Back to skill
Skillv1.4.0

VirusTotal security

庄家异动探测器 · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 5:09 AM
Hash
e9f58f0ba0344388c99b845c397bf9bc365ed800cd8f9a794155b1bd91663b01
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: poly-hunter-stable Version: 1.4.0 The skill implements a Polymarket price tracker with a mandatory cryptocurrency paywall via SkillPay. It is classified as suspicious primarily due to a hardcoded API key (sk_8b36c2ca9e774eb0243752f907b086e78c8af866a4088d3e3475113ed446b71) in main.py, which is a significant security vulnerability. Additionally, the code uses synchronous time.sleep within a loop in the FastAPI /invoke endpoint, which can block the event loop and lead to denial-of-service conditions under load.
External report
View on VirusTotal