Browse the trust index
Search by skill, publisher, category, or trust summary — then use the runtime filters to find cards with live test evidence. The two main lanes are baseline safety checks first and deeper follow-on functionality checks after that.
✨ Quick picks
🏷 Categories · web-and-frontend-development
🧾 Evidence level: source-scanned means local source evidence; catalog-only means thinner metadata-first coverage.
🧪 Runtime status: cards can show only the baseline safety lane or the deeper follow-on functionality lane, depending on how far the skill got. Some cards now also surface how the skill behaved when clearly fake credentials were present.
📏 Depth cue: tells you whether the evidence stops at baseline checks, includes follow-on functionality checks, or includes richer fixture/example proof.
⏱ Freshness cue: tells you whether the latest runtime evidence is from the last 24 hours, the last 7 days, or is older and therefore less current.
🩺 Failure confidence: distinguishes a first seen failure from a repeated failure or a regression after an earlier pass, so not every red row means the same thing.
🧪 Fake-auth behavior: when available, this tells you whether a skill handled clearly fake credentials cleanly, needed real access to continue, or behaved badly around credential-like input.
Results
shelv
Convert PDFs into structured Markdown filesystems and hydrate them into your workspace for exploration with standard Unix tools
+ 1 more
smart-contract-audit
Audit and analyze Solidity smart contracts for security vulnerabilities.
+ 1 more
smart-fetch
Fetch web pages for LLM use with markdown-first negotiation, strict output limits, cache/revalidation, and robust.
+ 1 more
smart-spawn-api
Pick the best AI model for any task using the Smart Spawn API.
+ 1 more
solid-agent-storage
Give your AI agent persistent identity (WebID) and personal data storage (Pod) using the Solid Protocol
+ 1 more
solo-deploy
Deploy project to hosting platform — read stack YAML for exact config, detect local CLI tools (vercel, wrangler.
+ 1 more
soul-pack
Export and import SOUL packages for OpenClaw agents. Use when creating a reusable persona package (SOUL.md + preview.md + manifest.json), installing a soul package into a new/existing agent workspace, or batch listing local soul packages for a Soul marketplace workflow.
+ 1 more
spirit
|
+ 1 more
stonebornbot
High-speed NFT mint bot for Ethereum and EVM chains. Use when the user wants to snipe NFT mints, speed-mint collections, set up multi-wallet minting bots, configure mint sniping with pre-signed transactions, or automate NFT minting across multiple wallets. Supports ERC721A, Archetype contracts, Flashbots, war mode gas, WebSocket monitoring, mempool watching, and batch minting with 100+ wallets.
+ 1 more
stripe-cli-skill
Stripe CLI operations for local development, webhook testing, fixture-based event simulation, API inspection.
+ 1 more
subagent-overseer
You spawned 4 sub-agents. One died 20 minutes ago. You're still waiting. Overseer watches them so you don't have to — zero tokens, pure OS-level process checks. No polling loops, no wasted heartbeats.
+ 1 more
sys-updater
Production-safe Ubuntu maintenance orchestrator: runs daily apt security updates, tracks non-security updates across apt/npm/pnpm/brew with quarantine + auto-review, applies only approved updates, rotates logs/state, and generates clear 09:00 MSK Telegram reports (including what was actually installed).
+ 2 more
the-only
A self-evolving, context-aware information curation engine.
+ 1 more
training-manager
Manage and optimize your OpenClaw training workspace -- scaffold files, generate skills, log training sessions.
+ 1 more
using-git-worktrees
Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktrees with smart directory selection and safety verification
+ 1 more
virtual-remote-desktop
KasmVNC-based virtual desktop for headless Linux with AI-first automation and human handoff. Use when most steps are automated but a user must manually intervene for captcha/risk-control/login approval, then return to automation. Includes requirement-driven setup for mobile/desktop takeover and browser mobile/desktop rendering.
+ 1 more
wallet
🔐 Base Wallet - Crypto Identity for AI Agents. Create wallets, sign messages (SIWE), send transactions programmatically. No browser extensions, no human intervention. The foundation for autonomous Web3 agents.
+ 1 more
web-automation-apify
This skill enables Claude to automate web interactions — filling forms, testing UIs,.
+ 1 more
webflow-designer-extension
Build Webflow Designer Extensions that run inside the Webflow Designer.
+ 1 more
website-flow-monitor
Analyze a website URL, discover business-critical user flows to monitor, propose a monitoring plan.
+ 1 more
website-generator
This skill allows you to create a professional, engaging, and user-friendly website in seconds using AI. To create a website, you need to provide a name for your project/business, along with a description of the project/business (goals, structure, etc.).
+ 1 more
website-usability-test-nova-act
AI-orchestrated usability testing using Amazon Nova Act. The agent generates personas, runs tests to collect raw data, interprets responses to determine goal achievement, and generates HTML reports. Tests real user workflows (booking, checkout, posting) with safety guardrails. Use when asked to "test website usability", "run usability test", "generate usability report", "evaluate user experience", "test checkout flow", "test booking process", or "analyze website UX".
+ 1 more
wreckit-ralph
>
+ 2 more
agent-passport
OAuth for the agentic era. Consent-gating for ALL sensitive agent actions. 75+ data-driven threat definitions with auto-updates (like antivirus signatures). Includes Skill Scanner, Injection Shield, SSRF Shield, Path Traversal Guard, spending caps, rate limits, allowlists, TTL expiry, audit trails, and KYA metadata. Pro tier adds real-time threat definition updates every 6 hours.