Agentic GitHub Actions Auditor
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
Scan any agent skill for security risks before you install or use it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills skill-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aig-skill-scanner .claude/skills/skill-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skill-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/aig-skill-scanner into .claude/skills/skill-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/aig-skill-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills skill-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/aig-skill-scanner .agents/skills/skill-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skill-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/aig-skill-scanner into .agents/skills/skill-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills skill-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/aig-skill-scanner .cursor/skills/skill-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skill-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/aig-skill-scanner into .cursor/skills/skill-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/aig-skill-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills skill-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/aig-skill-scanner .gemini/skills/skill-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skill-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/aig-skill-scanner into .gemini/skills/skill-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills skill-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/aig-skill-scanner .github/skills/skill-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skill-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/aig-skill-scanner into .github/skills/skill-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills skill-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/aig-skill-scanner .opencode/skills/skill-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skill-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/aig-skill-scanner into .opencode/skills/skill-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skill-scannerScan any agent skill for security risks before you install or use it.
Skill Scanner is an agent skill from LeoYeAI/openclaw-master-skills. Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your device. Compatible with CodeBuddy, Cursor, Windsurf, Claude Code, OpenClaw and more. Triggers on: 这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, audit skill, scan skill, check skill safety, analyze skill, inspect skill, verify skill, skill security, skill supply chain. Do NOT trigger for general agent usage, full system health…
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_meta.json`).
It sits in Security, covering Prompt injection and agent security and Static analysis and SAST. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skill Scanner loads about 3.7k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 1,761 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,761 words, ~3,722 tokens.
.claude/skills/skill-scanner/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Agent Skills security scanner powered by Tencent Zhuque Lab A.I.G. Compatible with any agent platform that supports skills (e.g. OpenClaw, Qclaw, WorkBuddy, CodeBuddy, Cursor, Windsurf, Claude Code, etc.).
Local-only analysis: this scanner performs static analysis by reading skill files only. No file contents, credentials, or personal data are sent externally.
Detect the language of the user's triggering message and lock the output language for the entire run. This detection is an internal step only — do NOT output any text that reveals the detection result, such as "当前输出语言为中文", "Detected language: English", or similar meta-statements. Simply use the detected language silently for all subsequent output.
| User message language | Output language |
|---|---|
| Chinese | Chinese — entire output in Chinese |
| English | English — entire output in English |
| Other language | Match that language |
| Cannot determine | Default to Chinese |
All output — scan start prompt, table headers, labels, prose, verdict, and footer — must be written exclusively in the detected language. Do NOT mix languages or announce the language choice at any point.
Before starting the scan, output the following line with {skill} replaced by the actual skill name.
Translate it to match the detected output language.
🔍 腾讯朱雀实验室 A.I.G Skill Scanner 正在检测 {skill} 的安全性,请稍候...
Determine which mode to use based on the user's request:
| User intent | Mode |
|---|---|
| Scan all skills on a platform, or asks "are my skills safe?" without specifying a file | Mode A — Full-platform scan |
| Scan a specific skill file or a named skill | Mode B — Single-skill audit |
Use this mode when the user wants to check the security of all skills on a given agent platform.
Determine which agent platform the user is referring to. Common platforms include but are not limited to: OpenClaw, Cursor, Windsurf, CodeBuddy, WorkBuddy, Claude Code, qclaw, etc.
How to determine:
Once the platform is identified, use the platform-specific method below to enumerate all installed skills. Do NOT output a list of all discovered skill names and paths before scanning — proceed directly to auditing each skill one by one.
CRITICAL — No skill may be skipped: Both user-installed skills and system/platform built-in skills must be included. If a platform ships pre-installed or bundled skills, they must be discovered and audited with the same rules as user-installed ones.
