Eu Trade Analytics

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent instruction-only trade analytics skill, but it sends queries to a third-party SputnikX API/MCP service and documents some paid endpoints.

This skill appears benign for querying EU trade data. Before installing, be aware that requests go to SputnikX rather than directly to a Eurostat domain, and some endpoints are marked as paid x402 calls.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Your trade research queries, including countries, partners, product codes, and years, may be visible to the third-party service.

Why it was flagged

The skill directs the agent to send trade analytics queries to an external API and MCP server operated by SputnikX.

Skill content
Base URL `https://sputnikx.xyz/api/v1/agent` ... `Endpoint: https://mcp.sputnikx.xyz/mcp`
Recommendation

Use it only for queries you are comfortable sending to SputnikX, and verify the provider if the analysis is commercially sensitive.

What this means

If your agent environment supports x402 payments, some analytics requests could incur small charges.

Why it was flagged

Several documented endpoints appear to require small x402 payments, so invoking them may have a cost even though the cost is disclosed.

Skill content
### Price Per Tonne ($0.10 x402) ... ### Seasonality ($0.10 x402) ... ### Concentration/HHI ($0.10 x402)
Recommendation

Confirm before using paid endpoints or configure your agent/payment settings to require approval for paid calls.