Free checklist for agent builders, buyers, and marketplaces

Review an AI-agent skill before it gets real authority.

Reusable agent skills are starting to look like software packages — except they can touch browser sessions, files, SaaS tools, memory, customer workflows, messages, and payments. This free checklist helps you catch dangerous authority before install, sale, listing, or delegation.

Download the free kit Use the browser scorecard Read the checklist

No signup. No tracking gate. ZIP SHA256: 23ce21ac89f4c429532b35504938cd1b9bc19a6a6060401bea5c64665bd3d4ce

For builders

Define the skill's input contract, tool scope, memory-write rules, receipts, evals, and safe-failure behavior before users install it.

For buyers

Decide whether to install, install with limits, ask for changes, or reject a skill before it touches private data or external systems.

For marketplaces

Add listing fields that expose authority boundaries, data access, rollback gaps, and proof requirements instead of vague trust claims.

The 10 checks

  1. Identity: What is this skill responsible for, and what is explicitly out of scope?
  2. Inputs: What user data, files, URLs, or credentials does it require?
  3. Tool authority: What can it read, write, call, send, buy, delete, or publish?
  4. Private data: What sensitive information can it see, transform, store, or leak?
  5. Memory policy: What may become durable memory, and who approves promotion?
  6. External actions: Which actions require human approval before execution?
  7. Receipts: What proof does the skill leave after file, browser, SaaS, messaging, or workflow actions?
  8. Rollback: What can be undone, compensated, or quarantined after a bad action?
  9. Evals: What adversarial and boundary tests prove the skill behaves under messy inputs?
  10. Portability: What breaks when the skill moves across OpenClaw, Claude Code, Hermes, Codex-style agents, or browser-only runtimes?

Recommended review flow

Start with the free kit. Use the 30-minute review to score one skill and produce a verdict. If the skill handles high-authority workflows — customer communication, finance, file writes, browser actions, SaaS admin, memory promotion, or publishing — use the browser scorecard and the redaction-friendly intake before requesting a custom mini-report.

FAQ

Is this only for OpenClaw?

No. It was built from OpenClaw/Hermes-style operating experience, but the review model applies to Claude Code skills, Codex-style agents, browser agents, internal registries, and marketplace listings.

Why not just trust the prompt?

Because prompts do not prove authority boundaries. A useful skill needs explicit scope, tool limits, memory-write policy, receipts, exception behavior, and rollback paths.

What is the paid path?

The free kit is enough for many low-risk skills. For high-authority or buyer-facing skills, the $29 custom mini-report produces a concise third-party-style review with risks, verdict, and next fixes.