Platform-specific skill discovery methods:
| Platform | Discovery method |
|---|---|
| OpenClaw | Ask the Agent: "你的 skill 有哪些" or "list your skills" to get the full skill list |
| CodeBuddy | Scan both the system directory ~/.codebuddy/plugins/marketplaces/ and the user directory ~/.codebuddy/plugins/ for all skill files and subdirectories. Also check if the platform exposes a built-in skill list via its tools (e.g. use_skill tool's <available_skills> section) and include those. |
| Cursor | Scan the local directory ~/.cursor/extensions/ and project-level .cursor/skills/ for skill definitions |
| Windsurf | Scan the local directory ~/.windsurf/skills/ and project-level .windsurf/skills/ for skill files |
| Claude Code | Scan project-level .claude/skills/ directory and check ~/.claude/skills/ for global skills |
| qclaw | Ask the Agent: "你的 skill 有哪些" or "list your skills" to get the full skill list |
| WorkBuddy | Ask the Agent: "你的 skill 有哪些" or "list your skills" to get the full skill list |
| Other / Unknown | Ask the Agent for its skill list |
Note: The paths above are common defaults and may vary by version or user configuration. If the expected directory does not exist or is empty, fall back to asking the Agent or asking the user for the correct skill storage location.
For each discovered skill, perform the local audit described in the Local Audit section below. Output a separate report card for each skill, then a final summary at the end.
Use this mode when the user specifies a particular skill file or skill name.
Output a short inventory with only the minimum context needed for audit:
SKILL.mdscripts/, shell files, package manifests, config filesPerform static analysis following these principles:
Core principles:
SKILL.md with actual code behavior.Audit rules:
SKILL.md, executable scripts, manifests, and configs.bash, subprocess, key read/write, or env-variable access as
a Medium+ finding by itself.🔴 high risk only when there is evidence of one or more of the following:Per-finding output format (Medium+ findings only):
CRITICAL — Strict format adherence: Every scan output must follow the exact template structure defined below. Do NOT freestyle, rearrange sections, add extra sections, or omit any required part. The output structure is fixed — only the fill-in content varies based on audit results.
All output must be written in the user's detected language, rendered in Markdown format with clean and readable layout. The writing style must be plain, friendly, and free of jargon — an ordinary non-technical user should be able to understand every sentence without prior knowledge. If a technical concept is unavoidable, immediately follow it with a parenthetical plain-language explanation.
✅ / ⚠️ / 🔴) matching the resultCRITICAL: Mode A does NOT output a separate report card per skill. Instead, use the following fixed two-part structure:
Output one single table that lists every discovered skill in one row. This table must include all skills — user-installed and system built-in — with no omissions.
## 🔍 Skill 安全扫描结果
共扫描 {N} 个 Skill:
| # | Skill 名称 | 来源 | 检测结果 |
|---|-----------|------|---------|
| 1 | {skill_name} | {source} | ✅ 未发现风险 |
| 2 | {skill_name} | {source} | ⚠️ 需关注 |
| 3 | {skill_name} | {source} | 🔴 发现风险 |
| ... | ... | ... | ... |Rules for the summary table:
✅ 未发现风险, ⚠️ 需关注, 🔴 发现风险.source is the skill's origin, e.g. "系统内置", "marketplace", "本地", "GitHub" etc.After the summary table, output detailed findings only for skills marked ⚠️ or 🔴.
Skills marked ✅ do NOT get a detail section — their row in the summary table is sufficient.
For each ⚠️ or 🔴 skill, output its detail using the corresponding template below (Needs Attention or Risk Detected). Include findings in the per-finding format (📍📝⚡🎯💡) when applicable.
If all skills are ✅, skip Part 2 entirely and go straight to the conclusion.
> 📌 温馨提示:本报告基于当前版本的静态扫描,无法覆盖未来更新可能引入的风险,建议定期复查。Use the individual report card templates (🟢 / 🟡 / 🔴) below as-is, followed by the footer.
