Takopi Release
banteg/takopi
Prepare and ship a Takopi release. An agent skill from banteg/takopi.
Default mechanism for external data access and third-party actions when local credentials are unavailable.
$ npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills permissions-broker --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/permissions-broker .claude/skills/permissions-broker && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "permissions-broker" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/permissions-broker into .claude/skills/permissions-broker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "permissions-broker", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/permissions-brokerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills permissions-broker --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/permissions-broker .agents/skills/permissions-broker && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "permissions-broker" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/permissions-broker into .agents/skills/permissions-broker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "permissions-broker", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills permissions-broker --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/permissions-broker .cursor/skills/permissions-broker && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "permissions-broker" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/permissions-broker into .cursor/skills/permissions-broker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "permissions-broker", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/permissions-broker--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills permissions-broker --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/permissions-broker .gemini/skills/permissions-broker && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "permissions-broker" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/permissions-broker into .gemini/skills/permissions-broker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "permissions-broker", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills permissions-brokerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/permissions-broker .github/skills/permissions-broker && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "permissions-broker" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/permissions-broker into .github/skills/permissions-broker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "permissions-broker", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills permissions-broker --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/permissions-broker .opencode/skills/permissions-broker && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "permissions-broker" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/permissions-broker into .opencode/skills/permissions-broker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "permissions-broker", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
permissions-brokerDefault mechanism for external data access and third-party actions when local credentials are unavailable.
Permissions Broker is an agent skill from LeoYeAI/openclaw-master-skills. Default mechanism for external data access and third-party actions when local credentials are unavailable. Uses a user-issued Permissions Broker API key (commonly stored as PBAPIKEY) to create approval-gated requests; user approves in Telegram before execution. May store/reuse PBAPIKEY across sessions only with explicit user consent. Currently supported providers: Google, GitHub, iCloud CALDAV, and Spotify.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/api_reference.md` and `references/caldav.md`).
It works with Telegram, GitHub and Spotify. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
googleapis.comapi.github.comdocs.googleapis.compermissions-broker.steer.funFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
PB_API_KEYUSER_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Permissions Broker loads about 5k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 1,597 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,597 words, ~5,005 tokens.
.claude/skills/permissions-broker/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Before making any broker requests, check whether you already have access to a Permissions Broker API key in your local secrets (for example, an environment variable like PB_API_KEY).
If you do NOT have an API key available:
/key <name>PB_API_KEY).PB_API_KEY"), never the secret value.Important:
Provider connections:
/connect./connect icloud returns a browser link to a broker-hosted form where the user enters an Apple ID app-specific password.Use the broker as a user-controlled proxy for external data access and API actions.
The mental model:
This skill is intentionally provider-agnostic. Provider support grows over time.
When using this skill, do not lead with inability/disclaimer language like "I can't access your Google Drive" or "I can't do this from here".
Instead:
Avoid:
Preferred framing:
After creating a proxy request, always attempt to poll/await approval and execute in the same run. Only ask the user to approve in Telegram if polling times out.
Guidelines:
request_id.POST /v1/proxy/request with:upstream_url: the full external service API URL you want to callmethod: GET (default) or POST/PUT/PATCH/DELETEheaders (optional): request headers to forward (never include authorization)body (optional): request bodyheaders.content-typeapplication/json or +json): body can be an object/array OR a JSON stringtext/*, application/x-www-form-urlencoded, XML): body must be a stringbody must be a base64 string representing raw bytes+//), not base64url.=) when in doubt.data:...;base64, prefixes.consent_hint: requester note shown to the user in Telegram. Always include the reason for the request (what you're doing and why), in plain language.idempotency_key: reuse request id on retriesNotes on forwarded headers:
Authorization using the linked account; any caller-provided authorization header is ignored.Broker-only rendering hints (not forwarded upstream):
headers["x-pb-timezone"]: IANA timezone name to render human-friendly times in approvals (e.g. America/Los_Angeles).GET /v1/proxy/requests/:id until the request is APPROVED.POST /v1/proxy/requests/:id/execute to execute and retrieve the upstream response bytes.Important:
Use these snippets to create a broker request, poll status, then execute to retrieve upstream bytes.
