OpenClaw Use Case Catalog

ReviewAudited by ClawScan on May 10, 2026.

Overview

This is mostly a Markdown use-case catalog, but it tells the agent to automatically save and push new findings to GitHub and includes platform bot-detection bypass guidance.

Install only if you want this skill to maintain a use-case repository. Before use, disable automatic `git push` or require approval, review diffs before publication, ensure GitHub credentials are narrowly scoped, and remove or caveat the social-media detection-bypass material.

Findings (4)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

ConcernHigh Confidence
ASI08: Cascading Failures
What this means

A simple request for use-case inspiration could cause new content to be committed and pushed externally, including mistakes, private context, or untrusted web material.

Why it was flagged

This makes unreviewed new findings propagate from web research into local files and then a remote Git repository as part of the default workflow.

Skill content
After each invocation that discovers new use cases, append to (or create) `findings/YYYY-MM-DD.md`... Then commit and push: `git add findings/ && git commit -m "findings: YYYY-MM-DD" && git push`
Recommendation

Require explicit user approval before writing findings or running `git push`; show a diff first and let the user choose the repository, branch, and visibility.

ConcernMedium Confidence
ASI03: Identity and Privilege Abuse
What this means

The agent may mutate a GitHub repository using the user's account authority without the user realizing that account credentials are involved.

Why it was flagged

Pushing to GitHub typically uses the user's local Git credentials or SSH keys, but the skill metadata declares no credential requirement or scope.

Skill content
Git commit and push to `{github_org}/openclaw-skill-usecases`
Recommendation

Declare the GitHub credential requirement, use a dedicated bot or deploy key with limited repository scope, and require confirmation before any push.

What this means

A user or agent could treat this as endorsed implementation guidance for social-media automation that bypasses platform protections and risks account abuse or policy violations.

Why it was flagged

The catalog is intended as inspiration for users, and this entry explicitly presents logged-in browser automation as a way to evade platform bot-detection.

Skill content
AppleScript controls real logged-in Chrome (not headless) to bypass Reddit's `navigator.webdriver=true` detection.
Recommendation

Remove or clearly quarantine anti-detection tactics; frame social-media automation examples around platform-approved APIs, rate limits, and human review.

What this means

Incorrect, untrusted, or sensitive material can become persistent context and influence future recommendations.

Why it was flagged

The skill builds a persistent knowledge base from web and social sources, then reuses it in later answers.

Skill content
Reference the catalog below and `findings/` directory for past discoveries; Search the web for fresh examples... Save new findings to `findings/YYYY-MM-DD.md`
Recommendation

Label web findings as untrusted, avoid storing private user details, and review or sanitize entries before reusing or publishing them.