Personal productivity system for task and capacity management.

MITAuto-check passedProduct & Project Management

Install Yatta

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill yatta -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills yatta --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/openclaw-yatta-skill .claude/skills/yatta && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
yatta
GitHub stars
2.2k
Token cost
~6.4k tokens
SKILL.md length
1,043 words
Files
15 (incl. scripts)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

Personal productivity system for task and capacity management.

  • Works in 3 steps: Get Your API Key → Configure the Skill → Test Connection
  • Tasks that involve Site reliability engineering
  • SKILL.md covers ⚠️ Security Warning, Setup, 🔒 Security: Input Validation and 🎯 Invocation Policy, plus 3 more sections
  • Runs Shell scripts from its folder; calls jq, curl and openssl; reaches zunahvofybvxpptjkwxk.supabase.co and api.yattadone.com; needs YATTA_API_KEY

What it does

Yatta is an agent skill from LeoYeAI/openclaw-master-skills. Personal productivity system for task and capacity management. Create and organize tasks with rich attributes (priority, effort, complexity, tags), track time and streaks, manage capacity across projects and contexts, view Eisenhower Matrix prioritization, sync calendar subscriptions, handle delegation and follow-ups, and get AI-powered insights. Supports batch operations, multi-project workflows, and real-time capacity planning to prevent overcommitment. Security: v0.2.0 eliminates RCE vulnerability from v0.1.3…

Its SKILL.md is about 6.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts (for example `API-REFERENCE.md`, `CHANGELOG.md` and `README.md`).

It sits in Product & Project Management, covering Site reliability engineering and Prioritization frameworks. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Tasks that involve Site reliability engineering
  • Tasks that involve Prioritization frameworks

Example prompts

  • “/yatta”

Requirements

  • A Bash shell
  • A credential in YATTA_API_KEY

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Get Your API Key
  2. Configure the Skill
  3. Test Connection

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • jq
    • curl
    • openssl
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • zunahvofybvxpptjkwxk.supabase.co
    • api.yattadone.com
    • calendar.google.com

    Also links to:

    • yattadone.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • YATTA_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Yatta loads about 6.4k tokens when it runs. Until then it costs about 154 tokens; SKILL.md has 1,043 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~154
When it runs · the whole SKILL.md, loaded when a task matches
~6.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,043 words, ~6,448 tokens.

Download SKILL.mdSave it as .claude/skills/yatta/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
yatta
description
Personal productivity system for task and capacity management. Create and organize tasks with rich attributes (priority, effort, complexity, tags), track time and streaks, manage capacity across projects and contexts, view Eisenhower Matrix prioritization, sync calendar subscriptions, handle delegation and follow-ups, and get AI-powered insights. Supports batch operations, multi-project workflows, and real-time capacity planning to prevent overcommitment. Security: v0.2.0 eliminates RCE vulnerability from v0.1.3 (shell/JSON injection in examples), adds endpoint verification, safe jq patterns throughout.
homepage
https://github.com/chrisagiddings/openclaw-yatta-skill
disable-model-invocation
true
metadata
{"openclaw":{"emoji":"✅","requires":{"env":["YATTA_API_KEY","YATTA_API_URL"],"bins":["curl","jq"],"anyBins":["openssl","dig"]},"primaryEnv":"YATTA_API_KEY","di…

Yatta! Skill

Interact with Yatta! task management system via API. Requires an API key from your Yatta! account.

⚠️ Security Warning

This skill can perform DESTRUCTIVE operations on your Yatta! account:

  • Task Management: Create, update, archive, and batch-modify tasks
  • Project Management: Create, update, and archive projects
  • Context Management: Create contexts and assign them to tasks
  • Comment Management: Add, update, and delete task comments
  • Calendar Management: Create, sync, and modify calendar subscriptions
  • Follow-Up Management: Update delegation schedules and mark complete
  • Capacity Management: Trigger capacity computations

Operation Types:

Read-Only Operations (✅ Safe):

  • List tasks, projects, contexts, comments
  • Get analytics, insights, streaks
  • View capacity and calendar data
  • Get Eisenhower Matrix view
  • All GET requests

Destructive Operations (⚠️ Modify or delete data):

  • Create/update/archive tasks (POST, PUT, DELETE)
  • Batch update tasks
  • Create/update projects
  • Create/assign contexts
  • Add/update/delete comments
  • Add/sync calendar subscriptions
  • Update follow-up schedules
  • All POST, PUT, DELETE requests

Best Practices:

  1. Review commands before running - Check what the API call will do
  2. No undo for deletions - Archived tasks can be recovered, but some operations are permanent
  3. Test on non-critical data first - Create test tasks/projects to verify behavior
  4. Batch operations affect multiple items - Be extra careful with batch updates
  5. Real-time sync - Changes appear in Yatta! UI immediately

For detailed API operation documentation, see API-REFERENCE.md.

