风险评分

76/100 (Low)

OpenClaw: benign
VirusTotal: suspicious
StaticScan: unknown

Pinata ERC-8004

作者: Matthias | Pinata
Slug:pinata-erc-8004
版本:1.0.6
更新时间:2026-03-24 12:13:47
风险信息

OpenClaw: benign

查看 OpenClaw 分析摘要(前 200 字预览)
The skill's requirements and runtime instructions are coherent with its stated purpose (registering ERC-8004 agents via Pinata + Viem) but it handles high-risk credentials and is instruction-only (no ...

[内容已截断]

VirusTotal: suspicious VT 报告

静态扫描: unknown

README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1771632806078,
        "_id": "k972fj3zcg2nhgar3xeqnk91es81kwyn",
        "changelog": "**Summary: Enhanced security posture with strict credential and external data handling restrictions.**\n\n- Added explicit rules prohibiting output or leakage of PRIVATE_KEY and PINATA_JWT in all forms of agent output.\n- Introduced a new \"THREAT MODEL\" section, outlining untrusted data sources and stricter denial by default for write operations.\n- Clarified boundaries for usage of addresses and data from untrusted external sources (IPFS\/API responses).\n- Added \"Credential Handling Rules (Absolute)\" including Node.js environment variable requirements in code generation.\n- Updated forbidden operations section to prohibit use of addresses\/contracts from IPFS or API responses unless validated against a hardcoded allowlist.\n- Emphasized that credentials must only be referenced as environment variables in code and must never appear in chat, file, HTTP request, log, or code outputs.",
        "changelogSource": "user",
        "createdAt": 1771632806078,
        "parsed": {
            "clawdis": {
                "emoji": "🤖",
                "primaryEnv": "PINATA_JWT",
                "requires": {
                    "bins": [
                        "node"
                    ],
                    "env": [
                        "PINATA_JWT",
                        "PINATA_GATEWAY_URL",
                        "PRIVATE_KEY"
                    ]
                }
            }
        },
        "version": "1.0.6"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "Matthias | Pinata",
        "handle": "iammatthias",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/5431737?v=4",
        "kind": "user",
        "linkedUserId": "kn75pszqsdbzq42x925mcdpc9d812x85"
    },
    "ownerHandle": "iammatthias",
    "skill": {
        "_creationTime": 1771437119281,
        "_id": "kd7f05t5a41vq7tet4424n8k6x81ccad",
        "badges": [],
        "createdAt": 1771437119281,
        "displayName": "Pinata ERC-8004",
        "latestVersionId": "k972fj3zcg2nhgar3xeqnk91es81kwyn",
        "ownerUserId": "kn75pszqsdbzq42x925mcdpc9d812x85",
        "slug": "pinata-erc-8004",
        "stats": {
            "comments": 0,
            "downloads": 504,
            "installsAllTime": 0,
            "installsCurrent": 0,
            "stars": 2,
            "versions": 7
        },
        "summary": "Register and verify ERC-8004 AI agents on-chain using Pinata IPFS and Viem for blockchain transactions",
        "tags": {
            "latest": "k972fj3zcg2nhgar3xeqnk91es81kwyn"
        },
        "updatedAt": 1774325627912
    }
}