首页龙虾技能列表 › PayLobster — 基于 Base 的信任无需的智能支付基础设施

PayLobster — 基于 Base 的信任无需的智能支付基础设施

v4.6.0

PayLobster 是一套面向自治代理的金融操作系统,提供信任无需的多链钱包、去中心化身份与信誉系统、跨链桥、法币进出站、智能合约支付、中英文自然语言支付指令、商户服务、支付中间件等功能,支持通过 SDK、CLI、REST API、MCP 等多种方式集成,适用于需要高级金融操作和信任管理的开发者和应用。

0· 0·0 当前·0 累计
by @itsgustav·MIT-0
下载技能包
License
MIT-0
最后更新
2026/3/28
安全扫描
VirusTotal
可疑
查看报告
OpenClaw
可疑
medium confidence
安全扫描发现技能描述与处理敏感凭证和链上/钱包操作的运行指令不符,尤其是涉及金融影响,建议澄清来源和凭证处理机制后再使用。
评估建议
该技能与资金和代理身份交互,使用前请验证提供者和来源。建议:1. 确认代码托管和运营位置;2. 要求声明环境变量和密钥管理流程;3. 对资金操作要求手动确认;4. 如果允许自主操作,限制交易签署和传输,要求用户明确批准支付。...
详细分析 ▾
用途与能力
The skill claims to be a full payments/escrow/treasury system on Base, which legitimately requires wallets, API keys, and integration credentials; however the registry metadata lists no required env vars, no primary credential, and no install/binaries. The lack of declared credentials and absent homepage/source makes the provenance and capability claims inconsistent with what a payments integration would normally require.
指令范围
SKILL.md contains concrete runtime instructions that call external endpoints (paylobster.com), create merchant API keys, perform charges, and show wallet signing flows. These instructions implicitly require handling secrets (sk_live_...), signing with wallets, and authorizing on-chain token transfers. The instructions do not limit or warn about secret handling, and they expose operations that could move funds or reveal rich agent identity data (SIWA profile endpoints that return full profiles).
安装机制
Instruction-only skill with no install spec and no code files — low install-time risk because nothing is written or executed locally by an installer. The main runtime risk is network calls to an external service rather than local code execution from an untrusted download.
凭证需求
The SKILL.md shows use of merchant secrets (sk_live_...), onramp/offramp, and wallet operations, but the skill declares no required environment variables or primary credential. That omission is disproportionate: a payment integration should explicitly declare needed credentials and scope. The skill also references Coinbase and third-party integrations without declaring required tokens or config paths.
持久化与权限
The skill does not request always:true, does not install code, and does not declare writing to agent/system config. Autonomous invocation is allowed by default but is not combined here with any declared persistent privilege in the package metadata.
安全有层次,运行前请审查代码。

License

MIT-0

可自由使用、修改和再分发,无需署名。

运行时依赖

无特殊依赖

版本

latestv4.6.02026/3/28
● 可疑

安装命令 点击复制

官方npx clawhub@latest install paylobster
镜像加速npx clawhub@latest install paylobster --registry https://cn.clawhub-mirror.com

技能文档

... (保持原 Markdown 格式,仅翻译非代码、非 YAML 部分)