Vercel
Repository: openclaw/skills
Author: byungkyu · Source status: Clear source
Vercel API integration with managed OAuth.
Score basis:Clear source · High risk signals · Cursor
Repository: openclaw/skills
Author: cinience·Source status: Clear source
Use when managing Alibaba Cloud Elastic Compute Service (ECS) via OpenAPI/SDK, including listing or creating instances, starting/stopping/rebooting, managing disks/snapshots/images/security groups/key pairs/ENIs, queryin
Score basis:Clear source · High risk signals · Universal
Trust level
85 · High trust
Strong recovered source and maintenance signals.
Risk decision
High attention
needs credentials, network access, runs shell, writes files
Install readiness
script-backed · copy-only command
SkillTrust only shows install guidance and copy actions; it never executes installs.
Before you install
Review source, permissions, and execution risk first, then alternatives. Scores prioritize review; they do not replace manual judgment.
Review weakest dimensions and next actions before copying commands.
Evidence or risk signals are incomplete; compare alternatives first.
Audit grade
C · Review first
Execution risk
High
Evidence confidence
71%
SAS-v2.1 radar
SAS-v2.1
Audit grade
C · Review first
Execution risk
High
Top threats
unexpected code execution, identity privilege abuse
Control gaps
missing license, broad permissions
Evidence confidence
71%
Repository
openclaw/skills
Author
cinience
Community signal
0 stars · 0 forks
Last updated
2026-04-01
Primary source
openclaw/skills
Source status
Clear source
Install method
script-backed
Permission scope & least privilege
33Focus: What it can access
Next action: Grant only task-required permissions and prefer Ask/manual confirmation.
Secrets, identity & credentials
42Focus: Whether it handles tokens, private keys, or agent identity
Next action: Do not provide long-lived tokens or private keys to source-pending skills.
Network & data egress
43Focus: Whether it may send data out
Next action: If unsure, restrict network access or allow only known domains.
Supported tools can change install steps; Universal entries need source review.
Explicitly supported
Candidate support (inferred)
Candidate tools are inferred signals, not official compatibility certifications.
mkdir -p output/aliyun-ecs-manageneeds credentials, network access, runs shell, writes files
Review source and permissions before copying install commands.
Evidence or risk signals are incomplete; compare alternatives first.
Focus: Who published it and whether it is traceable
Next action: Review repository, author, and README first; do not install directly when source is pending.
Focus: Whether install steps can be reviewed
Next action: Prefer candidates with install docs and repository evidence.
Focus: Whether tool descriptions may hide instructions
Next action: Read README, rules, and tool descriptions before install.
Focus: What it can access
Next action: Grant only task-required permissions and prefer Ask/manual confirmation.
Focus: Whether it runs commands or scripts
Next action: Manually confirm command-running skills in an isolated directory.
Focus: Whether file reads/writes can escape scope
Next action: Check working directory and file access scope before running.
Focus: Whether it may send data out
Next action: If unsure, restrict network access or allow only known domains.
Focus: Whether it handles tokens, private keys, or agent identity
Next action: Do not provide long-lived tokens or private keys to source-pending skills.
Focus: Whether external content can steer behavior
Next action: For browser/RAG/rules skills, review permissions and confirmation controls first.
Focus: Whether memory or retrieved context can be poisoned
Next action: Try RAG/memory skills in a low-privilege environment first.
Focus: Whether external tools and MCP access are clearly bounded
Next action: Confirm which external tools it will connect to before install, and start with the smallest possible set.
Focus: Whether destructive or external actions require confirmation
Next action: Avoid directly installing high-risk skills without confirmation controls.
Focus: How far impact can spread when something goes wrong
Next action: If unsure, test in an isolated project first.
Focus: Whether actions can be traced
Next action: Prefer candidates with logs or previews.
Focus: Whether it is maintained and reusable
Next action: Check license and maintenance before organizational use.
Strong recovered source and maintenance signals.
Phase 1 only shows installation-aware, source-backed signals. SkillTrust does not execute install scripts for users.
Risk factors
needs credentials, network access, runs shell, writes files
Permission hints
verify source provenance before install
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Same repository ecosystem
Repository: openclaw/skills
Author: alexanderliteplo · Source status: Clear source
Hire humans for physical-world tasks via RentAHuman.ai.
Score basis:Clear source · High risk signals · OpenClaw
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Same repository ecosystem
Repository: openclaw/skills
Author: diagnostikon · Source status: Clear source
Trades CPI range bin markets on Kalshi using the constraint that mutually exclusive bins must sum to ~100%.
Score basis:Clear source · High risk signals · Universal
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Same repository ecosystem
Repository: openclaw/skills
Author: cinience · Source status: Clear source
Use when working with OpenSearch vector search edition via the Python SDK (ha3engine) to push documents and run HA/SQL searches.
Score basis:Clear source · High risk signals · Claude
Why related: Keyword overlap, Same repository ecosystem...
Why related: Keyword overlap, Same repository ecosystem, Same author
Repository: openclaw/skills
Author: cinience · Source status: Clear source
Use when managing Alibaba Cloud RDS Supabase (RDS AI Service 2025-05-07) via OpenAPI, including creating, starting/stopping/restarting instances, resetting passwords, querying endpoints/auth/storage, configuring auth/RAG
Score basis:Clear source · High risk signals · Universal
Why related: Keyword overlap, Same repository ecosystem...
Why related: Keyword overlap, Same repository ecosystem, Same author
Repository: openclaw/skills
Author: kongbai233 · Source status: Clear source
This skill should be used when the user needs to analyze Git repositories, compare developer commit patterns, work habits, development efficiency, code style, code quality, and slacking behaviors.
Score basis:Clear source · High risk signals · Universal
Why related: Same task category, Keyword overlap...
Why related: Same task category, Keyword overlap, Same repository ecosystem
Repository: openclaw/skills
Author: cinience · Source status: Clear source
Use when multimodal embeddings are needed from Alibaba Cloud Model Studio models such as `qwen3-vl-embedding` for image, video, and text retrieval, cross-modal search, clustering, or offline vectorization pipelines.
Score basis:Clear source · High risk signals · Universal
Repository: openclaw/skills
Author: cinience · Source status: Clear source
Use when managing Alibaba Cloud RDS Supabase (RDS AI Service 2025-05-07) via OpenAPI, including creating, starting/stopping/restarting instances, resetting passwords, querying endpoints/auth/storage, configuring auth/RAG
Score basis:Clear source · High risk signals · Universal
Repository: openclaw/skills
Author: cinience · Source status: Clear source
Use when working with OpenSearch vector search edition via the Python SDK (ha3engine) to push documents and run HA/SQL searches.
Score basis:Clear source · High risk signals · Claude
Repository: openclaw/skills
Author: cinience · Source status: Clear source
Use when creating cloned voices with Alibaba Cloud Model Studio CosyVoice customization models, especially cosyvoice-v3.5-plus or cosyvoice-v3.5-flash, from reference audio and then reusing the returned voice_id in later
Score basis:Clear source · High risk signals · Universal