AI自主赚钱系统
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The SKILL.md describes an autonomous freelance/crypto-monitoring agent and instructs storing API keys and persistent memory files, but the registry metadata declares no credentials, env vars, or config paths — the behavior and requirements are inconsistent and warrant caution.
This skill instructs an agent to register a third-party mail bot, save its API key, poll blockchain APIs, and keep persistent memory files — but the registry metadata declares no credentials or config paths. Before installing, verify the legitimacy of the external service 'SendClaw' (don’t register with unknown providers), and decide where and how API keys will be stored (use secure secret storage rather than plaintext files). If you plan to run this, run the agent in an isolated environment, review and restrict what data it may store in SESSION-STATE.md / MEMORY.md, and avoid giving any private keys or broad credentials. Ask the skill author to: (1) declare required environment variables and recommended secure storage, (2) explain exactly what data is persisted and retention policy, and (3) provide provenance for external endpoints. If you’re uncomfortable, do not install or run it with real credentials or production data.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
