.claude/skills/Skill Audit & Publish1 structural issue
- error: name must contain lowercase ASCII letters, numbers and single hyphens only.
SKILL.md
Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.
Audit-first pipeline to publish an OpenClaw skill to ClawHub, SkillHub, and GitHub without leaking personal data, credentials, or model-specific references. Five stages — Sanitize, Transform, Verify, Publish, Install-check — with explicit user approval before every irreversible step. Use this when the user wants to publish a skill to ClawHub, sanitize a skill before publishing, run a pre-publish PII/secret audit, or follow the ClawHub publish workflow. A bundled sync helper (disclosed in the body below) mirrors a…
These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.
These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.
.claude/skills/Skill Audit & PublishSKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
.agents/skills/Skill Audit & PublishSKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
skills/Skill Audit & PublishSKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.
clawhub install @haiyangchenbj/skill-audit-publishclawhub inspect @haiyangchenbj/skill-audit-publish --version 1.5.9This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
sha256:3e5fa071e7bfa904e3d11443988e990e6bd2ac5fa6d95fa6cf55797f096bf2d6_meta.jsonREADME_zh.mdREADME.mdreferences/publish-rules.mdreferences/skillhub-publish.mdsanitize.mdscripts/sync_skill_to_github.jsskill-card.mdSKILL.mdtransform.mdverify.mdLP1 fix: SkillHub upload stage (5b) declared in frontmatter permissions (api.skillhub.cn network + local credential-file read) and allowed-tools env/network tokens; stage-5b auth disclosure added to the body; absolute credential claims scoped to the sync helper to remove self-contradiction; SkillHub 429 backoff corrected from ~60s to ~90s (field-verified).
Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.
These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.
sha256:84e4790353f155f466d3f564f561f1721924d22de5de9e2fefda81542ef7ccf5sha256:4179feef9c17cc7f7273561e76b0d9ed1cdecd00cf2a21752b0a7d8fe27aa316sha256:00f89cb7894ea99c2c47d79d365c1f4533f2a2ba8b1ef1e6ee35516ceec19ea0sha256:38520d87ad28411bd8a1865a0bbc6000bf450eef0db74d84b7185d1cf10a3eafsha256:7362696840a9dfd99f59f29049727904929df39570d869b43289dc046d3a7c06sha256:d48d2810891b350cc8c962eb6d7858d43a17495440fd7a09a5132f3bd72f139fsha256:41212ad2097a2b64dbeb6162f68076e15127288888f065ce2b0c50c88394a7bbsha256:1332814ac5cf67ea459dfe89b9ca613ebf9714a959a7c02e28f7ccbf6c4d38e3