Safety Guard
affaan-m/ECC
Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard…
Expose HybridClaw as a custom Alexa skill and prepare guarded Alexa smart-home/device control payloads without exposing Amazon credentials.
$ npx skills add HybridAIOne/hybridclaw --skill alexa -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install HybridAIOne/hybridclaw alexa --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/alexa .claude/skills/alexa && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "alexa" agent skill from https://github.com/HybridAIOne/hybridclaw/tree/main/skills/alexa into .claude/skills/alexa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alexa", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/HybridAIOne/hybridclaw/tree/main/skills/alexaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add HybridAIOne/hybridclaw --skill alexa -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install HybridAIOne/hybridclaw alexa --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/alexa .agents/skills/alexa && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "alexa" agent skill from https://github.com/HybridAIOne/hybridclaw/tree/main/skills/alexa into .agents/skills/alexa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alexa", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HybridAIOne/hybridclaw --skill alexa -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install HybridAIOne/hybridclaw alexa --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/alexa .cursor/skills/alexa && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "alexa" agent skill from https://github.com/HybridAIOne/hybridclaw/tree/main/skills/alexa into .cursor/skills/alexa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alexa", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/HybridAIOne/hybridclaw.git --path skills/alexa--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add HybridAIOne/hybridclaw --skill alexa -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install HybridAIOne/hybridclaw alexa --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/alexa .gemini/skills/alexa && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "alexa" agent skill from https://github.com/HybridAIOne/hybridclaw/tree/main/skills/alexa into .gemini/skills/alexa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alexa", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install HybridAIOne/hybridclaw alexaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add HybridAIOne/hybridclaw --skill alexa -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/alexa .github/skills/alexa && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "alexa" agent skill from https://github.com/HybridAIOne/hybridclaw/tree/main/skills/alexa into .github/skills/alexa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alexa", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HybridAIOne/hybridclaw --skill alexa -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install HybridAIOne/hybridclaw alexa --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/alexa .opencode/skills/alexa && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "alexa" agent skill from https://github.com/HybridAIOne/hybridclaw/tree/main/skills/alexa into .opencode/skills/alexa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alexa", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
alexaExpose HybridClaw as a custom Alexa skill and prepare guarded Alexa smart-home/device control payloads without exposing Amazon credentials.
Alexa is an agent skill from HybridAIOne/hybridclaw. Expose HybridClaw as a custom Alexa skill and prepare guarded Alexa smart-home/device control payloads without exposing Amazon credentials.
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files.
The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
alexa.amazon.deAlso links to:
developer.amazon.comgithub.comgitlab.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ALEXA_SMARTHOME_ACCESS_TOKENALEXA_LWA_CLIENT_SECRETALEXA_SMARTHOME_CLIENT_SECRETALEXA_SMARTHOME_REFRESH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Alexa loads about 5.4k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 1,476 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 1,476 words, ~5,388 tokens.
.claude/skills/alexa/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Use this skill for Amazon Alexa workflows in two narrow modes:
alexapy surface.Do not use this skill for arbitrary Amazon API calls, shopping account access, or browser automation. Keep all credentials behind SecretRef and use the helper to build bounded payloads instead of hand-writing URLs, headers, cookies, or request bodies.
