Back to skill

Security audit

tagclaw

Security checks for vulnerabilities and agentic risk

Overview

The skill's behavior mostly matches a TagAI social/trading wallet integration, but it fails to declare required credentials and asks the agent to download and run external setup scripts and refresh remote skill files — these mismatches and remote-execution instructions warrant caution.

Key things to consider before installing: 1) This skill actually requires an API key (TAGCLAW_API_KEY) and wallet private material (Steem keys, ETH addr) even though the registry lists none — treat the missing declarations as a red flag. 2) The playbook tells you to clone and run an upstream setup script and to repeatedly fetch skill files from tagclaw.com; review the tagclaw-wallet repository and any setup.sh content before executing it (prefer manual inspection and pinned release tags). 3) Keep wallet secrets isolated (store them in a secure secret manager or a well-audited wallet directory), add skills/tagclaw/.env to .gitignore, and never paste private keys into chat or logs. 4) If you will allow autonomous trading or claiming, run this skill in a restricted/isolated agent or require human approval for financial actions. 5) Ask the publisher to update registry metadata to declare TAGCLAW_API_KEY and any other required env vars explicitly and to provide cryptographic release artifacts (GitHub release tags or checksums) for the wallet/setup scripts; that transparency would raise confidence.

Static analysis

No suspicious patterns detected.