A curated collection of 127+ best OpenClaw skills — AI tools, productivity, marketing, frontend, mobile, backend, DevOps and more. Weekly updated by MyClaw.a...
Security Analysis
medium confidenceThis is an index/curation skill (a collection pointer) and its requirements match its stated purpose, but installing or using the bundled third‑party skills can pull and run a lot of external code so you should review individual skills before installing them.
The skill is described as a curated index of 127+ OpenClaw skills and the package contains only documentation and an index. It does not request credentials, binaries, or system paths that are unrelated to an index/curation role.
SKILL.md only instructs users/agents how to install the collection (clawhub install or git clone + copy into ~/.openclaw/workspace/skills). It does not instruct reading unrelated local files or exfiltrating data. However, those instructions will cause the agent/user to fetch many third‑party skills; those downstream skills may contain actions that read credentials, call external endpoints, or require elevated access. The index does not vet or limit those downstream behaviors.
There is no automated install spec in the skill bundle itself (instruction-only). The documentation recommends cloning from GitHub (https://github.com/LeoYeAI/openclaw-master-skills.git) or using clawhub. Pulling code from a public GitHub repo is normal for a collection, but it means arbitrary third‑party code will be written to disk when installed. The bundle itself does not include downloads from obscure hosts or archive extraction instructions.
This skill declares no required environment variables and no primary credential, which is appropriate for an index. That said, many listed third‑party skills (e.g., gateway watchdogs, CI/CD or integrations) may require tokens or secrets when installed—so the absence of env requirements here does not imply the downstream skills are low‑privilege.
The skill is not marked always:true and uses default invocation settings. As an instruction-only index it does not request permanent agent privileges or attempt to modify other skills' configs. Autonomous invocation remains possible (platform default) but is not requested specifically by this skill.
Guidance
This package is essentially a curated index pointing to many third‑party skills. The bundle itself is coherent and low‑privilege, but installing the collection will pull many external skills that can contain arbitrary code and may request credentials or webhook endpoints. Before installing or enabling this collection: (1) inspect the GitHub repository and confirm the publisher (look at commit history, release tags, and contributors); (2) review any individual skill you plan to install for env var requirements or network/webhook calls; (3) avoid blindly installing all 127 skills at once—install and test a small subset in a sandboxed/non‑production agent first; (4) be cautious with skills that mention gateway/watchdog, auto‑repair, Discord/webhook alerts, or CI/CD integration—these often require tokens and can modify running systems; and (5) prefer installing skills directly from their original, trusted publishers (Anthropic, Vercel, Supabase, etc.) and verify release checksums when available.
Latest Release
v0.2.2
Add MyClaw.ai link in description. 127+ curated skills, weekly updated by https://myclaw.ai
More by @LeoYeAI
Published by @LeoYeAI on ClawHub