Agent skill

Tsa Risk

by LeoYeAI in LeoYeAI/openclaw-master-skills

腾讯云智能顾问架构风险巡检分析报告生成工具。用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从API拉取数据并生成移动端友好的HTML可视化报告,最终将HTML转换为PNG图片输出。当用户提到智能顾问架构巡检、风险分析、巡检报告、架构图风险、腾讯云巡检等关键词时或对当前报告内容修改时,请务必使用此插件。

MITAuto-check: notes

Install Tsa Risk

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill tsa-risk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills tsa-risk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloudq/references/plugins/tsa-risk .claude/skills/tsa-risk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tsa-risk
GitHub stars
2.2k
Token cost
~1.7k tokens
SKILL.md length
335 words
Files
11 (incl. scripts)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

腾讯云智能顾问架构风险巡检分析报告生成工具。用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从API拉取数据并生成移动端友好的HTML可视化报告,最终将HTML转换为PNG图片输出。当用户提到智能顾问架构巡检、风险分析、巡检报告、架构图风险、腾讯云巡检等关键词时或对当前报告内容修改时,请务必使用此插件。

  • Works in 2 steps: 自动获取 ResultId:首先调用… → 依次调用三个数据接口并将数据合并为 JSON 文件,输出到…
  • SKILL.md covers 接口约束, 前置条件, 工作流程 and 注意事项与安全规范, plus 2 more sections
  • Runs Python scripts from its folder; calls python3; reaches console.cloud.tencent.com; needs TENCENTCLOUD_SECRET_KEY and TENCENTCLOUD_TOKEN

What it does

Tsa Risk is an agent skill from LeoYeAI/openclaw-master-skills. 腾讯云智能顾问架构风险巡检分析报告生成工具。用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从API拉取数据并生成移动端友好的HTML可视化报告,最终将HTML转换为PNG图片输出。当用户提到智能顾问架构巡检、风险分析、巡检报告、架构图风险、腾讯云巡检等关键词时或对当前报告内容修改时,请务必使用此插件。

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts (for example `ReportDesignSpec.md`, `scripts/generate_report_default.py` and `scripts/html_to_png.py`).

The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

Example prompts

  • “/tsa-risk”

Requirements

  • Python 3
  • A credential in TENCENTCLOUD_SECRET_KEY
  • A credential in TENCENTCLOUD_TOKEN
  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Write

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. 自动获取 ResultId:首先调用 DescribeArchScanReportLastInfo 接口,通过 ArchId 获取最新的报告 ID
  2. 依次调用三个数据接口并将数据合并为 JSON 文件,输出到 ./output/data_.json(当前工作目录下)

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • console.cloud.tencent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TENCENTCLOUD_SECRET_KEY
    • TENCENTCLOUD_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tsa Risk loads about 1.7k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 335 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 335 words, ~1,734 tokens.

Download SKILL.mdSave it as .claude/skills/tsa-risk/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
tsa-risk
description
腾讯云智能顾问架构风险巡检分析报告生成工具。用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从API拉取数据并生成移动端友好的HTML可视化报告,最终将HTML转换为PNG图片输出。当用户提到智能顾问架构巡检、风险分析、巡检报告、架构图风险、腾讯云巡检等关键词时或对当前报告内容修改时,请务必使用此插件。
allowed-tools
Bash, Read, Grep, Write
argument-hint
ArchId

腾讯云智能顾问 — 架构风险巡检分析报告

本 skill 用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,自动拉取数据并生成可视化报告。

接口约束

重要:本 skill 仅允许调用以下 references/ 中定义的 4 个智能顾问接口,不得调用任何 references 之外的接口:

#Action说明文档
1DescribeArchScanReportLastInfo获取最新巡检报告ID{baseDir}/references/api/DescribeArchScanReportLastInfo.md
2DescribeArchScanOverviewInfo查询巡检概览信息{baseDir}/references/api/DescribeArchScanOverviewInfo.md
3DescribeArchRiskTrendInfo查询风险趋势信息{baseDir}/references/api/DescribeArchRiskTrendInfo.md
4DescribeScanPluginRiskTrendListInfo查询风险明细列表{baseDir}/references/api/DescribeScanPluginRiskTrendListInfo.md

所有接口统一通过 {baseDir}/scripts/tcloud_api.py 调用,服务名 advisor,API 版本 2020-07-21。

路径约定:下文使用 {pluginDir} 表示 {baseDir}/references/plugins/tas-risk,插件专用脚本(数据拉取、报告生成、截图转换)位于 {pluginDir}/scripts/,公用脚本(环境检查、API调用、免密登录等)位于 {baseDir}/scripts/。

辅助脚本说明:{baseDir}/scripts/login_url.py 和 {baseDir}/scripts/setup_role.py 为可选辅助脚本,使用 STS/CAM 通用服务接口(非智能顾问业务接口),仅用于免密登录链接生成和角色配置,不在核心数据流程中。

前置条件

  • 系统需安装 python3(3.6 及以上版本)
  • 需配置腾讯云 API 密钥环境变量:TENCENTCLOUD_SECRET_ID、TENCENTCLOUD_SECRET_KEY

工作流程

第一步:获取用户输入
  • ArchId(必填):架构图 ID,如 arch-xxxxx

注意:ResultId 无需用户提供,系统会自动通过 DescribeArchScanReportLastInfo 接口获取最新的报告 ID。

第二步:环境检查
bash
python3 {baseDir}/check_env.py
第三步:拉取数据
bash
python3 {pluginDir}/scripts/risk_fetch_data.py <ArchId>

该脚本自动完成以下工作:

  1. 自动获取 ResultId:首先调用 DescribeArchScanReportLastInfo 接口,通过 ArchId 获取最新的报告 ID
    • 如果接口调用失败(报错),中断整个流程,脚本会输出错误信息,需向用户提示异常原因
    • 如果 ResultId 为空,说明该架构图尚未进行过巡检,中断整个流程,需提示用户前往 腾讯云智能顾问控制台 发起巡检
  2. 依次调用三个数据接口并将数据合并为 JSON 文件,输出到 ./output/data_<ArchId>.json(当前工作目录下)

数据拉取特性:

  • DescribeScanPluginRiskTrendListInfo 接口使用 Limit=200(最大分页) 并自动分页遍历,确保获取全部风险明细数据
  • 所有分页数据合并后统一写入 JSON,TotalCount 为实际获取的总条数
  • 其他接口单次调用即可

使用接口前,必须先加载对应的接口文档:{baseDir}/references/api/<Action>.md

第四步:生成 HTML 报告

数据来源:./output/data_<ArchId>.json

4a. 默认方案(无特殊样式要求)

脚本优先级机制:系统优先加载 generate_report_custom.py,不存在时回退到 generate_report_default.py。

规则:

  • generate_report_custom.py 不预置,仓库中只有 generate_report_default.py 作为基线版本
  • 当用户自定义报告需求通过 --template 模板配置无法满足、需要修改生成逻辑(如布局、模块增删、图表样式、数据处理等)时,先将 generate_report_default.py 复制为 generate_report_custom.py,再在副本上修改
  • 一旦 generate_report_custom.py 存在,后续所有生成都自动使用它;generate_report_default.py 始终保持不变作为基线
bash
# 如需修改生成逻辑,先创建自定义副本(仅首次)
if [ ! -f "{pluginDir}/scripts/generate_report_custom.py" ]; then
  cp {pluginDir}/scripts/generate_report_default.py {pluginDir}/scripts/generate_report_custom.py
fi

# 自动选择脚本(优先 _custom 版本)
GEN_SCRIPT="{pluginDir}/scripts/generate_report_custom.py"
if [ ! -f "$GEN_SCRIPT" ]; then
  GEN_SCRIPT="{pluginDir}/scripts/generate_report_default.py"
fi
python3 "$GEN_SCRIPT" ./output/data_<ArchId>.json --theme random

可指定主题:--theme ocean|sunset|forest|lavender|coral|slate

4b. 使用自定义模板

如果用户之前保存过自定义模板,可通过 --template 指定模板目录:

bash
# 同样优先使用 _custom 版本
python3 "$GEN_SCRIPT" ./output/data_<ArchId>.json --template <自定义模板名>
4c. 保存自定义模板

当用户对主题有自定义修改需求时:

  1. 复制 {pluginDir}/template/default/ 下对应主题 JSON 文件
  2. 按用户需求修改颜色、阈值、布局等配置
  3. 使用 --save-template 保存为新模板(会在 template/<名称>/ 下创建):
bash
python3 "$GEN_SCRIPT" ./output/data_<ArchId>.json --theme ocean --save-template my-custom
4d. 列出可用模板
bash
python3 "$GEN_SCRIPT" --list-templates
4e. 定制方案(用户有特殊样式需求且模板无法满足)

不使用脚本,而是:

  1. 读取 ./output/data_<ArchId>.json 数据
  2. 参考 {pluginDir}/ReportDesignSpec.md 了解报告模块与样式规范
  3. 根据用户样式要求直接生成自定义 HTML 报告
  4. 输出到 ./output/report_<ArchId>.html
第五步(可选):AI 报告分析

此步骤默认不启用。仅当用户明确要求生成 AI 分析摘要(如提到"分析一下"、"总结报告"、"AI 解读"等关键词)时才执行此步骤。默认流程直接从第四步跳到第六步。

如果用户要求启用 AI 分析,在生成 HTML 后、转 PNG 前,对巡检数据进行分析:

  1. 读取 ./output/data_<ArchId>.json 中的关键数据
  2. 生成简洁专业的中文分析文本(200-400字),具体要求参见 {pluginDir}/ReportDesignSpec.md
  3. 保存到 ./output/summary_<ArchId>.txt
  4. 重新生成报告(附带分析):
bash
python3 "$GEN_SCRIPT" ./output/data_<ArchId>.json --theme random --summary ./output/summary_<ArchId>.txt

也可同时指定自定义模板:--template <模板名> --summary ...

