TheBotique

Skill Audit & Publish

Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when t

as observed 2026-09-20T22:20:20.880Z
Identifier
skill-audit-publish
Source
ClawHub
Version observed
1.5.9
Source repository
not published
Repository observation
No source repository listed
First observed here
2026-08-28T22:06:37.311Z
Observations recorded
8
Installs (reported upstream)
8
Weekly downloads (upstream)
1,806
Declared license
MIT-0

Observation history

2026-09-20T22:20:20.880Z

Fields that differed: changelog latestVersion

FieldBeforeAfter
changelog "Add stage 5b: SkillHub publish. The pipeline covered ClawHub and GitHub only, which silently broke the unified three-platform version rule. New references/skillhub-publish.md hold "LP1 fix: SkillHub upload stage (5b) declared in frontmatter permissions (api.skillhub.cn network + local credential-file read) and allowed-tools env/network tokens; stage-5b auth
latestVersion "1.5.8" "1.5.9"
2026-09-18T20:20:38.833Z

Fields that differed: changelog latestVersion summary

FieldBeforeAfter
changelog "AE1 experiment: removed skill-file self-reference and script-name literals from SKILL.md to test scanner coverage findings; zero unpinned-runner mentions (RP1); optional zh-summar "Add stage 5b: SkillHub publish. The pipeline covered ClawHub and GitHub only, which silently broke the unified three-platform version rule. New references/skillhub-publish.md hold
latestVersion "1.5.7" "1.5.8"
summary "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P "Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize
2026-09-17T19:21:46.965Z

Fields that differed: license description

FieldBeforeAfter
license null "MIT-0"
description "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P null
2026-09-16T18:18:14.270Z

Fields that differed: changelog description latestVersion summary

FieldBeforeAfter
changelog "Restore correct display name (1.5.4 submit derived it from the staging folder name); no functional changes" "AE1 experiment: removed skill-file self-reference and script-name literals from SKILL.md to test scanner coverage findings; zero unpinned-runner mentions (RP1); optional zh-summar
description "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P
latestVersion "1.5.5" "1.5.7"
summary "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P
2026-09-10T12:18:05.693Z

Fields that differed: changelog latestVersion

FieldBeforeAfter
changelog "Align README external-side-effect notice with actual behavior: sync helper is upsert-only, nothing is ever deleted" "Restore correct display name (1.5.4 submit derived it from the staging folder name); no functional changes"
latestVersion "1.5.3" "1.5.5"
2026-09-09T11:17:27.097Z

Fields that differed: changelog latestVersion

FieldBeforeAfter
changelog "Fix scanner findings: remove token-file fallback (env-var only), replace internal GitHub playbook with generic upsert-only guidance, declare permissions in manifest" "Align README external-side-effect notice with actual behavior: sync helper is upsert-only, nothing is ever deleted"
latestVersion "1.5.2" "1.5.3"
2026-09-08T10:18:19.235Z

Fields that differed: changelog description latestVersion summary

FieldBeforeAfter
changelog "Add Release Type Gate: new-skill vs content-update vs patch pipeline strictness; mandatory slug-collision pre-check and structure completeness for new skills; frozen-skill list (s "Fix scanner findings: remove token-file fallback (env-var only), replace internal GitHub playbook with generic upsert-only guidance, declare permissions in manifest"
description "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P
latestVersion "1.4.0" "1.5.2"
summary "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P "Audit-first pipeline to publish an OpenClaw skill to ClawHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, P

Correction

If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.