Token导航 LogoToken导航TokenDH.com
效率操作浏览器clawhub未标认证来源可访问clear审计提醒

skill-releaser技能释放器

Agent Skill

skill-releaser 用于辅助安全审计、权限检查和凭据风险排查,适合在 OpenClaw 中需要复核安全边界、认证流程或敏感配置时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

23,731

周安装

960

GitHub Stars

公开资料未说明

下载量

7,450
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:skill-releaser(技能释放器)
来源仓库:https://github.com/chunhualiao/skill-releaser
安装命令:
openclaw skills install skill-releaser
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install skill-releaser

简介

通过完整管道向 ClawHub 发布技能,含自动脚手架和安全扫描。

  • 支持 OPSEC 扫描和双重审核(代理+用户)流程。
  • 通过 clawhub 安装,适合标准化发布流程管理。
  • 建议启用强制推送前确认所有检查项已通过。skill-releaser 属于效率类 Skill,可作为该场景下的辅助能力补充。
  • 注意发布权限需提前在平台配置好认证信息。

SKILL.md

name
skill-releaser
description
Release skills to ClawhHub through the full publication pipeline — auto-scaffolding, OPSEC scan, dual review (agent + user), force-push release, security scan verification. Use when releasing a skill, preparing a skill for release, reviewing a skill for publication, or checking release readiness.
version
1.5.0
triggers

Skill Releaser

Orchestrates the full skill publication pipeline from internal repo to ClawhHub.

When to Use

  • User says "release {skill}" or "publish {skill} to clawhub"
  • User says "prepare {skill} for release" or "check release readiness"
  • User says "review {skill} for publication"
  • Cron-triggered release check during refactory pipeline

Assumptions

How OpenClaw and user interact during release:

  • Agent runs on a machine with shell access (exec tool) for git and CLI operations
  • User communicates via messaging channel (Telegram, Discord, Signal, etc.) — likely on a phone
  • User reviews the private GitHub repo directly in their browser/phone — the repo IS the review artifact, not a text summary
  • User approves or rejects by replying to the agent's message (natural language: "approve", "revise: fix the readme", "reject")
  • Agent can create and manage GitHub repos via gh CLI on behalf of the user's authenticated account
  • Agent pushes to the private staging repo BEFORE requesting user review, so there is something to review
  • Agent does NOT publish anything publicly without explicit user approval — this is a hard gate
  • The repo starts private for staging and review. At release time, history is erased via orphan branch + force push (single clean commit), then flipped to public
  • The full release can span multiple sessions — the private staging repo preserves state so any agent can resume
  • Multiple skills can be in different stages of the pipeline simultaneously

Prerequisites

  • gh CLI authenticated (for repo creation and visibility changes)
  • clawhub CLI installed (for ClawhHub publishing)
  • A skill directory with at least a SKILL.md file

Scope & Boundaries

This skill handles: The full release pipeline — structure scaffolding, OPSEC scanning, review, publishing. This skill does NOT handle: Skill content creation or design. The SKILL.md must already describe what the skill does. Everything else (boilerplate, structure, scaffolding) is this pipeline's job.

A user with a finished SKILL.md should be able to say "release this skill" and this skill handles everything from there — including generating all missing structure files.

Automation Model

The pipeline has two fully automated phases separated by one human gate. Both single and batch releases follow the same model.

Single Skill

Phase 1 (AUTO): Steps 1-7 — scaffold, validate, stage, scan, review, push
     ↓
  GATE: User reviews private repo, replies "approve" / "revise" / "reject"
     ↓
Phase 2 (AUTO): Steps 9-12 — erase history, flip public, publish, verify scan, deliver

Batch Release (multiple skills)

Phase 1 (PARALLEL): Spawn subagents — one per skill, all run Phase 1 simultaneously
     ↓
  GATE: ONE batch review message with all repo links
        User replies: "approve all" / "approve A,C; revise B: fix readme"
     ↓
Phase 2 (PARALLEL): Spawn subagents for approved skills, all publish simultaneously
     ↓
  DELIVERY: ONE batch summary with all links and scan results

Batch rules:

  • Never serialize releases — spawn parallel subagents for Phase 1
  • Never block on one approval to start the next Phase 1
  • Assign each skill a short unique ID (A, B, C...) in the batch review message
  • Collect all Phase 1 results, present ONE batch review message with short IDs
  • Accept batch approvals: "approve all" / "approve A,C" / "revise B: fix readme"
  • Run all Phase 2s in parallel after approval

