Hyperliquid DEX Integration

v1.1.0

Query Hyperliquid DEX for account balances, positions, PnL, and margin data via ClawdBot API

0· 1.1k·0 current·0 all-time
byAlec Gutman@chipagosfinest
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The SKILL.md describes a read-only Hyperliquid query flow via a ClawdBot API proxy which matches the skill name and description. However, the SKILL.md expects an internal service (ClawdBot API) to exist and be callable; the registry metadata does not declare the required CLAWDBOT_API_URL (or any primary credential). This is an implementation gap: calling an internal proxy is plausible for a ClawdBot-targeted skill, but the required base URL must be declared.
!
Instruction Scope
Runtime instructions tell the agent to POST to {CLAWDBOT_API_URL}/api/hyperliquid/account and rely optionally on TRADING_WALLET_ADDRESS. The registry did not declare CLAWDBOT_API_URL; SKILL.md lists only TRADING_WALLET_ADDRESS as an env var (optional). The instructions do not ask for private keys and claim read-only access to public Hyperliquid endpoints, but they will transmit wallet addresses (public) to the ClawdBot proxy — the trustworthiness and authentication of that proxy are not described.
Install Mechanism
No install spec and no code files — instruction-only. This minimizes on-disk risk; nothing is downloaded or executed locally by the skill itself.
!
Credentials
The skill declares only an optional TRADING_WALLET_ADDRESS but the instructions require a CLAWDBOT_API_URL base endpoint which is not declared. No secrets or private keys are requested (good), but the undeclared dependency on a ClawdBot internal API endpoint is a proportionality/mis-declaration issue and could hide assumptions about authentication or headers that aren't documented.
Persistence & Privilege
The skill is not always-enabled, is user-invocable, and allows model invocation (normal). It requests no persistent presence or elevated system privileges.
What to consider before installing
This skill appears to be a read-only adapter that queries Hyperliquid through a ClawdBot proxy — that is reasonable for the described purpose. However: (1) SKILL.md references {CLAWDBOT_API_URL} but the registry does not declare that environment variable; ask the publisher where the ClawdBot API base URL comes from and whether the platform will supply it. (2) Confirm whether the ClawdBot proxy requires authentication or will add headers; if it does, understand what credentials are used and where they are stored. (3) Verify the source/homepage or request source code before installing — the package has no public repo or homepage. (4) Test with a public wallet address first (no private keys) to confirm only public read-only data is transmitted. If the publisher cannot explain the CLAWDBOT_API_URL or provide provenance for the proxy, treat the skill as untrusted.

Like a lobster shell, security has layers — review code before you run it.

clawdbotvk978r0ecfqq8r7gepahk4cra6180zdxzcryptovk978r0ecfqq8r7gepahk4cra6180zdxzdefivk978r0ecfqq8r7gepahk4cra6180zdxzderivativesvk978r0ecfqq8r7gepahk4cra6180zdxzdexvk978r0ecfqq8r7gepahk4cra6180zdxzhyperliquidvk978r0ecfqq8r7gepahk4cra6180zdxzlatestvk978r0ecfqq8r7gepahk4cra6180zdxzmargin-tradingvk978r0ecfqq8r7gepahk4cra6180zdxzperpetualsvk978r0ecfqq8r7gepahk4cra6180zdxzportfoliovk978r0ecfqq8r7gepahk4cra6180zdxztradingvk978r0ecfqq8r7gepahk4cra6180zdxz

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments