Canary Skill Install & Guide
io.clawhub.sukiraman/canary · v1.0.0
Scans your OpenClaw environment for leaked secrets — API keys, tokens, credentials in .env files, installed skills, and shell history. Runs silently on startup, deep scans on demand. Fixes issues with your permission.
Copy the install config on this page first, then verify docs and permissions upstream.
Popularity
Overview
Scans your OpenClaw environment for leaked secrets — API keys, tokens, credentials in .env files, installed skills, and shell history. Runs silently on startup, deep scans on demand. Fixes issues with your permission. Canary is a Agent Skill listed from ClawHub. This page includes an overview, setup tutorial, install commands, and use cases for Trae, Tongyi Lingma, Cursor, Claude Code, and VS Code.
AgentHub Verified AvailabilityTested & Ready
Automated pipeline validated install commands, protocol & client compatibility
Send this prompt to your AI to install the Skill
RecommendedFollow the install guide at https://myagenthub.cn/install/skill.md?lang=en to automatically detect the current IDE and install the skill "sukiraman/canary" without asking, and tell me how to verify it afterwards.
💡Paste into your AI coding assistant (Cursor, Trae, Claude Code) — the agent will handle download and configuration automatically.
Copy by platformAlternative
Choose your platform
Choose install method
# 改 --ai 切换客户端:trae | lingma | workbuddy | kimi | qwen | cursor | claude-code | windsurf | cline | vscode | codex | openclaw
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai cursor -ySetup tutorial
- Open the Canary page and confirm the source is ClawHub.
- Copy the install command for Trae, Lingma, Cursor, Claude Code, or universal CLI.
- Run it, or place SKILL.md under .trae/skills/, .lingma/skills/, or .cursor/skills/.
- Reload the client, then describe your task so the agent can match this skill.
Install commands
Install commands and setup steps are in the HTML so search engines and no-JS browsers can read them without running client JavaScript.
Universal — Skills CLI (recommended)
AgentHub CLI (change --ai)
# 改 --ai 切换客户端:trae | lingma | workbuddy | kimi | qwen | cursor | claude-code | windsurf | cline | vscode | codex | openclaw
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai cursor -yOne-click API download
# 手动下载(Cursor 项目级示例)
mkdir -p .cursor/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .cursor/skills/canaryCursor
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai cursor -yOne-click API download
mkdir -p .cursor/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .cursor/skills/canaryClawHub CLI, then copy
# 在项目根目录执行 install
clawhub install sukiraman/canary
mkdir -p .cursor/skills/canary
cp -R ./skills/canary/. .cursor/skills/canary/
# 源:./skills/canary/SKILL.md
# 目标:.cursor/skills/canary/SKILL.mdTrae (ByteDance)
- Trae natively supports Skill specs: project-level in .trae/skills/<name>/, global in ~/.trae/skills/
- Copy and run the command in your project terminal to download SKILL.md
- Reload Trae window, then describe your task in AI chat to activate automatically
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai trae -yOne-click API download
mkdir -p .trae/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .trae/skills/canaryUser directory
mkdir -p ~/.trae/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.trae/skills/canaryTongyi Lingma (Alibaba)
- Tongyi Lingma supports skills in project .lingma/skills/<name>/ or global ~/.lingma/skills/
- Run the command to install SKILL.md
- In Lingma Agent mode, prompt your task and the skill will be automatically loaded
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai lingma -yOne-click API download
mkdir -p .lingma/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .lingma/skills/canaryUser directory
mkdir -p ~/.lingma/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.lingma/skills/canaryWorkBuddy / CodeBuddy (Tencent)
- WorkBuddy reads skills only from .workbuddy/skills/<name>/ (user-level ~/.workbuddy/skills/); .codebuddy/skills/ belongs to CodeBuddy
- The Skills CLI command installs with -a codebuddy and appends a copy step into .workbuddy/skills
