OpenClaw: suspicious
VirusTotal: suspicious
StaticScan: unknown
OpenClaw: suspicious
The skill's purpose (music research) matches its instructions, but it asks the agent to run an unpinned npm package via npx and hands your Anthropic API key to that subprocess, which is a supply-chain... [内容已截断]
VirusTotal: suspicious VT 报告
静态扫描: unknown
README 未提供
无文件信息
{
"latestVersion": {
"_creationTime": 1772056683881,
"_id": "k971gtn4se7c43mxm9aray6f6d81tdvs",
"changelog": "Initial release — 92 tools across 17 sources. Influence tracing, track verification, playlist building, and publishing.",
"changelogSource": "user",
"createdAt": 1772056683881,
"parsed": {
"clawdis": {
"emoji": "🎵",
"homepage": "https:\/\/github.com\/tmoody1973\/crate-cli",
"primaryEnv": "ANTHROPIC_API_KEY",
"requires": {
"bins": [
"npx"
],
"env": [
"ANTHROPIC_API_KEY"
]
}
}
},
"version": "0.2.3"
},
"owner": {
"_creationTime": 0,
"_id": "publishers:missing",
"displayName": "Tarik Moody",
"handle": "tmoody1973",
"image": "https:\/\/avatars.githubusercontent.com\/u\/81526818?v=4",
"kind": "user",
"linkedUserId": "kn71dptvppc7cwnxpbth6x59y981tqrk"
},
"ownerHandle": "tmoody1973",
"skill": {
"_creationTime": 1772056683881,
"_id": "kd761n2vs9w54aw2c9qcp80f2h81t16b",
"badges": [],
"createdAt": 1772056683881,
"displayName": "Music Research (Crate)",
"latestVersionId": "k971gtn4se7c43mxm9aray6f6d81tdvs",
"ownerUserId": "kn71dptvppc7cwnxpbth6x59y981tqrk",
"slug": "crate-music-research",
"stats": {
"comments": 0,
"downloads": 285,
"installsAllTime": 0,
"installsCurrent": 0,
"stars": 0,
"versions": 1
},
"summary": "AI-powered music research with 92+ tools across 17 sources — MusicBrainz, Bandcamp, Discogs, Genius, Last.fm, Wikipedia, and more. Influence tracing, track v...",
"tags": {
"latest": "k971gtn4se7c43mxm9aray6f6d81tdvs"
},
"updatedAt": 1774327149015
}
}