Design principles:

  • User says "release these skills" once. Agent runs all Phase 1s in parallel without interruption.
  • Agent sends ONE message: all review links + recommendations. Then waits.
  • User replies once. Agent runs all Phase 2s in parallel without interruption.
  • Agent sends ONE delivery message with all results.
  • If any step fails, agent fixes it automatically and continues. Only report to user if unfixable.
  • Rate limits, retries, and delays are handled silently (sleep + retry, not "rate limited, should I try again?")

Anti-patterns (never do these):

  • Do not serialize releases — always parallelize with subagents
  • Do not block on approval for skill A before starting Phase 1 for skill B
  • Do not send per-skill review messages — batch them
  • Do not ask "should I create the repo?" — just create it
  • Do not report intermediate steps — only the batch review and batch delivery
  • Do not ask about rate limits or transient errors — retry silently

Process

Step 1: Structure Scaffolding (Auto-Generate Boilerplate)

Before any quality checks, generate all missing structure files from the existing SKILL.md:

Auto-generate if missing:

FileSourceGeneration Method
skill.ymlSKILL.md frontmatter + triggersExtract name, description, version, triggers from SKILL.md
README.mdSKILL.md description + usageGitHub landing page for humans: what it does, how to install, future work. NOT agent instructions.
CHANGELOG.mdVersion from skill.yml + git log## v{version} — {date} + summary of current state
tests/test-triggers.jsonSKILL.md triggers + "When to Use"shouldTrigger from triggers list, shouldNotTrigger from anti-patterns
scripts/Create directoryEmpty dir or placeholder README if no scripts needed
references/Create directoryEmpty dir or placeholder README if no references needed
LICENSEDefault MITStandard MIT license text
.gitignoreStandardnode_modules/, .DS_Store, *.log

Rules:

  • Never overwrite existing files — only generate what's missing
  • All generated content derives from SKILL.md — no hallucinated features
  • If SKILL.md lacks enough info to generate a file, flag it as a content gap (user must fix SKILL.md first)
  • Generated README.md must make sense to a stranger who has never seen the skill before

Validation after scaffolding:

  • Run scripts/validate-structure.sh — must score 8/8
  • If not 8/8, identify what's still missing and fix it

Step 1.5: Version Bump (updates only)

If this skill has been published before, bump the version before proceeding:

  1. Check current published version:
clawhub inspect {slug}
  1. Bump version in both skill.yml and SKILL.md frontmatter:

- Patch (1.0.0 → 1.0.1): bug fixes, typos, minor doc updates - Minor (1.0.0 → 1.1.0): new features, new sections, structural changes - Major (1.0.0 → 2.0.0): breaking changes, full rewrites

  1. Update CHANGELOG.md with new version entry describing what changed
  1. Verify display_name is set in skill.yml — this is the human-readable title shown on ClawhHub.

It must be set explicitly; never derive it from the slug or guess it. If missing, add it now:

   display_name: "Human Readable Title"  # Required — used as ClawhHub listing title

Rules: - Title case, plain English, no jargon - Describes what the skill does, not how it's implemented - Example: slug autonomous-task-runnerdisplay_name: "Autonomous Task Runner" - Example: slug skill-releaserdisplay_name: "Skill Releaser"

Skip this step for first-time releases (but still verify display_name exists).

Step 2: Readiness Check

Verify the skill directory is complete:

  • SKILL.md exists with description and usage instructions
  • skill.yml exists with name, description, triggers
  • Structure score 8/8 (from Step 1)
  • No obvious OPSEC violations (quick scan)

If any check fails, report what needs fixing. Do not proceed.

Step 3: Create Private Staging Repo

# Check if repo already exists
gh repo view your-org/openclaw-skill-{name} 2>/dev/null

# If not, create it — CRITICAL: use the SANITIZED description, not the source skill.yml
# Run OPSEC scan on the description string BEFORE passing to gh repo create
gh repo create your-org/openclaw-skill-{name} --private --description "{sanitized description}"

OPSEC on repo metadata: The description passed to gh repo create is public when the repo flips to public. It must be scanned for the same patterns as file contents (org names, personal info, internal project names). This is not covered by file-based scanners — it must be checked explicitly.

