publisher profilefirst-party

OpenClaw

OpenClaw publishes 52 tracked skills in DriftBot.

Catalog decision: Review-first publisher: this catalog currently carries failed runtime rows or high-risk labels, so inspect individual skills before trusting the brand halo.
52
indexed skills
60
average score
1
manual reviews
2
high-risk labels
catalog evidence snapshotno baseline-v3 receipts yetno functionality-v2 receipts yet1 manual review2 high-risk labels
Read this row as a catalog snapshot: runtime coverage, deeper follow-on coverage, human review presence, and high-risk concentration before you compare individual skills.

📊 Runtime quality summary

Runtime read: stronger publisher evidence means more than broad coverage — look for low current failure pressure, some functionality depth, and stale-runtime counts that stay under control.
eligible runtime skills: 0latest touch: n/ano current regressions
Baseline coverage
00% of eligible skills have baseline-v3 receipts
Baseline pass rate
0%0 passed · 0 currently failing
Functionality coverage
00% of baseline-cleared skills have functionality-v2
Fixture-backed rate
0%0 functionality-v2 rows have richer fixture/example proof
Stale baseline rows
0baseline receipts older than 7 days
Functionality failures
0current failed functionality-v2 rows in the latest publisher state

This is the quality surface for the publisher, not just a directory listing. It shows how much of the catalog has real receipts, how often those receipts are passing, whether richer fixture-backed proof exists, and whether the publisher currently carries regressions, reproduced failures, or stale runtime evidence.

Latest runtime touch: n/a. Publisher-level summaries do not replace skill-level review, but they do make reputation more earned: a publisher with broader coverage, stronger pass rates, and fixture-backed proof looks different from one living on thin smoke tests.

If you want the system-wide view, open the runtime dashboard. If you want the scoring logic, read the methodology.

No runtime receipts for this publisher yet.

Skills from this publisher

Showing 24 of 52 skills

Label mix on this page

Trusted: 2Use Caution: 2Insufficient Evidence: 19High Risk: 1

This distribution is a quick provenance cue, not a verdict. A publisher can have a mix of safer and riskier skills, so the useful move is to compare patterns here and then open the individual scorecards.

Publisher profiles are best for spotting catalog patterns: repeated shell access, common external services, whether manual review exists, and whether higher-risk labels are isolated or widespread.

On this page: 24 source-scanned, 0 catalog-only, and 1 manually reviewed entries in the current slice.

If you want the scoring logic, read the methodology. If you want the broader landscape, go back to the full index.

openhue

OpenClaw · vbundled
62
overall

Control Philips Hue lights and scenes via the OpenHue CLI.

Trustedconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

sonoscli

OpenClaw · vbundled
62
overall

Control Sonos speakers (discover/status/play/volume/group).

Trustedconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

gifgrep

OpenClaw · vbundled
61
overall

Search GIF providers with CLI/TUI, download results, and extract stills/sheets.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

goplaces

OpenClaw · vbundled
61
overall

Query Google Places API (New) via the goplaces CLI for text search, place details, resolve, and reviews. Use for human-friendly place lookup or JSON output for scripts.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

apple-reminders

OpenClaw · vbundled
60
overall

Manage Apple Reminders via remindctl CLI (list, add, edit, complete, delete). Supports lists, date filters, and JSON/plain output.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

github

OpenClaw · vbundled
60
overall

GitHub operations via `gh` CLI: issues, PRs, CI runs, code review, API queries. Use when: (1) checking PR status or CI, (2) creating/commenting on issues, (3) listing/filtering PRs or issues, (4) viewing run logs. NOT for: complex web UI interactions requiring manual browser flows (use browser tooling when available), bulk operations across many repos (script with gh api), or when gh auth is not configured.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

session-logs

OpenClaw · vbundled
60
overall

Search and analyze your own session logs (older/parent conversations) using jq.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token, whatsapp), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

sherpa-onnx-tts

OpenClaw · vbundled
60
overall

Local text-to-speech via sherpa-onnx (offline, no cloud)

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

weather

OpenClaw · vbundled
60
overall

Get current weather and forecasts via wttr.in or Open-Meteo. Use when: user asks about weather, temperature, or forecasts for any location. NOT for: historical weather data, severe weather alerts, or detailed meteorological analysis. No API key needed.

