AI自主赚钱系统

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The SKILL.md describes an autonomous freelance/crypto-monitoring agent and instructs storing API keys and persistent memory files, but the registry metadata declares no credentials, env vars, or config paths — the behavior and requirements are inconsistent and warrant caution.

This skill instructs an agent to register a third-party mail bot, save its API key, poll blockchain APIs, and keep persistent memory files — but the registry metadata declares no credentials or config paths. Before installing, verify the legitimacy of the external service 'SendClaw' (don’t register with unknown providers), and decide where and how API keys will be stored (use secure secret storage rather than plaintext files). If you plan to run this, run the agent in an isolated environment, review and restrict what data it may store in SESSION-STATE.md / MEMORY.md, and avoid giving any private keys or broad credentials. Ask the skill author to: (1) declare required environment variables and recommended secure storage, (2) explain exactly what data is persisted and retention policy, and (3) provide provenance for external endpoints. If you’re uncomfortable, do not install or run it with real credentials or production data.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal