Atlas / Skills / leoyeai / Promptfolio Summarize

Promptfolio SummarizeCAUTION

skills/leoyeai/promptfolio-summarize

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
7 documented
License
MIT
Stars
2,160
01

Overview

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Read from source at commit 4f3b4a2a472eOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
openclawmentioned
windsurfmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: promptfolio-summarize
description: Analyze AI conversation history across Claude Code, Cursor, Codex, ChatGPT, Gemini CLI, Trae, OpenCode, Antigravity, Windsurf, OpenClaw and other coding agents to find framework sentences — moments where the user teaches the AI how to think — and build a portrait that reveals who this person is.
allowed-tools: Bash, Read, Glob, Grep, Write, AskUserQuestion
---

# promptfolio-summarize

You are building a **portrait of the human user** — the person running this command is the subject being analyzed. Their portrait will be displayed on the **promptfolio** platform. You are not summarizing projects, not evaluating AI usage skills, not writing a performance review. You are finding the moments where this person teaches AI how to think — their **framework sentences** — and using those to paint a picture of who they are.

To do this, analyze their AI conversation history (Claude Code, Cursor, Codex, ChatGPT, Gemini CLI, Trae, OpenCode, Antigravity, Windsurf, OpenClaw and any other coding agents found on the system) from the **last 30 days**, extract an **activity heat map** and **framework sentences** that reveal this person's thinking, then build a portrait around those sentences.

**Fundamental principle: find where the user is TEACHING, not where they are COMMANDING.** "Fix this bug" tells you nothing. "Don't think about it that way — this isn't a performance problem, it's a user psychology problem" / "你不要这样想,这不是性能问题,是用户心理问题" tells you everything.

## Step 0: Auto-Update

Before anything else, run the auto-updater to ensure you have the latest skill files and data formats:

```bash
bash ~/.promptfolio/update-check.sh
```

- If output is `UPDATED v...` → tell the user: **"Skills updated to v{version}."** Then **re-read this SKILL.md file** since it may have changed, and continue from Step 1.
- If output is `UP_TO_DATE v...` → continue silently.
- If output is `OFFLINE v...` → tell the user: **"Could not check for updates (offline). Running with local v{version}."** Continue normally.

Then continue with Step 1 normally.

## Step 1: Authentication

Ensure `~/.promptfolio/config.json` exists and has a valid token.

### 1a. Validate existing token (if config exists):
```bash
if [ -f ~/.promptfolio/config.json ]; then
  API_TOKEN=$(python3 -c "import json; print(json.load(open('$HOME/.promptfolio/config.json'))['api_token'])")
  API_URL=$(python3 -c "import json; print(json.load(open('$HOME/.promptfolio/config.json')).get('api_url','https://promptfolio.club'))")
  HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" -H "Authorization: Bearer $API_TOKEN" "$API_URL/api/profile/me" || true)
  echo "HTTP_CODE=$HTTP_CODE"
fi
```
- If HTTP 200, proceed to Step 2.
- If config missing or HTTP is not 200, run the device auth script:

### 1b. Run device authorization:
```bash
bash "SKILL_DIR/../scripts/device-auth.sh"
```
Replace `SKILL_DIR` with the directory containing this SKILL.md file. The script handles everything: requesting a device code, opening the browser, polling until authorized, and saving `~/.promptfolio/config.json`.

**IMPORTANT:** You MUST run the script as-is. Do NOT reimplement the auth flow yourself. Do NOT construct auth URLs manually — let the script handle everything.

If the script fails, tell the user authorization timed out and to try again.

## Step 2: Discover Sessions

**Before running any commands, tell the user:**

> All conversation analysis happens locally on your machine. No raw conversation content is sent to any server during analysis. Only structured results are uploaded after your explicit confirmation.

### 2a. Detect installed tools

Before scanning, check which AI coding tools the user actually has installed. Look for their config/data directories:

| Tool | How to detect |
|------|---------------|
| Claude Code | `~/.claude/projects/` exists |
| Cursor | `~/.cursor/projects/` exists |
| Codex | `~/.codex/` exists |
| OpenClaw | `~/.openclaw/` exists |
| Gemini CLI | `~/.gemini/tmp/` exists (with `chats/` subdirs) |
| Antigravity | `~/Library/Application Support/Antigravity/` or `~/.gemini/antigravity/` exists |
| Windsurf | `~/.codeium/windsurf/`, `~/.windsurf/`, or `~/Library/Application Support/Windsurf/` exists |
| ChatGPT | `~/Desktop/chatgpt_history/` exists (user must export data manually) |
| Trae | `~/.trae/`, `~/.trae-cn/`, or App Support `Trae` directories exist (note: DB is encrypted) |
| OpenCode | `~/.local/share/opencode/opencode.db` exists |

Run a quick check:

```bash
echo "=== Detected AI tools ==="
[ -d ~/.claude/projects ] && echo "claude-code"
[ -d ~/.cursor/projects ] && echo "cursor"
[ -d ~/.codex ] && echo "codex"
[ -d ~/.openclaw ] && echo "openclaw"
[ -d ~/.gemini/tmp ] && echo "gemini-cli"
[ -d "$HOME/Library/Application Support/Antigravity" ] || [ -d ~/.gemini/antigravity ] && echo "antigravity"
[ -d ~/.codeium/windsurf ] || [ -d ~/.windsurf ] || [ -d "$HOME/Library/Application Support/Windsurf" ] && echo "windsurf"
[ -d ~/Desktop/chatgpt_history ] && echo "chatgpt"
[ -d "$HOME/Library/Application Support/Trae CN/ModularData/ai-agent" ] || [ -d "$HOME/Library/Application Support/Trae/ModularData/ai-agent" ] && echo "trae"
[ -f "$HOME/.local/share/opencode/opencode.db" ] && echo "opencode"
```

Then scan for **other coding agents** not in the list above. Look for dot-directories in `~/` and app directories in `~/Library/Application Support/` that look like AI coding tools (e.g. Kiro, Aider, Continue, Copilot Chat, Trae, Roo Code, etc.):

```bash
echo "=== Checking for other coding agents ==="
ls -d ~/.kiro ~/.aider* ~/.continue ~/.roo* 2>/dev/null || true
ls -d "$HOME/Library/Application Support/Kiro" "$HOME/Library/Application Support/Continue" 2>/dev/null || true
```

If you find any unknown tool directories, peek inside to see if they contain conversation logs (.jsonl, .json, .txt). If they do, include them — no need to ask the user.

Present the results: "Detected: Claude Code, Cursor. Also 
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
scripts/assemble-payload.py
assemble-payload.py
Why it matters. member named after an attack tool
Fix. remove or justify
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__promptfolio-summarize.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eCAUTIONB89first audit
06

Questions

What does the Promptfolio Summarize skill do?

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Is Promptfolio Summarize safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Promptfolio Summarize access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Promptfolio Summarize work with?

Its documentation mentions claude-code, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement