release-openclaw-skill — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited release-openclaw-skill (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Release a new version of the OpenClaw skill in tapo-mcp/openclaw-skill/ to ClawHub.
version: field in tapo-mcp/openclaw-skill/SKILL.md frontmatter.tapo-mcp server version from tapo-mcp/Cargo.toml.Suggest matching the tapo-mcp version. Ask the user to confirm or supply a different version. ClawHub validates version uniqueness on publish (not monotonic ordering) — any semver string that hasn't been published before for this skill is accepted.
version: in tapo-mcp/openclaw-skill/SKILL.md, update the frontmatter.tapo-mcp/openclaw-skill/SKILL.md to match the current tapo-mcp server version from step 1. This is a separate field from the skill's own version: — the pin tracks the MCP server version, not the skill version. git log --oneline -10 -- tapo-mcp/openclaw-skill/Propose a one-sentence summary of what's new in this release and ask the user to confirm or refine. This text is passed to --changelog at publish time and stored on ClawHub per version.
/commit with message chore(tapo-mcp): release openclaw skill vX.X.X. Skip this step if there is nothing to commit. npx clawhub publish tapo-mcp/openclaw-skill \
--slug tapo \
--name "Tapo" \
--version X.X.X \
--tags "tapo,smart-home,iot,mcporter" \
--changelog "<summary from step 3>"~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.