Real Skill packageSource verifiedClawHub registry

skill-release-plus

Multi-hub skill publisher. Sign → Audit (placeholder) → Pack (clean tar.gz with exclude rules) → Publish to clawhub.com, skillhub.cn (Tencent Cloud), or GitHub Releases, all in one command. Pluggable adapter framework — add your own hub via a user-hook script (subprocess + JSON envelope). Single source of truth: one exclude.json, one signing pass, one package, fan out to N targets. Default target: clawhub only. Use --target all for all three real hubs, or --target user-hook:./my-script.sh for custom destinations.…

Identity and source

Publisher attributionEvan Songregistry owner unverified by skillvetai
Functional categorySoftware Developmentautomatically inferred · 59% rule confidence
Package forminstruction with code12 recorded files
Canonical sourceClawHub registryclawhub:songhonglei:skill-release-plus
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/23/2026.claude/skills/skill-release-plus

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/23/2026.agents/skills/skill-release-plus

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/23/2026skills/skill-release-plus

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @songhonglei/skill-release-plus
clawhub inspect @songhonglei/skill-release-plus --version 1.1.0

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
12 / 12 inspected as text
Checked
9/23/2026, 1:28:05 PM
Scanner
0.1.3
Policy
1.0.3
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
12 dependency and API indicators
  • api: clawhub.ai
  • api: clawhub.com
  • api: github.com
  • api: img.shields.io
  • api: my-hub
  • api: my-hub.example.com
  • api: my-private-hub.example.com
  • api: opensource.org
  • api: skillhub.cn
  • api: www.npmjs.com
  • api: www.python.org
  • api: x-access-token
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/22/2026, 3:32:55 AM
Release binding
Matches this record
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:eca056749507e1bdc5a15f3765a4efd91bec9ba737d80771630196c47b82bf1b
Show up to 12 recorded paths
  • config/exclude.json
  • README.md
  • scripts/_adapter_clawhub.py
  • scripts/_adapter_github_release.py
  • scripts/_adapter_skillhub_cn.py
  • scripts/_adapter_user_hook.py
  • scripts/_lib_adapters_base.py
  • scripts/_lib_config.py
  • scripts/_lib_package.py
  • scripts/release.py
  • skill-card.md
  • SKILL.md

Source changelog

v1.1.0: port internal v1.3.0-v1.4.2 features — auto sign detection, clean-stage signing, deterministic --package-only ZIP