📦 Graph Aave Mcp — Aave数据监控
v4.0.7基于16个子图和Aave V4 API的MCP服务器,提供40款工具,覆盖准备金、持仓、跨链清算风险监控与治理数据。
0· 76·0 当前·0 累计
下载技能包
最后更新
2026/4/11
安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
Before installing: verify the npm package and GitHub repository (maintainer, stars, recent commits, package author) to ensure the code is trustworthy. Note that SKILL.md asks you to run 'npm install -g graph-aave-mcp' which will execute code downloaded from npm — consider installing in a sandbox/container or vetting the package source first. Confirm the package name matches the linked GitHub repo and check package versions and release notes. Also set a dedicated GRAPH_API_KEY (The Graph) with mi...详细分析 ▾
ℹ 用途与能力
The skill claims to provide Aave V2/V3/V4 tools via The Graph and Aave V4 API, which aligns with the instructions (queries to The Graph, npm package named graph-aave-mcp). However the registry metadata omitted the environment variable and the SKILL.md requires a GRAPH_API_KEY and implies npm is needed — a mismatch between declared requirements and runtime instructions.
✓ 指令范围
SKILL.md's runtime instructions are focused: install the npm package, run the binary, and set GRAPH_API_KEY. It does not instruct reading arbitrary system files or unrelated environment variables, nor sending data to unexpected endpoints beyond The Graph/npm. No broad data-collection steps are present in the instructions.
⚠ 安装机制
There is no install specification in the registry, yet SKILL.md instructs users to install an npm package globally (npm install -g graph-aave-mcp). Installing an external npm package executes remote code from the npm registry — a moderate-risk action. The SKILL.md provides npm and GitHub links (helpful), but the absence of an install spec in the skill bundle and no pinned release info means the installer behavior and provenance aren't enforced by the registry metadata.
⚠ 凭证需求
SKILL.md requires a single GRAPH_API_KEY for The Graph, which is appropriate for the claimed functionality. However the registry metadata claims 'Required env vars: none' and 'Primary credential: none', creating an inconsistency. Requesting one API key is proportional, but the metadata mismatch is confusing and could lead to unexpected runtime prompts.
✓ 持久化与权限
The skill does not request always:true, does not include install-time system modifications in the bundle, and is user-invocable. Autonomous invocation is allowed by default (normal). There is no indication the skill will attempt to modify other skills or agent-wide settings.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv4.0.72026/4/11
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install graph-aave-mcp
镜像加速npx clawhub@latest install graph-aave-mcp --registry https://cn.longxiaskill.com