Signature, invalid SignatureCertChainUrl, signing
certificates that do not cover echo-api.amazon.com, or timestamp drift of
150 seconds or more.build-response so
markdown, code blocks, and very long URLs are stripped before SSML is built.401, 403, or INVALID_AUTHORIZATION_CREDENTIAL
response. Emit or surface event: alexa.relink_required; do not retry-loop.hybridclaw secret set ....Show helper usage:
node skills/alexa/alexa.cjs --helpValidate an inbound ASK request body exactly as received by the HTTPS endpoint:
node skills/alexa/alexa.cjs --format json verify-request \
--request-body /tmp/alexa-request.json \
--signature-cert-url "$SIGNATURE_CERT_CHAIN_URL" \
--signature "$SIGNATURE"Exchange a linked Alexa account token for a HybridClaw operator-session handle outside model-visible output:
node skills/alexa/alexa.cjs --format json account-link-session \
--request-body /tmp/alexa-request.jsonParse a validated ASK request envelope into a bounded agent bridge:
node skills/alexa/alexa.cjs --format json parse-request \
--request-body /tmp/alexa-request.jsonBuild a voice-safe ASK response:
node skills/alexa/alexa.cjs --format json build-response \
--speech "On it. I'll text you when it's done." \
--reprompt "Anything else?"Run Smart Home Skill API calls through the helper:
node skills/alexa/alexa.cjs --format json run smarthome-discover
node skills/alexa/alexa.cjs --format json run smarthome-state \
--endpoint-id light-kitchen
node skills/alexa/alexa.cjs --format json plan smarthome-control \
--endpoint-id light-kitchen \
--action TurnOn
node skills/alexa/alexa.cjs --format json run smarthome-control \
--endpoint-id light-kitchen \
--action TurnOn \
--operator-grant approve-alexa-write
node skills/alexa/alexa.cjs --format json plan smarthome-control \
--endpoint-id thermostat-hallway \
--action SetTargetTemperature \
--temperature 20.5Run community Alexa Remote / alexapy reads through the helper:
node skills/alexa/alexa.cjs --format json run devices \
--amazon-domain amazon.de
node skills/alexa/alexa.cjs --format json run shopping-list
node skills/alexa/alexa.cjs --format json run todo-list
node skills/alexa/alexa.cjs --format json run last-commands
node skills/alexa/alexa.cjs --format json run dnd-state --device living-roomFor Alexa-connected smart plugs/lights exposed through the Alexa app (for
example Poolpumpe), use the smart-home helper commands. Do not use
connectedhomes/v1/appliances; Amazon can return a 200 HTML deeplink page
instead of JSON. The helper resolves the Alexa app device by name, runs the
discovery and status/control calls through the HybridClaw gateway, and returns
the result JSON. This path uses ALEXA_REFRESH_COOKIE; do not ask for
ALEXA_SMARTHOME_ACCESS_TOKEN or Smart Home Skill OAuth when the operator asks
to use the stored Alexa cookie for these Alexa-app appliances. If the helper
reports Unauthenticated call, FORBIDDEN, INVALID_AUTHORIZATION_CREDENTIAL,
or an HTTP 401/403, treat that as an auth failure for the cookie path. A gateway
error saying ALEXA_REFRESH_COOKIE is not set or has no csrf cookie means the
stored cookie is missing or incomplete. Inspect the stored cookie/import path
first; do not immediately start the browser proxy unless the operator
explicitly asks for a new proxy login.
node skills/alexa/alexa.cjs --format json smart-home status \
--name Poolpumpe \
--amazon-domain amazon.de
node skills/alexa/alexa.cjs --format json smart-home plan-control \
--name Poolpumpe \
--action off \
--amazon-domain amazon.de
node skills/alexa/alexa.cjs --format json smart-home control \
--name Poolpumpe \
--action off \
--amazon-domain amazon.de \
--operator-grant approve-alexa-red-writePrepare guarded community writes. First show the approval text to the operator.
After explicit approval, run the exact approvedCommand unchanged.
For Echo music playback, first call run devices, find the matching
accountName (for example OK Computer), then pass its serialNumber,
deviceType, and deviceOwnerCustomerId to music-play.
node skills/alexa/alexa.cjs --format json plan announce \
--device living-room \
--text "Package delivered."
node skills/alexa/alexa.cjs --format json run announce \
--device living-room \
--text "Package delivered." \
--operator-grant approve-alexa-write
node skills/alexa/alexa.cjs --format json plan music-play \
--device "<serialNumber from devices>" \
--device-name "OK Computer" \
--device-type "<deviceType from devices>" \
--customer-id "<deviceOwnerCustomerId from devices>" \
--query "Münchner Freiheit" \
--provider AMAZON_MUSIC \
--amazon-domain amazon.de
For exact song requests, do not concatenate artist and title into `--query`.
