Worldcoin
v1.0.0Filter human-critical workflows using proof-of-human logic. Designed for identity-sensitive commercial decisions, anti-bot gating, and “real human required”...
⭐ 0· 201·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
medium confidencePurpose & Capability
The skill's name and description claim to design human-verification decision logic and anti-bot gating; the runtime instructions only ask the agent to analyze workflows and recommend trust layers. No requested binaries, env vars, or installs are needed for that purpose, so requirements are proportionate.
Instruction Scope
SKILL.md contains a bounded, stepwise execution protocol (parse workflow, classify risk, recommend gate, show tradeoffs). It does not instruct the agent to read system files, access credentials, or send data to external endpoints. It explicitly states it does not integrate with World ID/Orb or perform biometric/KYC checks.
Install Mechanism
This is an instruction-only skill with no install spec and no code files to write or execute. That is the lowest-risk install surface and matches the advisory nature of the skill.
Credentials
The skill declares no required environment variables, credentials, or config paths. That is appropriate for a design/advisory skill that produces recommendations but does not perform verification or call external identity services.
Persistence & Privilege
The skill does not request always:true or other elevated persistent privileges. Autonomous invocation is allowed (the platform default) — appropriate for a user-invocable advisory skill. One small non-security note: the skill name ('Worldcoin') could mislead users into expecting ties to the Worldcoin project despite explicit disclaimers; consider provenance validation before trust.
Assessment
This skill is an advisory tool only — it analyzes workflows and recommends where to add human-verification gates. It does not perform biometric checks, call World ID/Orb, or perform KYC/AML. Before installing: verify the skill author's provenance (the registry owner is an ID string and homepage metadata is inconsistent), because instruction-only skills still run inside your agent and could produce policy decisions you might act on. Do not rely on this skill for legal or regulatory compliance — consult specialists for KYC/AML. Avoid sending raw personal or sensitive identifiers into the skill during testing. If you need technical integration steps or actual identity verification, this skill explicitly opts out — you'll need a different integration that legitimately requests API keys or credentials.Like a lobster shell, security has layers — review code before you run it.
latestvk9700ttjc88j4v04cxyn253phd82mvmb
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
