OpenClaw Field Guide · 12 of 24

11 · Find extensions you can trust

Updated 24 September 2026 · Community edition

ClawHub helps discover skills; GitHub provides source and development history. Publication is not the same as an endorsement.

A practical review

  1. Check the exact owner and spelling to avoid lookalike packages.
  2. Read the instructions and any scripts that install or run.
  3. Compare requested permissions with the stated job.
  4. Look for a maintained repository, meaningful changes, and documented dependencies.
  5. Review available verification results and then test with limited access.
openclaw skills search "calendar"

A search does not authorize installation. Choose a specific result and inspect it before using the install command in chapter 10.

Red flags

Unexplained encoded scripts, unrelated credential requests, pressure to disable protections, and misleading package names deserve investigation. Do not run a command just because a README says it is required.

Updates deserve review too

An update can add dependencies or change behavior. Note the version, review changes, and test the normal workflow. Keep a recovery path for critical extensions. Do not treat a previously reviewed publisher as permission to install every future package or accept every new permission.