Kraken Agent
v1.0.3Discover and use the official Kraken CLI — an AI-native trading tool for crypto, stocks, forex, and derivatives. Use when: setting up a trading agent, paper...
⭐ 0· 47·0 current·0 all-time
byDeonte Cooper@djc00p
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Benign
high confidencePurpose & Capability
The name and description match the SKILL.md content: it documents the official Kraken CLI, paper trading, MCP usage, and live auth. There are no unexplained environment variables, binaries, or config paths requested by the skill itself.
Instruction Scope
Runtime instructions stay on-topic: installation pointers, example CLI commands, MCP configuration, and guidance for using API keys for live trading. The doc does not instruct reading unrelated files, collecting arbitrary host data, or exfiltrating secrets. It does advise using environment variables for API keys when enabling live trading, which is reasonable but should be handled cautiously by the user/agent.
Install Mechanism
No install spec or code is included; the skill only links to the upstream project on GitHub and refers to the single binary 'kraken'. This minimizes on-disk risk but requires you to obtain the CLI from the upstream source and verify it yourself.
Credentials
The skill itself requires no environment variables, but it documents using KRAKEN_API_KEY and KRAKEN_API_SECRET for live trading. That is proportionate to the claimed feature (live trading) but is sensitive: exposing these creds to an agent or shell history could enable real trades. The doc correctly warns against passing keys directly on the CLI.
Persistence & Privilege
Skill flags are default (always:false, agent-invocable allowed). The skill does not request persistent presence or elevated privileges, nor does it attempt to modify other skills or system settings.
Assessment
This skill is an instruction-only guide to using an external Kraken CLI binary and appears coherent. Before installing or following its instructions: 1) Verify the upstream GitHub repo and release artifacts (checksums, signatures) to ensure you download the official kraken binary; 2) Prefer paper trading while testing; don't provide live API keys to an agent or paste them on the CLI — use secure environment storage or short-lived/least-privilege keys and rotate them; 3) If you enable the MCP server or add the CLI to an agent config, limit the server scope (e.g., market,paper) rather than allowing 'all' unless you fully trust the runtime and the agent's safeguards; 4) Consider running the CLI in an isolated environment (container or VM) and reviewing agent logs/commands that could trigger real trades; and 5) If you need higher assurance, inspect the upstream repo code and release process yourself or ask an engineer to do so.Like a lobster shell, security has layers — review code before you run it.
latestvk97348h66ejgw7q3jm1bkpm68h84spb6
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
📈 Clawdis
OSmacOS · Linux
