Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Crypto Short Signal Generator

v1.0.0

Generates short signals predicting 30%+ coin drops within 7 days based on historical token unlock schedules and price trends analysis.

0· 353·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dennyhuang2024/crypto-short-signal.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Crypto Short Signal Generator" (dennyhuang2024/crypto-short-signal) from ClawHub.
Skill page: https://clawhub.ai/dennyhuang2024/crypto-short-signal
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Canonical install target

openclaw skills install dennyhuang2024/crypto-short-signal

ClawHub CLI

Package manager switcher

npx clawhub@latest install crypto-short-signal
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill is a paid two-layer crypto signal generator and the code implements billing and a paid API call, which is consistent with the stated purpose. However, the registry metadata supplied to the evaluator lists no required environment variables or credentials while config.json and the code declare SKILLPAY_API_KEY as required — a clear metadata/requirement mismatch.
Instruction Scope
SKILL.md and the code limit runtime actions to billing (SkillPay) and calling the paid analysis API; they do not instruct reading unrelated system files or environment variables beyond SkillPay-related settings. The public layer validates input, charges users, and forwards requests to the paid layer as described.
Install Mechanism
There is no install spec (instruction-only install) and only Node.js source files are included. No external arbitrary download URLs or unusual installers are used. This is low-risk from an install mechanism perspective.
!
Credentials
The bundle contains an embedded SkillPay API key in config.json and both index.js/api.js default to that same key if SKILLPAY_API_KEY is not set. The registry metadata claims no required env vars, but config.json marks SKILLPAY_API_KEY as required. Hard-coded operational keys in the repo are disproportionate and dangerous (credential leak / potential misuse).
Persistence & Privilege
The skill does not request always:true, does not modify other skills or system-wide configuration, and is user-invocable only. It does not request elevated persistence or cross-skill privileges.
Scan Findings in Context
[hardcoded_api_key_in_config] unexpected: config.json contains a SkillPay API key (sk_...) embedded in the repository. A paid-skill should require the operator to provide their own key via SKILLPAY_API_KEY rather than shipping an operational key.
[hardcoded_api_key_in_code] unexpected: index.js and api.js both fallback to a hard-coded API key when process.env.SKILLPAY_API_KEY is absent. This makes the embedded key usable by anyone who deploys the skill unmodified.
[external_billing_api_calls] expected: index.js and api.js call SkillPay billing endpoints (https://skillpay.me/api/v1/billing) to charge users — expected for a paid two-layer skill.
[embedded_token_database] expected: api.js includes a small hard-coded TOKEN_DATABASE used to produce sample responses; reasonable for demo data but limited compared to claimed core 'database' in SKILL.md.
What to consider before installing
This skill implements a paid public layer and forwards requests to a paid API, which is coherent with its description — but the repository contains a hard-coded SkillPay API key and its metadata claims no required env vars while config.json marks SKILLPAY_API_KEY as required. Before installing: (1) Do not trust or use the embedded API key — treat it as leaked/compromised; prefer to set your own SKILLPAY_API_KEY in the environment. (2) If you plan to deploy or pay for this skill, rotate any keys the author published and avoid using their credentials. (3) Consider running the paid layer (api.js) on infrastructure you control or confirm SkillPay/author trustworthiness. (4) Review network endpoints and logs to ensure user identifiers or other sensitive data are not being sent anywhere unexpected. (5) Be cautious using this for live trading — the skill includes a disclaimer and historical metrics but trading risk and legal/regulatory concerns remain. If you need a safer posture, request the author remove embedded keys and update the registry metadata to declare required env vars correctly, or refuse to install the skill.

Like a lobster shell, security has layers — review code before you run it.

latestvk97avbfcray11jta68ze51cs1982bg1d
353downloads
0stars
1versions
Updated 9h ago
v1.0.0
MIT-0

Crypto Short Signal Generator

Version: 2.0.0 (Two-Layer Architecture)
Author: Denny Huang
Description: Know which coins will drop 30%+ 7 days in advance based on historical token unlock data


🏗️ Architecture

This skill uses a two-layer architecture for security and scalability:

Public Layer (ClawHub)

  • SkillPay billing interface
  • Basic validation
  • Calls paid layer API

Paid Layer (SkillPay Cloud)

  • Core analysis logic
  • Token database
  • API Key (secured)

📖 Overview

This skill analyzes token unlock schedules and generates short signals based on historical data. Historical win rate: 78%.


🎯 Features

  • Query token unlock dates
  • Analyze pre/post unlock price trends
  • Generate short signals (entry/exit/stop-loss)
  • Risk assessment report

💰 Pricing

  • Single Query: 0.001 USDT
  • Batch Query (5 tokens): 0.005 USDT

Payment: BNB Chain USDT via SkillPay


📊 Supported Tokens

TokenUnlock DateUnlock AmountExpected Drop
ZRO2026-03-2032.6M (3.26%)-5.97%
BARD2026-03-1811.35M (1.14%)-4.0%
STABLE2027-01-01TBDTBD

🚀 Usage

Basic Query

{
  "token": "ZRO"
}

Response

{
  "status": "success",
  "data": {
    "token": "ZRO",
    "name": "LayerZero",
    "unlock_date": "2026-03-20",
    "unlock_amount": "32.6M",
    "unlock_percent": "3.26%",
    "circulating_ratio": "20.26%",
    "fdv_mcap": "4.94x",
    "risk_level": "高",
    "short_signal": {
      "short_start": "2026-03-13",
      "short_end": "2026-03-19",
      "target_drop": "-5.97%",
      "target_price": "$0.94",
      "stop_loss": "$1.10",
      "win_rate": "78%"
    }
  }
}

⚠️ Disclaimer

This skill is for reference only and does not constitute investment advice. Cryptocurrency markets are highly volatile. Users trade at their own risk. Historical performance does not guarantee future results.


🔗 Links


Created: 2026-03-05
Updated: 2026-03-05
Architecture: Two-Layer (Public + Paid)

Comments

Loading comments...