Api2Cart
v1.0.0API2Cart integration. Manage data, records, and automate workflows. Use when the user wants to interact with API2Cart data.
⭐ 0· 45·0 current·0 all-time
byVlad Ursul@gora050
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description claim integration with API2Cart via Membrane; the SKILL.md exclusively instructs use of the Membrane CLI and browser-based connection flows. No unrelated credentials, binaries, or system paths are requested.
Instruction Scope
Instructions stay within the stated purpose (search/connect/run actions and proxy requests through Membrane). Important behavioral note: requests and credentials are proxied/managed by Membrane servers (not a direct api2cart.com call), so data and API credentials will transit/store on Membrane.
Install Mechanism
There is no platform install spec, but the SKILL.md directs installing @membranehq/cli via npm (global install) or using npx. That is expected for the described workflow but carries the normal risks of installing and running third‑party npm packages.
Credentials
The skill requests no environment variables or local secrets and explicitly instructs not to ask users for API keys, instead relying on Membrane-managed connections. This is proportionate, though it centralizes credentials with Membrane.
Persistence & Privilege
The skill does not request always:true, system-level persistence, or access to other skills' configs. It is user-invocable and can be invoked autonomously (default), which is normal for skills.
Assessment
This skill appears consistent and performs as described, but it relies on Membrane's service and an npm CLI: 1) Installing @membranehq/cli (global npm or npx) runs third-party code—verify the package and its repository before installing. 2) Using the skill requires a Membrane account and browser-based login; Membrane will proxy requests and manage API2Cart credentials on your behalf—only proceed if you trust Membrane to store and transmit your e‑commerce data. 3) Avoid pasting API keys directly into conversations; follow the connection flow. 4) On headless or shared machines, be cautious with the login-complete codes/URLs the CLI prints. If you need to keep credentials local or avoid third-party proxying, this skill is not appropriate.Like a lobster shell, security has layers — review code before you run it.
latestvk9719s58fv33ngp1kvyen584bd84f64r
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
