SkillChain
Supply chain intelligence and ecosystem analysis for OpenClaw skills. Operates offline-first against locally installed skills; optionally enriches with live clawhub metadata (stars, downloads, moderation verdicts) when network is available.
When to Use
| Trigger |
Action |
| "Analyze my skills" / "skill inventory" |
ingest analyze-all (one-shot) |
| "What tools / packages do my skills use?" |
analyze packages |
| "Show dependencies for skill X" |
analyze supply-chain --skill <slug> |
| "Which skills share package X?" |
analyze find-users --package <name> |
| "Skill categories / ecosystem breakdown" |
analyze categories |
| "How complete / healthy are my skills?" |
analyze health |
| "Do any skills overlap or duplicate?" |
analyze overlaps |
| "Sync online popularity / security data" |
ingest enrich |
| "Full ecosystem report with insights" |
analyze report |
| "Rebuild graph from scratch" |
ingest reset && ingest scan |
Workflow
One-shot (recommended)
# Reset, scan, health check, overlap analysis, full report — all in one command
python3 scripts/ingest.py analyze-all
# With custom directories
python3 scripts/ingest.py analyze-all --dirs ~/.cursor/skills-cursor ~/.openclaw/skills ~/Downloads/skills-main/skills
Step 1 — Ingest (build the graph from local skills)
# Auto-discover skills under default paths
python3 scripts/ingest.py scan
# Specify directories explicitly
python3 scripts/ingest.py scan --dirs ~/Downloads/skills-main/skills ~/.codex/skills ~/Downloads/ontology
# Online enrichment: adds stars, downloads, moderation verdict from clawhub
# Skipped automatically if network is unavailable
python3 scripts/ingest.py enrich
# Check what's currently in the graph
python3 scripts/ingest.py status
# Reset and rebuild
python3 scripts/ingest.py reset
python3 scripts/ingest.py scan
Step 2 — Analyze
# Ecosystem overview (counts, categories, top packages)
python3 scripts/analyze.py stats
# Category distribution
python3 scripts/analyze.py categories
# Skill completeness health scores (0-100 per skill, with specific issues)
python3 scripts/analyze.py health
# Detect overlapping or complementary skill pairs
python3 scripts/analyze.py overlaps
# Top N skills by a metric
python3 scripts/analyze.py top --by stars --limit 10
python3 scripts/analyze.py top --by downloads --limit 10
# Skill profile card (dependencies, tools, bins, invocation pattern, online metrics)
python3 scripts/analyze.py profile --skill ontology
# Full supply chain for a skill (invoked_via → requires_bin → tools → packages → skill deps)
python3 scripts/analyze.py supply-chain --skill agent-browser
# Find all skills that use a specific package
python3 scripts/analyze.py find-users --package playwright
# Most-used packages across all skills
python3 scripts/analyze.py packages --top 20
# Full markdown report with Key Insights section
python3 scripts/analyze.py report
Data Sources
| Source |
What it provides |
Required? |
SKILL.md frontmatter |
name, description, license, allowed-tools, metadata.requires.bins, read_when |
Yes |
requirements.txt |
Declared Python package deps (pypi) |
When present |
pyproject.toml |
Python deps: PEP 621, Poetry, optional-deps |
When present |
Pipfile |
Python deps (Pipfile format) |
When present |
package.json |
npm deps: dependencies / devDeps / peerDeps |
When present |
scripts/*.py AST scan |
Implicit Python imports (non-stdlib only) |
When present |
_meta.json / .clawhub/origin.json |
slug, version, registry |
When present |
| clawhub API (online) |
stars, downloads, moderation verdict, owner |
Optional |
Graph Relations
| Relation |
Meaning |
belongs_to_category |
skill belongs to a functional category |
requires_package |
skill depends on a pypi / npm package |
uses_tool |
skill uses a detected tool (heuristic) |
requires_tool |
skill requires a system binary (metadata.requires.bins) |
invoked_via |
skill is called through a tool channel (allowed-tools) |
depends_on_skill |
skill references another skill in its description |
Default Scan Paths
The ingest script checks these locations by default:
~/.openclaw/skills
~/.openclaw/extensions (extensions exposing their own skills via <plugin>/skills/*)
/Applications/OpenClaw.app/Contents/Resources/skills (macOS app bundle, when installed)
In addition, ingest scan augments the user-provided or default --dirs
arguments with:
<project_root>/skills — project-local skills folder when this skill lives
inside a repository
$(npm root -g)/openclaw/skills — globally installed OpenClaw skills from
a Node.js / npm environment
Any directory containing a SKILL.md file is treated as a skill.
