安全扫描
OpenClaw
安全
high confidenceInstruction-only Sui reference: the skill is a plaintext guide about Sui (object model, staking, Move, wallets) with no installs, no requested credentials, and behavior that matches its description.
评估建议
This skill is an educational/reference guide about Sui and appears internally consistent. It asks for no credentials and installs nothing, so the direct security risk is low. Considerations before installing: 1) the skill's source/homepage is unknown — prefer skills from known, trusted publishers for sensitive operations; 2) the guidance may be outdated or incomplete, so verify critical actions (validator choices, bridge addresses, ledger status) against official Sui docs; 3) never paste or type...详细分析 ▾
✓ 用途与能力
The name/description (Sui transactions, object model, staking, Move) match the SKILL.md content. All material is explanatory and aligned with a documentation/reference skill; nothing requires additional system access or credentials.
✓ 指令范围
SKILL.md is purely informative guidance (concepts, common issues, wallet options). It does not instruct the agent to run commands, read files, access environment variables, or transmit data to external endpoints. No scope creep detected.
✓ 安装机制
No install specification or code files — instruction-only skills are low-risk because nothing is written to disk or executed.
✓ 凭证需求
The skill requests no environment variables, credentials, or config paths. There are no disproportionate or unrelated secrets requested.
✓ 持久化与权限
Flags show default behavior (always: false, agent-invocable allowed). The skill does not request permanent presence or elevated privileges. Autonomous invocation is allowed by platform default but is not combined with other red flags here.
安全有层次,运行前请审查代码。
运行时依赖
🖥️ OSLinux · macOS · Windows
版本
latestv1.0.22026/2/11
- Added sui-network-review.html file for additional documentation or review. - Updated SKILL.md: removed "SUI" from the description, now reads "Assist with SUI transactions, object model, staking, and Move smart contracts" (minor wording change, no major content update).
● 无害
安装命令 点击复制
官方npx clawhub@latest install sui-network
镜像加速npx clawhub@latest install sui-network --registry https://cn.clawhub-mirror.com
技能文档
Object Model (Critical Difference)
- Sui uses objects, not accounts — everything is an object with unique ID
- Objects are owned or shared — owned objects enable parallel transactions
- Coins are objects too — SUI balance is sum of coin objects you own
- Object IDs are permanent — address doesn't change but objects move
- Different from Ethereum's account model — requires different mental model
SUI Token
- Native gas token — required for all transactions
- Total supply fixed at creation — no inflation, but distribution ongoing
- Gas fees burned — deflationary pressure
- Staking rewards from fees — validators and delegators earn from gas
Transaction Characteristics
- Sub-second finality — extremely fast confirmation
- Parallel execution for owned objects — independent transactions don't wait
- Gas is predictable — know exact cost before submitting
- Transactions are atomic — all or nothing, no partial execution
- Sponsored transactions possible — someone else pays gas
Address Format
- Addresses start with "0x" — 64 hex characters
- One address per wallet — but many objects owned
- Not the same as Ethereum addresses — different derivation
- Same seed gives different addresses than other chains
Wallet Options
- Sui Wallet (official) — browser extension
- Suiet, Ethos — alternative wallets with good UX
- Ledger support coming — check current status
- Mobile wallets available — Sui Wallet has mobile app
Staking
- Delegate to validators — no minimum to stake
- Epoch-based rewards — epochs are ~24 hours
- Staking locks SUI — but liquid staking options exist
- Choose validators carefully — commission rates vary
- Rewards compound automatically — unless you withdraw
Gas and Fees
- Gas denominated in MIST — 1 SUI = 10^9 MIST
- Gas budget set per transaction — unused gas refunded
- Storage fees separate — pay for object storage
- Gas prices stable — reference gas price updated per epoch
- Very cheap transactions — fractions of a cent
Move Language
- Smart contracts written in Move — not Solidity
- Object-centric programming — different from EVM
- Strong safety guarantees — resources can't be copied or lost
- Abilities system — controls what objects can do
- Package upgrades possible — but original stays on chain
DeFi and NFTs
- Cetus, Turbos for DEX — major decentralized exchanges
- NFTs are objects — natural fit for Sui's model
- Kiosk standard for NFT trading — built-in marketplace primitives
- SuiFrens and other NFT collections — active NFT ecosystem
- Dynamic NFTs easy — objects can change over time
Common Issues
- "Insufficient gas" — need more SUI for transaction
- Object not found — object was consumed or transferred
- Transaction failed — check error message, often gas or permission
- Coins fragmented — many small coin objects, merge them
- Staking delayed — rewards start next epoch after staking
Coin Management
- Coins are separate objects — can have many coin objects
- Merge coins to simplify — combine into fewer objects
- Split coins for exact amounts — needed for some dApps
- Gas paid from one coin object — automatically selected
- Wallet usually manages this — but understand the model
Cross-Chain
- Wormhole bridge available — connect to other chains
- Bridged assets are wrapped — not native on other chains
- Bridge verification important — verify official bridge addresses
- Native USDC coming — Circle deploying natively
Security
- Seed phrase controls everything — standard 12/24 word recovery
- Transaction preview shows effects — review before signing
- dApp permissions matter — revoke unused connections
- Objects can have transfer restrictions — check before assuming transferable
- Verify package addresses — scam dApps exist
数据来源:ClawHub ↗ · 中文优化:龙虾技能库
OpenClaw 技能定制 / 插件定制 / 私有工作流定制
免费技能或插件可能存在安全风险,如需更匹配、更安全的方案,建议联系付费定制