Setup

⚠️ API Key Security

Your Yatta! API key provides FULL access to your account:

  • Can create, read, update, and delete ALL tasks, projects, contexts
  • Can modify calendar subscriptions and follow-up schedules
  • Can archive data and trigger computations
  • No read-only scopes available - keys have full permissions

Security Best Practices:

  • Store keys in a secure password manager (1Password CLI recommended)
  • Use environment variables, never hardcode keys in scripts
  • Rotate keys regularly (every 90 days recommended)
  • Create separate keys for different integrations
  • Revoke unused keys immediately
  • Never commit keys to version control
1. Get Your API Key
  1. Log into Yatta! app
  2. Go to Settings → API Keys
  3. Create new key (e.g., "OpenClaw Integration")
  4. Copy the yatta_... key
  5. Store it securely
2. Configure the Skill

Option A: Environment Variables (Recommended)

bash
# Add to your shell profile (~/.zshrc, ~/.bashrc)
export YATTA_API_KEY="yatta_your_key_here"
export YATTA_API_URL="https://zunahvofybvxpptjkwxk.supabase.co/functions/v1"  # Default

Option B: 1Password CLI (Most Secure)

bash
# Store key in 1Password
op item create --category=API_CREDENTIAL \
  --title="Yatta API Key" \
  api_key[password]="yatta_your_key_here"

# Use in commands
export YATTA_API_KEY=$(op read "op://Private/Yatta API Key/api_key")
⚠️ API Endpoint Verification

The default API endpoint is hosted on Supabase:

Why Supabase?

  • Yatta! uses Supabase as its backend infrastructure
  • The URL is a direct Supabase project endpoint
  • Branded URL (api.yattadone.com) is on the roadmap

Verification steps:

  1. Verify app ownership:

  2. Check SSL certificate:

    bash
    openssl s_client -connect zunahvofybvxpptjkwxk.supabase.co:443 \
      -servername zunahvofybvxpptjkwxk.supabase.co < /dev/null 2>&1 \
      | openssl x509 -noout -subject -issuer
  3. Run verification script:

    bash
    # Automated endpoint verification
    bash scripts/verify-endpoint.sh
  4. Contact support if uncertain:

Branded URL (Coming Soon):

  • Future: https://api.yattadone.com/v1
  • Current Supabase URL will continue to work
  • Skill will auto-update default when branded URL is live

Security note: Only send your API key to endpoints you trust and have verified. If you prefer to wait for the branded API URL, that's a valid security choice.

3. Test Connection
bash
curl -s "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[:3]'  # Show first 3 tasks

🔒 Security: Input Validation

⚠️ CRITICAL: This skill is vulnerable to shell and JSON injection if user input is not properly sanitized.

Safe Coding Patterns (Required)

ALL examples in this skill use safe patterns:

  • ✅ JSON payloads: Built with jq -n --arg (prevents JSON injection)
  • ✅ URL parameters: Encoded with jq -sRr @uri (prevents shell injection)
  • ✅ No direct string interpolation in JSON or URLs
Quick Reference
bash
# ✅ SAFE: JSON construction
PAYLOAD=$(jq -n --arg title "$TITLE" '{title: $title}')
curl -d "$PAYLOAD" ...

# ✅ SAFE: URL encoding
TASK_ID_ENCODED=$(printf %s "$TASK_ID" | jq -sRr @uri)
curl "$API_URL/tasks/$TASK_ID_ENCODED" ...

# ✅ BEST: Use wrapper functions
source scripts/yatta-safe-api.sh
yatta_create_task "Finish report" "high"
Why This Matters

Unsafe patterns can lead to:

  • API key exfiltration
  • Arbitrary command execution (RCE)
  • Data manipulation and corruption

See SECURITY.md for:

  • Detailed vulnerability examples
  • Attack scenarios and impact
  • Safe coding patterns
  • Testing guidelines

See scripts/yatta-safe-api.sh for:

  • Pre-built safe wrapper functions
  • Ready-to-use examples
  • Zero boilerplate

🎯 Invocation Policy

This skill requires MANUAL invocation only.

