Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Dexscreener Openapi Skill

v1.0.0

Operate DexScreener public market data APIs through UXC with a curated OpenAPI schema, no-auth setup, and read-first guardrails.

0· 156·1 current·1 all-time
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Skill name, description, OpenAPI schema, and runtime instructions align with a read-only DexScreener integration. However, SKILL.md requires the 'uxc' tool to be installed and available in PATH while the registry metadata lists no required binaries — an undeclared runtime dependency. The included OpenAPI file and usage examples match the claimed operations.
Instruction Scope
Instructions are narrowly scoped to public read-only API calls through uxc/dexscreener-openapi-cli; they explicitly forbid write operations and wallet/trading actions and emphasize JSON parsing and rate-limit awareness. The skill requires network access to api.dexscreener.com and to a GitHub raw URL for the schema (both consistent with the purpose).
Install Mechanism
No install spec is present (instruction-only), so nothing will be written to disk by a packaged installer. The only script is a local validate.sh used for developer validation; it does not perform remote downloads or modify system configuration.
Credentials
The skill requests no environment variables or credentials, which is appropriate for public read-only APIs. Network access to the DexScreener API and the schema URL is required and justified by the skill's purpose.
Persistence & Privilege
The skill is not always-enabled and does not request any elevated platform privileges or attempts to modify other skills or system-wide agent settings. Autonomous invocation is allowed (default) but is not combined with other concerning indicators.
What to consider before installing
This skill appears to do what it says: read-only DexScreener queries via the 'uxc' OpenAPI tooling. Before installing, verify you have and trust the 'uxc' tool (SKILL.md requires it but the registry metadata does not declare it). The repo includes a validation script (scripts/validate.sh) that expects jq and ripgrep (rg) — those are developer/test tools and not required by the skill at runtime, but you should only run the script if you trust the package. Confirm you are comfortable allowing network access to https://api.dexscreener.com and the referenced raw.githubusercontent.com schema URL. If you want to reduce risk, run the skill in a constrained environment (network-restricted or read-only) and inspect or pin the exact uxc binary/source you will use.

Like a lobster shell, security has layers — review code before you run it.

latestvk9701znq6csjpk0sqnbb5g0w49837pba
156downloads
0stars
1versions
Updated 3h ago
v1.0.0
MIT-0

DexScreener API Skill

Use this skill to run DexScreener public market data operations through uxc + OpenAPI.

Reuse the uxc skill for shared execution, auth, and error-handling guidance.

Prerequisites

  • uxc is installed and available in PATH.
  • Network access to https://api.dexscreener.com.
  • Access to the curated OpenAPI schema URL:
    • https://raw.githubusercontent.com/holon-run/uxc/main/skills/dexscreener-openapi-skill/references/dexscreener-public.openapi.json

Scope

This skill covers a read-first DexScreener surface for:

  • token profile discovery
  • latest and top token boosts
  • pair search by free-text query
  • pair lookup by chain and pair address
  • token market lookup by chain and token address list

This skill does not cover:

  • write operations
  • private or authenticated workflows
  • every DexScreener endpoint
  • trading or wallet execution

Authentication

DexScreener public reads in this skill do not require authentication.

Core Workflow

  1. Use the fixed link command by default:

    • command -v dexscreener-openapi-cli
    • If missing, create it: uxc link dexscreener-openapi-cli https://api.dexscreener.com --schema-url https://raw.githubusercontent.com/holon-run/uxc/main/skills/dexscreener-openapi-skill/references/dexscreener-public.openapi.json
    • dexscreener-openapi-cli -h
  2. Inspect operation schema first:

    • dexscreener-openapi-cli get:/token-profiles/latest/v1 -h
    • dexscreener-openapi-cli get:/latest/dex/search -h
    • dexscreener-openapi-cli get:/latest/dex/pairs/{chainId}/{pairId} -h
    • dexscreener-openapi-cli get:/tokens/v1/{chainId}/{tokenAddresses} -h
  3. Prefer narrow reads before broader scans:

    • dexscreener-openapi-cli get:/token-profiles/latest/v1
    • dexscreener-openapi-cli get:/token-boosts/latest/v1
    • dexscreener-openapi-cli get:/latest/dex/search q=solana
  4. Execute with key/value parameters:

    • dexscreener-openapi-cli get:/latest/dex/pairs/{chainId}/{pairId} chainId=solana pairId=GgzbfpKtozV6Hyiahkh2yNVZBZsJa4pcetCmjNtgEXiM
    • dexscreener-openapi-cli get:/tokens/v1/{chainId}/{tokenAddresses} chainId=solana tokenAddresses=So11111111111111111111111111111111111111112

Operations

  • get:/token-profiles/latest/v1
  • get:/token-boosts/latest/v1
  • get:/token-boosts/top/v1
  • get:/latest/dex/search
  • get:/latest/dex/pairs/{chainId}/{pairId}
  • get:/tokens/v1/{chainId}/{tokenAddresses}

Guardrails

  • Keep automation on the JSON output envelope; do not use --text.
  • Parse stable fields first: ok, kind, protocol, data, error.
  • Treat this v1 skill as read-only. Do not imply order entry, swaps, or wallet operations.
  • Keep q focused to a token, pair, chain, or symbol rather than broad crawler-style searches.
  • For tokenAddresses, start with a single address or a short comma-separated list before scaling up.
  • DexScreener enforces endpoint-specific rate limits. Profile and boost endpoints are typically lower-throughput than pair and token lookup endpoints, so cache aggressively when polling discovery feeds.
  • DexScreener data is market-observation oriented and may be noisier on long-tail tokens than curated exchange-only feeds.
  • dexscreener-openapi-cli <operation> ... is equivalent to uxc https://api.dexscreener.com --schema-url <dexscreener_openapi_schema> <operation> ....

References

Comments

Loading comments...