OpenclawSAFE
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
Overview
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
3541031621f7OBSERVED · 2026-10-09What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: "MeiGen"
description: Compose MeiGen image/video and five dedicated image tools inside an existing workflow, or opt into creative planning. Preserves caller prompts, parameters, approved count and budget; includes discovery and recoverable task handles.
version: 2.0.3
homepage: https://github.com/jau123/MeiGen-AI-Design-MCP
metadata: {"clawdbot":{"emoji":"🎨","requires":{"bins":["mcporter","npx","node"]}}}
---
# MeiGen
This standalone ClawHub Skill supplies instructions. It does not install an MCP connection by itself. Its version is independent of the npm server and the `meigen-ai-design` plugin.
## Connect
Merge this server into your mcporter configuration (`~/.config/mcporter/config.json`), preserving existing entries:
```json
{
"mcpServers": {
"creative-toolkit": {
"command": "npx",
"args": ["-y", "[email protected]"]
}
}
}
```
If the `meigen-ai-design` plugin already exposes the same tools, use that connection instead of adding a duplicate. Create a MeiGen key at https://www.meigen.ai/profile/api-keys and enter it privately as `MEIGEN_API_TOKEN` in the MCP process environment or host credentials settings. Never ask for secrets in chat. Restart/reconnect after configuration changes. Free discovery works without a key:
```bash
mcporter call creative-toolkit.search_gallery query="product photography"
mcporter call creative-toolkit.enhance_prompt prompt="a cat in space" style="realistic"
mcporter call creative-toolkit.list_skills
```
## Caller owns orchestration
Use tools directly inside the caller's existing task. Preserve supplied prompts, models/providers, ratios, references, quality and count. Do not rewrite brief prompts, load preferences, delegate or start creative exploration unless requested. Public discovery can support any workflow. An authorized upstream plan already establishes its scope and budget; do not reconfirm each image, video or dependent step. Ask only for missing inputs or additional spending/tradeoffs outside that authorization. Return handles/status/results to the caller; it owns previews, downloads and final presentation. Visual inspection is permitted when available; descriptions must reflect actual inspection.
## Choosing dedicated Skills
For transparent cutouts use `remove_background`; for ecommerce detail images use `generate_product_detail_images`; for posters use `generate_marketing_poster`; for white, smart or custom product backgrounds use `generate_ai_background`; for still-image upscaling use `upscale_image`. Call these tools directly. Prefer them when choosing a tool for these use cases; preserve an upstream caller's explicit tool choice. They do not require prompt enhancement, preference loading or agent delegation. They require MeiGen credentials and purchased credits; ComfyUI and OpenAI-compatible providers cannot run them. No daily free credits or Web free attempts apply.
Use `list_skills` for current inputs, defaults and prices. Ask only for missing required information or unresolved output scope. An explicit requested count/modules/quality already authorizes that scope; do not reconfirm it or add paid images. Product Detail MCP requires explicit `modules` (use `[]` for custom modules only); each selected module is one image. Posters need only a subject; images and copy are optional. Use defaults for unspecified settings and never invent product facts, dates or discounts.
Use real accessible images only. Both remote and local connections expose `upload_skill_image`; local npm also accepts real file paths for the four ordinary image-input workflows. If the host cannot read an attachment, ask for a public direct HTTPS image URL; never invent paths or base64.
**Upscale is a separate original-image path:** pass the original public direct HTTPS PNG/JPEG/WebP URL as `imageUrl`, at most 64 MiB and 64 MP. Local npm also accepts an actual original PNG/JPEG/WebP path in `imageUrl` through its dedicated upload route, preserving source dimensions. For readable attachment bytes, call `upload_skill_image` with `purpose: "upscale"` (base64 up to 3 MiB decoded); use the returned `imageUrl`. Do not use `purpose: "reference"` or generic reference compression for Upscale. If the host cannot read the attachment, request a real public original-image URL. On every MCP submission, including the first, pass `confirmedCredits` from the live `list_skills` quote within the user or upstream workflow accepted budget; reuse an already explicit acceptance. This pre-dispatch recheck is not an atomic spending cap. Use `mode: "crisp"` (default) or `"creative"` as offered by `list_skills`. `allowDownscale` is opt-in: explain that it permits preprocessing to at most 4096px/16 MP and the final output can be smaller than the original; set it only after the user explicitly accepts that tradeoff. Upscale accepts still images, not video. For `upscale_resize_required` or `price_changed`, return the resize/cost decision to the caller. Reuse an already explicit acceptance; otherwise obtain acceptance of the new tradeoff or price before submitting a new `requestId` with accepted `allowDownscale` and `confirmedCredits`. These are changed, confirmed inputs—not a blind retry of an interrupted submission.
The caller generates and persists `requestId` for each logical step. For interrupted submissions, call `check_skill` with the original skill/ID before retrying. Follow `nextAction`, including waiting `afterSeconds`; retry only when instructed, using its exact original ID and parameters. Never use a new ID as a blind retry or automatically pay for failed-module replacements. Auth/payment/input rejections require their indicated action instead of polling. Return completed URLs, task handles and structured status, with failed modules and refund states separately. The caller owns presentation; end users do not need to manage technical IDs.
## Tool inventory
The current local npm release exposes **17 tools**: **14 cloud tools** plus **3 local additions**Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
3541031621f7full audit observations/trust-audit/skill/jau123__openclaw.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 3541031621f7 | SAFE | B | 89 | first audit |
Questions
What does the Openclaw skill do?
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
Is Openclaw safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Openclaw access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
What do I need installed to use Openclaw?
Its own instructions reference modules. Dependencies are pinned to exact versions.
How current is this page?
The grade is for one exact copy of the source (3541031621f7), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.