Policy Details

Setting: disable-model-invocation: true

What this means:

  • Agent will NOT automatically invoke Yatta! operations
  • User must explicitly request each action
  • No background task creation or modification
  • All operations require clear user intent
Show full SKILL.md (409 more words)Show less
Why Manual-Only?

Security rationale:

  1. Full account access: Yatta! API keys grant complete account access
  2. No read-only scopes: No way to limit API key permissions
  3. Destructive operations: Can delete/archive/modify data permanently
  4. User oversight required: Changes should be reviewed before execution
Examples

❌ Autonomous (NOT allowed):

User: "I should probably archive old tasks"
Agent: *silently archives tasks without confirmation*

✅ Manual (Required):

User: "Please archive tasks older than 30 days"
Agent: *executes explicit request, shows results*
Policy Enforcement

How it works:

  1. Skill metadata declares disable-model-invocation: true
  2. OpenClaw respects this setting
  3. Agent requires explicit user commands
  4. No autonomous background operations

Verification:

bash
# Check package.json
jq '.openclaw["disable-model-invocation"]' package.json
# Should output: true

# Check SKILL.md frontmatter
grep "disable-model-invocation" SKILL.md
# Should show: "disable-model-invocation":true
If You See Unexpected Operations

If Yatta! operations happen without your explicit request:

  1. Stop immediately - This indicates a policy violation
  2. Revoke API key - Create new key in Yatta! Settings → API Keys
  3. File issue - https://github.com/chrisagiddings/openclaw-yatta-skill/issues
  4. Report to OpenClaw - Policy enforcement bug

This should never happen - manual invocation is a security requirement.


Tasks API

List Tasks

All tasks:

bash
curl -s "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Filter by status:

bash
# TODO tasks only
curl -s "$YATTA_API_URL/tasks?status=todo" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

# Doing (active) tasks
curl -s "$YATTA_API_URL/tasks?status=doing" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

# Completed tasks
curl -s "$YATTA_API_URL/tasks?status=done" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Filter by priority:

bash
# High priority tasks
curl -s "$YATTA_API_URL/tasks?priority=high" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {title, due_date, priority}'

Filter by project:

bash
# Get project ID first
PROJECT_ID=$(curl -s "$YATTA_API_URL/projects" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq -r '.[] | select(.name=="Website Redesign") | .id')

# Get tasks for that project (URL-encode query parameter)
PROJECT_ID_ENCODED=$(printf %s "$PROJECT_ID" | jq -sRr @uri)
curl -s "$YATTA_API_URL/tasks?project_id=$PROJECT_ID_ENCODED" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Filter by matrix state:

bash
# Delegated tasks
curl -s "$YATTA_API_URL/tasks?matrix_state=delegated" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {title, delegated_to, follow_up_date}'

# Waiting tasks
curl -s "$YATTA_API_URL/tasks?matrix_state=waiting" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Date range queries:

bash
# Tasks due this week
WEEK_END=$(date -v+7d "+%Y-%m-%d")
curl -s "$YATTA_API_URL/tasks?due_date_lte=$WEEK_END" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {title, due_date}'

# Overdue tasks
TODAY=$(date "+%Y-%m-%d")
curl -s "$YATTA_API_URL/tasks?due_date_lte=$TODAY&status=todo" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {title, due_date}'

Pagination:

bash
# First 50 tasks
curl -s "$YATTA_API_URL/tasks?limit=50&offset=0" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

# Next 50 tasks
curl -s "$YATTA_API_URL/tasks?limit=50&offset=50" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Archived tasks:

bash
curl -s "$YATTA_API_URL/tasks?archived=true" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Create Task

Simple task:

bash
curl -s "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "Finish report",
    "priority": "high"
  }' \
  | jq '.'

Task with full details:

bash
curl -s "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "Review Q1 numbers",
    "description": "Go through revenue, costs, and projections",
    "priority": "high",
    "due_date": "2026-02-15",
    "effort_points": 5,
    "project_id": "uuid-of-project",
    "matrix_state": "active"
  }' \
  | jq '.'

Delegated task with follow-up:

bash
curl -s "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "Website redesign",
    "delegated_to": "Dev Team",
    "matrix_state": "delegated",
    "follow_up_schedule": {
      "type": "weekly",
      "day_of_week": "monday",
      "next_follow_up": "2026-02-17"
    }
  }' \
  | jq '.'

