Back to skill
Skillv1.1.1
ClawScan security
Learn Moralis · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignFeb 27, 2026, 7:11 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a documentation/onboarding (knowledge-only) skill about Moralis that only reads its bundled reference files and does not request credentials or install anything—its requirements and behavior are coherent with its stated purpose.
- Guidance
- This skill is a local documentation/onboarding guide for Moralis and appears safe to add: it only reads its bundled reference files and contains no code or install steps. Before using it, note that the skill will route you to technical skills (@moralis-data-api, @moralis-streams-api) for live queries — those other skills will require a MORALIS_API_KEY (and Streams require a webhook secret) and will perform network calls. If you plan to use the technical skills, verify those skills' sources and required environment variables before granting them access to credentials. Also confirm the publisher (metadata lists MoralisWeb3 and a GitHub repo) if you require an official-signer provenance.
Review Dimensions
- Purpose & Capability
- okThe skill is an onboarding/FAQ guide for Moralis and only references Moralis products and technical skills (@moralis-data-api, @moralis-streams-api). It does not request unrelated binaries, credentials, or access; its suggestion to set MORALIS_API_KEY is guidance for using the downstream technical skills rather than a requirement for this knowledge skill.
- Instruction Scope
- okSKILL.md confines runtime behavior to answering user questions and routing to the appropriate technical skills. It explicitly allows only Read/Grep/Glob on the bundled reference files (FAQ, ProductComparison, UseCaseGuide). There are no instructions to read system files, read environment variables, or transmit data to hidden endpoints.
- Install Mechanism
- okNo install spec and no code files — instruction-only skill. That minimizes disk writes and runtime install risk; nothing is downloaded or executed.
- Credentials
- okThe skill declares no required environment variables or credentials. The documentation mentions MORALIS_API_KEY as something the user should set when using the actual Moralis API skills, which is proportionate and expected for downstream usage. No unrelated secrets are requested.
- Persistence & Privilege
- okDefault privileges (always: false, agent invocation allowed) are used. The skill does not request permanent presence, modify other skills, or claim elevated system privileges.
