Browse the trust index
Search by skill, publisher, category, or trust summary — then use the runtime filters to find cards with live test evidence. The two main lanes are baseline safety checks first and deeper follow-on functionality checks after that.
✨ Quick picks
🏷 Categories · web-and-frontend-development
🧾 Evidence level: source-scanned means local source evidence; catalog-only means thinner metadata-first coverage.
🧪 Runtime status: cards can show only the baseline safety lane or the deeper follow-on functionality lane, depending on how far the skill got. Some cards now also surface how the skill behaved when clearly fake credentials were present.
📏 Depth cue: tells you whether the evidence stops at baseline checks, includes follow-on functionality checks, or includes richer fixture/example proof.
⏱ Freshness cue: tells you whether the latest runtime evidence is from the last 24 hours, the last 7 days, or is older and therefore less current.
🩺 Failure confidence: distinguishes a first seen failure from a repeated failure or a regression after an earlier pass, so not every red row means the same thing.
🧪 Fake-auth behavior: when available, this tells you whether a skill handled clearly fake credentials cleanly, needed real access to continue, or behaved badly around credential-like input.
Results
venice-router
Supreme model router for Venice.ai — the privacy-first, uncensored AI platform. Automatically classifies query complexity and routes to the cheapest adequate model. Supports web search, uncensored mode, private-only mode (zero data retention), conversation-aware routing, cost budgets, function calling, thinking/reasoning mode, and 35+ Venice.ai text models. Use when the user wants to chat via Venice.ai, send prompts through Venice, or needs smart model selection to minimize API costs while keeping data private from Big Tech.
+ 1 more
vn-market-news-monitor
Tracks Vietnam market and sector narratives from major domestic financial media; used when users ask for market stories, sector heat, and most-mentioned Vietnamese tickers.
+ 1 more
web-navigator
[TODO: Complete and informative explanation of what the skill does and when to use it. Include WHEN to use this skill - specific scenarios, file types, or tasks that trigger it.]
+ 1 more
web-pilot
Search the web and read page contents without API keys. Use when you need to search via DuckDuckGo/Brave/Google (multi-page), extract readable text from URLs, browse interactively with a persistent visible browser (with tabs, click, screenshot, text search), download files/PDFs, or dismiss cookie banners. Supports JSON/markdown/text output. Powered by Playwright + Chromium.
+ 1 more
webmcp
This skill should be used when browsing or automating web pages that expose tools via the WebMCP API (window.navigator.modelContext). It teaches agents how to discover, inspect, and invoke WebMCP tools on websites instead of relying on DOM scraping or UI actuation.
+ 1 more
aeo-prompt-frequency-analyzer
Analyze what search queries Gemini uses when answering a prompt, by running it multiple times with Google Search grounding and reporting frequency distribution. Use when investigating AEO query patterns, understanding how AI models search the web for a topic, or studying the probabilistic nature of AI-triggered search queries.
+ 1 more
agent-dashboard
>
+ 1 more
agent-rate-limiter
You know the drill. Your agent is mid-task — browsing, spawning sub-agents, filing emails — and then:
+ 1 more
agent-self-reflection
Periodic self-reflection on recent sessions. Analyzes what went well, what went wrong, and writes concise, actionable insights to the appropriate workspace files. Designed to run as a cron job.
+ 1 more
agent-topology-visualizer
Generate interactive SVG architecture diagrams for AI agent systems.
+ 1 more
aladdn-market
Buy and sell products & services on ClawMarket — the first AI agent marketplace.
+ 1 more
antfarm-cli
Always use full path: `node ~/.openclaw/workspace/antfarm/dist/cli/cli.js`.
+ 1 more
anti-panic-protocol
Handle tool failures under pressure with bounded retries, clean user communication, and safe escalation. Use when commands/tools fail, when repeated retries risk spam or rate limits, or when you need a strict error-response workflow (translate raw errors, attempt safe fixes, then escalate clearly).
+ 1 more
anydocs
Generic Documentation Indexing & Search. Index any documentation site (SPA/static) and search it instantly.
+ 1 more
approvals-ui
A web dashboard for managing OpenClaw device pairings, channel approvals, and a live terminal — all from your browser.
+ 1 more
arc-free-worker-dispatch
Route tasks to free AI models via OpenRouter to save money. Use when the agent needs to delegate content writing, research, code generation, or other tasks to cheaper/free models instead of using expensive primary models. Prevents surprise API bills.
+ 1 more
audos
Create AI-powered startup workspaces via Audos API. Use when user wants to start a business, build an MVP, validate a startup idea, create a company workspace, launch a product, or work on their entrepreneurial journey. Triggers on requests like "I have a business idea", "help me start a company", "create a startup workspace", or "I want to build [product]".
+ 1 more
benos-bootstrap
BenOS Bootstrap is a system-initialization skill for OpenClaw-based agent stacks.
+ 1 more
bria-ai-api
Use when generating visual assets with Bria.ai - product photos, hero images, icons, backgrounds.
+ 1 more
bria-ai-api-skill
Use when generating visual assets with Bria.ai - product photos, hero images, icons, backgrounds.
+ 1 more
bria-ai-client
Use when generating visual assets with Bria.ai - product photos, hero images, icons, backgrounds.
+ 1 more
buddhist-counsel
Calls the Anicca buddhist-counsel x402 paid API to reduce suffering using Buddhist wisdom + evidence-based therapy.
+ 1 more
bug-reaper
Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open redirect, API/GraphQL bugs; auditing locally downloaded GitHub repos or source code (white-box/source code review); writing platform-specific reports. Trigger on: 'pentest', 'find bugs', 'security audit', 'bug bounty', 'find vulnerabilities', 'source code review', 'audit this repo', 'review repo', 'white-box', 'local repo', vulnerability class names, or program/target names. Reports only real, confirmed medium+ severity bugs that pass real triage.
+ 1 more
bullybuddy
BullyBuddy — Claude Code session manager CLI wrapper.