Recurring task:

bash
curl -s "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "Team standup",
    "recurrence_rule": {
      "frequency": "daily",
      "interval": 1,
      "days_of_week": ["monday", "tuesday", "wednesday", "thursday", "friday"]
    },
    "effort_points": 1
  }' \
  | jq '.'
Update Task

Update single task:

bash
# ✅ SAFE: Use jq to build JSON payload
TASK_ID="uuid-of-task"
PAYLOAD=$(jq -n \
  --arg id "$TASK_ID" \
  --arg status "done" \
  --arg completed_at "$(date -u +"%Y-%m-%dT%H:%M:%SZ")" \
  '{id: $id, status: $status, completed_at: $completed_at}')

curl -s -X PUT "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'

Batch update tasks:

bash
curl -s -X PUT "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "ids": ["uuid-1", "uuid-2", "uuid-3"],
    "priority": "high",
    "project_id": "project-uuid"
  }' \
  | jq '.'
Archive Task
bash
# ✅ SAFE: Use jq to build JSON payload
TASK_ID="uuid-of-task"
PAYLOAD=$(jq -n --arg id "$TASK_ID" '{id: $id}')

curl -s -X DELETE "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'

Projects API

List Projects
bash
# All projects
curl -s "$YATTA_API_URL/projects" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

# With task counts
curl -s "$YATTA_API_URL/projects?with_counts=true" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {name, task_count, open_count}'
Create Project
bash
curl -s "$YATTA_API_URL/projects" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Website Redesign",
    "description": "Complete overhaul of company site",
    "color": "#3b82f6",
    "icon": "🌐"
  }' \
  | jq '.'
Update Project
bash
# ✅ SAFE: Use jq to build JSON payload
PROJECT_ID="uuid-of-project"
PAYLOAD=$(jq -n \
  --arg id "$PROJECT_ID" \
  --arg name "Website Redesign v2" \
  --argjson archived false \
  '{id: $id, name: $name, archived: $archived}')

curl -s -X PUT "$YATTA_API_URL/projects" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'
Get Project Tasks
bash
# ✅ SAFE: URL-encode path parameter
PROJECT_ID="uuid-of-project"
PROJECT_ID_ENCODED=$(printf %s "$PROJECT_ID" | jq -sRr @uri)

curl -s "$YATTA_API_URL/projects/$PROJECT_ID_ENCODED/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Contexts API

List Contexts
bash
# All contexts
curl -s "$YATTA_API_URL/contexts" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

# With task counts
curl -s "$YATTA_API_URL/contexts?with_counts=true" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {name, task_count}'
Create Context
bash
curl -s "$YATTA_API_URL/contexts" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "@deep-focus",
    "color": "#8b5cf6",
    "icon": "🧠"
  }' \
  | jq '.'
Assign Context to Task
bash
# ✅ SAFE: Use jq to build JSON payload with arrays
TASK_ID="uuid-of-task"
CONTEXT_ID="uuid-of-context"

PAYLOAD=$(jq -n \
  --arg task_id "$TASK_ID" \
  --arg context_id "$CONTEXT_ID" \
  '{task_id: $task_id, context_ids: [$context_id]}')

curl -s -X POST "$YATTA_API_URL/contexts/assign" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'
Get Task Contexts
bash
# ✅ SAFE: URL-encode path parameter
TASK_ID="uuid-of-task"
TASK_ID_ENCODED=$(printf %s "$TASK_ID" | jq -sRr @uri)

curl -s "$YATTA_API_URL/tasks/$TASK_ID_ENCODED/contexts" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Get Context Tasks
bash
# ✅ SAFE: URL-encode path parameter
CONTEXT_ID="uuid-of-context"
CONTEXT_ID_ENCODED=$(printf %s "$CONTEXT_ID" | jq -sRr @uri)

curl -s "$YATTA_API_URL/contexts/$CONTEXT_ID_ENCODED/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Comments API

