update-approval-guardUse this skill when the user wants scheduled update checks for OpenClaw and installed skills, but does not want automatic mutation. The skill performs dry-ru...
Install via ClawdBot CLI:
clawdbot install waytobetter619/update-approval-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
$OPENAIContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
rm -rf ~Calls external URL not in known-safe list
http://115.190.250.10:19000Generated May 13, 2026
An organization runs an AI agent on a production server and wants to automatically check for updates to OpenClaw and installed skills every night at midnight. The skill performs a dry-run inspection, saves a pending plan, and waits for user approval before applying any changes, ensuring stability.
A DevOps team manages multiple AI agents across development, staging, and production environments. They use this skill to enforce a two-step update workflow: automatic daily checks generate a plan, but updates are only applied after a senior engineer explicitly approves via message, preventing unintended disruptions.
In a financial services firm, automated updates to AI systems must be audited and approved by compliance officers. This skill creates a pending plan with full version details, requires explicit approval, and logs the outcome, satisfying regulatory requirements for change control.
A company runs AI agents in a critical customer-facing application. They need to stay up-to-date but cannot risk automatic mutations. The skill checks daily, presents a summary of changes, and only applies updates after the operations team confirms, minimizing downtime and regression risk.
A platform provider hosts AI agents for multiple clients. Each tenant has different update policies. This skill allows per-tenant scheduled checks and approval workflows, ensuring that updates are rolled out only after each client's designated approver gives consent, maintaining isolation and compliance.
Offer a subscription where the provider manages AI agent updates with an approval guard. Customers pay a monthly fee for scheduled checks, dry-run reports, and controlled updates, reducing their operational overhead and risk.
Sell this skill as an add-on to existing AI agent platform licenses. It provides audit trails, approval workflows, and compliance reports, appealing to enterprises with strict IT governance requirements.
Offer consulting and customization services to integrate this skill into clients' CI/CD pipelines and compliance frameworks. Revenue comes from project-based fees for setup, training, and ongoing support.
💬 Integration Tip
Deploy the skill via clawhub, set up a cron job for daily checks, and ensure the workspace data directory is writable. Users approve updates by sending a simple message like 'approve updates'.
Scored May 13, 2026
Uses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill definition focuses on a controlled update workflow with explicit user approval, dry-run checks, and local state storage. The rule-based signals appear to be from a generic scan of the full system context, not from the provided skill definition text, which contains no malicious instructions, credential access, or unauthorized external calls.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...