Solpaw Interaction Skill
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious due to its explicit requirement for the `SOLANA_PRIVATE_KEY` environment variable, which the OpenClaw agent is instructed to use for local transaction signing. While the skill's design emphasizes local signing (preventing direct server-side exposure of the key), exposing a private key to an AI agent environment, as detailed in `SKILL.md`, `skill.json`, and `README.md`, represents a significant security risk. There is no clear evidence of intentional malicious behavior like exfiltration by the skill itself, but the inherent risk of handling such a sensitive credential by an autonomous agent warrants a 'suspicious' classification. All network communication is directed to `https://api.solpaw.fun`.
