📦 Buy Sovereign Domain — 注册主权域名
v1.0.0通过 Impervious Domains 在 Ethereum 主网注册无需许可、永久续费的手写体域名(.badass、.forever、.fuck、.rebel、.pump、.hello、.howdy、.robo、.dnet、.f 及熊 emoji),实现真正的去中心化 Web3 身份与站点托管。
0· 644·0 当前·0 累计
下载技能包
最后更新
2026/4/22
安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
This skill is ambiguous rather than clearly malicious, but proceed cautiously. Before installing or using it, ask the author to: (1) provide the full ABIs and contract addresses used (not a relative `{baseDir}` reference), (2) explicitly describe how transactions are signed (do not share private keys — prefer user-side signing or hardware wallet), and (3) show the exact RPC endpoints and explain any API keys. Never paste your private key or seed phrase into the agent; instead, require the agent ...详细分析 ▾
ℹ 用途与能力
Name/description (registering Handshake-like domains on Ethereum via Impervious Domains contracts) aligns with requiring an Ethereum RPC endpoint, but the skill claims it will mint ERC‑721 NFTs yet does not declare how transactions will be signed or how the user's wallet is supplied.
⚠ 指令范围
SKILL.md instructs the agent to follow a full procedure and points to `{baseDir}/../../skills.md` for ABIs, addresses, and safety constraints — those files are not included. The instructions implicitly require sending signed transactions (commit/reveal) and waiting for confirmations but give no guidance on where signing keys or user wallet access come from. Referencing files outside the skill bundle is scope creep and could cause the agent to read arbitrary host files.
✓ 安装机制
No install spec and no code files — lowest-risk delivery method. However, being instruction-only means the runtime behavior depends entirely on what the agent is told to do (e.g., network calls to the RPC).
⚠ 凭证需求
Only ETHEREUM_RPC_URL is declared, but minting on-chain requires transaction signing (private key, hardware wallet, or user-signed payloads). The absence of any declared signing credential or explicit user-interactive signing workflow is a mismatch and could lead to the skill asking for private keys or other secrets at runtime. Also ETHEREUM_RPC_URL may embed API keys — the skill provides no guidance on acceptable RPC providers or scopes.
✓ 持久化与权限
always is false, no config paths requested, and no install steps that modify system or other skills. Persistence/privilege requirements appear minimal.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/2/15
NULL
● 可疑
安装命令
点击复制官方npx clawhub@latest install buy-handshake-domain
镜像加速npx clawhub@latest install buy-handshake-domain --registry https://cn.longxiaskill.com