Solidity Security
wshobson/agents
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.
Write, port, review, or test Solid 2 UI in OpenClaw (Control UI, plugin views, Canvas hosts), including state ownership, Lit interop during the migration, native overlays, testing, performance, and…
$ npx skills add openclaw/openclaw --skill solid -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openclaw/openclaw solid --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/solid .claude/skills/solid && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "solid" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/solid into .claude/skills/solid/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solid", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openclaw/openclaw/tree/main/.agents/skills/solidType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openclaw/openclaw --skill solid -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openclaw/openclaw solid --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/solid .agents/skills/solid && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "solid" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/solid into .agents/skills/solid/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solid", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill solid -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openclaw/openclaw solid --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/solid .cursor/skills/solid && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "solid" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/solid into .cursor/skills/solid/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solid", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openclaw/openclaw.git --path .agents/skills/solid--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openclaw/openclaw --skill solid -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openclaw/openclaw solid --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/solid .gemini/skills/solid && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "solid" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/solid into .gemini/skills/solid/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solid", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openclaw/openclaw solidInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openclaw/openclaw --skill solid -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/solid .github/skills/solid && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "solid" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/solid into .github/skills/solid/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solid", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill solid -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openclaw/openclaw solid --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/solid .opencode/skills/solid && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "solid" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/solid into .opencode/skills/solid/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "solid", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
solidWrite, port, review, or test Solid 2 UI in OpenClaw (Control UI, plugin views, Canvas hosts), including state ownership, Lit interop during the migration, native overlays, testing, performance, and…
Solid is an agent skill from openclaw/openclaw. Write, port, review, or test Solid 2 UI in OpenClaw (Control UI, plugin views, Canvas hosts), including state ownership, Lit interop during the migration, native overlays, testing, performance, and lessons learned.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `references/components.md`, `references/lessons.md` and `references/lit-interop.md`).
The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5843d60. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Solid loads about 1.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 574 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openclaw/openclaw at commit 5843d60, republished under its MIT licence (© openclaw). 574 words, ~1,576 tokens.
.claude/skills/solid/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.The Control UI, plugin views (extensions/x, extensions/workboard), and the Canvas A2UI hosts render with Solid 2 (solid-js, @solidjs/web, @solidjs/signals, compiled by @solidjs/vite-plugin/@solidjs/compiler). Lit 3 and Web Awesome are being removed. Until the last Lit file is gone, ported Solid code runs next to unported Lit at every commit.
Read ui/AGENTS.md first; its state-ownership rules apply to Solid unchanged. Use the exact installed Solid pins from the owning package.json. Dependencies follow the repository's seven-day release-age gate.
lib/sessions/*, caches, persistence, and mutation authority keep synchronous mutate-then-read semantics. Solid 2 writes become visible only after a microtask flush, so authoritative state never lives in a signal. → state and ownershipui/src/lib/reactive/ (one per owner and scope, never a second store) and useApplication() for the application context.openclaw-* tag as a plain host element in light DOM; CSS and E2E select it. Never rename a tag or a class. → componentsdefineSolidBridge. → Lit interopcreateMemo before createSignal; no copies of owner state; no defensive guards for states the owner already excludes. Prefer smaller code than the Lit you replace.An illustrative component (the tag is an example): it renders its host tag, reads an owner through a projection, and derives instead of copying state.
import { createMemo, Show } from "solid-js";
import { useApplication } from "../lib/reactive/context.ts";
import { projectAgents } from "../lib/reactive/domain-capabilities.ts";
export function AgentCount(props: { compact?: boolean }) {
const app = useApplication();
// Reads through to the synchronous owner; disposed with this component's owner.
const agents = projectAgents(app.agents);
// Never destructure props: reads must stay reactive.
const count = createMemo(() => agents.read().agentsList?.agents.length ?? 0);
return (
<openclaw-agent-count class={["agent-count", { "agent-count--compact": props.compact }]}>
<Show when={count() > 0} fallback={<span class="muted">—</span>}>
<span>{count()}</span>
</Show>
</openclaw-agent-count>
);
}Use jsxImportSource: "@solidjs/web" and its JSX types, not Solid 1's solid-js/web.
on:x, attr:x, bool:x, classList, and use: are gone in Solid 2; they compile to literal attributes or no-ops (lint flags them). prop: is the only namespace left.onClick). onWaSelect listens to waselect; dashed custom events need onWa-select or a listen(...) ref factory.flush(). Don't write-then-read in handlers; derive.await in an async memo are untracked, and async memos get no AbortSignal.onCleanup inside them does nothing.aria-pressed={pressed() ? "true" : "false"}, never a boolean.createResource, onMount, mergeProps, Context.Provider) don't carry over: use async computations, onSettled, merge, and the context component itself.More, each with its root cause: lessons learned.
mountSolid, waitForSolid/flush, renderSolidRef, and the Solid application-context provider live in ui/src/test-helpers/. .test.tsx files are discovered. Keep assertions when you replace a harness. Visual changes need pnpm ui:parity or inspected before/after screenshots. → testing
| Topic | Read when |
|---|---|
| components | porting or writing components: Lit → Solid table, JSX bindings, events, refs, styles |
| state and ownership | touching owners, projections, async reads, lifetimes, parking, chat render lifecycle |
| Lit interop | a Lit caller uses your component, or your component hosts unported Lit |
| overlays | menus, popovers, tooltips, dialogs, focus, positioning, the platform floor |
| testing | unit, browser, E2E, WebKit, parity, retention suites |
| performance | startup bundle, lazy loading, render budgets |
| plugins | building a plugin's Control UI view in Solid |
| migration | porting the remaining Lit, the final sweep, the inventory |
| lessons learned | before a new kind of change; most entries cost a failed CI run to learn |
© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references) in .agents/skills/solid of openclaw/openclaw.
Open the folder on GitHubat commit 5843d60
Solid next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Solid this skillopenclaw/openclaw | 392k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Solidity Securitywshobson/agents | 40k | 12 repos | ~892 | Automated safety check: Pass | MIT | |
| Saleor Port Changessaleor/saleor | 23k | — | ~969 | Automated safety check: Pass | BSD-3-Clause | |
| Porthashgraph-online/awesome-codex-plugins | 1.3k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Platform PortFastLED/FastLED | 7.5k | — | ~580 | Automated safety check: Pass | MIT | |
| Detecting Port Scanning With Fail2banmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 |
wshobson/agents
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.
saleor/saleor
Forward-ports or backports a single PR or branch onto the currently checked-out Saleor branch, handling GraphQL version markers and migration numbering along the way.
hashgraph-online/awesome-codex-plugins
Make an existing single-player web game multiplayer in a Homie studio.
FastLED/FastLED
Guide porting FastLED to new MCU platforms, including int.h types, clockless drivers, SPI implementations, and platform detection.
mukul975/Anthropic-Cybersecurity-Skills
Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting…
ramziddin/solid-skills
A skill your agent uses when writing code, implementing features, refactoring, planning architecture, designing systems, reviewing code, or debugging.
openclaw/openclaw
Summarize CodexBar local cost logs by model for Codex or Claude, including current or full breakdowns.
openclaw/openclaw
Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.
openclaw/openclaw
Feishu document read/write workflows. An agent skill from openclaw/openclaw.
openclaw/openclaw
Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.
openclaw/openclaw
Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.
openclaw/openclaw
A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.
Write, port, review, or test Solid 2 UI in OpenClaw (Control UI, plugin views, Canvas hosts), including state ownership, Lit interop during the migration, native overlays, testing, performance, and…. Solid is an agent skill from openclaw/openclaw. Write, port, review, or test Solid 2 UI in OpenClaw (Control UI, plugin views, Canvas hosts), including state ownership, Lit interop during the migration, native overlays, testing, performance, and lessons learned.
Run `npx skills add openclaw/openclaw --skill solid -a claude-code`. Or copy the skill folder (.agents/skills/solid in openclaw/openclaw) into .claude/skills/solid in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openclaw/openclaw --skill solid -a codex`. Or copy the skill folder (.agents/skills/solid in openclaw/openclaw) into .agents/skills/solid in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill solid -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/solid, .gemini/skills/solid, .github/skills/solid and .opencode/skills/solid in your project.
Going by SKILL.md and its folder, Solid needs the command-line tools its instructions call (pnpm).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Solid is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Solid: Solidity Security (wshobson/agents, 40k stars), Saleor Port Changes (saleor/saleor, 23k stars), Port (hashgraph-online/awesome-codex-plugins, 1.3k stars) and Platform Port (FastLED/FastLED, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,658 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 11, 2026.
Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.