Pass the song title and artist separately so the helper can build a
locale-aware Alexa search phrase:
```bash
node skills/alexa/alexa.cjs --format json plan music-play \
--device "<serialNumber from devices>" \
--device-name "OK Computer" \
--device-type "<deviceType from devices>" \
--customer-id "<deviceOwnerCustomerId from devices>" \
--song "Junge Römer" \
--artist "Falco" \
--provider APPLE_MUSIC \
--amazon-domain amazon.denode skills/alexa/alexa.cjs --format json run music-play
--device "<serialNumber from devices>"
--device-name "OK Computer"
--device-type "<deviceType from devices>"
--customer-id "<deviceOwnerCustomerId from devices>"
--query "Münchner Freiheit"
--provider AMAZON_MUSIC
--amazon-domain amazon.de
--operator-grant approve-alexa-write
Use `voice-command` only as a last-resort equivalent of typing/speaking a
command into Alexa, because it can trigger arbitrary Alexa behavior. Prefer
specific helpers such as `music-play`, `announce`, list actions, routines, or
Smart Home directives when they cover the task.
```bash
node skills/alexa/alexa.cjs --format json plan voice-command \
--device "<serialNumber from devices>" \
--device-name "OK Computer" \
--device-type "<deviceType from devices>" \
--customer-id "<deviceOwnerCustomerId from devices>" \
--voice-command "play Münchner Freiheit" \
--amazon-domain amazon.de
node skills/alexa/alexa.cjs --format json run voice-command \
--device "<serialNumber from devices>" \
--device-name "OK Computer" \
--device-type "<deviceType from devices>" \
--customer-id "<deviceOwnerCustomerId from devices>" \
--voice-command "play Münchner Freiheit" \
--amazon-domain amazon.de \
--operator-grant approve-alexa-red-writenode skills/alexa/alexa.cjs --format json run shopping-list-add \
--item milk \
--operator-grant approve-alexa-write
node skills/alexa/alexa.cjs --format json run shopping-list-complete \
--item-id item-123 \
--operator-grant approve-alexa-write
node skills/alexa/alexa.cjs --format json run todo-list-add \
--item "call plumber" \
--operator-grant approve-alexa-write
node skills/alexa/alexa.cjs --format json run todo-list-complete \
--item-id item-456 \
--operator-grant approve-alexa-write
node skills/alexa/alexa.cjs --format json run routine-trigger \
--routine evening \
--operator-grant approve-alexa-writeUse http-request ... only as a debugging dry run when you need to inspect the
gateway-ready request object. For normal reads and writes, use run ... so the
CJS owns endpoint selection, headers, CSRF handling, execution, and result
reporting. When run ... returns ok: true and outcome: "accepted", treat
the operation as accepted even if Alexa's response body is {}. Do not infer
an auth failure from an empty successful response body. For music-play,
accepted only means Alexa accepted the playback request. Do not tell the
operator the requested song is now playing unless the result includes
successful verification or a separate read confirms the selected track.
Set or update required secrets in this order:
/admin/secrets./chat or TUI fallback with /secret set NAME value.hybridclaw secret set NAME value.Path A custom ASK skill local-console examples:
hybridclaw secret set ALEXA_ASK_SKILL_ID "amzn1.ask.skill.<uuid>"
hybridclaw secret set ALEXA_LWA_CLIENT_ID "amzn1.application-oa2-client.<id>"
hybridclaw secret set ALEXA_LWA_CLIENT_SECRET "<lwa client secret>"Path B Smart Home Skill API local-console examples:
hybridclaw secret set ALEXA_SMARTHOME_CLIENT_ID "<smart-home oauth client id>"
hybridclaw secret set ALEXA_SMARTHOME_CLIENT_SECRET "<smart-home oauth client secret>"
hybridclaw secret set ALEXA_SMARTHOME_REFRESH_TOKEN "<refresh token>"Path B community Alexa Remote / alexapy surface local-console example:
hybridclaw secret set ALEXA_AMAZON_DOMAIN "amazon.de"Use HybridClaw or slash commands for operator setup. Do not ask the operator to install or run external auth tools.
