安全扫描
OpenClaw
安全
medium confidenceNULL
评估建议
Before installing or enabling this skill: verify you trust the remote MCP server (competitive-intel-mcp.apify.actor) and the GitHub/homepage owner; confirm the provenance of the mcporter binary you already have; inspect or manually add the ~/.openclaw/mcp.json entry rather than blindly running commands; avoid sending sensitive or proprietary data in queries (the remote server will receive your queries); if you’re uncomfortable trusting a third party, run a local or organizational MCP endpoint th...详细分析 ▾
✓ 用途与能力
The skill claims to provide SEC filings, news, contracts, and profiles and its SKILL.md describes tools that map directly to those data sources. The declared required binary (mcporter) matches the setup instructions for adding a remote MCP server, so the requested capability is proportionate to the stated purpose.
ℹ 指令范围
Instructions do not ask the agent to read unrelated local files or environment variables, but they do tell you to add a remote MCP server URL (https://competitive-intel-mcp.apify.actor/mcp) and/or write that entry into ~/.openclaw/mcp.json. That delegates runtime tool behavior to a third party; the agent will send queries and accept responses from that remote server, which is expected for this skill but is a privacy/trust consideration.
✓ 安装机制
There is no install spec and no code files — this is instruction-only. Risk from installation is low, but it requires the mcporter binary to already be present on the system.
✓ 凭证需求
The skill declares no required environment variables or credentials, consistent with its claim of using free public APIs. No unrelated secrets are requested.
ℹ 持久化与权限
The skill does not request 'always' or system-wide elevated privileges. However, the setup instructs adding a persistent entry to ~/.openclaw/mcp.json or running mcporter add, which stores the external MCP server configuration on disk and gives the agent persistent access to that server until you remove it.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/2/28
NULL
● 可疑
安装命令
点击复制官方npx clawhub@latest install gov-competitive-intel
镜像加速npx clawhub@latest install gov-competitive-intel --registry https://cn.longxiaskill.com镜像同步中