Step 4: Prepare Release Content

Copy ONLY the skill directory content to a clean staging area:

mkdir -p /tmp/skill-release-{name}
cp -r skills/{name}/* /tmp/skill-release-{name}/

# Remove internal-only files
rm -f /tmp/skill-release-{name}/WORKSPACE.md
rm -f /tmp/skill-release-{name}/.gitignore
rm -rf /tmp/skill-release-{name}/_meta.json
rm -rf /tmp/skill-release-{name}/.clawhub

CRITICAL VALIDATION — verify before proceeding:

# The release directory must contain ONLY skill files.
# If you see ANY of these, you copied from the wrong directory — STOP and fix:
#   - USER.md, MEMORY.md, AGENTS.md, SOUL.md (workspace/repo root files)
#   - audits/, shared/, scripts/ (repo directories)
#   - memory/, slides/, projects/ (personal data)
#   - .gitmodules (repo root)
ls /tmp/skill-release-{name}/
# Expected: SKILL.md, skill.yml, README.md, CHANGELOG.md, LICENSE, tests/, references/, scripts/
# If file count exceeds ~15 files, something is wrong. Verify source path.

Add release files if missing:

  • LICENSE (MIT by default)
  • README.md (must work as GitHub landing page for strangers)
  • .gitignore

Step 5: Release Content Validation (HARD GATE)

bash scripts/validate-release-content.sh /tmp/skill-release-{name}

This is a deterministic script that blocks pushes if the release directory contains repo-level files (USER.md, MEMORY.md, audits/, etc.), has too many files (>50), or contains suspicious file types (logs, images, PDFs).

Must return SAFE (exit 0). If BLOCKED, you copied from the wrong directory. Do NOT proceed. Fix the source path and re-copy.

Step 6: OPSEC Deep Scan

bash scripts/opsec-scan.sh /tmp/skill-release-{name}

Must return CLEAN (exit 0). If violations found, fix them in the release copy. Do NOT modify the source in openclaw-knowledge — keep the internal version as-is.

Step 7: Agent Review

Generate review document:

# Release Review: {skill-name}

## Checklist
- [ ] SKILL.md clear and useful to a stranger
- [ ] README.md works as GitHub landing page
- [ ] skill.yml triggers accurate and complete
- [ ] Scripts work without hardcoded dependencies
- [ ] Tests present and described
- [ ] CHANGELOG.md current
- [ ] LICENSE present
- [ ] No references to internal repos, infrastructure, or personal info
- [ ] OPSEC scan: CLEAN
- [ ] Competitive position: {novel|ahead}

## OPSEC Scan Output
{paste scan output}

## Competitive Summary
{from audits/{name}-competitive.md}

## Recommendation
APPROVE / REVISE: {reasons}

Save to openclaw-knowledge/reviews/{name}-release-review.md

Step 8: Push to Private Staging Repo

Push sanitized content so user can review the actual repo on any device (phone, laptop):

cd /tmp/skill-release-{name}
git init
git config user.email "agent@localhost"
git config user.name "SkillEngineer"

# Install OPSEC pre-commit hook — prevents sensitive data from entering git history
cp /tmp/openclaw-knowledge/scripts/opsec-precommit-hook.sh .git/hooks/pre-commit
chmod +x .git/hooks/pre-commit

git add .
git commit -m "v{version}: Initial release of {name}"
git remote add origin https://github.com/your-org/openclaw-skill-{name}.git
git branch -M main
git push -u origin main

Step 9: User Review

For single skills, send review link. For batch releases, collect all Phase 1 results and send ONE message.

Single skill:

RELEASE REVIEW: {skill-name}

{score} | OPSEC: CLEAN
{1-line description}
https://github.com/your-org/openclaw-skill-{name}

Reply: approve / revise:{feedback} / reject

Batch review (assign short IDs for easy approval):

BATCH RELEASE REVIEW — {N} skills

A. {skill-name} — {score} | CLEAN | {1-line description}
https://github.com/your-org/openclaw-skill-{name}

B. {skill-name} — {score} | CLEAN | {1-line description}
https://github.com/your-org/openclaw-skill-{name}

C. {skill-name} — {score} | CLEAN | {1-line description}
https://github.com/your-org/openclaw-skill-{name}

Reply: approve all / approve A,C / revise B:{feedback}

Rules:

  • Links on their own line (never in tables — not clickable on mobile)
  • Short IDs (A, B, C) for batch approval — user should never type full skill names
  • The repo IS the review artifact. User reviews actual files, not a summary.
  • Wait for user response. Do not proceed without explicit approval.

