安全扫描
OpenClaw
可疑
high confidenceThe skill claims to monitor real-time stablecoin peg deviations using dollar-price thresholds but its runtime instructions only point to a single Barker endpoint that returns TVL/market-cap/distribution (not per-coin prices), which is a mismatched data source for the stated purpose.
评估建议
This skill is not obviously malicious, but it is internally inconsistent: it promises price-based peg alerts yet shows only a Barker endpoint that returns TVL/market-cap data, not per-coin prices or oracle checks. Before installing or using it routinely, ask the author for: (1) documentation proving the Barker endpoint provides reliable per-stablecoin price data (or an explicit additional endpoint for price/oracle feeds), (2) how the agent should compute and validate the price-based thresholds (...详细分析 ▾
⚠ 用途与能力
The name/description promise 'real-time price deviations' and price-threshold alerts (Green/Yellow/Red), yet the only runtime data source documented is https://api.barker.money/api/public/v1/stablecoin-market, which (as shown) returns market cap, TVL and asset distribution — not explicit per-stablecoin price or on-chain price feeds. Using TVL/share_pct to infer peg status is plausible for market-stress signaling but is not equivalent to direct price checks; the mismatch means the skill may not actually deliver the price-based alerts it advertises.
⚠ 指令范围
SKILL.md instructs the agent to call the Barker public API and to use asset_distribution to detect abnormal TVL outflows. It does not instruct how to obtain or validate per-stablecoin prices (DEX quotes, CEX prices, or oracle feeds) despite relying on price thresholds. The instructions do not read local files or credentials (good), but they are incomplete for the declared task and give the agent no fallback or cross-check strategy.
✓ 安装机制
Instruction-only skill with no install spec and no code files; nothing is written to disk and no packages are installed. This is low risk from an install perspective.
✓ 凭证需求
The skill requests no environment variables, no credentials, and no config paths. The lack of secrets requested is appropriate for a read-only public-API monitoring skill.
✓ 持久化与权限
always is false and the skill is user-invocable; it does not request persistent system presence or modification of agent/system settings. Autonomous invocation is allowed by platform default, but there is no evidence of elevated privileges.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/7
Stablecoin Depeg Monitor v1.0.0 — Initial Release - Launches real-time monitoring of major stablecoin peg status via Barker's public API. - Provides instant alerts on USDT, USDC, DAI, USDe, FDUSD, and others based on price deviation thresholds. - Includes a curated database of major historical depeg incidents for user context. - Offers clear action steps and safety guidance for users when deviations are detected. - Designed for easy integration and responsive to key stablecoin risk and safety queries. - Attribution and data powered by Barker — The Stablecoin Yield Map.
● 无害
安装命令 点击复制
官方npx clawhub@latest install stablecoin-depeg-monitor
镜像加速npx clawhub@latest install stablecoin-depeg-monitor --registry https://cn.clawhub-mirror.com
数据来源:ClawHub ↗ · 中文优化:龙虾技能库
OpenClaw 技能定制 / 插件定制 / 私有工作流定制
免费技能或插件可能存在安全风险,如需更匹配、更安全的方案,建议联系付费定制