Security
Public-safe by design
Khan Studios shares templates and stories — not Mark's private OpenClaw installation, client systems, or credentials.
Public-safe catalog only
Agents and skills share workspace patterns, compatibility metadata, and install handoffs — not live configs from private setups.
No credential collection
OAuth, API keys, tokens, and SSH secrets are never requested or stored in the browser. Skill pages may name required credentials for later OpenClaw configuration.
Client work stays off-site
Commercial patterns, paywalled projects, and sensitive infrastructure are excluded or shown as access boundaries only.
Review status is metadata
Reviewed, experimental, and deprecated labels reflect catalog curation — not runtime safety guarantees.
Swarm Builder boundaries
- • Draft state persists locally under a versioned key — no server upload.
- • Manifest download is a deterministic JSON blob for local installation.
- • Install commands are preview-only until production installer integration.
- • Invalid saved drafts are discarded with a user-visible notice.
Questions about a specific agent or skill? Check its review panel on the OpenClaw library.