In Mode A, safe skills only appear in the summary table — do NOT output this template for them. In Mode B (single-skill audit), use this full template when no Medium+ findings exist:
## ✅ {skill} 安全检测通过
| 检测项目 | 检测结果 |
|---------|---------|
| 🏠 来源是否可信 | {✅ 来自已知的可信来源 / ⚠️ 来源未知,建议关注后续版本更新} |
| 📂 是否会动你的文件 | {✅ 不会,只读取自己的配置 / ⚠️ 会访问文件,但属于它正常工作所需} |
| 🌐 是否偷偷联网 | {✅ 没有发现联网行为 / ✅ 仅连接了它说明中提到的地址} |
| ⚠️ 是否有危险操作 | ✅ 未发现 |
**结论**:本次检测未发现安全隐患,可以放心使用。
> 📌 温馨提示:本报告基于当前版本的静态扫描,无法覆盖未来更新可能引入的风险,建议定期复查。Output rules:
Use this template in Mode B for single-skill audit, or in Mode A Part 2 to expand ⚠️ skills.
## ⚠️ {skill} 需要留意
这个 skill **没有发现明确的恶意行为**,但它拥有{具体的敏感能力描述},
这些能力主要用于完成它声明的「{功能描述}」。
**建议**:如果你信任这个 skill 的来源,并且觉得它需要这些权限是合理的,可以继续使用。
如果不确定,建议先暂停使用,或咨询开发者了解详情。Fill-in rules:
{具体的敏感能力描述}: only list confirmed capabilities, described in everyday language, e.g. "可以执行系统命令", "可以访问你工作区以外的文件", "可以联网发送数据", "可以读取你的配置信息".{功能描述}: only use the purpose stated in SKILL.md; do not add your own interpretation.Use this template in Mode B for single-skill audit, or in Mode A Part 2 to expand 🔴 skills.
## 🔴 {skill} 发现安全风险
**不建议直接安装或继续使用。**
这个 skill 存在以下问题:{用通俗语言描述主要风险,例如"它会在你不知情的情况下执行系统命令"、"它会访问不属于自己功能范围的敏感文件"等}。
**建议**:
1. 先停用这个 skill
2. 联系 skill 的开发者确认是否为正常行为
3. 在确认安全前不要重新启用If multiple findings exist, summarize only the most severe 1–2 in plain language unless the user asks for full details.
CRITICAL: Every scan output MUST end with the following footer line. Never omit it. Translate to match the output language, but keep the link and "A.I.G" unchanged.
Skill Scanner 由腾讯朱雀实验室开源的 [A.I.G](https://github.com/tencent/AI-Infra-Guard) 提供核心能力支持,欢迎 Star 关注并参与共建。
© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/aig-skill-scanner of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in LeoYeAI/openclaw-master-skills, which our catalogue first saw on October 7, 2026.
Skill Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skill Scanner this skillLeoYeAI/openclaw-master-skills | 2.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Skylos Securityduriantaco/skylos | 844 | — | ~545 | Automated safety check: Pass | Apache-2.0 | |
| Skill Safety EvaluatoropenJiuwen-ai/agent-core | 446 | — | ~3.5k | Automated safety check: Warn | Apache-2.0 | |
| Moai Ref Secopsmodu-ai/moai-adk | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Security Audit 2sundial-org/awesome-openclaw-skills | 663 | — | ~875 | Automated safety check: Pass | None |
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
duriantaco/skylos
Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.
openJiuwen-ai/agent-core
Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score.
modu-ai/moai-adk
DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…
sundial-org/awesome-openclaw-skills
Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Categories
Scan any agent skill for security risks before you install or use it. Skill Scanner is an agent skill from LeoYeAI/openclaw-master-skills. Scan any agent skill for security risks before you install or use it.
Skill Scanner fits situations like: check skill safety; skill supply chain; general agent usage; full system health checks.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a claude-code`. Or copy the skill folder (skills/aig-skill-scanner in LeoYeAI/openclaw-master-skills) into .claude/skills/skill-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a codex`. Or copy the skill folder (skills/aig-skill-scanner in LeoYeAI/openclaw-master-skills) into .agents/skills/skill-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill skill-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-scanner, .gemini/skills/skill-scanner, .github/skills/skill-scanner and .opencode/skills/skill-scanner in your project.
SKILL.md names no scripts, command-line tools or credentials: Skill Scanner is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Skill Scanner is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Skill Scanner: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Skylos Security (duriantaco/skylos, 844 stars), Skill Safety Evaluator (openJiuwen-ai/agent-core, 446 stars) and Moai Ref Secops (modu-ai/moai-adk, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.