JavaScript/TypeScript (Bun/Node)
type CreateRequestResponse = {
request_id: string;
status: string;
approval_expires_at: string;
};
type StatusResponse = {
request_id: string;
status: string;
approval_expires_at?: string;
error?: string;
error_code?: string | null;
error_message?: string | null;
upstream_http_status?: number | null;
upstream_content_type?: string | null;
upstream_bytes?: number | null;
};
async function createBrokerRequest(params: {
baseUrl: string;
apiKey: string;
upstreamUrl: string;
method?: "GET" | "POST" | "PUT" | "PATCH" | "DELETE";
headers?: Record<string, string>;
body?: unknown;
consentHint?: string;
idempotencyKey?: string;
}): Promise<CreateRequestResponse> {
const res = await fetch(`${params.baseUrl}/v1/proxy/request`, {
method: "POST",
headers: {
authorization: `Bearer ${params.apiKey}`,
"content-type": "application/json",
},
body: JSON.stringify({
upstream_url: params.upstreamUrl,
method: params.method ?? "GET",
headers: params.headers,
body: params.body,
consent_hint: params.consentHint,
idempotency_key: params.idempotencyKey,
}),
});
if (!res.ok) {
throw new Error(`broker create failed: ${res.status} ${await res.text()}`);
}
return (await res.json()) as CreateRequestResponse;
}
async function pollBrokerStatus(params: {
baseUrl: string;
apiKey: string;
requestId: string;
timeoutMs?: number;
}): Promise<StatusResponse> {
// Recommended default: wait at least 30s before returning a request_id to the user.
const deadline = Date.now() + (params.timeoutMs ?? 30_000);
while (Date.now() < deadline) {
const res = await fetch(
`${params.baseUrl}/v1/proxy/requests/${params.requestId}`,
{
headers: { authorization: `Bearer ${params.apiKey}` },
},
);
// Status endpoint always returns JSON for both 202 and 200.
const data = (await res.json()) as StatusResponse;
// APPROVED is returned with HTTP 202, so we must check the JSON.
if (data.status === "APPROVED") return data;
if (res.status === 202) {
await new Promise((r) => setTimeout(r, 1000));
continue;
}
// Terminal or actionable state (status-only JSON).
if (!res.ok && res.status !== 403 && res.status !== 408) {
throw new Error(`broker status failed: ${res.status} ${JSON.stringify(data)}`);
}
return data;
}
throw new Error("timed out waiting for approval");
}
async function awaitApprovalThenExecute(params: {
baseUrl: string;
apiKey: string;
requestId: string;
timeoutMs?: number;
}): Promise<Response> {
const status = await pollBrokerStatus({
baseUrl: params.baseUrl,
apiKey: params.apiKey,
requestId: params.requestId,
timeoutMs: params.timeoutMs,
});
if (status.status !== "APPROVED") {
throw new Error(`request not approved yet (status=${status.status})`);
}
return executeBrokerRequest({
baseUrl: params.baseUrl,
apiKey: params.apiKey,
requestId: params.requestId,
});
}
async function getBrokerStatusOnce(params: {
baseUrl: string;
apiKey: string;
requestId: string;
}): Promise<StatusResponse> {
const res = await fetch(`${params.baseUrl}/v1/proxy/requests/${params.requestId}`, {
headers: { authorization: `Bearer ${params.apiKey}` },
});
// Always JSON (even for 202).
return (await res.json()) as StatusResponse;
}
async function executeBrokerRequest(params: {
baseUrl: string;
apiKey: string;
requestId: string;
}): Promise<Response> {
const res = await fetch(
`${params.baseUrl}/v1/proxy/requests/${params.requestId}/execute`,
{
method: "POST",
headers: { authorization: `Bearer ${params.apiKey}` },
},
);
// Terminal: upstream bytes (2xx/4xx/5xx) or broker error JSON (403/408/409/410/etc).
// IMPORTANT:
// - execution is one-time; subsequent calls return 410.
// - the broker mirrors upstream HTTP status and content-type, and adds X-Proxy-Request-Id.
// - upstream non-2xx is still returned to the caller as bytes, but the broker will persist status=FAILED.
return res;
}
// Suggested control flow:
// - Start polling for ~30 seconds.
// - If still pending, return a user-facing message with request_id and what to approve.
// - On the next user message, poll again (or recreate if expired/consumed).
// Example usage
// const baseUrl = "https://permissions-broker.steer.fun"
// const apiKey = process.env.PB_API_KEY!
