─────────────────────────────────────────────────────────────────\nSkill                  Score  Tier        Reason\n─────────────────────── ─────  ──────────  ─────────────────────\ntdd-workflow           88     AUTO-APPLY  intent=create, domain=testing, keyword=test\nsecurity-review        82     AUTO-APPLY  intent=fix, domain=security, keyword=auth\ntypescript-reviewer    75     AUTO-APPLY  stack=typescript, domain=code-quality\ncode-review            72     AUTO-APPLY  intent=review match\ndatabase-reviewer      55     SUGGEST     domain=database, weak intent match\n...\nseo                    8      SKIP        no frontend/content signals\n─────────────────────────────────────────────────────────────────\nAUTO-APPLY: N skills | SUGGEST: M skills | SKIP: K skills\n```\n\n## Phase 4 — User Confirmation (for SUGGEST tier only)\n\nIf there are any SUGGEST-tier skills (score 40–69):\n\nUse **AskUserQuestion** with this format:\n\n> **autoskill found [N] skills to auto-apply and [M] to suggest.**\n>\n> Auto-applying (score ≥70): [list]\n>\n> Also applicable (score 40–69) — want any of these?\n> - `skill-name` — [one-line reason it might apply]\n> - `skill-name` — [one-line reason it might apply]\n>\n> Which would you like to add to the run? (Enter names, \"all\", or \"none\")\n\nIf there are NO suggest-tier skills, skip this step and proceed directly to Phase 5.\n\nAdd any user-selected skills to the execution queue before continuing.\n\n## Phase 5 — Skill Execution\n\n**Goal:** Apply each queued skill in order.\n\n**Execution order:**\n1. Sort auto-apply skills by score descending\n2. User-selected suggest-tier skills append at the end\n\n**For each skill in the queue:**\n\n1. Print: `→ Applying \\`[skill-name]\\` (score: [N]) — [one-line reason]`\n2. Invoke: `Skill(skill=\"[skill-name]\", args=\"[relevant portion of the original problem statement]\")`\n3. Wait for the skill to complete before starting the next one\n4. Note the outcome (completed / blocked / needs-context)\n\n**If a skill returns BLOCKED or NEEDS_CONTEXT:** note it in the audit table and continue to the next skill. Do not abort the entire queue for one blocked skill.\n\n**If NO skills score ≥40:**\n\nDo not silently do nothing. Instead use AskUserQuestion:\n\n> No skills scored above the applicability threshold for: \"[problem statement]\"\n>\n> This usually means the request is best handled directly (not via a specialized skill),\n> or the problem description needs more context.\n>\n> Options:\n> A) Let me handle this directly without a skill\n> B) Tell me more about what you need (I'll re-score)\n> C) Show me all available skills so I can pick manually\n\n## Phase 6 — Decision Audit Report\n\nAfter all skills have run (or been skipped), print the final report:\n\n```markdown\n## autoskill Run Complete\n\n**Problem:** [problem statement]\n**Intent:** [action intent] | **Stack:** [stack] | **Domains:** [domains]\n\n| Skill | Score | Applied | Outcome | Reason |\n|-------|-------|---------|---------|--------|\n| tdd-workflow | 88 | ✅ Auto | completed | create intent + testing domain |\n| security-review | 82 | ✅ Auto | completed | fix intent + security domain |\n| database-reviewer | 55 | ⏸ User | completed | user added from suggest list |\n| seo | 8 | ❌ Skip | — | no frontend signals |\n\n**Summary:** [N] skills applied, [M] skipped, [K] blocked.\n```\n\n## Completion Status Protocol\n\nReport final status as one of:\n- **DONE** — All queued skills completed successfully\n- **DONE_WITH_CONCERNS** — Completed, but one or more skills returned BLOCKED or NEEDS_CONTEXT\n- **BLOCKED** — Could not determine applicable skills or all skills failed\n- **NEEDS_CONTEXT** — Problem statement too vague to score skills reliably\n\n## Design Constraints\n\n- **Never bulk-read skill files.** The system-reminder list is sufficient for scoring. Only read a specific SKILL.md file if you need to understand invocation details for an edge case.\n- **Never hardcode skill assumptions.** Always derive the candidate list from the live system-reminder. New skills added to the system are automatically included.\n- **Graceful degradation.** If the Skill tool is unavailable, print the scored table and explain which skills the user should invoke manually.\n- **Max 5 auto-applied skills.** Prevents runaway chaining on broad problem statements.\n- **Sequential execution.** Skills run one at a time, in score order. Never parallel — each skill may change project state that the next skill depends on.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn77vxcwht8y7b07j822fsk0a985da95\",\n  \"slug\": \"autoskill\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778335722573\n}\n\nArchive v1.0.0: 3 files, 5877 bytes\n\nFiles: install.sh (1119b), SKILL.md (11545b), _meta.json (128b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: autoskill\npreamble-tier: 2\nversion: 1.0.0\ndescription: |\n  Intelligent skill router. Analyzes the current problem statement and context,\n  scores all available skills for applicability, and automatically invokes the\n  most relevant ones in priority order.\n\n  Use when you want Claude to automatically identify and apply the right skills\n  without manually choosing them. Great for complex tasks where the right set\n  of skills is non-obvious.\n\n  Invocation:\n    /autoskill [problem description]\n    /autoskill (uses current conversation context if no args given)\n\n  Examples:\n    /autoskill fix the login bug that crashes on empty password\n    /autoskill add unit tests for the payment module\n    /autoskill review my PR before I merge\n    /autoskill (running with no args analyzes the current conversation)\nallowed-tools:\n  - Bash\n  - Read\n  - Glob\n  - Grep\n  - AskUserQuestion\n  - Skill\n---\n\n## Preamble (run first)\n\n```bash\n_BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo \"no-git\")\necho \"BRANCH: $_BRANCH\"\n_LANG_SIGNALS=\"\"\n[ -f package.json ] && _LANG_SIGNALS=\"$_LANG_SIGNALS typescript,javascript\"\n[ -f requirements.txt ] || [ -f pyproject.toml ] || [ -f setup.py ] && _LANG_SIGNALS=\"$_LANG_SIGNALS python\"\n[ -f Cargo.toml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS rust\"\n[ -f go.mod ] && _LANG_SIGNALS=\"$_LANG_SIGNALS go\"\n[ -f pom.xml ] || [ -f build.gradle ] && _LANG_SIGNALS=\"$_LANG_SIGNALS java\"\n[ -f pubspec.yaml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS dart,flutter\"\nls *.csproj 2>/dev/null | head -1 | grep -q . && _LANG_SIGNALS=\"$_LANG_SIGNALS csharp\"\necho \"LANG_SIGNALS:${_LANG_SIGNALS:-unknown}\"\n_GIT_CHANGES=$(git status --short 2>/dev/null | head -20 || echo \"\")\necho \"GIT_CHANGES: $(echo \"$_GIT_CHANGES\" | wc -l | tr -d ' ') files\"\necho \"CHANGED_EXTS: $(echo \"$_GIT_CHANGES\" | grep -oE '\\.[a-zA-Z]+$' | sort -u | tr '\\n' ',' 2>/dev/null || echo 'none')\"\n```\n\n## Phase 1 — Problem Extraction\n\n**Goal:** Build a structured context profile from the arguments and project state.\n\n**Input:** `$ARGUMENTS` — the user's problem description. If empty, synthesize from the current conversation: look at the most recent user messages, any error output, open files, or recent tool calls visible in context.\n\n**Build the context profile by answering these questions:**\n\n1. **Problem statement** — What is the user trying to accomplish? (1-2 sentences, concrete)\n2. **Action intent** — What category of work is this?\n   - `create` — building something new (feature, file, component, test)\n   - `fix` — repairing broken behavior (bug, error, crash, regression)\n   - `review` — evaluating quality (code review, security audit, PR check)\n   - `deploy` — shipping or releasing (push, merge, publish, CI)\n   - `document` — writing or updating docs\n   - `refactor` — improving structure without changing behavior\n   - `test` — adding or improving test coverage\n   - `analyze` — understanding or investigating something\n   - `design` — UI/UX or architecture planning\n   - `optimize` — improving performance\n3. **Language/stack** — From the preamble `LANG_SIGNALS` and `CHANGED_EXTS`\n4. **Domain tags** — Select all that apply from: `frontend`, `backend`, `database`, `security`, `testing`, `deployment`, `performance`, `documentation`, `architecture`, `mobile`, `api`, `infrastructure`, `data`\n5. **Keywords** — Extract 5-10 specific nouns and verbs from the problem statement (e.g., \"authentication\", \"token\", \"crash\", \"refactor\", \"test coverage\")\n\nPrint the context profile in this format before proceeding:\n```\nCONTEXT PROFILE\n───────────────\nProblem:  [1-2 sentences]\nIntent:   [action intent]\nStack:    [languages/frameworks]\nDomains:  [comma-separated domain tags]\nKeywords: [comma-separated keywords]\n```\n\n## Phase 2 — Skill Inventory Scan\n\n**Goal:** Build a candidate list from the available skills.\n\nThe full skill list is already loaded in your context (from the system-reminder's \"The following skills are available\" section). You do NOT need to read files — use the in-context list directly.\n\n**Steps:**\n\n1. From the system-reminder skill list, extract every skill's name and description.\n\n2. Group skills by domain bucket:\n\n| Bucket | Skill name patterns to look for |\n|--------|--------------------------------|\n| `testing` | tdd, test, pytest, jest, coverage, e2e, playwright, spec |\n| `security` | security, auth, vulnerability, owasp, bounty, pentest |\n| `code-quality` | review, lint, simplify, refactor, clean, style, standards |\n| `deployment` | ship, deploy, land, canary, pm2, docker, ci, cd |\n| `frontend` | frontend, ui, design, figma, css, react, vue, html, animation |\n| `backend` | backend, api, rest, graphql, server, express, fastapi, spring |\n| `database` | database, sql, postgres, clickhouse, migration, schema |\n| `documentation` | docs, readme, update-docs, codemaps, openapi |\n| `planning` | plan, autoplan, blueprint, office-hours, architect, prp |\n| `performance` | performance, optimize, bundle, lighthouse, profil |\n| `infrastructure` | kubernetes, terraform, aws, cloud, gstack, mcp |\n| `mobile` | flutter, android, ios, kotlin, swift, react-native |\n| `meta` | checkpoint, learn, memory, session, instinct, hookify |\n\n3. Build a flat candidate list: every skill that appears in at least one domain bucket relevant to the context profile's `Domain tags`.\n\nPrint the candidate count: `Found N candidate skills in relevant buckets.`\n\n## Phase 3 — Relevance Scoring\n\n**Goal:** Score every candidate skill and decide what to apply, suggest, or skip.\n\nFor each candidate skill, score 0–100 using this rubric:\n\n| Criterion | Weight | How to evaluate |\n|-----------|--------|-----------------|\n| **Intent match** | 35% | Does the skill's purpose directly match the context profile's `action intent`? Exact match = 35, close match = 20, weak match = 10, no match = 0 |\n| **Domain match** | 30% | How many of the context profile's `domain tags` appear in this skill's description or bucket? Each match adds ~10 points up to 30 |\n| **Keyword overlap** | 20% | How many of the context profile's `keywords` appear (roughly) in the skill name or description? Each match adds ~4 points up to 20 |\n| **Stack match** | 15% | Does the skill explicitly target the detected language/framework? Match = 15, stack-agnostic = 10, mismatch = 0 |\n\n**Thresholds:**\n- **≥ 70** → Auto-apply (includes in the execution queue without asking)\n- **40–69** → Suggest (present to user in a batch question)\n- **< 40** → Skip silently\n\n**Constraint: max 5 auto-apply skills per invocation.