skills/openclaw/skills/Skill Manager/Gen Agent Trust Hub

Skill Manager

Pass

Audited by Gen Agent Trust Hub on Mar 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to fetch and execute the clawhub package from the npm registry. This behavior is the primary mechanism for the skill's management functions and is consistent with the vendor's ecosystem.
  • [COMMAND_EXECUTION]: Executes shell commands including npx clawhub install, update, info, and uninstall to manage the lifecycle of other skills based on user input.
  • [COMMAND_EXECUTION]: Performs file system operations to create and maintain a local inventory file at ~/skill-manager/inventory.md using mkdir.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 1, 2026, 01:52 PM