Pebblecrab
v1.0.0The Pebblecrab is a common-tier Buddy. At animalhouse.ai, the Pebblecrab is a Hedgehog. Both curl up when scared. Only one of them dies. At animalhouse.ai, t...
⭐ 0· 69·0 current·0 all-time
byLee Brown@leegitw
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description claim a virtual-pet Buddy tied to animalhouse.ai; the SKILL.md contains only API examples (register, adopt, status, care) and links to the project—requirements match the stated purpose and do not request unrelated capabilities.
Instruction Scope
Runtime instructions are limited to making HTTPS requests to animalhouse.ai endpoints using a bearer token returned by the register endpoint. The instructions do not instruct reading local files, accessing unrelated env vars, or transmitting data to unexpected endpoints.
Install Mechanism
No install spec and no code files are present (instruction-only). Nothing will be written to disk or downloaded by an installation step.
Credentials
The skill declares no required environment variables or credentials. It expects the user to obtain and supply a bearer token from animalhouse.ai for API calls, which is appropriate and proportional for the described functionality.
Persistence & Privilege
always is false and model invocation is allowed (the platform default). The skill does not request permanent presence or system-wide configuration changes.
Assessment
This SKILL.md is an API usage guide for animalhouse.ai and appears coherent with that purpose. Before using it: (1) verify you trust https://animalhouse.ai (review their privacy/security policy) because API calls will send data there; (2) treat the returned bearer token (starts with ah_) as sensitive—don’t reuse it for unrelated accounts or paste it into untrusted places; (3) the skill examples send only the token and simple JSON actions (adopt, feed, etc.), so avoid including other secrets in those payloads; (4) if you want stronger isolation, create a dedicated account/token for testing; and (5) note the SKILL.md mentions an alleged Anthropic leak as flavor text—that claim is unrelated to the security posture of these curl examples. Overall the skill is internally consistent and does not request disproportionate access.Like a lobster shell, security has layers — review code before you run it.
latestvk97cxwmfgekp0a4pke3e247rq9841mts
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🪨 Clawdis
