ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      steipete

      Safety Report

      Blogwatcher

      @steipete

      Monitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.

      21,420Downloads
      776Installs
      36Stars
      1Versions
      CLI & Shell Tools1,805Monitoring & Logging1,579Writing & Content1,082

      Security Analysis

      high confidence
      Clean0.04 risk

      The skill's requirements, instructions, and install method match its stated purpose (a CLI-based RSS/blog watcher); nothing requested is disproportionate or unexplained.

      Feb 11, 20261 files1 concern
      Purpose & Capabilityok

      Name/description (monitor blogs/RSS via blogwatcher) align with the SKILL.md and metadata which call out the blogwatcher CLI and provide example commands. The declared need for a blogwatcher binary (and the provided Go install instruction) is appropriate for this purpose.

      Instruction Scopeok

      SKILL.md only instructs installing and running the blogwatcher CLI (add, scan, list, read, remove). It does not instruct reading unrelated files, accessing unrelated credentials, or exfiltrating data to unexpected endpoints. Running 'scan' will fetch feeds from networked blog URLs, which is expected behavior.

      Install Mechanismnote

      No install spec in the package itself, but metadata suggests installation via 'go install github.com/Hyaxia/blogwatcher/cmd/blogwatcher@latest'. This is a standard Go workflow (fetch source from GitHub and build); it is traceable but executes third-party code on the host when you install/run the binary, so review the upstream repo if you don't trust it.

      Credentialsok

      The skill requests no environment variables, no credentials, and no config paths. That is proportionate for a local CLI tool that only needs to access feed URLs the user configures.

      Persistence & Privilegeok

      always:false (not force-included) and disable-model-invocation:false (agent may invoke it autonomously) — this is the platform default. The skill does not request elevated or permanent system privileges. Consider that allowing the agent to autonomously run local binaries gives it the ability to execute any installed CLI the agent can access.

      Guidance

      This skill is internally consistent: it expects you to install and run a third-party Go CLI (github.com/Hyaxia/blogwatcher). If you plan to install it, review the GitHub repository before running 'go install' to ensure the code is trustworthy. Install and run the binary in a user account or isolated environment if you want to limit risk. Note: the skill does not request secrets, but the agent can invoke the CLI autonomously (platform default) — only allow that if you are comfortable with the agent running local commands and network requests to the feeds you add.

      Latest Release

      v1.0.0

      More by @steipete

      Gog

      672 stars

      Github

      267 stars

      Weather

      229 stars

      Frontend Design

      186 stars

      Openai Whisper

      173 stars

      Nano Banana Pro

      164 stars

      Published by @steipete on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]