Corbits Marketplace
moonpay/skills
Paid API marketplace for AI agents via Corbits. An agent skill from moonpay/skills.
Runtime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills.
$ npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills runtime-sentinel --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/runtime-sentinel .claude/skills/runtime-sentinel && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "runtime-sentinel" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/runtime-sentinel into .claude/skills/runtime-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-sentinel", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/runtime-sentinelType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills runtime-sentinel --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/runtime-sentinel .agents/skills/runtime-sentinel && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "runtime-sentinel" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/runtime-sentinel into .agents/skills/runtime-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-sentinel", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills runtime-sentinel --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/runtime-sentinel .cursor/skills/runtime-sentinel && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "runtime-sentinel" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/runtime-sentinel into .cursor/skills/runtime-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-sentinel", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/runtime-sentinel--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills runtime-sentinel --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/runtime-sentinel .gemini/skills/runtime-sentinel && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "runtime-sentinel" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/runtime-sentinel into .gemini/skills/runtime-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-sentinel", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills runtime-sentinelInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/runtime-sentinel .github/skills/runtime-sentinel && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "runtime-sentinel" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/runtime-sentinel into .github/skills/runtime-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-sentinel", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills runtime-sentinel --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/runtime-sentinel .opencode/skills/runtime-sentinel && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "runtime-sentinel" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/runtime-sentinel into .opencode/skills/runtime-sentinel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-sentinel", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
runtime-sentinelRuntime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills.
Runtime Sentinel is an agent skill from LeoYeAI/openclaw-master-skills. Runtime security guardian for OpenClaw agents. Use this skill whenever the user mentions security, skill safety, prompt injection, malware, suspicious behavior, credential leaks, network monitoring, skill integrity, or the ClawHavoc attack. Also trigger for phrases like "is this skill safe", "audit my skills", "check for threats", "my agent is acting weird", "scan for malware", "protect my agent", or any concern about what installed skills are doing at runtime. runtime-sentinel provides five active defenses…
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including scripts and reference files (for example `.clawhub/origin.json`, `LICENSE.md` and `README.md`). Compatibility notes: {"binaries":["sentinel"],"env":["SENTINELWALLET","SENTINELRPC","SENTINELVTKEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}
It sits in Security, covering Anomaly detection and Prompt injection and agent security. It works with x402 and Circle USDC. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 8 files in scripts/ (Rust, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
cargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
{"binaries":["sentinel"],"env":["SENTINEL_WALLET","SENTINEL_RPC","SENTINEL_VT_KEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}
From compatibility in the SKILL.md frontmatter.
Runtime Sentinel loads about 1.7k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 222 tokens; SKILL.md has 551 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 551 words, ~1,690 tokens.
.claude/skills/runtime-sentinel/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.A runtime security skill for OpenClaw. Defends against the threat landscape exposed by ClawHavoc: backdoored skills, prompt injection via external data, credential exfiltration, and process-level abuse.
Free tier: skill integrity checks, basic injection scanning.
Premium (x402/USDC/Base): continuous daemon monitoring, network egress
monitoring, process anomaly detection, full audit log.
# One-shot audit of all installed skills (free)
sentinel audit
# Continuous guardian daemon (premium — will prompt for x402 payment)
sentinel daemon start
# Scan a single skill before installing
sentinel check <skill-path-or-clawhub-id>See references/threat-model.md for the full threat matrix. In brief:
| Threat | Feature | Tier |
|---|---|---|
| Tampered skill files post-install | Integrity hashing | Free |
| Prompt injection via email/web/skill output | Injection scanner | Free |
| Plaintext secrets in skill dirs / SOUL.md | Credential auditor | Free |
| Unexpected outbound connections | Egress monitor | Premium |
| Shell commands outside declared behavior | Process anomaly | Premium |
| Continuous real-time protection | Daemon mode | Premium |
# Install the binary (built from scripts/src/)
cargo install --path scripts/ --bin sentinel
# Verify installation and print wallet address
sentinel setupsentinel setup will:
~/.sentinel/wallet)When the user says anything like "scan my skills", "audit", "check for threats":
sentinel audit [--path ~/.openclaw/skills]Output: a structured report of hash mismatches, injection patterns, and exposed credentials. No payment required.
When the user wants to vet a skill before running clawhub install:
sentinel check <skill-directory-or-clawhub-id>Prints a risk score (LOW / MEDIUM / HIGH / CRITICAL) with findings.
