ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      tmchow

      Safety Report

      Clawpatch

      @tmchow

      This skill is specifically for the Clawpatch CLI (openclaw/clawpatch, https://clawpatch.ai) — an npm-installed automated code-review and per-finding fix tool...

      0Downloads
      0Installs
      0Stars
      1Versions
      Workflow Automation9,945Browser Automation5,886CLI & Shell Tools4,287DevOps & Infrastructure2,491

      Security Analysis

      high confidence
      Clean0.12 risk

      This skill is a disclosed operating guide for the Clawpatch code-review CLI, with expected terminal use, local review state, and user-directed fixing workflows.

      Jun 12, 20262 files3 concerns
      Purpose & Capabilityok

      The artifacts consistently describe a Clawpatch-specific workflow for running automated code review, reading findings, and optionally fixing or opening PRs; those capabilities match the stated software-development purpose.

      Instruction Scopeok

      The skill limits activation to explicit Clawpatch requests, warns not to use it for generic code review, and includes guardrails around false positives, dirty worktrees, force flags, provider login, and parallel fixing.

      Install Mechanismnote

      Installation relies on an npm package named clawpatch and optional provider CLIs or API credentials; this is disclosed and coherent with the CLI integration purpose.

      Credentialsnote

      Terminal access, repository scanning, .gitignore edits, new worktrees, and optional PR creation are high-impact capabilities, but the instructions keep them tied to explicit user requests and review/fix workflows.

      Persistence & Privilegenote

      The skill discloses persistent .clawpatch/ state for findings and resume behavior, recommends gitignoring it with user confirmation, and does not instruct hidden background execution or credential harvesting.

      Guidance

      Install only if you intend to let your agent use Clawpatch on repositories. Expect it to run terminal commands, create local .clawpatch review state, use your configured provider CLI, and potentially apply code fixes or open PRs when you ask it to; review findings before allowing fixes.

      Latest Release

      v0.1.3

      Publish clawpatch 0.1.3 from 81838d116d012eb3b6f1dd3cdb02e0c9ea91e209

      More by @tmchow

      HZL

      6 stars

      Telegram Compose

      4 stars

      Camofox Cloaked Browser

      0 stars

      Chrome Devtools Axi

      0 stars

      Illo

      0 stars

      Image Sprout

      0 stars

      Published by @tmchow on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]