Shopify/WooCommerce Marketing Partner: Attribuly AllyClaw
v2026.4.6A comprehensive AI marketing partner for DTC ecommerce. Combines multiple diagnostic and optimization skills powered by Attribuly first-party data.
⭐ 1· 197·0 current·0 all-time
byAlex@Attribuly@alexchulee
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The skill's name, description, and runtime instructions consistently describe a DTC ecommerce marketing analyst that calls Attribuly first-party data APIs. Requesting an ATTRIBULY_API_KEY is appropriate for this purpose. Minor inconsistency: the registry metadata shown earlier listed "Required env vars: none" while the SKILL.md declares ATTRIBULY_API_KEY (and metadata.primaryEnv). This is likely a metadata omission but should be corrected.
Instruction Scope
SKILL.md limits runtime actions to checking/using ATTRIBULY_API_KEY, loading local reference files, and calling Attribuly endpoints (e.g., https://data.api.attribuly.com) for analytics. It explicitly instructs not to request keys in chat and to set the env var via agent config. There are no instructions to read unrelated local files or exfiltrate arbitrary data.
Install Mechanism
This is an instruction-only skill with no install spec or downloadable archives. That presents low installation risk (nothing is written/executed by the skill bundle itself). README mentions an external GitHub repo and optional cloud offering, but no installer is embedded in the provided files.
Credentials
The only sensitive item used is ATTRIBULY_API_KEY (declared in SKILL.md metadata). That is proportionate to the stated functionality. As noted above, the registry summary omitted required env var metadata — confirm the platform will prompt/expect the ATTRIBULY_API_KEY before use. Recommend using a scoped/read-only API key if Attribuly supports it.
Persistence & Privilege
The skill is not marked always:true and uses the platform's normal autonomous invocation model. The SKILL.md suggests scheduled/automatic triggers conceptually (daily/weekly scans), but those are behavioral instructions consistent with monitoring analytics; the skill does not request elevated system privileges or modify other skills' configs in the files provided.
Assessment
This skill appears to be what it says: an Attribuly-powered marketing analyst that needs an ATTRIBULY_API_KEY to call Attribuly's data API (https://data.api.attribuly.com). Before installing: 1) Confirm you trust attribuly.com and the data it will expose; 2) Configure the API key via your Agent Settings/Secrets (do not paste it into chat); 3) If possible, create a scoped/read-only API key that limits access to only the analytics endpoints the skill needs; 4) Note the small metadata inconsistency (registry reported no required env vars while SKILL.md requires ATTRIBULY_API_KEY) — ensure the platform will prompt you to set that env var before the skill runs; 5) If you do not want automated scans, adjust the agent's skill invocation/scheduling settings to prevent autonomous or scheduled runs. If additional files or install scripts (downloads, executables, or extra env vars) are added later, re-evaluate for proportionality.Like a lobster shell, security has layers — review code before you run it.
latestvk971zrsr8hry1gng7qaz943ged844d5h
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
