Agent skill

Todo Tracker Safe

by LeoYeAI in LeoYeAI/openclaw-master-skills

Secure TODO tracker with input validation and safe file operations.

MITAuto-check passedProductivity & Automation

Install Todo Tracker Safe

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill todo-tracker-safe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills todo-tracker-safe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/todo-tracker-safe .claude/skills/todo-tracker-safe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
todo-tracker-safe
GitHub stars
2.2k
Token cost
~303 tokens
SKILL.md length
78 words
Files
5 (incl. scripts)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

Secure TODO tracker with input validation and safe file operations.

  • Works in 6 steps: 输入验证 - 所有用户输入经过 sanitize_input() 过滤 → 固定字符串匹配 - 使用 grep -F 避免正则注入 → 文件权限检查 - 验证 TODO 文件权限不过于宽松 → …
  • Task management across sessions
  • SKILL.md covers 安全改进, 用法, 配置 and 触发条件, plus 1 more section
  • Runs Shell scripts from its folder

What it does

Todo Tracker Safe is an agent skill from LeoYeAI/openclaw-master-skills. Secure TODO tracker with input validation and safe file operations. Use for task management across sessions.

Its SKILL.md is about 300 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `.clawhub/origin.json`, `README.md` and `_meta.json`).

It sits in Productivity & Automation, covering Task management. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Task management across sessions
  • Tasks that involve Task management

Example prompts

  • “/todo-tracker-safe”

Requirements

  • A Bash shell

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. 输入验证 - 所有用户输入经过 sanitize_input() 过滤
  2. 固定字符串匹配 - 使用 grep -F 避免正则注入
  3. 文件权限检查 - 验证 TODO 文件权限不过于宽松
  4. 无动态执行 - 不使用 eval 或命令替换执行用户输入
  5. 错误处理 - 使用 set -euo pipefail 严格模式
  6. 长度限制 - 输入限制为 200 字符

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Todo Tracker Safe loads about 303 tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 78 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~303

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 78 words, ~303 tokens.

Download SKILL.mdSave it as .claude/skills/todo-tracker-safe/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
todo-tracker-safe
description
Secure TODO tracker with input validation and safe file operations. Use for task management across sessions.
homepage
https://github.com/openclaw/openclaw

📋 TODO Tracker (安全版本)

安全的跨会话任务追踪工具,带有输入验证和安全文件操作。

安全改进

相比原始版本,此版本包含以下安全增强:

  1. 输入验证 - 所有用户输入经过 sanitize_input() 过滤
  2. 固定字符串匹配 - 使用 grep -F 避免正则注入
  3. 文件权限检查 - 验证 TODO 文件权限不过于宽松
  4. 无动态执行 - 不使用 eval 或命令替换执行用户输入
  5. 错误处理 - 使用 set -euo pipefail 严格模式
  6. 长度限制 - 输入限制为 200 字符

用法

bash
# 添加任务
todo.sh add high "完成项目报告"
todo.sh add medium "回复邮件"
todo.sh add low "整理文件"

# 标记完成
todo.sh done "项目报告"

# 删除任务
todo.sh remove "整理文件"

# 列出任务
todo.sh list          # 全部
todo.sh list high     # 高优先级
todo.sh list done     # 已完成

# 摘要(用于 heartbeat)
todo.sh summary

配置

  • TODO_FILE - 自定义 TODO 文件路径(默认:~/.openclaw/workspace/TODO.md)

触发条件

当用户说:

  • "添加到 TODO" / "add to TODO"
  • "标记 X 完成" / "mark X done"
  • "TODO 列表" / "TODO list"
  • "还有什么任务" / "what's on the TODO"
  • 心跳时自动显示摘要

安全审计

  • ✅ 无外部 API 调用
  • ✅ 无网络请求
  • ✅ 无环境变量读取(除 TODO_FILE)
  • ✅ 无动态代码执行
  • ✅ 输入经过严格过滤
  • ✅ 文件操作有权限检查

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in skills/todo-tracker-safe of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • .clawhub/origin.json
  • README.md
  • _meta.json
  • scripts/todo.sh

