DISABLE_TELEMETRY=1 to opt out before using. finopsy-cloud-finopsAnalyze and optimize cloud costs across AWS, Azure, and GCP. Use when evaluating cloud spending, identifying cost optimization opportunities, analyzing cloud...
Install via ClawdBot CLI:
clawdbot install krishnakumarmahadevan-cmd/finopsy-cloud-finopsGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://portal.toolweb.in/apis/tools/finopsyCalls external URL not in known-safe list
https://portal.toolweb.inAI Analysis
The skill explicitly instructs the AI to send sensitive cloud provider credentials (AWS keys, Azure secrets, GCP service accounts) to an external, undocumented API endpoint controlled by a third party. While the skill's purpose is legitimate, the credential handling and mandatory external transmission create a significant data exfiltration risk, as the API's security and data retention policies are not disclosed.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
A tech startup using AWS for its SaaS platform wants to review its cloud spending after rapid growth. They need to identify cost inefficiencies and rightsize instances to reduce monthly bills without impacting performance, using a 3-month analysis to spot trends.
A large enterprise with workloads across AWS, Azure, and GCP seeks a consolidated cost report for management. They aim to detect unused resources, optimize reserved instances, and generate savings estimates to improve cloud governance and financial planning.
An e-commerce company experiences fluctuating cloud costs during peak seasons like holidays. They use this skill to analyze spending over the past 6 months, identify over-provisioned services, and plan for future scaling while minimizing waste.
A healthcare provider on Azure needs to audit cloud costs while ensuring data security with read-only credentials. They analyze bills to find savings opportunities, such as rightsizing VMs, to allocate funds toward patient care and compliance initiatives.
A DevOps team in a software company uses GCP and wants to clean up unused resources like idle VMs and storage. They run a cost analysis to get actionable recommendations, freeing up budget for new development projects and improving operational efficiency.
Revenue is generated through tiered subscription plans on portal.toolweb.in, offering different API call limits per month. Users pay for access to the proprietary cost analysis algorithms, with plans ranging from free trials to enterprise levels.
Each successful API call is tracked for billing, ensuring the skill creator earns revenue based on usage. This model incentivizes frequent use by teams needing regular cloud cost audits, with higher-tier plans offering more calls.
Targets large organizations with custom needs, such as higher API limits or tailored reporting. Revenue comes from enterprise subscriptions and potential add-ons like dedicated support or integration services for enhanced cloud management.
💬 Integration Tip
Ensure the TOOLWEB_API_KEY is set in the environment and use curl for API calls; always validate credential formats per provider to avoid errors.
Scored Apr 19, 2026
Fetch GitHub issues, spawn sub-agents to implement fixes and open PRs, then monitor and address PR review comments. Usage: /gh-issues [owner/repo] [--label b...
全功能智能股票监控预警系统。支持成本百分比、均线金叉死叉、RSI超买超卖、成交量异动、跳空缺口、动态止盈等7大预警规则。符合中国投资者习惯(红涨绿跌)。
Essential SSH commands for secure remote access, key management, tunneling, and file transfers.
Deploy applications and manage projects with complete CLI reference. Commands for deployments, projects, domains, environment variables, and live documentation access.
Full desktop computer use for headless Linux servers. Xvfb + XFCE virtual desktop with xdotool automation. 17 actions (click, type, scroll, screenshot, drag,...
Parse, search, and analyze application logs across formats. Use when debugging from log files, setting up structured logging, analyzing error patterns, correlating events across services, parsing stack traces, or monitoring log output in real time.