List Task Comments
bash
# ✅ SAFE: URL-encode path parameter
TASK_ID="uuid-of-task"
TASK_ID_ENCODED=$(printf %s "$TASK_ID" | jq -sRr @uri)

curl -s "$YATTA_API_URL/tasks/$TASK_ID_ENCODED/comments" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Add Comment
bash
# ✅ SAFE: URL-encode path + jq for JSON
TASK_ID="uuid-of-task"
TASK_ID_ENCODED=$(printf %s "$TASK_ID" | jq -sRr @uri)
PAYLOAD=$(jq -n \
  --arg content "Waiting on client feedback before proceeding" \
  '{content: $content}')

curl -s -X POST "$YATTA_API_URL/tasks/$TASK_ID_ENCODED/comments" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'
Update Comment
bash
# ✅ SAFE: Use jq to build JSON payload
COMMENT_ID="uuid-of-comment"
PAYLOAD=$(jq -n \
  --arg id "$COMMENT_ID" \
  --arg content "Client responded, moving forward" \
  '{id: $id, content: $content}')

curl -s -X PUT "$YATTA_API_URL/task-comments" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'
Delete Comment
bash
# ✅ SAFE: Use jq to build JSON payload
COMMENT_ID="uuid-of-comment"
PAYLOAD=$(jq -n --arg id "$COMMENT_ID" '{id: $id}')

curl -s -X DELETE "$YATTA_API_URL/task-comments" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'

Follow-Ups API

Get Today's Follow-Ups
bash
curl -s "$YATTA_API_URL/follow-ups" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {title, delegated_to, follow_up_date}'
Get Follow-Ups for Date
bash
DATE="2026-02-15"
curl -s "$YATTA_API_URL/follow-ups?date=$DATE" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Mark Follow-Up Complete
bash
# ✅ SAFE: URL-encode path parameter
TASK_ID="uuid-of-task"
TASK_ID_ENCODED=$(printf %s "$TASK_ID" | jq -sRr @uri)

curl -s -X POST "$YATTA_API_URL/tasks/$TASK_ID_ENCODED/follow-up" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}' \
  | jq '.'
Update Follow-Up Schedule
bash
# ✅ SAFE: URL-encode path + jq for JSON
TASK_ID="uuid-of-task"
TASK_ID_ENCODED=$(printf %s "$TASK_ID" | jq -sRr @uri)

PAYLOAD=$(jq -n \
  --arg type "every_n_days" \
  --argjson interval 3 \
  --arg next_follow_up "2026-02-12" \
  '{type: $type, interval: $interval, next_follow_up: $next_follow_up}')

curl -s -X PUT "$YATTA_API_URL/tasks/$TASK_ID_ENCODED/follow-up-schedule" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD" \
  | jq '.'

Calendar API

List Calendar Subscriptions
bash
curl -s "$YATTA_API_URL/calendar/subscriptions" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Add Calendar Subscription
bash
curl -s -X POST "$YATTA_API_URL/calendar/subscriptions" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Work Calendar",
    "ical_url": "https://calendar.google.com/calendar/ical/...",
    "default_context_id": "context-uuid"
  }' \
  | jq '.'
Trigger Calendar Sync
bash
# ✅ SAFE: URL-encode path parameter
SUBSCRIPTION_ID="uuid-of-subscription"
SUBSCRIPTION_ID_ENCODED=$(printf %s "$SUBSCRIPTION_ID" | jq -sRr @uri)

curl -s -X POST "$YATTA_API_URL/calendar/subscriptions/$SUBSCRIPTION_ID_ENCODED/sync" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
List Calendar Events
bash
# Events for date range
START="2026-02-10"
END="2026-02-17"
curl -s "$YATTA_API_URL/calendar/events?start=$START&end=$END" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Capacity API

Get Today's Capacity
bash
curl -s "$YATTA_API_URL/capacity/today" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '{date, utilization_percent, status, used_minutes, total_minutes}'
Get Capacity for Date Range
bash
START="2026-02-10"
END="2026-02-17"
curl -s "$YATTA_API_URL/capacity?start=$START&end=$END" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.[] | {date, status, utilization_percent}'
Trigger Capacity Computation
bash
curl -s -X POST "$YATTA_API_URL/capacity/compute" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Analytics API

Get Summary Insights
bash
curl -s "$YATTA_API_URL/analytics/summary" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Get Velocity Metrics
bash
curl -s "$YATTA_API_URL/analytics/velocity" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Get Task Distribution
bash
curl -s "$YATTA_API_URL/analytics/distribution" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '{by_status, by_priority, by_matrix_state}'
Get Streaks
bash
curl -s "$YATTA_API_URL/analytics/streaks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'
Get AI Insights
bash
curl -s "$YATTA_API_URL/analytics/insights" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '.'

