Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Samcart
v1.0.2SamCart integration. Manage Products, Orders, Customers, Funnels, Upsells. Use when the user wants to interact with SamCart data.
⭐ 0· 113·0 current·0 all-time
byVlad Ursul@gora050
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (SamCart integration) match the runtime instructions: discover and run SamCart actions via the Membrane CLI and proxy. No unrelated credentials, binaries, or platform access are requested.
Instruction Scope
Instructions stay on-topic (install Membrane CLI, create a connection, run actions, or proxy requests). They do direct SamCart traffic through the Membrane proxy/service, so SamCart data and API requests will be sent to Membrane-managed infrastructure rather than directly to SamCart from the agent; this is expected but worth noting.
Install Mechanism
No install spec in the registry (instruction-only). The SKILL.md recommends installing @membranehq/cli via npm (a public npm package) — a typical, moderate-risk step because it requires running a third-party installer and potentially global/package-manager permissions.
Credentials
The skill does not request environment variables, local config paths, or other unrelated credentials. It explicitly instructs not to ask users for API keys and to let Membrane manage credentials.
Persistence & Privilege
always is false and there is no install that writes persistent skill-owned configuration here. The skill instructs the user/agent to run a CLI and create a connection in Membrane (normal for this integration).
Assessment
This skill is instruction-only and simply tells the agent to use the Membrane CLI to access SamCart. Before installing or following the instructions: (1) confirm you trust Membrane (getmembrane.com / the @membranehq npm package and its GitHub repo) because SamCart API access and credentials will be managed and proxied by Membrane; (2) note that installing the CLI with npm -g may require elevated permissions and installs third‑party code on your machine; and (3) if you need stricter data residency or trust boundaries, consider connecting SamCart directly (instead of via Membrane) or review Membrane's privacy/security docs and the connector's permissions before proceeding.Like a lobster shell, security has layers — review code before you run it.
latestvk977ztdqjkns9a27af0jvgj86x84277b
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