Ontology Contract
ontology:
reads: [Skill, SkillCategory, Tool, SoftwarePackage]
writes: [Skill, SkillCategory, Tool, SoftwarePackage]
storage: memory/skillchain/graph.jsonl
schema: schema/skillchain.yaml
preconditions:
- "At least one local skill directory is accessible"
postconditions:
- "Every discovered skill has a Skill entity"
- "Skills with requirements.txt have SoftwarePackage entities and requires_package relations"
Storage
Graph data is written to memory/skillchain/graph.jsonl using the same append-only JSONL format as the ontology skill. Reuse scripts/ontology.py from the ontology skill for low-level graph operations.
References
references/model.md — Full ontology model (types, relations, constraints)
schema/skillchain.yaml — Machine-readable schema for validation
1---2name: skill-chain3description: Supply chain intelligence for OpenClaw skills. Use when analyzing the local skill ecosystem, understanding tool and package dependencies, discovering skill categories, mapping relationships between skills, checking security posture, auditing skill health, detecting overlaps, or generating an ecosystem health report. Trigger on "analyze my skills", "skill supply chain", "what tools do my skills use", "skill dependencies", "skill inventory", "ecosystem report", "which skills use X package", "skill categories", "popular skills", "skill security", "skill health", "skill completeness", "overlapping skills".4---56# SkillChain78Supply chain intelligence and ecosystem analysis for OpenClaw skills. Operates offline-first against locally installed skills; optionally enriches with live clawhub metadata (stars, downloads, moderation verdicts) when network is available.910## When to Use1112| Trigger | Action |13|---------|--------|14| "Analyze my skills" / "skill inventory" | `ingest analyze-all` (one-shot) |15| "What tools / packages do my skills use?" | `analyze packages` |16| "Show dependencies for skill X" | `analyze supply-chain --skill <slug>` |17| "Which skills share package X?" | `analyze find-users --package <name>` |18| "Skill categories / ecosystem breakdown" | `analyze categories` |19| "How complete / healthy are my skills?" | `analyze health` |20| "Do any skills overlap or duplicate?" | `analyze overlaps` |21| "Sync online popularity / security data" | `ingest enrich` |22| "Full ecosystem report with insights" | `analyze report` |23| "Rebuild graph from scratch" | `ingest reset && ingest scan` |2425## Workflow2627### One-shot (recommended)2829```bash30# Reset, scan, health check, overlap analysis, full report — all in one command31python3 scripts/ingest.py analyze-all3233# With custom directories34python3 scripts/ingest.py analyze-all --dirs ~/.cursor/skills-cursor ~/.openclaw/skills ~/Downloads/skills-main/skills35```3637### Step 1 — Ingest (build the graph from local skills)3839```bash40# Auto-discover skills under default paths41python3 scripts/ingest.py scan4243# Specify directories explicitly44python3 scripts/ingest.py scan --dirs ~/Downloads/skills-main/skills ~/.codex/skills ~/Downloads/ontology4546# Online enrichment: adds stars, downloads, moderation verdict from clawhub47# Skipped automatically if network is unavailable48python3 scripts/ingest.py enrich4950# Check what's currently in the graph51python3 scripts/ingest.py status5253# Reset and rebuild54python3 scripts/ingest.py reset55python3 scripts/ingest.py scan56```5758### Step 2 — Analyze5960```bash61# Ecosystem overview (counts, categories, top packages)62python3 scripts/analyze.py stats6364# Category distribution65python3 scripts/analyze.py categories6667# Skill completeness health scores (0-100 per skill, with specific issues)68python3 scripts/analyze.py health6970# Detect overlapping or complementary skill pairs71python3 scripts/analyze.py overlaps7273# Top N skills by a metric74python3 scripts/analyze.py top --by stars --limit 1075python3 scripts/analyze.py top --by downloads --limit 107677# Skill profile card (dependencies, tools, bins, invocation pattern, online metrics)78python3 scripts/analyze.py profile --skill ontology7980# Full supply chain for a skill (invoked_via → requires_bin → tools → packages → skill deps)81python3 scripts/analyze.py supply-chain --skill agent-browser8283# Find all skills that use a specific package84python3 scripts/analyze.py find-users --package playwright8586# Most-used packages across all skills87python3 scripts/analyze.py packages --top 208889# Full markdown report with Key Insights section90python3 scripts/analyze.py report91```9293## Data Sources9495| Source | What it provides | Required? |96|--------|-----------------|-----------|97| `SKILL.md` frontmatter | name, description, license, `allowed-tools`, `metadata.requires.bins`, `read_when` | Yes |98| `requirements.txt` | Declared Python package deps (pypi) | When present |99| `pyproject.toml` | Python deps: PEP 621, Poetry, optional-deps | When present |100| `Pipfile` | Python deps (Pipfile format) | When present |101| `package.json` | npm deps: dependencies / devDeps / peerDeps | When present |102| `scripts/*.py` AST scan | Implicit Python imports (non-stdlib only) | When present |103| `_meta.json` / `.clawhub/origin.json` | slug, version, registry | When present |104| clawhub API (online) | stars, downloads, moderation verdict, owner | Optional |105106## Graph Relations107108| Relation | Meaning |109|----------|---------|110| `belongs_to_category` | skill belongs to a functional category |111| `requires_package` | skill depends on a pypi / npm package |112| `uses_tool` | skill uses a detected tool (heuristic) |113| `requires_tool` | skill requires a system binary (`metadata.requires.bins`) |114| `invoked_via` | skill is called through a tool channel (`allowed-tools`) |115| `depends_on_skill` | skill references another skill in its description |116117## Default Scan Paths118119The ingest script checks these locations by default:120121- `~/.openclaw/skills`122- `~/.openclaw/extensions` (extensions exposing their own skills via `<plugin>/skills/*`)123- `/Applications/OpenClaw.app/Contents/Resources/skills` (macOS app bundle, when installed)124125In addition, `ingest scan` augments the user-provided or default `--dirs`126arguments with:127128- `<project_root>/skills` — project-local skills folder when this skill lives129 inside a repository130- `$(npm root -g)/openclaw/skills` — globally installed OpenClaw skills from131 a Node.js / npm environment132133Any directory containing a `SKILL.md` file is treated as a skill.134135## Ontology Contract136137```yaml138ontology:139 reads: [Skill, SkillCategory, Tool, SoftwarePackage]140 writes: [Skill, SkillCategory, Tool, SoftwarePackage]141 storage: memory/skillchain/graph.jsonl142 schema: schema/skillchain.yaml143 preconditions:144 - "At least one local skill directory is accessible"145 postconditions:146 - "Every discovered skill has a Skill entity"147 - "Skills with requirements.txt have SoftwarePackage entities and requires_package relations"148```149150## Storage151152Graph data is written to `memory/skillchain/graph.jsonl` using the same append-only JSONL format as the `ontology` skill. Reuse `scripts/ontology.py` from the ontology skill for low-level graph operations.153154## References155156- `references/model.md` — Full ontology model (types, relations, constraints)157- `schema/skillchain.yaml` — Machine-readable schema for validation