Back to skill
Skillv1.0.2

VirusTotal security

Token Vesting · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

BenignApr 30, 2026, 3:42 AM
Hash
cf3213367320be274ed554b0af45e046158fee042e0925ff3a964abb2dc522e0
Source
palm
Verdict
benign
Code Insight
Type: OpenClaw Skill Name: token-vesting Version: 1.0.2 The OpenClaw AgentSkills skill bundle is classified as benign. It provides instructions and examples for creating and managing token vesting streams using the Sablier Lockup protocol via Foundry's `cast` and `forge` CLI tools. The skill explicitly includes robust security guidelines for the AI agent, instructing it to never log, embed, or ask for raw private keys, and to prioritize secure signing methods (hardware wallets, Foundry keystore, environment variables). Crucially, the `SKILL.md` header contains `disable-model-invocation: true`, which significantly limits the agent's ability to execute arbitrary commands or deviate from the predefined secure practices, mitigating prompt injection risks. All commands and operations are aligned with the stated purpose and use standard, legitimate blockchain interaction methods.
External report
View on VirusTotal