Step 10: Erase History & Flip to Public (after user approval)

Erase git history (may contain OPSEC fixes from earlier revisions) and make the repo public:

cd /tmp/skill-release-{name}
# Orphan branch erases all history
git checkout --orphan clean
git add -A
git commit -m "v{version}: {name}"
git branch -D main
git branch -m main
git push -f origin main

# Flip visibility
gh repo edit your-org/openclaw-skill-{name} --visibility public

# Verify repo metadata is OPSEC-clean (description, topics are now public)
gh repo view your-org/openclaw-skill-{name} --json description,repositoryTopics -q '.description + " " + (.repositoryTopics | join(" "))'
# Manually check output for org names, personal info, internal project names
# If dirty: gh repo edit your-org/openclaw-skill-{name} --description "{clean description}"

Single commit, clean history, one repo. No dual-repo complexity.

Step 11: Prepare Publish Package and Request Approval

ClawhHub publish is an irreversible external action. It requires explicit user approval via a D-## ID before execution.

Extract the publish parameters and log an approval request — do NOT run clawhub publish yet:

# Extract publish parameters directly from skill.yml
SLUG=$(grep '^name:' /tmp/skill-release-{name}/skill.yml | awk '{print $2}')
DISPLAY_NAME=$(grep '^display_name:' /tmp/skill-release-{name}/skill.yml | sed 's/display_name: *//' | tr -d '"')
VERSION=$(grep '^version:' /tmp/skill-release-{name}/skill.yml | awk '{print $2}')

echo "slug:         $SLUG"
echo "display_name: $DISPLAY_NAME"
echo "version:      $VERSION"

if [ -z "$SLUG" ] || [ -z "$DISPLAY_NAME" ] || [ -z "$VERSION" ]; then
  echo "ERROR: Missing slug, display_name, or version in skill.yml — fix before proceeding"
  exit 1
fi

If display_name is missing from skill.yml, add it now (see Step 1.5).

Then add a pending publish entry to ESCALATIONS.md:

D-##: Publish {display_name} v{version} (slug: {slug}) to ClawhHub? — yes/no

Stop here. Wait for My Lord to reply "D-## yes" before proceeding to Step 11.5.

Only proceed to Step 11.5 if My Lord has explicitly approved this specific publish in the current session.

Step 11.5: Execute Publish + Verify (APPROVAL REQUIRED)

Only run this step after receiving explicit "D-## yes" from My Lord.

clawhub publish /tmp/skill-release-{name} \
  --slug "$SLUG" \
  --name "$DISPLAY_NAME" \
  --version "$VERSION" \
  --changelog "{summary of changes from CHANGELOG.md}"

Post-publish verification — verify the live listing matches skill.yml exactly:

After publishing, verify the live listing matches the source skill.yml exactly. This step catches wrong titles, version mismatches, and stale metadata before delivery.

clawhub inspect "$SLUG" 2>&1

Compare the output against skill.yml:

FieldExpected (from skill.yml)Actual (from clawhub inspect)Match?
Display namedisplay_name valueFirst line of inspect output✅ / ❌
Versionversion valueLatest: field✅ / ❌
DescriptionFirst sentence of descriptionSummary: field (truncated)✅ / ❌
Owneryour ClawhHub usernameOwner: field✅ / ❌

If any field does not match:

  1. Do NOT proceed to Step 12
  2. Identify the mismatch (wrong --name, wrong --slug, stale skill.yml)
  3. Fix the source (skill.yml or publish command), bump patch version, republish
  4. Re-run Step 11.5 until all fields match
  5. Only proceed to Step 12 when the table shows ✅ on all rows

Common mismatches and fixes:

MismatchCauseFix
Wrong display namedisplay_name missing from skill.yml; name was guessedAdd display_name to skill.yml, republish
Wrong versionskill.yml not updated before publishBump version in skill.yml, republish
Wrong slugname field in skill.yml doesn't match intended slugFix name in skill.yml or use correct --slug
Wrong ownerPublished under wrong accountCheck clawhub whoami, re-authenticate if needed

Step 12: Verify Security Scan (Browser Required)

ClawhHub automatically scans all published skills via VirusTotal (Code Insight) and OpenClaw's own scanner. Do not consider the release complete until scans are reviewed.

