OpenClaw: benign
VirusTotal: suspicious
StaticScan: unknown
OpenClaw: benign
The skill's requirements and runtime instructions are coherent with its stated purpose (registering ERC-8004 agents via Pinata + Viem) but it handles high-risk credentials and is instruction-only (no ... [内容已截断]
VirusTotal: suspicious VT 报告
静态扫描: unknown
README 未提供
无文件信息
{
"latestVersion": {
"_creationTime": 1771632806078,
"_id": "k972fj3zcg2nhgar3xeqnk91es81kwyn",
"changelog": "**Summary: Enhanced security posture with strict credential and external data handling restrictions.**\n\n- Added explicit rules prohibiting output or leakage of PRIVATE_KEY and PINATA_JWT in all forms of agent output.\n- Introduced a new \"THREAT MODEL\" section, outlining untrusted data sources and stricter denial by default for write operations.\n- Clarified boundaries for usage of addresses and data from untrusted external sources (IPFS\/API responses).\n- Added \"Credential Handling Rules (Absolute)\" including Node.js environment variable requirements in code generation.\n- Updated forbidden operations section to prohibit use of addresses\/contracts from IPFS or API responses unless validated against a hardcoded allowlist.\n- Emphasized that credentials must only be referenced as environment variables in code and must never appear in chat, file, HTTP request, log, or code outputs.",
"changelogSource": "user",
"createdAt": 1771632806078,
"parsed": {
"clawdis": {
"emoji": "🤖",
"primaryEnv": "PINATA_JWT",
"requires": {
"bins": [
"node"
],
"env": [
"PINATA_JWT",
"PINATA_GATEWAY_URL",
"PRIVATE_KEY"
]
}
}
},
"version": "1.0.6"
},
"owner": {
"_creationTime": 0,
"_id": "publishers:missing",
"displayName": "Matthias | Pinata",
"handle": "iammatthias",
"image": "https:\/\/avatars.githubusercontent.com\/u\/5431737?v=4",
"kind": "user",
"linkedUserId": "kn75pszqsdbzq42x925mcdpc9d812x85"
},
"ownerHandle": "iammatthias",
"skill": {
"_creationTime": 1771437119281,
"_id": "kd7f05t5a41vq7tet4424n8k6x81ccad",
"badges": [],
"createdAt": 1771437119281,
"displayName": "Pinata ERC-8004",
"latestVersionId": "k972fj3zcg2nhgar3xeqnk91es81kwyn",
"ownerUserId": "kn75pszqsdbzq42x925mcdpc9d812x85",
"slug": "pinata-erc-8004",
"stats": {
"comments": 0,
"downloads": 504,
"installsAllTime": 0,
"installsCurrent": 0,
"stars": 2,
"versions": 7
},
"summary": "Register and verify ERC-8004 AI agents on-chain using Pinata IPFS and Viem for blockchain transactions",
"tags": {
"latest": "k972fj3zcg2nhgar3xeqnk91es81kwyn"
},
"updatedAt": 1774325627912
}
}