Insufficient Evidenceconfidence: reviewedsource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Better than average evidence here — there is a human review note, not just automation.

oracle

OpenClaw · vbundled
59
overall

Best practices for using the oracle CLI (prompt + file bundling, engines, sessions, and file attachment patterns).

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

sag

OpenClaw · vbundled
59
overall

ElevenLabs text-to-speech with mac-style say UX.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

bear-notes

OpenClaw · vbundled
58
overall

Create, search, and manage Bear notes via grizzly CLI.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

imsg

OpenClaw · vbundled
57
overall

iMessage/SMS CLI for listing chats, history, and sending messages via Messages.app.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (telegram, whatsapp), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

things-mac

OpenClaw · vbundled
57
overall

Manage Things 3 via the `things` CLI on macOS (add/update projects+todos via URL scheme; read/search/list from the local Things database). Use when a user asks OpenClaw to add a task to Things, list inbox/today/upcoming, search tasks, or inspect projects/areas/tags.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

bluebubbles

OpenClaw · vbundled
56
overall

Use when you need to send or manage iMessages via BlueBubbles (recommended iMessage integration). Calls go through the generic message tool with channel="bluebubbles".

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
suspicious
Take: Potentially suspicious implementation signals detected: password.
Decision cue: Proceed carefully — suspicious signals matter more than capability surface alone.

gog

OpenClaw · vbundled
55
overall

Google Workspace CLI for Gmail, Calendar, Drive, Contacts, Sheets, and Docs.

Use Cautionconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (oauth, gmail, email), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

summarize

OpenClaw · vbundled
55
overall

Summarize or extract text/transcripts from URLs, podcasts, and local files (great fallback for “transcribe this YouTube/video”).

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

canvas

OpenClaw · vbundled
54
overall

Display HTML content on connected OpenClaw nodes (Mac app, iOS, Android).

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Normal operational surface detected via environment, network, or shell-related references.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

eightctl

OpenClaw · vbundled
54
overall

Control Eight Sleep pods (status, temperature, alarms, schedules).

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
suspicious
Take: Potentially suspicious implementation signals detected: password.
Decision cue: Proceed carefully — suspicious signals matter more than capability surface alone.

healthcheck

OpenClaw · vbundled
53
overall

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

notion

OpenClaw · vbundled
53
overall

Notion API for creating and managing pages, databases, and blocks.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (email), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

trello

OpenClaw · vbundled
53
overall

Manage Trello boards, lists, and cards via the Trello REST API.

Insufficient Evidenceconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

coding-agent

OpenClaw · vbundled
49
overall

Delegate coding tasks to Codex, Claude Code, or Pi agents via background process. Use when: (1) building/creating new features or apps, (2) reviewing PRs (spawn in temp dir), (3) refactoring large codebases, (4) iterative coding that needs file exploration. NOT for: simple one-liner fixes (just edit), reading code (use read tool), thread-bound ACP harness requests in chat (for example spawn/run Codex or Claude Code in a Discord thread; use sessions_spawn with runtime:"acp"), or any work in ~/clawd workspace (never spawn agents here). Claude Code: use --print --permission-mode bypassPermissions (no PTY). Codex/Pi/OpenCode: pty:true required.

Use Cautionconfidence: source evidencesource-scanned
+ 1 more
privileged capability
Take: Higher-privilege capability areas are present (token), but that alone is not evidence of malicious behavior.
Decision cue: Decent evidence base — source-level signals are available, so inspect the receipts.

ordercli

OpenClaw · vbundled
47
overall

Foodora-only CLI for checking past orders and active order status (Deliveroo WIP).

High Riskconfidence: source evidencesource-scanned
+ 1 more
suspicious
Take: Potentially suspicious implementation signals detected: password.
Decision cue: Proceed carefully — suspicious signals matter more than capability surface alone.

Trust reading guide

Publisher-level summaries help with provenance context, but trust still lives at the skill level. Use this page to compare patterns across the publisher’s catalog, then inspect the raw findings on individual skill pages.

Back to the full index