Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Graph Limitless Mcp

v1.0.0

Query Limitless prediction markets on Base — live odds, trader P&L, whale tracking, market stats, and daily volume from The Graph's decentralized network.

0· 106·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for paulieb14/graph-limitless-mcp.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Graph Limitless Mcp" (paulieb14/graph-limitless-mcp) from ClawHub.
Skill page: https://clawhub.ai/paulieb14/graph-limitless-mcp
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: GRAPH_API_KEY
Required binaries: node
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install graph-limitless-mcp

ClawHub CLI

Package manager switcher

npx clawhub@latest install graph-limitless-mcp
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description (querying Limitless subgraphs via The Graph) matches the declared requirement of a GRAPH_API_KEY and node runtime. The declared endpoints (gateway.thegraph.com and api.limitless.exchange) are consistent with the stated functionality. Minor mismatch: SKILL.md's install invocation uses npx but the required binaries list only 'node' (npx/npm are not explicitly listed).
!
Instruction Scope
Runtime instructions direct the user/agent to run 'npx graph-limitless-mcp' — that will download and execute remote code at runtime. The SKILL.md claims only two endpoints are contacted and that no data is stored locally, but because the package code is not included in the skill bundle there is no way to confirm those claims. An npx-executed package could read other env vars, files, or contact additional endpoints unless audited.
!
Install Mechanism
There is no install spec in the bundle; instead SKILL.md instructs use of 'npx' to fetch the package from npm. This is a remote-download-and-execute pattern (moderate-to-high risk) because arbitrary code will be retrieved at runtime. The npm and GitHub links are provided which is normal, but absent bundled code the scanner could not verify package behavior.
Credentials
The only declared required environment variable is GRAPH_API_KEY (the Graph gateway API key), which is appropriate for querying The Graph. However, because execution is delegated to an npm package fetched at runtime, that code could access additional environment variables or secrets on the host — something the SKILL.md cannot be validated to prevent.
Persistence & Privilege
The skill does not request persistent privileges: always is false, no config paths, and it is user-invocable. Autonomous invocation by the agent is allowed (platform default) but that alone is not flagged. The SKILL.md claims no local storage; this cannot be verified without reviewing the package code.
What to consider before installing
This skill is plausible for querying Limitless via The Graph, but it is instruction-only and tells you to run 'npx graph-limitless-mcp', which will download and execute code from npm at install/run time. Before installing or running: (1) inspect the npm package contents and GitHub repo to confirm the code only calls gateway.thegraph.com and api.limitless.exchange and does not exfiltrate other data; (2) verify the npm package name and maintainers match the GitHub repo to avoid typosquatting; (3) consider creating a limited-scope Graph API key (or rotate/delete the key after testing); (4) run the package in a sandbox or CI environment first if you can; (5) if you cannot audit the package, avoid using npx to execute it directly or disable autonomous invocation for the agent. The main risks are remote code execution via npx and inability to confirm the package won’t access other env vars or endpoints.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎯 Clawdis
Binsnode
EnvGRAPH_API_KEY
Primary envGRAPH_API_KEY
latestvk978p0fzfkj47q02bzcqc11hjh83hwth
106downloads
0stars
1versions
Updated 1mo ago
v1.0.0
MIT-0

Graph Limitless MCP

Query Limitless prediction markets on Base. Get live market data, trader analytics, positions, and volume — powered by The Graph's decentralized network.

Try it

  • "What are the top markets on Limitless by volume?"
  • "Show me the biggest traders on Limitless"
  • "Daily volume trends for the last 30 days"
  • "Who holds the largest positions in this market?"
  • "What markets resolved today?"
  • "Show me whale trades over $10K"

What's inside

ToolWhat it does
get_platform_statsTotal markets, volume, trades, users across Simple + NegRisk
get_marketsBrowse markets with volume, trade counts, resolution status
search_marketsSearch by keyword or category via Limitless API
get_market_detailsDeep dive on a specific market — conditions, outcomes, payouts
get_tradesRecent trades with USD amounts, buy/sell, maker/taker
get_user_statsTrader profile — volume, trade count, first/last trade
get_user_tradesFull trade history for any wallet
get_user_positionsCurrent holdings with token balances
get_daily_snapshotsDaily volume, trades, splits, merges, redemptions
get_market_daily_snapshotsPer-market daily breakdown
get_top_tradersLeaderboard by volume
get_whale_tradesLarge trades filtered by minimum USD amount

Data coverage

  • Simple Markets: 8,000+ markets, 3.9M trades, $317M volume
  • NegRisk Markets: 700+ markets, multi-outcome prediction markets
  • Network: Base L2
  • Updated: Real-time via The Graph's decentralized indexing network

Install

GRAPH_API_KEY=your-key npx graph-limitless-mcp

Get a free API key at The Graph Market.

External Endpoints

EndpointData sentPurpose
gateway.thegraph.comGraphQL queries with your API keyQueries 2 Limitless subgraphs on Base
api.limitless.exchangeMarket search queriesFetches market metadata and categories

No other endpoints are contacted. No data is stored locally.

Security & Privacy

  • Runs locally via npx — no remote server
  • Your API key stays local — only sent to The Graph Gateway
  • No persistent storage — no database, no local files
  • Open source — full code at github.com/PaulieB14/limitless-subgraphs

Model Invocation Note

This skill may be invoked autonomously by your AI agent when it detects a prediction market question about Limitless. Disable the skill to opt out.

Trust Statement

By using this skill, GraphQL queries are sent to gateway.thegraph.com using your API key, and market metadata requests go to api.limitless.exchange. Only install if you trust these endpoints with your query data.

Links

Comments

Loading comments...