Start a local session and invoke the Alexa skill:
hybridclaw tuiThen use these prompts:
/alexa set up Echo control for amazon.de and store the cookie
/alexa list my Alexa devices for amazon.de
/alexa play Münchner Freiheit on OK ComputerFor a CLI-only operator, the same requests can be sent through any HybridClaw channel that supports slash skill invocation:
/skill alexa set up Echo control for amazon.de and store the cookie
/skill alexa list my Alexa devices for amazon.de
/skill alexa play Münchner Freiheit on OK ComputerStatus-only prompts such as /skill alexa status for amazon.de are read-only.
For those prompts, inspect stored credentials and detached setup state, but do
not start a new auth proxy. If credentials are missing, tell the operator to run
the setup prompt explicitly.
When handling the setup prompt, run the bundled auth helper from the agent workspace. First check live detached setup state:
node skills/alexa/alexa-auth.cjs --format json status --domain amazon.deIf that status returns exists: true, processAlive: true, state: "listening", and a proxyUrl, return that exact proxyUrl to the operator
instead of starting another proxy. Ignore recalled URLs, prior slash output, and
session transcript text unless they match the current live status. Never print a
proxy URL that did not come from the current helper output.
For slash handling, use detached mode so the local browser proxy survives while the operator completes Amazon login, OTP, and CVF pages across turns:
node skills/alexa/alexa-auth.cjs setup --domain amazon.de --write-secret --detach --timeout-ms 600000If the operator reports Amazon's "Wir können deine Handynummer nicht
verifizieren" challenge on a 127.0.0.1:<port> proxy URL, do not reuse that
proxy. Stop the stale process if it is still alive, then start a fresh detached
setup on localhost so the browser uses a separate local cookie jar:
node skills/alexa/alexa-auth.cjs setup --domain amazon.de --write-secret --detach --timeout-ms 600000 --proxy-host localhostReturn the proxyUrl from the helper output to the operator. When the operator
comes back after login, check the same setup with:
node skills/alexa/alexa-auth.cjs status --domain amazon.deDo not keep the setup proxy alive with ad hoc shell process management. Detached mode is the supported lifecycle: it writes a status file, keeps the proxy process alive after the slash turn ends, and stores the secret itself after Amazon returns the token.
If invoking non-detached foreground setup through a shell tool, set that tool
timeout to at least 600000 ms too. Browser login, OTP, CAPTCHA, and Safari
handoff regularly take longer than 60 seconds; killing the shell command also
kills the local proxy and produces Safari errors such as "server unexpectedly
closed the connection" on 127.0.0.1:<port>/www.amazon.com/ap/signin.
The bundled helper owns the browser proxy and token callback. It uses Amazon's
device-login domain rules: western marketplaces such as amazon.de must use
amazon.com as the auth proxy base while the target Alexa marketplace remains
amazon.de. Routing the device-login URL through amazon.de produces Amazon's
"Suchst du etwas?" 404 page. If the browser shows that 404 at the local proxy
URL, stop that run and restart through alexa-auth.cjs.
The helper starts Amazon's Alexa device-login flow on a local callback port,
captures the resulting Atnr|... refresh token, exchanges it for Alexa Remote
cookies through Amazon's token exchange endpoint, verifies the account against
the regional Alexa Remote API (layla.amazon.com for amazon.de), stores
ALEXA_REFRESH_COOKIE when requested, and returns device metadata. Re-run the
same slash setup prompt when Amazon expires the stored cookie. Port 8080 is
preferred for compatibility with the cookie helper, but HybridClaw automatically
uses another free local port when 8080 is already occupied.
If using HybridClaw's direct http_request helper path instead of invoking
the browser setup flow, ALEXA_REFRESH_COOKIE must be the complete Cookie
header for an authenticated Alexa Remote API request such as
https://alexa.amazon.de/api/devices-v2/device. A single cookie value such as
session-id or ubid-main is not enough. The gateway sends the stored header
as Cookie and, for writes, copies its csrf cookie into the csrf header, so
the header must include csrf=.... Do not paste Amazon passwords,
one-time codes, or raw tokens into chat; store only the resulting cookie header
through the HybridClaw secret store. The alexa-auth.cjs import-cookie helper
can store a cookie with --write-secret when a local JSON file, copied cURL
request, raw headers file, or raw text file exposes a recognizable full cookie
header. Use this fallback when Amazon's device-login proxy is blocked by CVF
phone verification but the operator can log into Amazon normally in a browser.
Use the community credentials only for operator-approved, opt-in workflows.
Amazon OTP or CAPTCHA prompts require F14 2FA handover. The helper output uses
<secret:...> placeholders and SecretRef names, never cleartext values.
alexapy:
https://gitlab.com/keatontaylor/alexapy© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in skills/alexa of HybridAIOne/hybridclaw.
Open the folder on GitHubat commit 8162701
Alexa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Alexa this skillHybridAIOne/hybridclaw | 159 | — | ~5.4k | Automated safety check: Pass | MIT | |
| Safety Guardaffaan-m/ECC | 276k | 2 repos | ~554 | Automated safety check: Notes | MIT | |
| Guard Modegarrytan/gstack | 136k | — | ~1k | Automated safety check: Notes | MIT | |
| Smart Contract Formal Verificationsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Smart Contract Upgrade Governancesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Audit Preparationsickn33/agentic-awesome-skills | 47k | 1 repos | ~5.3k | Automated safety check: Pass | MIT |
affaan-m/ECC
Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard…
garrytan/gstack
Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.
sickn33/agentic-awesome-skills
Foundry and Soroban formal invariant verification register: state transition rules, boundary invariant properties, and symbolic execution checks.
sickn33/agentic-awesome-skills
Soroban WASM upgrade governance register: executable bytecode hash, timelocked migration delays, and multi-sig authorization quorum.
sickn33/agentic-awesome-skills
Audit preparation register: required document, period covered, request and receipt dates, preparer and reviewer, auditor queries and adjustments.
sickn33/agentic-awesome-skills
Integracao completa com Amazon Alexa para criar skills de voz inteligentes, transformar Alexa em assistente com Claude como cerebro (projeto Auri) e integrar com AWS ecosystem (Lambda, DynamoDB…
HybridAIOne/hybridclaw
Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.
HybridAIOne/hybridclaw
Plan, script, render, and stitch Manim Community Edition videos in Python.
HybridAIOne/hybridclaw
Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.
HybridAIOne/hybridclaw
Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.
HybridAIOne/hybridclaw
Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.
HybridAIOne/hybridclaw
Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.
Expose HybridClaw as a custom Alexa skill and prepare guarded Alexa smart-home/device control payloads without exposing Amazon credentials. Alexa is an agent skill from HybridAIOne/hybridclaw. Expose HybridClaw as a custom Alexa skill and prepare guarded Alexa smart-home/device control payloads without exposing Amazon credentials.
Run `npx skills add HybridAIOne/hybridclaw --skill alexa -a claude-code`. Or copy the skill folder (skills/alexa in HybridAIOne/hybridclaw) into .claude/skills/alexa in your project. Claude Code loads it when a task matches its description.
Run `npx skills add HybridAIOne/hybridclaw --skill alexa -a codex`. Or copy the skill folder (skills/alexa in HybridAIOne/hybridclaw) into .agents/skills/alexa in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill alexa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alexa, .gemini/skills/alexa, .github/skills/alexa and .opencode/skills/alexa in your project.
Going by SKILL.md and its folder, Alexa needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node) and credentials named ALEXA_SMARTHOME_ACCESS_TOKEN, ALEXA_LWA_CLIENT_SECRET, ALEXA_SMARTHOME_CLIENT_SECRET and ALEXA_SMARTHOME_REFRESH_TOKEN. Our summary lists: A credential in ALEXA_LWA_CLIENT_SECRET; A credential in ALEXA_SMARTHOME_REFRESH_TOKEN.
SKILL.md names 4 domains. In commands or code: alexa.amazon.de; the agent is likely to contact it when it follows the instructions. As links in the text: developer.amazon.com, github.com and gitlab.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Alexa is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Alexa: Safety Guard (affaan-m/ECC, 276k stars), Guard Mode (garrytan/gstack, 136k stars), Smart Contract Formal Verification (sickn33/agentic-awesome-skills, 47k stars) and Smart Contract Upgrade Governance (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.
Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.