Real Skill packageSource verifiedClawHub registry

元开 yotta-dev-mcp

元开(yotta-dev-mcp)—— 一个 stdio MCP server 提供 18 个确定性开发工具:repo_map(代码库地图)、system_model(系统模型与 .yotta/architecture.json 契约分层)、architecture_review(契约评审)、impact_analysis(变更影响锥)、verify_change(L0-L5 验证账本)、self_test(完整性检查与 seeded defect / mutation 反证)、run_adapter(显式运行 import-linter / dependency-cruiser / Repomix)、find_code(符号定位)、compress_output(长输出压缩)、review_code / review_diff(规则化评审)、scan_secrets(密钥脱敏扫描)、scan_dependencies(依赖与 typosquat 启发式)、check_publish_readiness(发布前守门)、run_checks(白名单检查,默认关闭执行)、scaffold_skill(技能脚手架,默认 dry-…

Identity and source

Publisher attributionYottaMetaregistry owner unverified by skillvetai
Functional categorySoftware Developmentautomatically inferred · 67% rule confidence
Package forminstruction with code25 recorded files
Canonical sourceClawHub registryclawhub:yottameta:yotta-dev-mcp
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 10/2/2026.claude/skills/yotta-dev-mcp

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 10/2/2026.agents/skills/yotta-dev-mcp

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 10/2/2026skills/yotta-dev-mcp

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @yottameta/yotta-dev-mcp
clawhub inspect @yottameta/yotta-dev-mcp --version 0.2.3

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
25 / 25 inspected as text
Checked
10/2/2026, 5:33:28 AM
Scanner
0.1.3
Policy
1.0.3
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
4 dependency and API indicators
  • api: clawhub.ai
  • api: github.com
  • api: json-schema.org
  • api: static.modelcontextprotocol.io
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
10/2/2026, 1:56:17 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:bfa1cac491d9d71414b4db2d4b8bf166ef564af9962f372a1db832835d492c9f
Show up to 25 recorded paths
  • bin/install.js
  • bin/yotta-dev-mcp.js
  • CHANGELOG.md
  • install.sh
  • package.json
  • README.md
  • README.zh-CN.md
  • references/adapters.md
  • references/architecture-contract.md
  • references/tools.md
  • scripts/dev_adapters.py
  • scripts/dev_architecture.py
  • scripts/dev_common.py
  • scripts/dev_contract.py
  • scripts/dev_engine.py
  • scripts/dev_impact.py
  • scripts/dev_mcp_doctor.py
  • scripts/dev_model.py
  • scripts/dev_rules.py
  • scripts/dev_selftest.py
  • scripts/dev_verify.py
  • scripts/yotta_dev_mcp.py
  • server.json
  • skill-card.md
  • SKILL.md

Source changelog

- Remove obsolete skill-card.md for improved maintainability. - Update documentation in SKILL.md and CHANGELOG.md to reflect latest changes and version bump. - Update server configuration and install scripts for better compatibility. - Refactor and adjust code in bin/install.js and scripts/dev_engine.py for minor fixes and enhancements. - Bump version to 0.2.3.

Release security diff

mediumCompared fixed releases 0.2.2 and 0.2.3; 0 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

0.2.29/26/2026sha256:94505eebf6d7e5174b93fcfa45c8b305ce85cc81652dff76d1a33d56e9d858b5
0.2.19/25/2026sha256:b9cf8a7f44df1807a70c1084ac382b10eb30cd65033cc14436b2cbd93ab5bd45
0.2.09/25/2026sha256:16757ccbe44ffd88fa0af89b5fc785d3dd1ac5fc7f6fa02ccf90b2725499c92c