Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Ooze Agents
v2.0.0Visual identity that evolves with reputation - create and nurture your agent's digital creature with XP and evolution stages
⭐ 0· 1.9k·3 current·3 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description match the content: SKILL.md documents an external web API (ooze-agents.net) for registering agents, earning XP, verification, and ERC-8004 minting. There are no unrelated required binaries, env vars, or config paths — everything requested is proportionate to an API-doc skill.
Instruction Scope
Runtime instructions are purely API usage examples (curl) and documentation for verification/XP rules. This stays within the stated purpose. Note: verification requires posting a public claim_code to third-party platforms (Clawstr, MoltCities) which intentionally binds/publishes identity data — that is expected for verification but is a privacy consideration users should be aware of. Also ERC-8004 minting implies blockchain interactions (gas/transactions) which the docs reference but do not automate within this skill.
Install Mechanism
Instruction-only skill with no install spec or code files; nothing is written to disk or downloaded by the skill itself.
Credentials
The skill declares no required environment variables or credentials. However authenticated API endpoints use a service API key (Authorization: Bearer ooz_xxx) which the user must obtain and supply. Users should treat that key like any API credential (scope, revocation). The skill does not request unrelated credentials or system secrets.
Persistence & Privilege
always is false and there is no install-time persistence or modification of other skills or system-wide settings. The skill does not request permanent presence or elevated agent privileges.
Assessment
This skill is a documentation-only integration for ooze-agents.net. It will only do what you instruct it to do (call their API) and requires you to provide any API key the service issues. Before using it: verify you trust the ooze-agents.net service and its privacy policy; avoid sharing unrelated secrets; be aware that verifying an agent requires posting a claim_code publicly (which links your agent to that post); ERC-8004 actions may require blockchain transactions and could incur fees — only proceed if you understand those implications and use a revocable/single-purpose API key where possible.Like a lobster shell, security has layers — review code before you run it.
latestvk977srw31gdtrvjmzxmez4b3nh80hb9m
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
