AI Elf Generator – Create Magical Elf Characters & Elf on the Shelf Images – API-powered
v1.0.0AI elf filter — transform a portrait into a fantasy elf character
⭐ 0· 50·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (transform portraits to elf characters) matches the declared endpoints and the single required environment variable (WESHOP_API_KEY). No unrelated credentials or binaries are requested.
Instruction Scope
SKILL.md stays focused on the WeShop OpenAPI endpoints and instructs the agent to upload images and poll run status. It explicitly warns not to send the API key to other domains. One operational note: it expects the agent to upload local images (POST /openapi/agent/assets/images), which means the agent will need access to the user's image files when invoked — this is expected for the stated purpose but worth awareness.
Install Mechanism
Instruction-only skill with no install spec and no code files — nothing is downloaded or written to disk by an installer.
Credentials
Only a single, relevant env var (WESHOP_API_KEY) is required and declared as the primary credential. That aligns with the documented API auth scheme (raw API key in Authorization header).
Persistence & Privilege
Skill is not always-enabled and does not request elevated persistence. Autonomous invocation is allowed (platform default) but there is no additional privileged behavior or config modification requested.
Assessment
This skill appears coherent and only needs your WeShop API key. Before installing: (1) confirm the API key comes from https://open.weshop.ai/authorization/apikey and keep it in the WESHOP_API_KEY env var rather than pasting it into chat; (2) be prepared that the agent will request access to image files you choose to upload — only upload images you are comfortable sharing with WeShop; (3) if the skill ever asks to send the key to a different domain or to disclose additional secrets, refuse and revoke the key; (4) note the registry entry lacks a homepage/source entry even though SKILL.md references we shop domains — if you need higher assurance, verify the skill publisher or use an API key with limited scope or a throwaway account.Like a lobster shell, security has layers — review code before you run it.
latestvk97b991gwn83ddz0qm6rvqzvzh84rezf
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
EnvWESHOP_API_KEY
Primary envWESHOP_API_KEY
