Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Evolink Image — AI Image Generation (GPT Image, Nano Banana 2, Seedream, GPT-4o)
v1.4.0AI image generation & editing — GPT Image, GPT-4o, Nano Banana 2, Seedream, Qwen, WAN, Gemini. Text-to-image, image-to-image, inpainting. 20 models, one API...
⭐ 2· 635·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description, declared endpoints (api.evolink.ai, files-api.evolink.ai), and the single required env var (EVOLINK_API_KEY) all match an image-generation/editing service; nothing requested is unrelated to that purpose.
Instruction Scope
SKILL.md is an instruction-only skill that documents API calls, file uploads, polling, and MCP tool usage. It may instruct the agent (via MCP tools) to upload user-provided local files or base64 data — expected for image editing, but users should be aware the upload creates publicly accessible URLs (expire in 24–72h). The instructions do not ask for unrelated system files or other credentials.
Install Mechanism
There is no install spec in the registry (instruction-only). However, the README suggests running npx -y @evolinkai/evolink-media@latest or adding an MCP package, which would pull and execute code from npm/GitHub if the user runs it. That is relevant to the skill's purpose but should be audited before execution.
Credentials
Only EVOLINK_API_KEY is required and declared as the primary credential, which is appropriate for an API-based image-generation service. No unrelated credentials or broad system config paths are requested.
Persistence & Privilege
always:false and no indications the skill modifies other skills or system-wide settings. The skill is user-invocable and may be autonomously invoked (platform default), which is expected for skills.
Assessment
This skill appears coherent for image generation and only needs an Evolink API key. Before installing or running the suggested MCP/npm commands, verify the evolink.ai domain and the @evolinkai/evolink-media package (review its npm/GitHub source) — running npx will download and execute code. Use a limited API key if possible, avoid uploading sensitive/private images (uploads generate public URLs for a limited time), and don't grant broader credentials than required. If you want extra assurance, ask for the package source code or a vetted release before running the npx install steps.Like a lobster shell, security has layers — review code before you run it.
latestvk9769dt5wxdfnb5h72kdc5gven81xa58
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🖼️ Clawdis
OSmacOS · Linux · Windows
EnvEVOLINK_API_KEY
Primary envEVOLINK_API_KEY