- AgentHub CLI (--ai workbuddy) syncs it for you; reload the chat panel so the skill gets indexed
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai workbuddy -yOne-click API download
mkdir -p .workbuddy/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .workbuddy/skills/canaryUser directory
mkdir -p ~/.workbuddy/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.workbuddy/skills/canaryClaude Code
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai claude-code --global -yOne-click API download
mkdir -p ~/.claude/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.claude/skills/canaryClawHub CLI, then copy
clawhub install sukiraman/canary
mkdir -p ~/.claude/skills/canary
cp -R ./skills/canary/. ~/.claude/skills/canary/
# 源:./skills/canary/SKILL.md
# 目标:~/.claude/skills/canary/SKILL.md
# https://clawhub.ai/sukiraman/canaryKimi Code (Moonshot AI)
- Kimi Code supports standard Agent Skills: project-level in .agents/skills/<name>/, global in ~/.agents/skills/
- Run the command to install
- In Kimi Code CLI, describe your task to trigger the skill
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai kimi -yOne-click API download
mkdir -p .agents/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .agents/skills/canaryUser directory
mkdir -p ~/.agents/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.agents/skills/canaryQwen Code (Alibaba)
- Qwen Code supports project .qwen/skills/<name>/ and global ~/.qwen/skills/
- Run the command to deploy SKILL.md
- Prompt the agent to trigger the skill
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai qwen -yOne-click API download
mkdir -p .qwen/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .qwen/skills/canaryUser directory
mkdir -p ~/.qwen/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.qwen/skills/canaryWindsurf
- Windsurf supports project-level .windsurf/skills/<name>/ or global ~/.codeium/windsurf/skills/
- Run the install command and refresh Cascade
- Cascade will auto-activate the skill based on its description
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai windsurf -yOne-click API download
mkdir -p .windsurf/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .windsurf/skills/canaryUser directory
mkdir -p ~/.codeium/windsurf/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.codeium/windsurf/skills/canaryCline
- Cline supports standard .agents/skills/<name>/ structure
- Run the command to install the skill
- Ask questions in the Cline panel to trigger the skill
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai cline -yOne-click API download
mkdir -p .agents/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d .agents/skills/canaryCherry Studio
- Use this skill as an Assistant system prompt in Cherry Studio
- Copy the command to view SKILL.md text
- Paste the contents into Cherry Studio Assistant system prompt
# 下载并提取 SKILL.md 指令内容
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -p /tmp/canary.zip SKILL.md
# 复制上述输出,粘贴至 Cherry Studio → 助手设置 →「系统提示词」VS Code / GitHub Copilot
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai vscode -yOne-click API download
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
mkdir -p .github/skills/canary
unzip -o /tmp/canary.zip -d .github/skills/canaryOpenAI Codex
AgentHub CLI (change --ai)
curl -fsSL "https://myagenthub.cn/cli/agenthub-skill.mjs" | node --input-type=module - init sukiraman/canary --ai codex --global -yOne-click API download
mkdir -p ~/.codex/skills/canary
curl -sL "https://clawhub.ai/api/v1/download?slug=canary&version=1.0.0" -o /tmp/canary.zip
unzip -o /tmp/canary.zip -d ~/.codex/skills/canaryClawHub CLI, then copy
clawhub install sukiraman/canary
mkdir -p ~/.codex/skills/canary
cp -R ./skills/canary/. ~/.codex/skills/canary/
# 源:./skills/canary/SKILL.md
# 目标:~/.codex/skills/canary/SKILL.mdOpenClaw — ClawHub CLI
# OpenClaw / ClawHub CLI(推荐)
# 在项目根或 OpenClaw 工作区目录执行
clawhub install sukiraman/canary
# 安装后 SKILL.md 位于:
# ./skills/canary/SKILL.md
# (若已配置 OpenClaw 工作区,则在 <workspace>/skills/canary/)
# 仅查看不安装
clawhub inspect sukiraman/canaryTroubleshooting & Common ErrorsFAQ
Common connection errors and verified fixes for Canary
Getting 'connection closed' or exit code 1 in Cursor / Claude Code for Canary?
Usually caused by missing runtime paths or IDE environment inheritance. Fix steps: 1. Verify Node.js 18+ (npx) or Python 3.10+ (uvx) is installed; 2. Run 'which npx' or 'which uvx' in terminal, and replace 'command' with absolute path; 3. Reload or restart the client window after modifying config.
# Check binary path in terminal: which npx node -v
Getting 'spawn npx ENOENT' or 'command not found'?
The editor background process does not inherit your full terminal PATH. Solution: Globally install the package, or set the absolute binary path (e.g. C:\Program Files\nodejs\npx.cmd on Windows, or /usr/local/bin/npx on macOS).
Tool calls timing out or failing to download packages?
First-time package downloading might be slow or timeout due to network limits. Configure a reliable mirror or check outbound proxy settings.
Agent does not match or apply Canary during conversations?
Verify SKILL.md is located at .cursor/skills/Canary/SKILL.md (Cursor) or ~/.claude/skills/Canary/SKILL.md (Claude Code). You can explicitly mention the skill name in your prompt to boost match confidence.
Tool Mock Playground
SandboxCanary Rule Injection & Agent Behavior Simulation · Preview tool schema & outputs without local runtime
{
"skill": "Canary",
"rulePath": ".cursor/skills/canary/SKILL.md",
"userGoal": "请使用 Canary 的方法与标准帮我完成当前任务",
"client": "Cursor / Claude Code"
}Click 'Run Mock' above
to preview the raw response returned to the LLM
Decision Guide: Why & When to Use
Assess suitability before installing to save trial-and-error time
- When your AI Agent needs tool calling capabilities in this domain
- Automating repetitive workflows in your IDE or terminal
- Pairing with modern clients supporting MCP/Skill standards
- When missing required API secrets or local runtime prerequisites
- Pure conversational requests that don't need external system access
Canary + Scenario Prompt → Complete Agent Automation
Skill hands-on: install to visible results
Follow the full lab (expected UI/output + contrast checks). After installing this item, verify with the tutorial prompts.
An Agent Skill is a folder with SKILL.md instructions. After install, the AI loads it automatically when your task matches its description.
How to use
After installing, describe your task in chat (or mention the skill name). The agent reads the skill description to decide when to activate it, then follows the instructions in SKILL.md. Check loaded skills via /skills in Claude Code or in your client settings.
Related resources
WP Multitool — WordPress Optimization Toolkit
v1.9.9
io.clawhub.marcindudekdev/wp-multi-tool
WordPress site health audit, performance optimization, database cleanup, autoload tuning, slow query detection, wp-config management, image size control, frontend speed fixes, and server diagnostics. Combines 19 optimization and control modules into a single paid plugin (Pro $79/year single-site, $199/year or $499 lifetime unlimited). The diagnostic commands in this skill work on any WordPress 5.8+ site without the plugin.
PlanetScale CLI Skills
v1.0.31
io.clawhub.vince-winkintel/planetscale-cli-skills
PlanetScale CLI command reference and workflows. Use for authentication; org, SSO, teams, and billing; databases, branches, Neki, internal or external keyspaces, logs, maintenance, extensions, metrics, insights, inspect, and SQL; deploy requests, schema migrations, MoveTables, throttlers, rollout concurrency, disk-storage settings, and Traffic Control; PgBouncers, read-only replicas, roles, passwords, backups, webhooks, audit logs, service tokens, D1 imports, and automation. Routes to focused pscale sub-skills. Triggers on PlanetScale CLI, pscale, pscale --skill, database, branch, Neki, keyspace, create-external, external keyspace, deploy request, move-tables, vtctl, vtctld, max rollout, disk scaling, max storage, throttler, traffic-control, metrics, insights, inspect, SQL, role, password, pgbouncer, read-only replica, backup, webhook, audit-log, billing, org, SSO, service token, import d1.