第六步:HTML 转 PNG
bash
python3 {pluginDir}/scripts/html_to_png.py ./output/report_<ArchId>.html

最终输出 PNG 到 ./output/report_<ArchId>.png。

第七步:生成报告的结果处理

⚠️ 核心原则:报告图片优先! 无论何种场景,都必须 优先尝试发送/展示报告图片,只有在确认图片无法发送时才降级。

报告生成完毕后,按以下优先级策略处理:

策略 A:IM 回复场景(Web端、企微、飞书等在线对话)
  1. 优先发送报告图片(必须!)

    • 调用 read_image 工具读取 ./output/report_<ArchId>.png,让图片 直接内联显示 在对话消息中
    • 发送图片后,附上文字提示(见下方模板)
  2. 降级方案:仅当图片确实无法发送时(如 read_image 工具不可用、图片文件生成失败、PNG 转换全部失败等)

    • 读取 ./output/data_<ArchId>.json 数据,将报告内容解读为 Markdown 格式文本 发送
    • 必须在消息开头添加降级说明,格式如下:
    > ⚠️ 图片报告未能发送(原因:{{具体原因,如"PNG截图工具均不可用"或"read_image工具调用失败"等}}),以下为文本版报告:
    • 然后输出 Markdown 格式的报告内容
    • 在末尾补充提示:💡 建议:升级至最新版 CLAW 客户端以获得图片报告的最佳体验
策略 B:本地 CLAW 场景(qclaw 等本地客户端)

如果检测到当前运行环境为本地 CLAW(如 qclaw)且不支持在对话中发送/内联图片:

  1. 直接在本地打开报告图片:
    bash
    # macOS
    open ./output/report_<ArchId>.png
    # Linux
    xdg-open ./output/report_<ArchId>.png
    # Windows
    start ./output/report_<ArchId>.png
  2. 在对话中回复:📷 报告图片已在本地打开,请查看。
  3. 如果本地打开也失败,则降级为 Markdown 文本(同策略 A 的降级方案)
文字提示模板

发送图片后(或降级文本报告后),参考下面文字提示模板补充提示:

<简洁总结报告>
若需修改可以直接发送修改意见
🔗 查看更多: 如需查看完整架构详情、历史报告及更多风险分析,请前往 [腾讯云智能顾问控制台](https://console.cloud.tencent.com/advisor?archId={{ArchId}}&plugin=cloud-inspection-sdk)

⚠️ 重要: [腾讯云智能顾问控制台] 对应链接为免密登录链接每次都必须重新生成,不可缓存或复用之前生成的链接。每次向用户展示时,都必须重新调用 scripts/login_url.py 生成新的链接。


注意事项与安全规范

密钥安全
  1. 严禁将 AK/SK 硬编码在代码中,必须通过环境变量传入
  2. 建议使用子账号密钥,仅授予 QcloudAdvisorReadOnlyAccess 权限
  3. 生产环境推荐使用 STS 临时密钥,设置 TENCENTCLOUD_TOKEN
API 限制
  • 所有接口限制 20 次/秒(维度:API + 接入地域 + 子账号)
  • 地域默认 ap-guangzhou,Region 为可选参数
平台兼容性
  • 所有脚本均为 Python 实现,跨平台兼容 macOS、Linux 和 Windows
免密链接
  • 默认有效期 30 分钟,可通过 TENCENTCLOUD_STS_DURATION 调整(最大 7200 秒)
  • 当返回结果包含架构图时,只需为第一张架构图生成免密登录控制台链接
  • 以 [腾讯云智能顾问控制台](免密登录URL) 超链接形式展示,严禁直接展示完整 URL
  • 每次展示都必须重新调用 login_url.py 生成新链接,不可缓存或复用

错误处理

  • 如果某个接口调用失败,报告中对应模块显示"数据获取失败"提示,不影响其他模块
  • HTML 转 PNG 依赖 Python 截图能力,可能需要安装额外依赖

参考资料(按需加载)

文档说明
{baseDir}/references/api/DescribeArchScanReportLastInfo.md获取最新报告ID接口
{baseDir}/references/api/DescribeArchScanOverviewInfo.md巡检概览接口
{baseDir}/references/api/DescribeArchRiskTrendInfo.md风险趋势接口
{baseDir}/references/api/DescribeScanPluginRiskTrendListInfo.md风险明细列表接口
{pluginDir}/ReportDesignSpec.md报告内容与样式规范