When the user asks for daemon mode, egress monitoring, or process anomaly
detection, sentinel will automatically:
402 Payment Required with price in the X-Payment-Request
header (typically $0.01–$0.05/day for daemon mode)~/.sentinel/walletThe user will see the price before their wallet signs anything. All
non-custodial. See references/x402-payment.md for the full payment flow.
sentinel daemon start # runs in foreground, writes to ~/.sentinel/daemon.log
# Run in background from your shell if needed:
# sentinel daemon start > ~/.sentinel/daemon.log 2>&1 &
# disown
sentinel daemon status
sentinel daemon stop
sentinel daemon logs # tail the audit logThe daemon watches:
~/.openclaw/skills/** for file mutations (inotify / FSEvents)~/.openclaw/SOUL.md and MEMORY.md for unauthorized writesAlerts are delivered via OpenClaw's notification system and written to the audit log.
sentinel isolate <skill-name> — quarantines the skill (moves it out of
the active skills directory)~/.sentinel/audit.logclawhub uninstall <skill> and report via
sentinel report <skill-name>Read these when you need deeper detail:
references/threat-model.md — Full threat matrix and attack descriptions
from ClawHavoc and similar campaignsreferences/x402-payment.md — x402 payment flow, wallet setup, and
troubleshootingreferences/binary-build.md — How to build sentinel from source, cross-
compilation targets, CI/CDsentinel wallet show # print address and USDC balance
sentinel wallet fund # print QR code and address to send USDC
sentinel wallet export # export mnemonic for backup (handle carefully)
sentinel wallet recover # restore from mnemonic on a new machineMinimum recommended balance for uninterrupted daemon mode: $1 USDC (roughly 20–100 days of coverage depending on scan frequency).
sentinel is fully local. No skill content, file paths, or scan results are
sent to any server. The only outbound calls are:
Both can be disabled with --offline for air-gapped environments (free tier
only in offline mode).
© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 18 other files (scripts, references) in skills/runtime-sentinel of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Runtime Sentinel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Runtime Sentinel this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Corbits Marketplacemoonpay/skills | 113 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Instagram APIaiskillstore/marketplace | 430 | — | ~2.1k | Automated safety check: Pass | None | |
| Twitter APIaiskillstore/marketplace | 430 | — | ~2.2k | Automated safety check: Pass | None | |
| Agentic Walletcoinbase/agentic-wallet-skills | 127 | 2 repos | ~1k | Automated safety check: Pass | MIT | |
| Predexon Prediction Market DataBlockRunAI/ClawRouter | 6.6k | — | ~4.7k | Automated safety check: Pass | MIT |
moonpay/skills
Paid API marketplace for AI agents via Corbits. An agent skill from moonpay/skills.
aiskillstore/marketplace
An Instagram API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no login and no session cookies.
aiskillstore/marketplace
A Twitter API alternative and X API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no OAuth and no developer application.
coinbase/agentic-wallet-skills
Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API…
BlockRunAI/ClawRouter
Reads structured prediction market data for Polymarket, Kalshi and other venues through a local BlockRun gateway: markets, search, leaderboards, wallet analytics and odds.
BlockRunAI/blockrun-mcp
Pay-per-call access to AI models, real-time data, media generation and multi-chain RPC over x402 micropayments (USDC on Base or Solana), or a BlockRun account API key.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Works with
Categories
Runtime security guardian for OpenClaw agents. An agent skill from LeoYeAI/openclaw-master-skills. Runtime Sentinel is an agent skill from LeoYeAI/openclaw-master-skills. Runtime security guardian for OpenClaw agents.
Runtime Sentinel fits situations like: the user mentions security; prompt injection; suspicious behavior; credential leaks.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a claude-code`. Or copy the skill folder (skills/runtime-sentinel in LeoYeAI/openclaw-master-skills) into .claude/skills/runtime-sentinel in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a codex`. Or copy the skill folder (skills/runtime-sentinel in LeoYeAI/openclaw-master-skills) into .agents/skills/runtime-sentinel in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill runtime-sentinel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runtime-sentinel, .gemini/skills/runtime-sentinel, .github/skills/runtime-sentinel and .opencode/skills/runtime-sentinel in your project.
Going by SKILL.md and its folder, Runtime Sentinel needs Rust for the scripts in its folder and the command-line tools its instructions call (cargo). Our summary lists: A credential in SENTINEL_VT_KEY. Compatibility (from SKILL.md): {"binaries":["sentinel"],"env":["SENTINEL_WALLET","SENTINEL_RPC","SENTINEL_VT_KEY"],"source":"https://github.com/spaceman420urdog-afk/runtime-sentinel"}.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Runtime Sentinel is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Runtime Sentinel: Corbits Marketplace (moonpay/skills, 113 stars), Instagram API (aiskillstore/marketplace, 430 stars), Twitter API (aiskillstore/marketplace, 430 stars) and Agentic Wallet (coinbase/agentic-wallet-skills, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,158 GitHub stars. The repository holds 1,215 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.