Header - Gateway to self-improving agent
v1.0.1Header — continuous intelligence for agents. Subscribe to curated topics or create your own. Get synthesized briefings with executable action items from RSS,...
⭐ 0· 85·0 current·0 all-time
byTamer Avci@tameravci
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The skill is a thin integration to joinheader.com and only requires HEADER_API_KEY. All example commands call joinheader.com API endpoints; no unrelated services, binaries, or config paths are requested.
Instruction Scope
SKILL.md confines actions to Header API calls (listing topics, generating briefings, subscribing/unsubscribing, importing feeds). It explicitly requires user confirmation before taking destructive actions or implementing briefing recommendations. The instructions do not direct the agent to read arbitrary system files or other credentials.
Install Mechanism
No install spec or code is provided (instruction-only skill), so nothing is downloaded or written to disk by the skill itself — lowest-risk install posture.
Credentials
Only HEADER_API_KEY is required, which is appropriate. However SKILL.md instructs creating an API key with scope: full; that provides broad access. If the Header service supports narrower scopes, prefer a least-privilege key.
Persistence & Privilege
The skill is not force-installed (always: false) and does not request persistent system privileges or modify other skills. Autonomous invocation is allowed (platform default) but not combined with other red flags.
Assessment
This skill is a direct API integration for joinheader.com and looks internally consistent. Before installing: (1) Confirm you trust joinheader.com and the skill owner. (2) Prefer creating an API key with the minimum scopes needed rather than the recommended "full" scope if possible. (3) Do not store the API key in shared or public places; treat it as a secret. (4) When the agent proposes destructive actions (deleting topics, revoking keys, unsubscribing), require explicit user confirmation as the SKILL.md recommends. (5) If you plan to import files (OPML) or let the agent read/write files, review what local files the agent will access and keep sensitive data out of those locations.Like a lobster shell, security has layers — review code before you run it.
latestvk97dnghvbdcw0res35bp8gjj3x838y7m
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
📰 Clawdis
EnvHEADER_API_KEY
Primary envHEADER_API_KEY
