Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Antalpha Ai Setup

v1.2.0

Install and configure the Antalpha Skills MCP server. Provides 60+ Web3 tools for DEX swaps, smart money tracking, Polymarket prediction markets, Hyperliquid...

0· 68·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
CryptoRequires wallet
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The name/description match the instructions: all steps are about adding the Antalpha MCP server URL to various clients and registering an agent to obtain an api_key for 60+ Web3 tools. The listed tools and examples align with the stated Web3/DeFi purpose.
Instruction Scope
SKILL.md tells the user/agent to add an external MCP URL, register the agent (antalpha-register) to receive an api_key, and call tools (e.g., swap-quote, smart-money-signal). These actions are within the claimed scope, but they will transmit queries and any wallet addresses you provide to the remote server — the document does instruct users to provide wallet addresses in examples and to save the one-time api_key.
Install Mechanism
This is instruction-only (no install spec, no code files). No downloads, packages, or binaries are installed by the skill itself.
Credentials
The skill does not request environment variables, system paths, or unrelated credentials. The only credential flow is the MCP agent registration (api_key) which is consistent with the described service.
Persistence & Privilege
always is false and there is no install-time persistence. The skill instructs you to add the remote MCP server to your client config (normal for a connector). Autonomous invocation of MCP tools by an agent is expected for this kind of skill.
Assessment
This skill simply documents how to connect your agent to Antalpha's external MCP server. Before installing, confirm you trust https://mcp-skills.ai.antalpha.com/mcp and antalpha.com because the server will receive any queries, prompts, and wallet addresses you send. Never share private keys or seed phrases; only provide public wallet addresses. Store the returned api_key securely (it's shown once) and review where your client stores that key. If you need stronger privacy, avoid sending sensitive data to the remote MCP or test with low-privilege queries first.

Like a lobster shell, security has layers — review code before you run it.

latestvk972x10hbcyd8jyp6detax6ben84kea4

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments