Atlas / Skills / leoyeai / Productclank Community Growth

Productclank Community GrowthSAFE

skills/leoyeai/productclank-community-growth

🧠 Curated collection of 1209+ best OpenClaw skills β€” weekly updated by MyClaw.ai

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
3.0.0
Hosts
3 documented
License
MIT
Stars
2,160
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An Agent Skill and CLI tool for community-powered engagement on ProductClank.

What is This?

This is an Agent Skill and CLI that enable community-driven brand advocacy on ProductClank. Two capabilities:

  1. Boost β€” Rally your community to engage with a specific tweet (replies, likes, reposts). One API call, instant results.
  2. Discover β€” AI agents find relevant conversations on Twitter/X, generate contextual replies, and community members post them.

ProductClank Communiply solves the authenticity problem in social media marketing: when your brand promotes itself, people dismiss it as advertising. Communiply enables real people (employees, users, community members) to naturally recommend your brand in relevant conversationsβ€”creating authentic word-of-mouth at scale.

Quick Start

CLI (Fastest)

npm install -g @productclank/communiply-cli
communiply auth register MyAgent
communiply boost https://x.com/myproduct/status/123 --action replies \
--guidelines "Congratulate the team, ask about features"

For AI Agents

This skill is loaded automatically when an agent needs to create Twitter/X marketing campaigns. The agent will:

  1. Gather campaign requirements from the user
  2. Authenticate with ProductClank API
  3. Boost: POST /agents/campaigns/boost with tweet URL (200-300 credits)
  4. Or Discover: Create campaign (10 credits) β†’ Generate posts (12 credits/post)
  5. Return the campaign dashboard URL for tracking

For Developers

export PRODUCTCLANK_API_KEY=pck_live_YOUR_KEY
node scripts/create-campaign.mjs    # Discover flow
node scripts/boost-tweet.mjs        # Boost flow

See SKILL.md for complete documentation.

Directory Structure

productclank-campaigns/
β”œβ”€β”€ SKILL.md                    # Main skill documentation (loaded by agents)
β”œβ”€β”€ README.md                   # Th
Read from source at commit 4f3b4a2a472eOBSERVED Β· 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

npm install -g @productclank/communiply-cli
npm install @x402/fetch viem
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
cursormentioned
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit β€” this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: productclank-campaigns
description: Community-powered growth for builders. Boost amplifies your social posts with authentic community engagement (replies, likes, reposts). Discover finds relevant conversations and generates AI-powered replies at scale. Use Boost when the user has a post URL. Use Discover when the user wants to find and engage in conversations about their product.
license: Proprietary
metadata:
  author: ProductClank
  version: "3.0.0"
  api_endpoint: https://app.productclank.com/api/v1/agents
  website: https://www.productclank.com
  web_ui: https://app.productclank.com/communiply/
  cli: https://github.com/covariance-network/communiply-cli
compatibility: Requires ProductClank credits. Credits can be purchased via the webapp or topped up via the API using USDC on Base (chain ID 8453).
---

# ProductClank β€” Community-Powered Growth for Builders

Turn your community into a growth engine. Launch campaigns where real people amplify your product across social platforms β€” authentic engagement, not bots.

Supports Twitter/X, Instagram, TikTok, LinkedIn, Reddit, and Farcaster.

## Capability 1: Boost

**Amplify a specific social post with community-powered engagement.**

Use Boost when the user has a post URL they want to amplify. One API call, instant results. Works across platforms β€” just pass the URL.

### Supported Platforms

| Platform | Replies | Likes | Reposts |
|----------|---------|-------|---------|
| Twitter/X | Yes | Yes | Yes |
| Instagram | Yes | Yes | β€” |
| TikTok | Yes | Yes | β€” |
| LinkedIn | Yes | Yes | β€” |
| Reddit | Yes | Yes | β€” |
| Farcaster | Yes | Yes | Yes |

### How It Works
1. Provide a post URL from any supported platform
2. Platform is auto-detected from the URL
3. Choose action: replies, likes, or reposts (availability varies by platform)
4. Community members execute from their personal accounts
5. You get authentic, third-party engagement

### Pricing

| Action | What You Get | Credits |
|--------|-------------|---------|
| Replies | 10 AI-generated reply threads | 200 |
| Likes | 30 community likes | 300 |
| Reposts | 10 community reposts | 300 |

### API

```
POST /api/v1/agents/campaigns/boost
```

```json
{
  "post_url": "https://x.com/user/status/123456",
  "product_id": "product-uuid",
  "action_type": "replies",
  "reply_guidelines": "optional custom instructions",
  "post_text": "optional β€” pass post text to skip server-side fetch",
  "post_author": "optional β€” post author username (used with post_text)"
}
```

> `tweet_url`, `tweet_text`, and `tweet_author` are still accepted for backward compatibility.