Matrix Endpoint

Get Eisenhower Matrix View
bash
curl -s "$YATTA_API_URL/tasks/matrix" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq '{do_first, schedule, delegate, eliminate}'

Common Patterns

Daily Workflow Automation

Morning briefing:

bash
#!/bin/bash
echo "=== Today's Tasks ==="
curl -s "$YATTA_API_URL/tasks?status=todo&due_date_lte=$(date +%Y-%m-%d)" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq -r '.[] | "- [\(.priority)] \(.title)"'

echo ""
echo "=== Follow-Ups Due ==="
curl -s "$YATTA_API_URL/follow-ups" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq -r '.[] | "- \(.title) (delegated to: \(.delegated_to))"'

echo ""
echo "=== Capacity Status ==="
curl -s "$YATTA_API_URL/capacity/today" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq -r '"Utilization: \(.utilization_percent)% - \(.status)"'
Create Task from Email
bash
#!/bin/bash
# Extract email subject and body
SUBJECT="$1"
BODY="$2"

curl -s "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "'"$SUBJECT"'",
    "description": "'"$BODY"'",
    "priority": "medium",
    "import_source": "email"
  }' \
  | jq -r '"Task created: \(.title)"'
Weekly Planning Report
bash
#!/bin/bash
WEEK_START=$(date -v+mon "+%Y-%m-%d")
WEEK_END=$(date -v+sun "+%Y-%m-%d")

echo "=== Week of $WEEK_START ==="
curl -s "$YATTA_API_URL/capacity?start=$WEEK_START&end=$WEEK_END" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq -r '.[] | "\(.date): \(.status) (\(.utilization_percent)%)"'

echo ""
echo "=== Tasks Due This Week ==="
curl -s "$YATTA_API_URL/tasks?due_date_gte=$WEEK_START&due_date_lte=$WEEK_END" \
  -H "Authorization: Bearer $YATTA_API_KEY" \
  | jq -r '.[] | "[\(.due_date)] \(.title)"'

Error Handling

Check response status:

bash
RESPONSE=$(curl -s -w "\n%{http_code}" "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY")

STATUS=$(echo "$RESPONSE" | tail -n1)
BODY=$(echo "$RESPONSE" | sed '$d')

if [ "$STATUS" -eq 200 ]; then
  echo "$BODY" | jq '.'
else
  echo "Error: HTTP $STATUS"
  echo "$BODY" | jq '.error'
fi

Rate limit handling:

bash
RESPONSE=$(curl -s -i "$YATTA_API_URL/tasks" \
  -H "Authorization: Bearer $YATTA_API_KEY")

# Check X-RateLimit headers
REMAINING=$(echo "$RESPONSE" | grep -i "X-RateLimit-Remaining" | cut -d' ' -f2)
RESET=$(echo "$RESPONSE" | grep -i "X-RateLimit-Reset" | cut -d' ' -f2)

if [ "$REMAINING" -lt 10 ]; then
  echo "Warning: Only $REMAINING requests remaining"
  echo "Rate limit resets at: $(date -r $RESET)"
fi

Tips

  • Store API key securely: Use 1Password CLI, env vars, or secrets manager
  • Use jq for filtering: Pipe responses through jq for clean output
  • Batch operations: Update multiple tasks at once when possible
  • Rate limits: 100 requests/minute per API key
  • Date formats: Always use ISO 8601 (YYYY-MM-DD for dates, YYYY-MM-DDTHH:MM:SSZ for timestamps)
  • Error responses: Include error field with description

Resources

API URL Note

Currently using the direct Supabase Edge Functions URL for reliability:

https://zunahvofybvxpptjkwxk.supabase.co/functions/v1

Branded URLs (yattadone.com/api) will be available in a future release once proxy configuration is resolved with the hosting provider.

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (scripts) in skills/openclaw-yatta-skill of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • API-REFERENCE.md
  • CHANGELOG.md
  • README.md
  • SECURITY-ASSESSMENT-ISSUE-15.md
  • SECURITY-ASSESSMENT-ISSUE-16.md
  • SECURITY-ASSESSMENT-ISSUE-17.md
  • SECURITY-ASSESSMENT-v0.2.0.md
  • SECURITY-ASSESSMENT-v0.2.1.md
  • SECURITY-ASSESSMENT-v0.2.2.md
  • SECURITY.md
  • _meta.json
  • package.json
  • scripts/verify-endpoint.sh
  • scripts/yatta-safe-api.sh

