Requirements
- Target platform
- OpenClaw
- Install method
- Manual import
- Extraction
- Extract archive
- Prerequisites
- OpenClaw
- Primary doc
- SKILL.md
Compare two versions of an OpenClaw skill to detect security-relevant changes. Use before updating any skill from ClawHub. Highlights new capabilities, chang...
Compare two versions of an OpenClaw skill to detect security-relevant changes. Use before updating any skill from ClawHub. Highlights new capabilities, chang...
This item's current download entry is known to bounce back to a listing or homepage instead of returning a package file.
Use the source page and any available docs to guide the install because the item currently does not return a direct package file.
I tried to install a skill package from Yavira, but the item currently does not return a direct package file. Inspect the source page and any extracted docs, then tell me what you can confirm and any manual steps still required.
I tried to upgrade a skill package from Yavira, but the item currently does not return a direct package file. Compare the source page and any extracted docs with my current installation, then summarize what changed and what manual follow-up I still need.
Compare two versions of an OpenClaw skill to find security-relevant changes before updating.
A skill that was clean at v1.0 could add credential stealing in v1.1. The skill scanner catches known bad patterns in a single version. The differ catches new capabilities between versions — things a skill couldn't do before but can do now.
python3 {baseDir}/scripts/differ.py diff --old ~/.openclaw/skills/some-skill/ --new /tmp/some-skill-v2/
python3 {baseDir}/scripts/differ.py diff --old ./v1/ --new ./v2/ --json
python3 {baseDir}/scripts/differ.py diff --old ./v1/ --new ./v2/ --summary
Network access (skill didn't make HTTP requests before, now it does) Credential access (didn't read env vars or API keys before, now it does) File system access (wasn't touching home directory, now it is) Code execution patterns (eval/exec that didn't exist before) Data exfiltration (new outbound POST requests) Obfuscation (new encoded/obfuscated content)
New files added (especially in scripts/) Deleted files (could remove safety checks) Modified files with security-relevant diffs
SAFE — No new security-relevant capabilities. Update freely. REVIEW — New capabilities detected. Read the changes before updating. BLOCK — Critical new capabilities (code execution, credential access). Manual audit required.
Always diff before updating any third-party skill Pair with skill-scanner: scan before first install, diff before every update Pay attention to new files — attackers add payloads in new scripts If a "bug fix" update adds network access, that's suspicious
Long-tail utilities that do not fit the current primary taxonomy cleanly.
Largest current source with strong distribution and engagement signals.