**Response:**
```json
{
  "success": true,
  "campaign": {
    "id": "uuid",
    "campaign_number": "CP-042",
    "platform": "twitter",
    "url": "https://app.productclank.com/communiply/uuid"
  },
  "post": {
    "id": "123456789",
    "url": "https://x.com/user/status/123456789",
    "text": "Post content...",
    "author": "username",
    "platform": "twitter"
  },
  "items_generated": 10,
  "credits": {
    "credits_used": 200,
    "credits_remaining": 100
  }
}
```

**Consolidation:** All boost actions for the same product share one campaign. Boosting again adds to the existing campaign (`is_reboost: true`).

### When to Use Boost
- "Boost this post" / "get engagement on my announcement"
- "Get community replies on my LinkedIn post"
- "Get likes on my tweet" / "get reposts on my cast"
- User shares a post URL from any platform and wants community engagement
- Launch announcements, product updates, partnership posts β€” any post you want your community to rally behind

### How to Run a Boost (Agent Interaction Guide)

1. **Get the post URL** β€” ask the user for their post URL (the post they want community to engage with). Any supported platform works.
2. **Choose action type** β€” ask: "How should the community engage? Replies (support, questions, congrats), likes, or reposts?" Default to replies if unclear. Note: reposts only available on Twitter and Farcaster.
3. **Find the product** β€” search `GET /agents/products/search?q=<name>` and confirm with user (see [Confirm Product Selection](#confirm-product-selection-required))
4. **Get reply guidelines** (for replies) β€” ask what kind of engagement they want: "Should community replies congratulate the team? Ask about features? Show excitement?" Use this to set `reply_guidelines`
5. **Confirm cost** β€” "This will use 200 credits for 10 community replies. Proceed?"
6. **Execute** β€” `POST /agents/campaigns/boost`
7. **Share results** β€” show campaign URL and credits remaining

### Complete Boost Example

```typescript
// User says: "Get my community to engage with my latest announcement"
const API = "https://app.productclank.com/api/v1/agents";
const headers = {
  "Authorization": `Bearer ${process.env.PRODUCTCLANK_API_KEY}`,
  "Content-Type": "application/json",
};

// 1. Search for the product
const search = await fetch(`${API}/products/search?q=MyProduct&limit=5`, { headers });
const { products } = await search.json();
// β†’ Confirm with user: "I found MyProduct. Is this correct?"

// 2. Boost a Twitter post
const res = await fetch(`${API}/campaigns/boost`, {
  method: "POST",
  headers,
  body: JSON.stringify({
    post_url: "https://x.com/myproduct/status/123456789",
    product_id: products[0].id,
    action_type: "replies",
    reply_guidelines: "Show genuine excitement about the launch. Ask thoughtful questions about the new features or congratulate the team. Keep it authentic β€” no sales pitch.",
    post_text: "We just shipped v2.0! New API with 10x faster response times, batch endpoints, and webhook support. Try it out β†’", // optional, skips server fetch
    post_author: "myproduct", // optional, used with post_text
  }),
});

const result = await res.json();

if (result.success) {
  console.log(`βœ… Boosted on ${result.campaign.platform}! ${result.items_generated} community replies generated`);
  console.log(`πŸ“Š Dashboard: ${result.campaign.url}`);
  console.log(`πŸ’° Credits remain
05

Trust audit

SAFEgrade B Β· trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMObfuscation / stealth Β· obf.base64_blob Β· CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
LOWPrompt injection Β· prompt.transfer_instruction Β· CWE-94, CWE-1427
README.md:209
| POST | `/api/v1/agents/telegram/create-link` | Generate a linking token for a Telegram user |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection Β· prompt.transfer_instruction Β· CWE-94, CWE-1427
references/API_REFERENCE.md:38
| POST | `/agents/telegram/create-link` | Bearer (trusted) | Free | Generate Telegram linking token |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 Β· audit v0.4.1 Β· source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__productclank-community-growth.json Β· Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eSAFEB89first audit
07

Questions

What does the Productclank Community Growth skill do?

🧠 Curated collection of 1209+ best OpenClaw skills β€” weekly updated by MyClaw.ai

Is Productclank Community Growth safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Productclank Community Growth access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Productclank Community Growth work with?

Its documentation mentions claude-code, cursor and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes β€” this is the first audit.

Advertisement