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts) in skills/cloudq/references/plugins/tsa-risk of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • ReportDesignSpec.md
  • scripts/generate_report_default.py
  • scripts/html_to_png.py
  • scripts/risk_fetch_data.py
  • template/default/coral.json
  • template/default/forest.json
  • template/default/lavender.json
  • template/default/ocean.json
  • template/default/slate.json
  • template/default/sunset.json

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Tsa Risk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tsa Risk compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tsa Risk this skillLeoYeAI/openclaw-master-skills2.2k—~1.7kAutomated safety check: NotesMIT
Riskalsk1992/CloddsBot3k—~2.4kAutomated safety check: PassMIT
Trader Riskruvnet/ruflo74k—~358Automated safety check: NotesMIT
Risk Management Specialistalirezarezvani/claude-skills28k1 repos~4.1kAutomated safety check: PassMIT
Conducting Cyber Risk Assessment With Nist 800 30mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Prediction Market Risk Reviewaffaan-m/ECC276k1 repos~471Automated safety check: PassMIT

Similar skills

  • Risk

    alsk1992/CloddsBot

    Unified risk engine with VaR, stress testing, volatility regimes, and automated controls

    3k GitHub stars~2.4k tokensUpdated 7 days ago
    Testing & QAAuto-check passed
  • Trader Risk

    ruvnet/ruflo

    Assess portfolio risk using npx neural-trader — VaR, CVaR, Sharpe, position sizing, circuit breaker status

    74k GitHub stars~358 tokensUpdated today
    Auto-check: notes
  • Risk Management Specialist

    alirezarezvani/claude-skills

    Medical device risk management specialist implementing ISO 14971 throughout product lifecycle.

    28k GitHub starsUsed in 1 repo~4.1k tokens
    Legal & ComplianceAuto-check passed
  • Conducting Cyber Risk Assessment With Nist 800 30

    mukul975/Anthropic-Cybersecurity-Skills

    Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Review prediction-market, basket, oracle, and trading-agent workflows for compliance, safety, data-quality, privacy, and execution risk.

    276k GitHub starsUsed in 1 repo~471 tokens
    Data & AnalyticsAuto-check passed
  • Portfolio Risk Metrics

    wshobson/agents

    Covers portfolio risk measurement with VaR, CVaR, Sharpe, Sortino and drawdown, plus guidance on limits, stress tests and tail risk.

    40k GitHub starsUsed in 12 repos~502 tokens
    Business, Finance & HRAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Tsa Risk

What does Tsa Risk do?

腾讯云智能顾问架构风险巡检分析报告生成工具。用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从API拉取数据并生成移动端友好的HTML可视化报告,最终将HTML转换为PNG图片输出。当用户提到智能顾问架构巡检、风险分析、巡检报告、架构图风险、腾讯云巡检等关键词时或对当前报告内容修改时,请务必使用此插件。. Tsa Risk is an agent skill from LeoYeAI/openclaw-master-skills.

How do I install Tsa Risk in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill tsa-risk -a claude-code`. Or copy the skill folder (skills/cloudq/references/plugins/tsa-risk in LeoYeAI/openclaw-master-skills) into .claude/skills/tsa-risk in your project. Claude Code loads it when a task matches its description.

How do I install Tsa Risk in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill tsa-risk -a codex`. Or copy the skill folder (skills/cloudq/references/plugins/tsa-risk in LeoYeAI/openclaw-master-skills) into .agents/skills/tsa-risk in your project. Codex loads it when a task matches its description.

Can I use Tsa Risk in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill tsa-risk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tsa-risk, .gemini/skills/tsa-risk, .github/skills/tsa-risk and .opencode/skills/tsa-risk in your project.

What does Tsa Risk need to run?

Going by SKILL.md and its folder, Tsa Risk needs Python for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named TENCENTCLOUD_SECRET_KEY and TENCENTCLOUD_TOKEN. Our summary lists: Python 3; A credential in TENCENTCLOUD_SECRET_KEY; A credential in TENCENTCLOUD_TOKEN. Its frontmatter pre-approves these tools: Bash, Read, Grep, Write.

Does Tsa Risk access the network?

SKILL.md names 1 domain. In commands or code: console.cloud.tencent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Tsa Risk safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tsa Risk use?

Tsa Risk is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tsa Risk use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tsa Risk?

Skills that share tags, products or a category with Tsa Risk: Risk (alsk1992/CloddsBot, 3k stars), Trader Risk (ruvnet/ruflo, 74k stars), Risk Management Specialist (alirezarezvani/claude-skills, 28k stars) and Conducting Cyber Risk Assessment With Nist 800 30 (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tsa Risk?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.