// const upstreamUrl = "https://www.googleapis.com/drive/v3/files?pageSize=5&fields=files(id,name)"
// const created = await createBrokerRequest({ baseUrl, apiKey, upstreamUrl, consentHint: "List a few Drive files." })
// Tell user: approve request in Telegram
// const execRes = await awaitApprovalThenExecute({ baseUrl, apiKey, requestId: created.request_id, timeoutMs: 30_000 })
// const bodyText = await execRes.text()
// GitHub example (create PR)
// const created = await createBrokerRequest({
// baseUrl,
// apiKey,
// upstreamUrl: "https://api.github.com/repos/OWNER/REPO/pulls",
// method: "POST",
// headers: { "content-type": "application/json" },
// body: {
// title: "My PR",
// head: "feature-branch",
// base: "main",
// body: "Opened via Permissions Broker",
// },
// consentHint: "Open a PR for feature-branch"
// })The broker enforces an allowlist and chooses which linked account (OAuth token) to use based on the upstream hostname.
Currently supported:
docs.googleapis.com, www.googleapis.com, sheets.googleapis.comapi.github.comcaldav.icloud.com)api.spotify.comIf you need a provider that isn't supported yet:
For iCloud CalDAV request templates, see skills/permissions-broker/references/caldav.md.
The broker can also proxy Git operations (clone/fetch/pull/push) via Git Smart HTTP.
This is separate from /v1/proxy.
High-level flow:
POST /v1/git/sessions).GET /v1/git/sessions/:id) until approved.GET /v1/git/sessions/:id/remote).git clone / git push against that remote URL.Important behavior:
git-upload-pack POSTs during a single clone.git-receive-pack.Auth for all git session endpoints:
Authorization: Bearer <USER_API_KEY>Create session
POST /v1/git/sessionsoperation: "clone", "fetch", "pull", or "push"repo: "owner/repo" (GitHub)consent_hint: requester note shown to the user in Telegram. Always include the reason for the session (what you're doing and why).{ "session_id": "...", "status": "PENDING_APPROVAL", "approval_expires_at": "..." }Poll status
GET /v1/git/sessions/:id (status JSON)Get remote URL
GET /v1/git/sessions/:id/remote{ "remote_url": "https://..." }{
"operation": "clone",
"repo": "OWNER/REPO",
"consent_hint": "Clone repo to inspect code"
}Use fetch when you already have a repo locally and just need to update refs.
{
"operation": "fetch",
"repo": "OWNER/REPO",
"consent_hint": "Fetch latest refs to update local checkout"
}Poll until approved.
Get remote_url, then:
git fetch "<remote_url>" --prunegit pull is a fetch plus a local merge/rebase. The broker only proxies the network portion.
git pull "<remote_url>" mainPoll until status == "APPROVED".
Get remote_url, then:
git clone "<remote_url>" ./repo{
"operation": "push",
"repo": "OWNER/REPO",
"consent_hint": "Push branch feature-x for a PR"
}Poll until approved.
Get remote_url, add as a remote, then push to a non-default branch:
git remote add broker "<remote_url>"
git push broker "HEAD:refs/heads/feature-x"Notes:
pb/<task>/<timestamp>) rather than pushing to main.USED, create a new push session.Python (requests)
import time
import requests
def create_request(base_url, api_key, upstream_url, consent_hint=None, idempotency_key=None):
# Optional: method/headers/body for non-GET requests.
r = requests.post(
f"{base_url}/v1/proxy/request",
headers={"Authorization": f"Bearer {api_key}"},
json={
"upstream_url": upstream_url,
# "method": "POST",
# "headers": {"accept": "application/vnd.github+json"},
# "headers": {"content-type": "application/json"},
# "body": {"title": "...", "head": "...", "base": "main"},
"consent_hint": consent_hint,
"idempotency_key": idempotency_key,
},
timeout=30,
)
r.raise_for_status()
return r.json()
def await_result(base_url, api_key, request_id, timeout_s=120):
deadline = time.time() + timeout_s
while time.time() < deadline:
r = requests.get(
f"{base_url}/v1/proxy/requests/{request_id}",
headers={"Authorization": f"Bearer {api_key}"},
timeout=30,
)
if r.status_code == 202:
time.sleep(1)
continue
# Terminal response (status-only JSON).
return r.json()
raise TimeoutError("timed out waiting for approval")
def execute_request(base_url, api_key, request_id):
# IMPORTANT: execution is one-time; read and store now.
return requests.post(
f"{base_url}/v1/proxy/requests/{request_id}/execute",
headers={"Authorization": f"Bearer {api_key}"},
timeout=60,
)
def await_approval_then_execute(base_url, api_key, request_id, timeout_s=30):
status = await_result(base_url, api_key, request_id, timeout_s=timeout_s)
if status.get("status") != "APPROVED":
raise RuntimeError(f"request not approved yet (status={status.get('status')})")
return execute_request(base_url, api_key, request_id)GET/POST/PUT/PATCH/DELETE.The broker supports the Google Sheets API host (sheets.googleapis.com).
