ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      tenlifejosh

      Safety Report

      Librarian Mastery — World-Class AI Knowledge & Memory System

      @tenlifejosh

      World-class autonomous institutional memory, version control, and knowledge management skill system. Use ANY time the user asks to save, version, archive, or...

      109Downloads
      0Installs
      0Stars
      1Versions
      Notes & Knowledge2,526Git & Version Control2,122

      Security Analysis

      medium confidence
      Suspicious

      The skill's documentation prescribes broad read/write/rename/archive/delete operations across a workspace (and references secrets/config paths and external deployments) but declares no required permissions or credentials and instructs aggressive auto-triggering and autonomous deletion rules — the capability/requirements mismatch is suspicious.

      Mar 21, 202615 files4 concerns
      Purpose & Capabilityconcern

      The skill claims to be an institutional memory/version-control system and the reference docs describe intensive filesystem operations (moving files, renaming, modifying registries, creating archives, running commands like `wc -c MEMORY.md`, updating source-of-truth registries). That functionality is consistent with the stated purpose. However, the package declares no required env vars, no config paths, and no required binaries — yet the docs assume access to workspace paths (e.g., /workspace-main/, memory/, system/registries/, ~/.openclaw/, .secrets/). The missing declared permissions/requirements vs. the heavy filesystem operations is a meaningful incoherence.

      Instruction Scopeconcern

      The SKILL.md and included reference files explicitly instruct agents to read reference files, scan and move files, archive or delete assets, update registries, run maintenance checklists, and enforce deletion authorization (including autonomous deletion of exact duplicates and temp files). The docs also direct changes to central indexes and source-of-truth registries. These are high-impact operations (potential for irreversible deletions or mass moves) and the skill both recommends aggressive triggering and gives the Librarian autonomous deletion authority for certain classes of files. The instructions reference system and secret paths (.secrets, ~/.openclaw/cron/) that lie outside the skill bundle.

      Install Mechanismok

      This is an instruction-only skill with no install spec and no code files. No third-party downloads or installers are used, which minimizes supply-chain risk at install time.

      Credentialsconcern

      The manifest declares no environment variables or credentials, yet the reference docs mention external platforms and account dependencies (Gumroad, KDP, tracking external deployment URLs) and point to local secret/config paths (.secrets, ~/.openclaw/). That mismatch means the skill's instructions presuppose access to credentials and system config that are not declared, making the requested scope unclear and potentially excessive if the agent is granted file/secret access implicitly by the runtime.

      Persistence & Privilegeconcern

      always:false (good), but autonomous invocation is allowed by default and the skill explicitly requests aggressive triggering on many keywords. Combined with built-in authority described in the docs to autonomously delete exact duplicates and temp files and update canonical registries, this creates a non-trivial blast radius if the agent is allowed write/delete access. The skill also encourages automatic archival and renaming patterns without requiring human confirmation for several deletion categories.

      Guidance

      This skill is not obviously malicious, but it contains instructions that assume broad read/write/delete access to your workspace and to config/secret locations while declaring no required permissions or credentials. Before installing or enabling it: 1) Back up your workspace and registries. 2) Run the skill in a sandbox or allow only read-only access initially. 3) Ensure the platform enforces an explicit permission model (disallow writes/deletes) or require human confirmation before any destructive operations. 4) Review and, if needed, edit the deletion/archival rules in the reference files (prevent autonomous hard-deletes; require human approval for anything beyond temp/exact-duplicate). 5) Confirm how/if the skill would access external services (KDP, Gumroad) and never provide credentials implicitly; prefer manual sync. 6) If you cannot audit every action the agent will take, do not enable autonomous invocation for this skill and require explicit human invocation for each change. These steps will reduce the risk of accidental data loss or inadvertent exposure of secrets.

      Latest Release

      v1.0.0

      Complete institutional memory and version control skill system. 14 domain references covering version control, naming conventions, directory architecture, source of truth management, prompt libraries, SOP libraries, asset archives, status lifecycles, lessons learned, knowledge graphs, maintenance audits, archive/deletion logic, migration/onboarding, and more.

      More by @tenlifejosh

      Instagram Agent — Complete Operations Playbook

      2 stars

      TikTok Agent — Complete Operations Playbook

      2 stars

      Guardian Security — World-Class AI Security & Compliance

      1 stars

      Navigator PM — World-Class AI Strategy & Planning

      0 stars

      Sentinel QA — World-Class AI Audit & Quality System

      0 stars

      Faith Content Cron — Daily Scripture & Devotional Posts

      0 stars

      Published by @tenlifejosh on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]