** If more than 5 score ≥70, take the top 5 by score.\n\nPrint the scoring table (show only skills scoring ≥ 30):\n\n```\nSKILL SCORING\n─────────────────────────────────────────────────────────────────\nSkill                  Score  Tier        Reason\n─────────────────────── ─────  ──────────  ─────────────────────\ntdd-workflow           88     AUTO-APPLY  intent=create, domain=testing, keyword=test\nsecurity-review        82     AUTO-APPLY  intent=fix, domain=security, keyword=auth\ntypescript-reviewer    75     AUTO-APPLY  stack=typescript, domain=code-quality\ncode-review            72     AUTO-APPLY  intent=review match\ndatabase-reviewer      55     SUGGEST     domain=database, weak intent match\n...\nseo                    8      SKIP        no frontend/content signals\n─────────────────────────────────────────────────────────────────\nAUTO-APPLY: N skills | SUGGEST: M skills | SKIP: K skills\n```\n\n## Phase 4 — User Confirmation (for SUGGEST tier only)\n\nIf there are any SUGGEST-tier skills (score 40–69):\n\nUse **AskUserQuestion** with this format:\n\n> **autoskill found [N] skills to auto-apply and [M] to suggest.**\n>\n> Auto-applying (score ≥70): [list]\n>\n> Also applicable (score 40–69) — want any of these?\n> - `skill-name` — [one-line reason it might apply]\n> - `skill-name` — [one-line reason it might apply]\n>\n> Which would you like to add to the run? (Enter names, \"all\", or \"none\")\n\nIf there are NO suggest-tier skills, skip this step and proceed directly to Phase 5.\n\nAdd any user-selected skills to the execution queue before continuing.\n\n## Phase 5 — Skill Execution\n\n**Goal:** Apply each queued skill in order.\n\n**Execution order:**\n1. Sort auto-apply skills by score descending\n2. User-selected suggest-tier skills append at the end\n\n**For each skill in the queue:**\n\n1. Print: `→ Applying \\`[skill-name]\\` (score: [N]) — [one-line reason]`\n2. Invoke: `Skill(skill=\"[skill-name]\", args=\"[relevant portion of the original problem statement]\")`\n3. Wait for the skill to complete before starting the next one\n4. Note the outcome (completed / blocked / needs-context)\n\n**If a skill returns BLOCKED or NEEDS_CONTEXT:** note it in the audit table and continue to the next skill. Do not abort the entire queue for one blocked skill.\n\n**If NO skills score ≥40:**\n\nDo not silently do nothing. Instead use AskUserQuestion:\n\n> No skills scored above the applicability threshold for: \"[problem statement]\"\n>\n> This usually means the request is best handled directly (not via a specialized skill),\n> or the problem description needs more context.\n>\n> Options:\n> A) Let me handle this directly without a skill\n> B) Tell me more about what you need (I'll re-score)\n> C) Show me all available skills so I can pick manually\n\n## Phase 6 — Decision Audit Report\n\nAfter all skills have run (or been skipped), print the final report:\n\n```markdown\n## autoskill Run Complete\n\n**Problem:** [problem statement]\n**Intent:** [action intent] | **Stack:** [stack] | **Domains:** [domains]\n\n| Skill | Score | Applied | Outcome | Reason |\n|-------|-------|---------|---------|--------|\n| tdd-workflow | 88 | ✅ Auto | completed | create intent + testing domain |\n| security-review | 82 | ✅ Auto | completed | fix intent + security domain |\n| database-reviewer | 55 | ⏸ User | completed | user added from suggest list |\n| seo | 8 | ❌ Skip | — | no frontend signals |\n\n**Summary:** [N] skills applied, [M] skipped, [K] blocked.\n```\n\n## Completion Status Protocol\n\nReport final status as one of:\n- **DONE** — All queued skills completed successfully\n- **DONE_WITH_CONCERNS** — Completed, but one or more skills returned BLOCKED or NEEDS_CONTEXT\n- **BLOCKED** — Could not determine applicable skills or all skills failed\n- **NEEDS_CONTEXT** — Problem statement too vague to score skills reliably\n\n## Design Constraints\n\n- **Never bulk-read skill files.** The system-reminder list is sufficient for scoring. Only read a specific SKILL.md file if you need to understand invocation details for an edge case.\n- **Never hardcode skill assumptions.** Always derive the candidate list from the live system-reminder. New skills added to the system are automatically included.\n- **Graceful degradation.** If the Skill tool is unavailable, print the scored table and explain which skills the user should invoke manually.\n- **Max 5 auto-applied skills.** Prevents runaway chaining on broad problem statements.\n- **Sequential execution.** Skills run one at a time, in score order. Never parallel — each skill may change project state that the next skill depends on.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn77vxcwht8y7b07j822fsk0a985da95\",\n  \"slug\": \"autoskill\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1778335539488\n}","readmeExcerpt":"Skill: autoskill Owner: science-prof-robot Summary: Intelligent skill router. Analyzes the current problem statement and context, scores all available skills for applicability, and recommends the most relevant... Tags: latest:1.1.1 Version history: v1.1.1 | 2026-05-09T18:11:14.070Z | user ClawScan security review fixes: mandatory confirmation for all runs, expanded high-risk registry, heuristic detection, and removed","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"_BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo \"no-git\")\necho \"BRANCH: $_BRANCH\"\n_LANG_SIGNALS=\"\"\n[ -f package.json ] && _LANG_SIGNALS=\"$_LANG_SIGNALS typescript,javascript\"\n[ -f requirements.txt ] || [ -f pyproject.toml ] || [ -f setup.py ] && _LANG_SIGNALS=\"$_LANG_SIGNALS python\"\n[ -f Cargo.toml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS rust\"\n[ -f go.mod ] && _LANG_SIGNALS=\"$_LANG_SIGNALS go\"\n[ -f pom.xml ] || [ -f build.gradle ] && _LANG_SIGNALS=\"$_LANG_SIGNALS java\"\n[ -f pubspec.yaml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS dart,flutter\"\nls *.csproj 2>/dev/null | head -1 | grep -q . && _LANG_SIGNALS=\"$_LANG_SIGNALS csharp\"\necho \"LANG_SIGNALS:${_LANG_SIGNALS:-unknown}\"\n_GIT_CHANGES=$(git status --short 2>/dev/null | head -20 || echo \"\")\necho \"GIT_CHANGES: $(echo \"$_GIT_CHANGES\" | wc -l | tr -d ' ') files\"\necho \"CHANGED_EXTS: $(echo \"$_GIT_CHANGES\" | grep -oE '\\.[a-zA-Z]+$' | sort -u | tr '\\n' ',' 2>/dev/null || echo 'none')\""},{"language":"text","snippet":"HIGH_RISK_SKILLS = [\n  # Deployment / release / CI\n  ship, land-and-deploy, canary, deploy, setup-deploy, prp-pr, deployment-patterns,\n\n  # Payment / billing / money\n  customer-billing-ops, finance-billing-ops, agent-payment-x402,\n\n  # Database mutations\n  database-migrations,\n\n  # External communications / public posts\n  github-ops, x-api, email-ops, messages-ops, unified-notifications-ops,\n  crosspost, content-writer,\n\n  # Account / enterprise / credential operations\n  enterprise-agent-ops, investor-outreach, cso, security-bounty-hunter,\n\n  # Broad shell / file system access\n  careful, guard, safety-guard,\n]"},{"language":"text","snippet":"CONTEXT PROFILE\n───────────────\nProblem:  [1-2 sentences]\nIntent:   [action intent]\nStack:    [languages/frameworks]\nDomains:  [comma-separated domain tags]\nKeywords: [comma-separated keywords]"},{"language":"text","snippet":"SKILL SCORING\n─────────────────────────────────────────────────────────────────\nSkill                  Score  Tier             Reason\n─────────────────────── ─────  ──────────────   ─────────────────────\ntdd-workflow           88     RECOMMENDED      intent=create, domain=testing, keyword=test\nsecurity-review        82     RECOMMENDED      intent=fix, domain=security, keyword=auth\ntypescript-reviewer    75     RECOMMENDED      stack=typescript, domain=code-quality\ncode-review            72     RECOMMENDED      intent=review match\ndatabase-reviewer      55     SUGGEST          domain=database, weak intent match\nship                   71     SUGGEST [HIGH-RISK]  score≥70 but forced to SUGGEST — deployment skill\nseo                    8      SKIP             no frontend/content signals\n─────────────────────────────────────────────────────────────────\nRECOMMENDED: N skills | SUGGEST: M skills (K high-risk) | SKIP: K skills"},{"language":"text","snippet":"EXECUTION PLAN\n──────────────────────────────────────────────────\n #  Skill                Tier        Score  Why\n──  ─────────────────── ──────────  ─────  ─────────────────────────\n 1  security-review      RECOMMENDED 88     fix intent + security domain\n 2  investigate          RECOMMENDED 82     fix intent + keyword=crash\n 3  typescript-reviewer  RECOMMENDED 75     stack=typescript\n 4  code-review          RECOMMENDED 72     review intent match\n 5  ship                 HIGH-RISK   71     deployment — requires confirmation\n──────────────────────────────────────────────────"},{"language":"markdown","snippet":"## autoskill Run Complete\n\n**Problem:** [problem statement]\n**Intent:** [action intent] | **Stack:** [stack] | **Domains:** [domains]\n\n| Skill | Score | Tier | Applied | Outcome | Reason |\n|-------|-------|------|---------|---------|--------|\n| tdd-workflow | 88 | RECOMMENDED | ✅ | completed | create intent + testing domain |\n| security-review | 82 | RECOMMENDED | ✅ | completed | fix intent + security domain |\n| ship | 71 | HIGH-RISK | ⏸ User | skipped | user declined |\n| database-reviewer | 55 | SUGGEST | ⏸ User | completed | user approved |\n| seo | 8 | SKIP | ❌ | — | no frontend signals |\n\n**Summary:** [N] skills applied, [M] skipped, [K] blocked."}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: autoskill\npreamble-tier: 2\nversion: 1.1.1\nauthor: Science-Prof-Robot\nhomepage: https://github.com/Science-Prof-Robot/autoskill\nlicense: MIT\ndescription: |\n  Intelligent skill router. Analyzes the current problem statement and context,\n  scores all available skills for applicability, and recommends the most relevant\n  ones in priority order. **No skill is ever invoked without your explicit approval.**\n\n  Use when you want Claude to automatically identify and recommend the right\n  skills without manually choosing them. Great for complex tasks where the right set\n  of skills is non-obvious.\n\n  Invocation:\n    /autoskill [problem description]\n    /autoskill (uses current conversation context if no args given)\n\n  Examples:\n    /autoskill fix the login bug that crashes on empty password\n    /autoskill add unit tests for the payment module\n    /autoskill review my PR before I merge\n    /autoskill (running with no args analyzes the current conversation)\nallowed-tools:\n  - Bash\n  - Read\n  - Glob\n  - Grep\n  - AskUserQuestion\n  - Skill\n---\n\n## Preamble (run first)\n\nThe commands below inspect local git state and detect the project language from\nconfig files. They do not modify anything, send data externally, or run project\ncode. They are safe to run in any local workspace.\n\n```bash\n_BRANCH=$(git rev-parse --abbrev-ref HEAD 2>/dev/null || echo \"no-git\")\necho \"BRANCH: $_BRANCH\"\n_LANG_SIGNALS=\"\"\n[ -f package.json ] && _LANG_SIGNALS=\"$_LANG_SIGNALS typescript,javascript\"\n[ -f requirements.txt ] || [ -f pyproject.toml ] || [ -f setup.py ] && _LANG_SIGNALS=\"$_LANG_SIGNALS python\"\n[ -f Cargo.toml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS rust\"\n[ -f go.mod ] && _LANG_SIGNALS=\"$_LANG_SIGNALS go\"\n[ -f pom.xml ] || [ -f build.gradle ] && _LANG_SIGNALS=\"$_LANG_SIGNALS java\"\n[ -f pubspec.yaml ] && _LANG_SIGNALS=\"$_LANG_SIGNALS dart,flutter\"\nls *.csproj 2>/dev/null | head -1 | grep -q . && _LANG_SIGNALS=\"$_LANG_SIGNALS csharp\"\necho \"LANG_SIGNALS:${_LANG_SIGNALS:-unknown}\"\n_GIT_CHANGES=$(git status --short 2>/dev/null | head -20 || echo \"\")\necho \"GIT_CHANGES: $(echo \"$_GIT_CHANGES\" | wc -l | tr -d ' ') files\"\necho \"CHANGED_EXTS: $(echo \"$_GIT_CHANGES\" | grep -oE '\\.