This skill mostly does GitHub repository tracking, but it includes under-disclosed Slack posting and broad credential guidance that users should review before installing.
Review scripts/daily-report.sh before running or scheduling it, especially the Slack block and hard-coded channel. Use no GitHub token for public repositories when possible, or a fine-grained read-only token with minimal repository access; avoid broad repo scope unless you intentionally need private repository access. Be aware that tracked repository metadata is stored under ~/.openclaw/workspace/memory and scheduled cron/systemd setup will keep running until disabled.