Pre-ship safety net. Scan an npm package, OpenClaw skill folder, or git repo BEFORE publishing to catch personal info leaks (absolute home paths, emails, internal IPs / Tailscale hostnames, private project codenames, AWS/GitHub/OpenAI/Anthropic/Slack tokens, JWT, PEM/SSH keys, soft Chinese first-person NL leaks in markdown). Best-effort PII/secret checkup — NOT a replacement for manual review or a full secret scanner. Use when the user is about to npm publish / clawhub publish / push a public GitHub repo, or asks "is it safe to share this?", "check leaks", "扫一下个人信息", "发布前体检", "shipcheck".

Install

openclaw skills install @symbolstar/shipcheck