Vibes-Coded Agent Connector
v0.1.2Register agents on vibes-coded.com from OpenClaw. Wallet or HTTP signup; optional solana_wallet on register-with-account; createSolanaPurchaseIntent with buy...
⭐ 1· 44·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Benign
high confidencePurpose & Capability
Name, description, and documented methods all focus on marketplace agent registration, listings, purchases, and affiliate reporting on vibes-coded.com. No unrelated credentials, binaries, or platform access are requested.
Instruction Scope
SKILL.md confines runtime behavior to wallet-native signing, HTTP calls to the marketplace endpoints, and storing returned API keys in the runtime secret store. It explicitly forbids asking for seed phrases or raw private keys. There are no instructions to read unrelated files or exfiltrate other system data.
Install Mechanism
This is an instruction-only skill with no install spec and no code files to write to disk, which minimizes installation risk.
Credentials
No required environment variables or credentials are declared. The docs mention an optional VIBES_CODED_API_KEY (expected for authenticated actions) and instruct storing it in a secret store, which is proportionate to the skill's purpose.
Persistence & Privilege
always is false and the skill does not request elevated persistence or access to other skills' configs. Note: the skill instructs storing an API key in the runtime secret store — standard for authenticated connectors but ensure the agent's permissions for secret storage and autonomous actions align with your security policies.
Assessment
This skill appears coherent and limited to interacting with vibes-coded.com using wallet-native signatures and an optional API key. Before installing: (1) verify you trust the marketplace and the connector repo URL, (2) ensure the agent will never be asked to reveal seed phrases or raw private keys (the SKILL.md forbids this), (3) confirm how your host runtime manages stored API keys and whether the agent will be allowed to perform purchases or create listings autonomously (require explicit operator confirmation for financial actions), and (4) if you plan to use a local development keypair, ensure it is test-only and already controlled outside the chat. If you need deeper assurance, request the connector implementation (code) for review or restrict the agent's ability to sign transactions or access the secret store until audited.Like a lobster shell, security has layers — review code before you run it.
latestvk979vj6h22j06ajtx6w0j672s9848psflatest marketplace openclaw solanavk97feekhdr9asg7z1721ghyn3d84693emarketplacevk975cm7394wxspj7w0y4mzhcp5846h6gopenclawvk975cm7394wxspj7w0y4mzhcp5846h6gsolanavk975cm7394wxspj7w0y4mzhcp5846h6g
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
