Agent Sync
Repository: openclaw/skills
Author: SingggggYee · Source status: Clear source
One config, everywhere.
Score basis:Clear source · High risk signals · Claude
Repository: claude-code-templates
Author: davila7·Source status: Clear source
Test-Driven Development workflow principles.
Score basis:Clear source · Low risk signals · Claude
Trust level
70 · Review first
Usable, but inspect source, install method, and risk hints before adoption.
Risk decision
No explicit risk signals
No explicit risk signal is available.
Install readiness
registry-install · copy-only command
SkillTrust only shows install guidance and copy actions; it never executes installs.
Before you install
Review source, permissions, and execution risk first, then alternatives. Scores prioritize review; they do not replace manual judgment.
Review weakest dimensions and next actions before copying commands.
Evidence or risk signals are incomplete; compare alternatives first.
Audit grade
C · Review first
Execution risk
High
Evidence confidence
63%
SAS-v2.1 radar
SAS-v2.1
Audit grade
C · Review first
Execution risk
High
Top threats
data exfiltration, human approval gap
Control gaps
missing license, network without allowlist
Evidence confidence
63%
Repository
davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/tdd-workflow
Author
davila7
Community signal
19.9K stars · 1.9K forks
Last updated
2026-02-04
Primary source
davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/tdd-workflow
Source status
Clear source
Install method
registry-install
High-risk action confirmation
38Focus: Whether destructive or external actions require confirmation
Next action: Avoid directly installing high-risk skills without confirmation controls.
Network & data egress
43Focus: Whether it may send data out
Next action: If unsure, restrict network access or allow only known domains.
Observability & auditability
45Focus: Whether actions can be traced
Next action: Prefer candidates with logs or previews.
Supported tools can change install steps; Universal entries need source review.
Explicitly supported
Candidate support (inferred)
Candidate tools are inferred signals, not official compatibility certifications.
npx -y @smithery/cli install davila7/tdd-workflowNo explicit risk signals recorded
Review source and permissions before copying install commands.
Evidence or risk signals are incomplete; compare alternatives first.
Focus: Who published it and whether it is traceable
Next action: Review repository, author, and README first; do not install directly when source is pending.
Focus: Whether install steps can be reviewed
Next action: Prefer candidates with install docs and repository evidence.
Focus: Whether tool descriptions may hide instructions
Next action: Read README, rules, and tool descriptions before install.
Focus: What it can access
Next action: Grant only task-required permissions and prefer Ask/manual confirmation.
Focus: Whether it runs commands or scripts
Next action: Manually confirm command-running skills in an isolated directory.
Focus: Whether file reads/writes can escape scope
Next action: Check working directory and file access scope before running.
Focus: Whether it may send data out
Next action: If unsure, restrict network access or allow only known domains.
Focus: Whether it handles tokens, private keys, or agent identity
Next action: Do not provide long-lived tokens or private keys to source-pending skills.
Focus: Whether external content can steer behavior
Next action: For browser/RAG/rules skills, review permissions and confirmation controls first.
Focus: Whether memory or retrieved context can be poisoned
Next action: Try RAG/memory skills in a low-privilege environment first.
Focus: Whether external tools and MCP access are clearly bounded
Next action: Confirm which external tools it will connect to before install, and start with the smallest possible set.
Focus: Whether destructive or external actions require confirmation
Next action: Avoid directly installing high-risk skills without confirmation controls.
Focus: How far impact can spread when something goes wrong
Next action: If unsure, test in an isolated project first.
Focus: Whether actions can be traced
Next action: Prefer candidates with logs or previews.
Focus: Whether it is maintained and reusable
Next action: Check license and maintenance before organizational use.
Usable, but inspect source, install method, and risk hints before adoption.
Phase 1 only shows installation-aware, source-backed signals. SkillTrust does not execute install scripts for users.
Risk factors
No explicit risk signals.
Permission hints
registry access, remote metadata pull, runtime dependencies may be required
Why related: Same task category, Also supports Claude, Codex...
Why related: Same task category, Also supports Claude, Codex, Keyword overlap
Repository: ui-ux-pro-max-skill
Author: nextlevelbuilder · Source status: Clear source
UI/UX design intelligence.
Score basis:Clear source · Low risk signals · Claude
Why related: Also supports Claude, Codex, Keyword overlap...
Why related: Also supports Claude, Codex, Keyword overlap, Similar install method
Repository: openclaw/skills
Author: nic-yuan · Source status: Clear source
Spec-first, TDD, subagent-driven software development workflow for OpenClaw agents.
Score basis:Clear source · High risk signals · OpenClaw
Why related: Same task category, Keyword overlap
Why related: Same task category, Keyword overlap
Repository: openclaw/skills
Author: tenequm · Source status: Clear source
Convert documentation, GitHub repos, PDFs, codebases, videos, and more into structured AI skills using the skill-seekers CLI.
Score basis:Clear source · High risk signals · Claude
Why related: Same task category, Also supports Claude, Cursor...
Why related: Same task category, Also supports Claude, Cursor, Keyword overlap
Repository: Claude-Code-Agent-Monitor
Author: hoangsonww · Source status: Clear source
A real-time monitoring dashboard for Claude Code agents, built with SQLite3, Node.js, Express, React, Vite, TailwindCSS, and WebSockets.
Score basis:Clear source · High risk signals · Universal
Why related: Same task category, Keyword overlap
Why related: Same task category, Keyword overlap
Repository: openclaw/skills
Author: kongbai233 · Source status: Clear source
This skill should be used when the user needs to analyze Git repositories, compare developer commit patterns, work habits, development efficiency, code style, code quality, and slacking behaviors.
Score basis:Clear source · High risk signals · Universal
Why related: Same task category, Keyword overlap
Why related: Same task category, Keyword overlap
Repository: youtube-gpt
Author: davila7 · Source status: Clear source
Youtube GPT: OpenAI Whisper + Embedding + Davinci
Score basis:Clear source · Risk needs review · Universal
Repository: claude-code-templates
Author: davila7 · Source status: Clear source
Curated collection of high-quality prompts for various use cases.
Score basis:Clear source · Low risk signals · Claude
Repository: claude-code-templates
Author: davila7 · Source status: Clear source
Memory is the cornerstone of intelligent agents.
Score basis:Clear source · Low risk signals · Claude
Repository: claude-code-templates
Author: davila7 · Source status: Clear source
When the user wants to optimize, improve, or increase conversions on any marketing page — including homepage, landing pages, pricing pages, feature pages, or blog posts.
Score basis:Clear source · Low risk signals · Claude