Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

gate-mcp-installer

v1.0.0

One-click installer and configurator for Gate MCP (mcporter) in OpenClaw. Use when the user wants to (1) Install mcporter CLI tool, (2) Configure Gate MCP se...

0· 334·0 current·0 all-time
bykobin2@kobin-be
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description match the included script and SKILL.md: the script installs mcporter (npm i -g mcporter), adds a Gate MCP config pointing at https://api.gatemcp.ai/mcp, and verifies connectivity. These actions are proportionate to an installer/configurator.
!
Instruction Scope
The runtime instructions and script are limited to installing mcporter, running mcporter config commands, and listing tools. However, SKILL.md's troubleshooting mentions an unrelated host (fulltrust.link), which is inconsistent with the script's Gate URL (api.gatemcp.ai) and could indicate stale or erroneous text that should be clarified. The script prompts interactively and does not exfiltrate data, but the mismatch is a red flag to verify before running.
Install Mechanism
There is no packaged installer spec; the script uses npm to globally install an npm package (mcporter). Pulling and running a package from the public npm registry is common but carries moderate risk (npm package install scripts run arbitrary code on install). Global installs may require elevated privileges and modify your system PATH.
Credentials
The skill requests no environment variables, reads no credentials, and the script does not access secrets or unrelated config paths. No disproportionate credential access is requested.
Persistence & Privilege
The skill is not forced-always and does not modify other skills, but it causes a system-wide change by installing a global npm package. That persistence (a globally installed binary) is expected for an installer but increases blast radius if the npm package is malicious or compromised.
What to consider before installing
Before running this installer: (1) Verify the mcporter npm package and its maintainers on npmjs.org (review package source, install scripts, and recent publish history). (2) Confirm the intended Gate MCP endpoint—the script uses https://api.gatemcp.ai/mcp but SKILL.md mentions fulltrust.link; ask the publisher which is correct. (3) Prefer running the manual commands yourself (npm i -g mcporter or npx mcporter) in a controlled environment or container rather than blindly executing the script. (4) Be aware a global npm install can execute arbitrary install-time code and may require sudo; if you cannot verify the package, do not install globally on a production machine. (5) If you want higher assurance, request the skill author/publisher identity and source repository or run the steps in an isolated VM.

Like a lobster shell, security has layers — review code before you run it.

latestvk972r784vfayv9e9bg262kwzm582a1bb
334downloads
0stars
1versions
Updated 7h ago
v1.0.0
MIT-0

Gate MCP Installer

One-click setup for Gate MCP (mcporter) in OpenClaw.

Quick Start

To set up Gate MCP, run the install script:

bash ~/.openclaw/skills/gate-mcp-installer/scripts/install-gate-mcp.sh

Or execute the skill directly and I will guide you through the installation.

What This Skill Does

This skill automates the complete Gate MCP setup process:

  1. Installs mcporter CLI globally via npm
  2. Configures Gate MCP server with proper endpoint
  3. Verifies connectivity by listing available tools
  4. Provides usage examples for common queries

Manual Installation Steps (if script fails)

Step 1: Install mcporter

npm i -g mcporter
# Or verify installation
npx mcporter --version

Step 2: Configure Gate MCP

mcporter config add gate https://api.gatemcp.ai/mcp --scope home

Step 3: Verify Configuration

# Check config is written
mcporter config get gate

# List available tools
mcporter list gate --schema

If tools are listed, Gate MCP is ready to use!

Common Usage Examples

After installation, use Gate MCP with queries like:

  • "查询 BTC/USDT 的价格"
  • "用 gate mcp 分析 SOL"
  • "Gate 有什么套利机会?"
  • "查看 ETH 的资金费率"

Troubleshooting

IssueSolution
command not found: mcporterRun npm i -g mcporter
Config not foundRun the config add command again
Connection timeoutCheck internet connection to fulltrust.link
No tools listedVerify config URL is correct

Resources

  • Install Script: scripts/install-gate-mcp.sh - Automated one-click installer

Comments

Loading comments...