Preferred approach for reading spreadsheet data:
Fallback:
Note: large exports can exceed the broker's 1 MiB upstream response cap. If an export fails due to size, narrow the scope (smaller range, fewer tabs, or fewer rows/columns).
status (often PENDING_APPROVAL, APPROVED, or EXECUTING).status == APPROVED, execute immediately.{error: ...}.Prefer narrow reads so approvals are understandable and responses are small.
https://www.googleapis.com/drive/v3/files?...q, pageSize, and fields to minimize payload.https://www.googleapis.com/drive/v3/files/{fileId}/export?mimeType=...text/plain or text/csv.https://docs.googleapis.com/v1/documents/{documentId}?fields=...See references/api_reference.md for endpoint details and a Google URL cheat sheet.
POST https://api.github.com/repos/<owner>/<repo>/pulls{ "title": "...", "head": "branch", "base": "main", "body": "..." }POST https://api.github.com/repos/<owner>/<repo>/issues{ "title": "...", "body": "..." }references/api_reference.md© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/permissions-broker of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Permissions Broker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Permissions Broker this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~5k | Automated safety check: Pass | MIT | |
| Takopi Releasebanteg/takopi | 1.1k | — | ~734 | Automated safety check: Pass | MIT | |
| Keen Pbr Release Postmaksimkurb/keen-pbr | 141 | — | ~844 | Automated safety check: Pass | GPL-3.0 | |
| Project Managerpwrdrvr/openclaw-codex-app-server | 265 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Chat SDKdatabuddy-analytics/Databuddy | 1.2k | — | ~2.6k | Automated safety check: Pass | AGPL-3.0 | |
| Releasepwrdrvr/openclaw-codex-app-server | 265 | — | ~2.2k | Automated safety check: Pass | MIT |
banteg/takopi
Prepare and ship a Takopi release. An agent skill from banteg/takopi.
maksimkurb/keen-pbr
Draft keen-pbr release posts for GitHub and Telegram from git history.
pwrdrvr/openclaw-codex-app-server
Manage GitHub issues and the GitHub Project board for the current repository, while keeping the local tracker in sync.
databuddy-analytics/Databuddy
Build multi-platform chat bots with Chat SDK (chat npm package).
pwrdrvr/openclaw-codex-app-server
Plan and publish a GitHub Release in a tag-driven repository.
better-notify/better-notify
End-to-end typed notification infrastructure for Node.js — typed catalog of email, SMS, push, web push, WhatsApp, Slack, Discord, Telegram, and GitHub notifications with provider-agnostic transports.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Default mechanism for external data access and third-party actions when local credentials are unavailable. Permissions Broker is an agent skill from LeoYeAI/openclaw-master-skills. Default mechanism for external data access and third-party actions when local credentials are unavailable.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a claude-code`. Or copy the skill folder (skills/permissions-broker in LeoYeAI/openclaw-master-skills) into .claude/skills/permissions-broker in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a codex`. Or copy the skill folder (skills/permissions-broker in LeoYeAI/openclaw-master-skills) into .agents/skills/permissions-broker in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/permissions-broker, .gemini/skills/permissions-broker, .github/skills/permissions-broker and .opencode/skills/permissions-broker in your project.
Going by SKILL.md and its folder, Permissions Broker needs the command-line tools its instructions call (git) and credentials named PB_API_KEY and USER_API_KEY. Our summary lists: A credential in PB_API_KEY.
SKILL.md names 4 domains. In commands or code: googleapis.com, api.github.com, docs.googleapis.com and permissions-broker.steer.fun; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Permissions Broker is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Permissions Broker: Takopi Release (banteg/takopi, 1.1k stars), Keen Pbr Release Post (maksimkurb/keen-pbr, 141 stars), Project Manager (pwrdrvr/openclaw-codex-app-server, 265 stars) and Chat SDK (databuddy-analytics/Databuddy, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.