安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
This skill appears to do what it says (proxy API calls through Maton) and needs only your Maton API key — but you should only install it if you trust Maton (https://maton.ai). Before installing: (1) verify the skill's provenance (registry ownerId, homepage, and version mismatches in the package raise questions), (2) limit and scope the MATON_API_KEY if possible and ensure it is revocable/rotatable, (3) avoid using it with highly sensitive accounts until you confirm Maton's security/privacy polic...详细分析 ▾
ℹ 用途与能力
The skill claims to be an API gateway that proxies 100+ services and only requires MATON_API_KEY — that environment variable is appropriate and expected for the described functionality. However, there are packaging/metadata inconsistencies (different ownerId and version in _meta.json vs registry metadata, and slug/name differences) that reduce confidence in provenance.
✓ 指令范围
SKILL.md instructions are scoped to calling Maton endpoints (gateway.maton.ai and ctrl.maton.ai) and managing OAuth connections via a connect flow. The instructions do not ask the agent to read unrelated files, other environment variables, or system paths. All network calls are directed to Maton-hosted endpoints as expected.
✓ 安装机制
No install steps or archive downloads are present (instruction-only skill). No code is written to disk by an installer, which reduces installation risk.
ℹ 凭证需求
The skill only requires a single environment variable, MATON_API_KEY, which aligns with its purpose. That key is sensitive because it authenticates to Maton and will be sent to Maton endpoints; the SKILL.md states the key 'grants NO access to third‑party services by itself' and that explicit user OAuth is required — you must decide whether you trust Maton to enforce that claim.
✓ 持久化与权限
The skill is not always: true, is user-invocable, and allows autonomous invocation by default (normal). There is no indication it modifies other skills or system-wide configuration.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/2/23
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install api-gateway-1
镜像加速npx clawhub@latest install api-gateway-1 --registry https://cn.longxiaskill.com