Atoship
v1.0.8Ship packages with AI — compare rates across USPS, FedEx, and UPS, buy discounted labels, track shipments, and manage orders. Requires user confirmation befo...
⭐ 2· 809·3 current·3 all-time
byatoship dev@atoship-dev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (shipping: compare rates, buy labels, track) align with the declared primary credential (ATOSHIP_API_KEY) and the SKILL.md which describes calling the atoship API. The functionality requested (rate lookups, purchases, tracking) reasonably requires an API key that can charge a wallet.
Instruction Scope
SKILL.md is an instruction-only runtime spec that describes API calls to atoship.com, workflows for comparing rates, collecting addresses, purchasing labels, and tracking. It does not instruct the agent to read local files, unrelated env vars, system config, or exfiltrate data. It explicitly requires explicit user confirmation before purchases, which keeps billing actions scoped.
Install Mechanism
No install spec or code files — instruction-only — so nothing is written to disk or downloaded during install. This is the lowest-risk install model.
Credentials
The skill only needs a single API credential (ATOSHIP_API_KEY), which is proportional to its purpose. Note: there is a small metadata inconsistency in the registry summary (top-level 'Required env vars: none') versus the SKILL.md/metadata that declare ATOSHIP_API_KEY as required; the primary credential is still appropriate, but users should verify the key's permissions and scope before use since it can authorize wallet charges.
Persistence & Privilege
The skill is not 'always' installed and allows normal autonomous invocation (disable-model-invocation:false). Autonomous invocation is expected for skills; however because the API key can perform purchases, ensure the agent's implementation reliably prompts for explicit user confirmation before any wallet-affecting action. The SKILL.md instructs to always ask, which is good practice.
Assessment
This skill appears coherent for shipping tasks, but before installing: 1) Verify the API endpoint (https://atoship.com) and that the API key you create is scoped as intended. 2) Use a test/sandbox key while evaluating and start with a small wallet balance (the SKILL.md recommends $20). 3) Confirm the agent implementation actually prompts and requires explicit user confirmation before any purchase — autonomous agents can act quickly, so make sure purchases are gated. 4) Enable spending alerts and be prepared to revoke/rotate keys if anything looks wrong. 5) Review atoship's billing and privacy docs and confirm label void/refund policies. The only minor inconsistency is the registry summary saying no required env vars while the skill requires ATOSHIP_API_KEY; verify the platform will supply/require that key before use.Like a lobster shell, security has layers — review code before you run it.
automationvk9778p3n117nsyeq2bgny6w6q981dfwxecommercevk9778p3n117nsyeq2bgny6w6q981dfwxfedexvk9778p3n117nsyeq2bgny6w6q981dfwxlabelsvk9778p3n117nsyeq2bgny6w6q981dfwxlatestvk9769096gme6619ppd711nxkds81h8valogisticsvk9778p3n117nsyeq2bgny6w6q981dfwxpostagevk9778p3n117nsyeq2bgny6w6q981dfwxshipmentvk9778p3n117nsyeq2bgny6w6q981dfwxshippingvk9778p3n117nsyeq2bgny6w6q981dfwxshipping-managervk9778p3n117nsyeq2bgny6w6q981dfwxshipping-solutionvk9778p3n117nsyeq2bgny6w6q981dfwxtrackingvk9778p3n117nsyeq2bgny6w6q981dfwxupsvk9778p3n117nsyeq2bgny6w6q981dfwxuspsvk9778p3n117nsyeq2bgny6w6q981dfwx
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
📦 Clawdis
Primary envATOSHIP_API_KEY
