Hardcover.app skill for tracking books you're reading, reading goal, and finding books you'd love to read
v1.0.7Query reading lists and book data from Hardcover.app via GraphQL API. Triggers when user mentions Hardcover, asks about their reading list/library, wants book progress, searches for books/authors/series, or references "currently reading", "want to read", or "books I've read". Also use for syncing reading data to other systems (Obsidian, etc.) or tracking reading goals.
⭐ 1· 1.7k·2 current·2 all-time
byAsaph M. Kotzin@asaphko
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description and required asset (HARDCOVER_API_TOKEN) align: the skill only documents querying Hardcover's GraphQL endpoint for user/library/book data and searching the catalog. No unrelated services, binaries, or credentials are requested.
Instruction Scope
SKILL.md contains only API endpoint, authentication header format, rate/timeout guidance, and example GraphQL queries. It does not instruct the agent to read local files, access unrelated environment variables, or send data to endpoints other than https://api.hardcover.app/v1/graphql. The 'syncing to other systems (Obsidian, etc.)' mention is advisory and does not include instructions to exfiltrate data to third-party endpoints.
Install Mechanism
No install specification or packaged code is provided (instruction-only), so nothing is downloaded or written to disk by an installer. This minimizes install-time risk.
Credentials
Only one environment variable is required: HARDCOVER_API_TOKEN. That single credential is appropriate and proportionate for a skill that queries a user's Hardcover account. No unrelated secrets or multiple credentials are requested.
Persistence & Privilege
Skill is not always-enabled (always: false) and is user-invocable; it does not request persistent system modifications or cross-skill configuration changes. Being able to be invoked autonomously by the agent is the platform default and is not by itself concerning here.
Assessment
This skill is instruction-only and will use the HARDCOVER_API_TOKEN you provide to make read-only GraphQL requests to api.hardcover.app. Before installing, confirm you trust the skill source (homepage is hardcover.app) and understand that anyone with that token can access your Hardcover account data until you revoke it. If you have the option, use a token with limited scope or rotate/revoke the token after use. Because the skill can be invoked by the agent, consider whether you want automatic/unsupervised access to your reading data; if not, keep it user-invocable only. If you want additional assurance, ask the publisher for source code or verify an official marketplace listing.Like a lobster shell, security has layers — review code before you run it.
authorsvk97epar3vdh20n35m5x3vpm6qd80frabbooksvk97epar3vdh20n35m5x3vpm6qd80frabcharactersvk97epar3vdh20n35m5x3vpm6qd80frabhardcovervk97epar3vdh20n35m5x3vpm6qd80frabknowledgevk97epar3vdh20n35m5x3vpm6qd80frablatestvk97epar3vdh20n35m5x3vpm6qd80frablibraryvk97epar3vdh20n35m5x3vpm6qd80frabpublishersvk97epar3vdh20n35m5x3vpm6qd80frabsoftcovervk97epar3vdh20n35m5x3vpm6qd80frab
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
📚 Clawdis
EnvHARDCOVER_API_TOKEN