Use the browser tool to check scan results — ClawhHub pages require JS rendering:

  1. Open the skill detail page with browser:
browser start (profile=openclaw)
browser navigate → https://clawhub.ai/{username}/{slug}
browser snapshot (refs=aria)
  1. Find the "Security Scan" section in the snapshot. It shows:

- VirusTotal verdict: Benign / Suspicious / Malicious / Pending - OpenClaw verdict: Benign / Suspicious / Malicious with confidence level - Detail text: Explanation of what was flagged (expand "Details" if collapsed) - VirusTotal report link: Direct URL to full analysis

  1. Interpret results and act:
VerdictMeaningAction
Benign (both)Clean, auto-approvedProceed to Step 13
PendingStill processingWait 2 minutes, re-snapshot
Suspicious (undeclared permissions)Skill needs privileged access not in metadataAdd permissions to skill.yml, bump version, re-publish
Suspicious (other)Flagged behaviorReview detail text. If false positive, contact OpenClaw security team. If real, fix and re-publish
MaliciousBlocked from downloadFix immediately, bump version, re-run from Step 1.5
  1. Common fix — undeclared permissions:

If flagged for privileged CLI access (gh, clawhub, git, filesystem), add a permissions field to skill.yml:

   permissions:
     - exec: git, gh CLI (repo creation, visibility changes)
     - exec: clawhub CLI (publishing)
     - filesystem: read/write skill directories
     - browser: verify scan results on ClawhHub

Then bump version and re-publish. This declares intent and resolves the flag.

  1. If VirusTotal is still Pending after 5 minutes, proceed to Step 12 but note it in the delivery. The scan completes asynchronously.

Step 13: Deliver

Confirm the release is live and deliver all links and scan status to the user:

RELEASED: {skill-name} v{version}

GitHub: https://github.com/your-org/openclaw-skill-{name}
ClawhHub: https://clawhub.ai/{username}/{slug}
VirusTotal: {verdict} — {report link}
OpenClaw Scan: {verdict} ({confidence})

{1-line description}

Pipeline Ends Here

Skill-releaser scope ends at Step 13 (delivery). Post-release bookkeeping (STATUS.json updates, submodule conversion, memory logging) is a refactory system responsibility, not a release pipeline responsibility. See REFACTORY-SYSTEM.md "Post-Release Stage."

Error Handling

ErrorCauseFix
Readiness check failsScore too low or OPSEC dirtyComplete refactoring first
OPSEC scan finds violations in release copySanitization incompleteFix in release copy, re-scan
gh repo create failsAuth issue or name takenCheck gh auth status, try different name
clawhub publish failsCLI not installed or authRun npm install -g clawhub, authenticate
User rejectsFeedback providedAddress feedback, restart from Step 4

Configuration

No persistent configuration required. The pipeline uses environment-level tools (gh, clawhub, git) that must be authenticated before use.

Required tools:

ToolPurposeCheck
gh CLIGitHub repo creation, visibility changesgh auth status
clawhub CLIPublish to ClawhHub registryclawhub whoami
gitVersion controlBuilt-in
python3OPSEC scanner (optional)python3 --version

Pipeline scripts (in scripts/):

ScriptPurpose
validate-structure.shScore skill structure completeness (8 checks)
validate-release-content.shBlock placeholder text, empty files
opsec-scan.shScan for sensitive data before public release

Org/username: Update your-org in the pipeline steps to your GitHub username or org. The clawhub --slug argument uses the skill's name field from skill.yml.

Examples

Release a specific skill: "Release skill-engineer to clawhub"

Check readiness without releasing: "Is evidence-based-investigation ready for release?"

Batch readiness check: "Which skills are ready to publish?"

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

75.48%
按下载量换算5,623

安全审计

VirusTotal

通过

ClawScan

可疑

Static analysis

未展示

权限和风险

操作浏览器

该 Skill 可能涉及浏览器控制能力,使用时可能读取或操作网页内容,需要在受控环境中确认权限边界。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills