skill-hub

OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.

Safety Notice

This listing is from the official public ClawHub registry. Review SKILL.md and referenced scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "skill-hub" with this command: npx skills add PhenixStar/skill-hub

Skill Hub

Unified skill discovery, security vetting, and installation for OpenClaw.

Commands

Search Skills

Find skills by keyword, category, or credibility score.

python3 scripts/skill-hub-search.py --query "spreadsheet"
python3 scripts/skill-hub-search.py --category "DevOps" --min-score 60
python3 scripts/skill-hub-search.py --query "auth" --live        # include live ClawHub results
python3 scripts/skill-hub-search.py --installed                  # show only installed
python3 scripts/skill-hub-search.py --not-installed --limit 20   # discovery mode

Install Skills

After finding a skill, install via ClawHub:

npx clawhub@latest install <skill-slug>

Vet Skills (Security Scan)

Scan a skill for malicious patterns, prompt injection, and logic weaknesses.

python3 scripts/skill-hub-vet.py --slug google-sheets     # vet single skill
python3 scripts/skill-hub-vet.py --all-installed           # vet all installed
python3 scripts/skill-hub-vet.py --category "DevOps"       # vet category
python3 scripts/skill-hub-vet.py --top 10                  # vet top N unvetted

Status Dashboard

See installed vs catalog coverage, unvetted warnings, recommendations.

python3 scripts/skill-hub-status.py

Quick Check (GitHub API)

Fast check if new skills were added since last sync. Uses gh CLI — no full download needed.

python3 scripts/skill-hub-quick-check.py              # check for updates
python3 scripts/skill-hub-quick-check.py --sync        # auto-sync if updates found
python3 scripts/skill-hub-quick-check.py --query "ai"  # check + search new skills

Browse Full Catalog

Export catalog as formatted table (terminal or markdown), grouped by category.

python3 scripts/skill-hub-table-export.py                          # terminal table
python3 scripts/skill-hub-table-export.py --format markdown        # markdown table
python3 scripts/skill-hub-table-export.py --category "AI"          # filter category

Sync Catalog

Full re-fetch from GitHub awesome-list. Computes credibility, preserves vet results, shows diff.

python3 scripts/skill-hub-sync.py

Credibility Scores (0-100)

TierScoreMeaning
Trusted85-100Curated + vetted + mature
Good60-84Curated or vetted, some signals
Unvetted30-59Exists in registry, not scanned
Caution0-29Missing signals or security warnings

Security Checks

Code-level: eval/exec, shell injection, obfuscation, network access, env harvesting, destructive ops.

NLP/Prompt-level: hidden instructions, role hijacking, invisible unicode, exfiltration prompts, authority escalation, social engineering.

When to Use

  • User asks "find a skill for X" or "is there a skill that can..."
  • User wants to extend capabilities with new tools
  • User wants to check if installed skills are safe
  • Before installing unknown skills from registry

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

aig-scanner

Comprehensive OpenClaw security scanning powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). Use when the user asks to start a security health check or sec...

Registry SourceRecently Updated
Security

Dataset Intake Auditor

在新数据集接入前检查字段、单位、缺失率、异常值与可用性。;use for data, dataset, audit workflows;do not use for 伪造统计结果, 替代正式数据治理平台.

Registry SourceRecently Updated
02
Profile unavailable
Security

Session Password

Provides secure session authentication using bcrypt-hashed passwords, security questions, email recovery, and lockout protection with audit logging.

Registry SourceRecently Updated
118
Profile unavailable