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Yatta next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Yatta compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Yatta this skillLeoYeAI/openclaw-master-skills2.2k—~6.4kAutomated safety check: PassMIT
Roadmap Planningrampstackco/claude-skills945—~2.7kAutomated safety check: PassMIT
Roadmap Planningmanager-dot-dev/manager-skills114—~4.9kAutomated safety check: PassMIT
Agile Product Owneralirezarezvani/claude-skills28k3 repos~3.2kAutomated safety check: PassMIT
Prioritization Framework Advisordeanpeters/Product-Manager-Skills7.2k2 repos~4.2kAutomated safety check: PassCustom licence
Strategic Roadmap Planningdeanpeters/Product-Manager-Skills7.2k2 repos~4.7kAutomated safety check: PassCustom licence

Similar skills

  • Roadmap Planning

    rampstackco/claude-skills

    Build a multi-quarter roadmap from a backlog of ideas, requests, and ongoing initiatives.

    945 GitHub stars~2.7k tokensUpdated 3 days ago
    Product & Project ManagementAuto-check passed
  • Roadmap Planning

    manager-dot-dev/manager-skills

    Helps engineering managers plan roadmaps, prioritize work, and communicate priorities effectively — produces the 20% tech debt framework (and its 5 traps), a phased release pressure-test, a…

    114 GitHub stars~4.9k tokensUpdated 5 mo ago
    Product & Project ManagementAuto-check passed
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Product & Project ManagementAuto-check passed
  • Prioritization Framework Advisor

    deanpeters/Product-Manager-Skills

    Picks the right prioritization framework for your stage and context instead of defaulting to RICE or ICE out of habit.

    7.2k GitHub starsUsed in 2 repos~4.2k tokens
    Product & Project ManagementAuto-check passed
  • Strategic Roadmap Planning

    deanpeters/Product-Manager-Skills

    Sequences prioritization, epic definition, and stakeholder alignment into a release plan that ladders up to business outcomes.

    7.2k GitHub starsUsed in 2 repos~4.7k tokens
    Product & Project ManagementAuto-check passed
  • Idea Validator

    aakashg/pm-claude-skills

    A skill your agent uses when the user asks to validate a product idea, stress-test an idea, evaluate whether an idea is good, or decide whether to build something.

    112 GitHub stars~2.3k tokensUpdated 2 mo ago
    Product & Project ManagementAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Yatta

What does Yatta do?

Personal productivity system for task and capacity management. Yatta is an agent skill from LeoYeAI/openclaw-master-skills. Personal productivity system for task and capacity management.

When should I use Yatta?

Yatta fits situations like: tasks that involve Site reliability engineering; tasks that involve Prioritization frameworks.

How do I install Yatta in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill yatta -a claude-code`. Or copy the skill folder (skills/openclaw-yatta-skill in LeoYeAI/openclaw-master-skills) into .claude/skills/yatta in your project. Claude Code loads it when a task matches its description.

How do I install Yatta in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill yatta -a codex`. Or copy the skill folder (skills/openclaw-yatta-skill in LeoYeAI/openclaw-master-skills) into .agents/skills/yatta in your project. Codex loads it when a task matches its description.

Can I use Yatta in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill yatta -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/yatta, .gemini/skills/yatta, .github/skills/yatta and .opencode/skills/yatta in your project.

What does Yatta need to run?

Going by SKILL.md and its folder, Yatta needs a shell for the scripts in its folder, the command-line tools its instructions call (jq, curl, openssl and bash) and credentials named YATTA_API_KEY. Our summary lists: A Bash shell; A credential in YATTA_API_KEY.

Does Yatta access the network?

SKILL.md names 5 domains. In commands or code: zunahvofybvxpptjkwxk.supabase.co, api.yattadone.com and calendar.google.com; the agent is likely to contact these when it follows the instructions. As links in the text: yattadone.com and github.com. This is read from the text; nothing was executed.

Is Yatta safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Yatta use?

Yatta is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Yatta use?

About 6.4k tokens (SKILL.md is roughly 26k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Yatta?

Skills that share tags, products or a category with Yatta: Roadmap Planning (rampstackco/claude-skills, 945 stars), Roadmap Planning (manager-dot-dev/manager-skills, 114 stars), Agile Product Owner (alirezarezvani/claude-skills, 28k stars) and Prioritization Framework Advisor (deanpeters/Product-Manager-Skills, 7.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Yatta?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.