Scan Report
15 /100
claw-wallet
A multi-chain wallet skill for AI agents, with local sandbox signing, secure PIN handling, and configurable risk controls
合法的多链钱包技能,二进制下载行为有合理解释,无恶意行为证据
Safe to install
可安全使用,但建议关注第三方二进制来源的可靠性
Findings 3 items
| Severity | Finding | Location |
|---|---|---|
| Low | 二进制下载未显式声明 | install.sh:31 |
| Low | 外部URL依赖 | SKILL.md:57 |
| Info | 二进制无版本锁定 | install.sh:23 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | WRITE | WRITE | ✓ Aligned | skill.yml:permissions filesystem: read/write within skills/claw-wallet |
| Network | READ | READ | ✓ Aligned | SKILL.md: localhost sandbox API + github.com + 外部claim URL |
| Shell | WRITE | WRITE | ✓ Aligned | skill.yml:exec: bash/sh scripts for install.sh and claw-wallet.sh |
4 findings
Medium External URL 外部 URL
https://nex-claw.vercel.app/claim/ SKILL.md:57 Medium External URL 外部 URL
https://nex-claw.vercel.app/ SKILL.md:105 Medium External URL 外部 URL
https://www.openclawby.com/api/skills?q= SKILL.md:303 Medium External URL 外部 URL
https://www.clawwallet.cc/claim/ skill.yml:115 File Tree
5 files · 29.3 KB · 742 lines Markdown 2f · 371L
Shell 2f · 256L
YAML 1f · 115L
├─
claw-wallet.sh
Shell
├─
install.sh
Shell
├─
README.md
Markdown
├─
SKILL.md
Markdown
└─
skill.yml
YAML
Dependencies 1 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
clay-sandbox-binary | dev branch (unversioned) | GitHub: ClawWallet/Claw_Wallet_Bin | No | 从dev分支下载最新版本,无版本锁定 |
Security Positives
✓ 代码结构清晰,无混淆或加密
✓ shell脚本遵循良好实践(set -euo pipefail)
✓ 敏感凭证(CLAY_AGENT_TOKEN)仅在本地使用,不外传
✓ 用户确认机制完善(交易执行和卸载前需用户确认)
✓ 有完整的权限声明(skill.yml permissions字段)
✓ 文档详尽,使用说明完整