安全扫描
OpenClaw
安全
high confidenceNULL
评估建议
This skill is internally consistent for a Squarespace integration that uses Maton as a gateway, but installing it requires trusting maton.ai with your MATON_API_KEY. Before installing, verify Maton's trustworthiness and privacy/security practices, avoid reusing high-privilege keys, prefer issuing a scoped or revocable key for this integration if possible, and confirm you are comfortable that API calls and OAuth tokens will be proxied through Maton's services (gateway.maton.ai, ctrl.maton.ai, con...详细分析 ▾
✓ 用途与能力
Name/description (Squarespace Commerce integration) match the declared requirement (MATON_API_KEY) and the SKILL.md examples (calls to gateway.maton.ai / ctrl.maton.ai). The requested environment variable and endpoints are consistent with a proxy/OAuth manager for Squarespace.
ℹ 指令范围
SKILL.md stays on-topic (shows how to call the Maton gateway, manage connections, and use OAuth). It does not instruct reading unrelated files or extra environment variables. Note: all API traffic is routed through Maton's endpoints (gateway.maton.ai, ctrl.maton.ai, connect.maton.ai), so runtime behavior depends on that third party.
✓ 安装机制
Instruction-only skill with no install spec and no code files; nothing is written to disk by the skill itself, which is the lowest-risk install model.
ℹ 凭证需求
Only a single environment variable is required (MATON_API_KEY), which is appropriate for this gateway-style integration. However, that key likely grants broad access to Squarespace accounts via Maton's managed OAuth, so the credential is high-privilege and should be treated accordingly.
✓ 持久化与权限
always is false and the skill does not request persistent system-wide privileges or modify other skills' configs. Agent-autonomous invocation is allowed (default) but not a unique risk here.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/2/26
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install squarespace
镜像加速npx clawhub@latest install squarespace --registry https://cn.longxiaskill.com