[a-zA-Z]+$' | sort -u | tr '\\n' ',' 2>/dev/null || echo 'none')\"\n```\n\n## High-Risk Skill Registry\n\nThe following skills perform irreversible, externally-visible, or broadly-scoped\nactions. They are **always treated as SUGGEST-tier** — they will never be\nrecommended for automatic inclusion and always require individual user\nconfirmation before running.\n\n```\nHIGH_RISK_SKILLS = [\n  # Deployment / release / CI\n  ship, land-and-deploy, canary, deploy, setup-deploy, prp-pr, deployment-patterns,\n\n  # Payment / billing / money\n  customer-billing-ops, finance-billing-ops, agent-payment-x402,\n\n  # Database mutations\n  database-migrations,\n\n  # External communications / public posts\n  github-ops, x-api, email-ops, messages-ops, unified-notifications-ops,\n  crosspost, content-writer,\n\n  # Account / enterprise / credentia"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn77vxcwht8y7b07j822fsk0a985da95\",\n  \"slug\": \"autoskill\",\n  \"version\": \"1.1.1\",\n  \"publishedAt\": 1778350274070\n}"},{"path":"skill-card.md","content":"## Description:\n\nIntelligent skill router that analyzes the current problem statement and context, scores available skills for applicability, and recommends the most relevant ones in priority order.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[science-prof-robot](https://clawhub.ai/user/science-prof-robot)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use Autoskill to identify applicable agent skills for a task, review a scored execution plan, and explicitly approve which skills may run.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Approved downstream skills may perform file, network, or external-service actions outside Autoskill's own behavior.\n\nMitigation: Review the execution plan before approval, decline high-risk skills that are not needed, and cancel when the proposed queue is broader than intended.\n\nRisk: Skill recommendations could route work to an unsuitable or overly broad skill.\n\nMitigation: Use the scored table and mandatory confirmation step to select only the skills that match the task.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/science-prof-robot/skills/autoskill)\n- [Project homepage](https://github.com/Science-Prof-Robot/autoskill)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown with scored recommendations, execution previews, confirmation prompts, and audit tables]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires explicit user confirmation before invoking recommended, suggested, or high-risk downstream skills.]\n\n## Skill Version(s):\n\n1.1.1 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Intelligent skill router. Analyzes the current problem statement and context, scores all available skills for applicability, and recommends the most relevant... Skill: autoskill Owner: science-prof-robot Summary: Intelligent skill router. Analyzes the current problem statement and context, scores all available skills for applicability, and recommends the most relevant... Tags: latest:1.1.1 Version history: v1.1.1 | 2026-05-09T18:11:14.070Z | user ClawScan security review fixes: mandatory confirmation for all runs, expanded high-risk registry, heuristic detection, and removed","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":938,"uniquenessScore":58,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T10:11:35.491Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T10:11:35.491Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:13:16.153Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}