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Todo Tracker Safe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Todo Tracker Safe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Todo Tracker Safe this skillLeoYeAI/openclaw-master-skills2.2k—~303Automated safety check: PassMIT
Superset Agent Standupsuperset-sh/superset15k—~712Automated safety check: PassCustom licence
AgentRQ Workspace Agentagentrq/agentrq1.1k—~1.9kAutomated safety check: PassAGPL-3.0
Markdown Task Managerioniks/MarkdownTaskManager535—~2.2kAutomated safety check: PassMPL-2.0
Pi Messenger Crewnicobailon/pi-messenger720—~3.7kAutomated safety check: PassNone
Codekanban CLIfy0/CodeKanban225—~2.7kAutomated safety check: PassApache-2.0

Similar skills

  • Superset Agent Standup

    superset-sh/superset

    Sweeps every Superset workspace, task and agent terminal to report what finished, what needs review and what is blocked, read-only, and can publish the digest as a page.

    15k GitHub stars~712 tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Guides a workspace agent through executing assigned tasks, replying to a remote human operator, and creating sub-tasks, memory and events inside an AgentRQ workspace.

    1.1k GitHub stars~1.9k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Markdown Task Manager

    ioniks/MarkdownTaskManager

    A skill your agent uses when managing tasks, the system is a Kanban task manager based on local Markdown files (kanban.md and archive.md).

    535 GitHub stars~2.2k tokensUpdated 3 mo ago
    Productivity & AutomationAuto-check passed
  • Pi Messenger Crew

    nicobailon/pi-messenger

    Orchestrator reference for pi-messenger Crew planning, task management, configuration, and agent coordination.

    720 GitHub stars~3.7k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Codekanban CLI

    fy0/CodeKanban

    Operate CodeKanban workflows, terminal sessions, and web sessions through the installable codekanban-cli command.

    225 GitHub stars~2.7k tokensUpdated 5 days ago
    Productivity & AutomationAuto-check passed
  • Kanban Video Orchestrator

    Luciole-Studio/Misaka-Agent

    Plan and run multi-agent video production pipelines. An agent skill from Luciole-Studio/Misaka-Agent.

    158 GitHub starsUsed in 2 repos~2.4k tokens
    Productivity & AutomationAuto-check: notes

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Todo Tracker Safe

What does Todo Tracker Safe do?

Secure TODO tracker with input validation and safe file operations. Todo Tracker Safe is an agent skill from LeoYeAI/openclaw-master-skills. Secure TODO tracker with input validation and safe file operations.

When should I use Todo Tracker Safe?

Todo Tracker Safe fits situations like: task management across sessions; tasks that involve Task management.

How do I install Todo Tracker Safe in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill todo-tracker-safe -a claude-code`. Or copy the skill folder (skills/todo-tracker-safe in LeoYeAI/openclaw-master-skills) into .claude/skills/todo-tracker-safe in your project. Claude Code loads it when a task matches its description.

How do I install Todo Tracker Safe in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill todo-tracker-safe -a codex`. Or copy the skill folder (skills/todo-tracker-safe in LeoYeAI/openclaw-master-skills) into .agents/skills/todo-tracker-safe in your project. Codex loads it when a task matches its description.

Can I use Todo Tracker Safe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill todo-tracker-safe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/todo-tracker-safe, .gemini/skills/todo-tracker-safe, .github/skills/todo-tracker-safe and .opencode/skills/todo-tracker-safe in your project.

What does Todo Tracker Safe need to run?

Going by SKILL.md and its folder, Todo Tracker Safe needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Todo Tracker Safe access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Todo Tracker Safe safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Todo Tracker Safe use?

Todo Tracker Safe is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Todo Tracker Safe use?

About 303 tokens (SKILL.md is roughly 1.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Todo Tracker Safe?

Skills that share tags, products or a category with Todo Tracker Safe: Superset Agent Standup (superset-sh/superset, 15k stars), AgentRQ Workspace Agent (agentrq/agentrq, 1.1k stars), Markdown Task Manager (ioniks/MarkdownTaskManager, 535 stars) and Pi Messenger Crew (nicobailon/pi-messenger, 720 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Todo Tracker Safe?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.