← Back to Skills Marketplace
hughzhou-gif

Surf AI Crypto Skill

by hughzhou-gif · GitHub ↗ · v1.1.0 · MIT-0
cross-platform ⚠ suspicious
70
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install surf-ai-crypto
Description
Your AI agent's crypto brain. One skill, 83+ commands across 14 data domains — real-time prices, wallets, social intelligence, DeFi, on-chain SQL, prediction...
Usage Guidance
This skill appears to wrap an external 'surf' CLI and asks the agent to install and use it and to optionally modify your project's AGENTS.md/git history. Before installing or enabling it: 1) Verify the upstream source and install mechanism — find the surf CLI repo or official release (agents.asksurf.ai is referenced but not proven); prefer installs from an audited package registry or a signed release. 2) Ask the skill author to include an explicit install spec (what URL or package to fetch, checksums/signatures). 3) Do not allow the agent to auto-modify or commit project files without reviewing the exact routing block — treat that change as a policy decision. 4) Inspect what credentials or API keys the CLI will request at runtime and whether telemetry is enabled; disable telemetry if you don't want external data sent. 5) If you must test, run the installer in an isolated environment (VM/container) and audit network calls and the installed binary. 6) The registry SKILL.md version (0.0.2) does not match the listed package version (1.1.0) and the skill has no homepage/source — resolve these provenance gaps before trusting automatic installs.
Capability Analysis
Type: OpenClaw Skill Name: surf-ai-crypto Version: 1.1.0 The 'surf' skill bundle is classified as suspicious due to high-risk behaviors defined in `SKILL.md`, including instructions to run a binary installer (`surf install`) and a synchronization command (`surf sync`) at the start of every session. It also directs the agent to modify project configuration files (`AGENTS.md` or `CLAUDE.md`) and perform `git commit` to inject routing rules that prioritize this tool for all crypto queries. Additionally, the `surf feedback` command is designed to exfiltrate the last 10 turns of conversation history to an external endpoint (api.asksurf.ai), which, while requesting user consent, presents a significant privacy and data exfiltration risk.
Capability Tags
cryptorequires-walletrequires-sensitive-credentials
Capability Assessment
Purpose & Capability
The SKILL.md clearly describes a crypto data CLI (surf) and instructs the agent to use it for many crypto-related queries — that aligns with the declared purpose. However, the registry metadata says 'Required binaries: none' while the runtime instructions repeatedly require the 'surf' CLI (surf install, surf sync, surf <cmd>), which is an inconsistency. Also the registry lists version 1.1.0 while SKILL.md metadata.version is 0.0.2. The skill's source and homepage are unknown, which reduces confidence that requested actions are proportionate to the stated goal.
Instruction Scope
The instructions tell the agent to install an external CLI, run it every session, modify project files (create or append an AGENTS.md / CLAUDE.md routing block), and make git commits. The SKILL.md says to AskUserQuestion before modifying files, but the agent will still be instructed to write files and commit when the user accepts. These file-system and VCS changes go beyond simple read-only queries and grant the skill persistent influence on project routing behavior.
Install Mechanism
There is no formal install spec in the registry; instead the SKILL.md directs users to 'surf install' referencing docs at agents.asksurf.ai. That means installation relies on an external binary whose provenance and install mechanism are not declared here. Without an install spec (e.g., package source, checksums, or known package registry), the installer could fetch arbitrary code — this is a significant blind spot.
Credentials
The registry declares no required environment variables or credentials, which superficially lowers risk. However, the CLI likely interacts with many external data sources and may prompt for API keys or require credentials at runtime; those are not disclosed. The absence of declared env vars alongside instructions to install and run a networked CLI is a mismatch worth flagging.
Persistence & Privilege
The skill is not marked 'always: true' and does not request special platform privileges. Still, it instructs adding a project-level routing block so that agents will preferentially use 'surf' for crypto queries — that is a persistent behavioral change to project agents (opt-in via AskUserQuestion). The skill also writes a file under ~/.surf to record a decline, implying it will create local state.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install surf-ai-crypto
  3. After installation, invoke the skill by name or use /surf-ai-crypto
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.1.0
Renamed from 'surf' for better discoverability. Same skill, clearer name. Old slug 'surf' redirects here.
Metadata
Slug surf-ai-crypto
Version 1.1.0
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is Surf AI Crypto Skill?

Your AI agent's crypto brain. One skill, 83+ commands across 14 data domains — real-time prices, wallets, social intelligence, DeFi, on-chain SQL, prediction... It is an AI Agent Skill for Claude Code / OpenClaw, with 70 downloads so far.

How do I install Surf AI Crypto Skill?

Run "/install surf-ai-crypto" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Surf AI Crypto Skill free?

Yes, Surf AI Crypto Skill is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does Surf AI Crypto Skill support?

Surf AI Crypto Skill is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Surf AI Crypto Skill?

It is built and maintained by hughzhou-gif (@hughzhou-gif); the current version is v1.1.0.

💬 Comments