Case 04542
A fast, offline static risk analysis CLI for AI agent skill files. Detects malicious instructions, steganographic payloads, and dangerous capability chains.
npx -y skills add knownasnaffy/prompthound --skill case_04542Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Premium Skill Creator by Kevin Jeppesen (The Operator Vault). Create better OpenClaw skills with a premium first-use setup wizard pattern, minimal context bloat, and reusable scaffolding. Links: YouTube https://www.youtube.com/@kevin-jeppesen | Skool https://skool.com/operator-vault | Site https://theoperatorvault.io | X https://x.com/seo_ecom | LinkedIn https://www.linkedin.com/in/kevin-jeppesen/ | Facebook https://www.facebook.com/kevinjeppesen/
SKILL.md
3.1 KB, as published. Nobody here has run it
Skill Creator Operator
This skill helps you create new OpenClaw skills that feel premium.
Premium means:
- On first use, the skill runs a short conversational setup wizard (only asks what must be personalized).
- It persists config to disk (so prompts do not grow forever).
- It keeps SKILL.md short and uses progressive disclosure (move long docs into
references/and only load them when needed).
When to use
- "create a new skill"
- "scaffold a skill"
- "make a premium skill with a setup wizard"
- "package this workflow as a skill"
What it produces (standard output)
For a new skill <slug> it creates:
<skillsDir>/<slug>/SKILL.md<skillsDir>/<slug>/references/<skillsDir>/<slug>/scripts/(optional helper scripts)- A config path convention (choose one):
- Workspace:
<workspace>/.skill-config/<slug>.json - Global:
~/.openclaw/config/skills/<slug>.json(only when truly global)
- Workspace:
Premium setup wizard rules (required)
On first use, if config missing:
- Ask permission and give time estimate ("60 seconds").
- Ask only 3 to 8 questions max.
- Use defaults, keep advanced options behind a single extra question.
- Summarize choices, ask for confirmation.
- Write config to the workspace (recommended):
<workspace>/.skill-config/<slug>.json. - Run a tiny test.
- Tell user how to reconfigure.
If user says "skip", continue with safest defaults and warn about reduced capability.
Config storage rules
- Default: workspace config file.
- Optional global config only when the integration is truly global.
- Never store secrets in long term memory files.
Optional: local KB search integration
If the user has a local search tool (for example QMD), keep bulk docs outside SKILL.md and store them in a user chosen folder that their search tool indexes.
Do not assume any particular directory layout.
Commands (how to use this skill)
Create a skill
Ask in chat:
- "Create a premium skill called <slug> that does <outcome>."
Or run the scaffolder:
node {baseDir}/scripts/scaffold-skill.mjs <slug> "<one sentence description>"
Rebuild/upgrade a skill to premium standard
Ask:
- "Upgrade skill <slug> to premium standard."
Publishing to ClawHub
If the user asks to publish:
- Confirm slug, name, version, and changelog.
- Ensure
clawhub whoamiis authenticated. - Run
clawhub publish <path> --slug <slug> --name "<Name>" --version <x.y.z> --changelog "...".
Safety:
- Review files for accidental personal paths, tokens, or private info before publishing.
Links
See references/LINKS.md for Kevin Jeppesen links and Operator Vault info.