论衡 — 严肃长文流水线
v2.15.4
io.clawhub.zuoyunlai/lunheng-article-pipeline
学术论文/深度长文/行业分析流水线:含同行评审与期刊/发布渠道匹配建议(advisory)。不调用执行类工具(exec/process/code_execution,声明式);主控持有会话编排与状态类工具(多 Agent 派发/收报告的设计内必需面)。标准架构 = 多 Agent 九角色;worker 不可用按节点接管并披露(详正文)。Routine 写盘(status.md / audits/)已声明;心跳为 opt-in「Operational Telemetry」。v2.14.0 起新增 G18 方法论审计(12 项清单 + D2 评分)。
API Gateway
v1.2.25
io.clawhub.byungkyu/api-gateway
Call third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, etc.
v1.2.6
io.clawhub.byungkyu/linkedin-api
LinkedIn API integration with managed OAuth. Share posts, manage profile, and access LinkedIn features. Use this skill when users want to share content on LinkedIn, get profile/organization information, or interact with LinkedIn's platform.
WhatsApp Business
v1.2.8
io.clawhub.byungkyu/whatsapp-business
WhatsApp Business API integration with managed OAuth. Send messages, manage templates, and handle conversations. Use this skill when users want to interact with WhatsApp Business. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).
Often paired with
DDG Agent Services
v0.9.1
com.daedalusdevelopmentgroup/ddg-agent-services-mcp
Pay-per-call x402 gateway: agent tools, OpenAI-compatible LLM, market data, RPC, security audits.
Skarn
v0.33.0
com.getskarn/skarn
Scans AI coding sessions and assistant configs for leaked secrets and risky hooks; local, redacted
GlobalGov — Government Contracts, Tenders & Procurement
v1.0.8
io.globalgov/mcp
Find government contracts, tenders and RFPs you can still bid on, in 193 countries. Free, no key.
Fillo
v0.10.0
io.github.jacobfunch/usefillo
Fillo MCP server — provision, scaffold, publish, and query forms from your coding agent.
Keep exploring AgentHub
Most people compare similar tools or check scenario guides before installing—start here.
Listing badge: put AgentHub on your site
Copy either snippet into your project homepage, docs, or GitHub README. The badge is a hotlinked SVG — nothing to host — and it links back to this page so visitors can find the install steps.
<a href="https://myagenthub.cn/p/io.clawhub.sukiraman/canary" title="Listed on AgentHub: Canary" target="_blank" rel="noopener">
<img src="https://myagenthub.cn/badge/io.clawhub.sukiraman/canary?lang=en" alt="Listed on AgentHub: Canary" height="20" style="border:0"/>
</a>[](https://myagenthub.cn/p/io.clawhub.sukiraman/canary)Badges are generated on the fly from /badge/<package-id>, so name and listing changes propagate automatically. Keep the link target unchanged — it is what counts as the referral.
Unified Manifest
{
"id": "io.clawhub.sukiraman/canary",
"type": "skill",
"version": "1.0.0",
"displayName": "Canary",
"description": "Scans your OpenClaw environment for leaked secrets — API keys, tokens, credentials in .env files, installed skills, and shell history. Runs silently on startup, deep scans on demand. Fixes issues with your permission.",
"author": {
"name": "sukiraman",
"url": "https://clawhub.ai/sukiraman"
},
"homepage": "https://clawhub.ai/sukiraman/canary",
"distribution": {
"packages": [
{
"registryType": "source",
"identifier": "sukiraman/canary",
"version": "1.0.0",
"runtimeHint": "clawhub install"
}
],
"remotes": []
},
"dependencies": [],
"installTargets": [
"openclaw",
"claude-code",
"claude-desktop",
"cursor",
"codex",
"vscode"
],
"keywords": [
"downloads:4063",
"stars:0",
"installs:129",
"Credentials",
"Secrets",
"Audit",
"Hardening",
"Privacy"
],
"provenance": {
"origin": "clawhub",
"originalId": "sukiraman/canary",
"originalUrl": "https://clawhub.ai/sukiraman/canary",
"isOfficial": false,
"status": "active"
}
}