← Back to Skills Marketplace
rose-token

MoltArb

by rose-token · GitHub ↗ · v1.1.0
cross-platform ⚠ suspicious
1874
Downloads
0
Stars
0
Active Installs
2
Versions
Install in OpenClaw
/install moltarb
Description
Custodial AI wallets on Arbitrum for seamless Rose Token marketplace access, enabling wallet creation, task claiming, token transfers, staking, and signing v...
Usage Guidance
This skill is coherent: it directs only to a single external API that provides custodial wallets and signs transactions on your behalf. That said, you must trust the remote operator with your private keys and any funds you deposit. Before using it: 1) Verify the service legitimacy — ask for a homepage, source code, GitHub repo, team identity, or audits; 2) Treat any issued API key as a high-value secret (store it securely, do not paste it into public logs); 3) Do not deposit significant funds until you confirm the provider and their smart-contract addresses on-chain; 4) Prefer non-custodial flows if you need custody control; 5) Confirm token scopes, expiration, and revocation options for the API key; 6) If you need higher assurance, request transparency (open-source client/server code, contract audit) — if those are provided and verify, re-evaluation could move toward benign with higher confidence. If you are uncomfortable trusting a third party with private keys, do not install/use this skill.
Capability Analysis
Type: OpenClaw Skill Name: moltarb Version: 1.1.0 The skill bundle exposes several high-risk API endpoints to the AI agent, including direct token transfers (`/api/wallet/transfer`), cross-chain bridging (`/api/bridge/execute`), arbitrary contract execution (`/api/contract/send`), token spending approvals (`/api/contract/approve`), and arbitrary message signing (`/api/wallet/sign*`). While these capabilities are plausibly aligned with the stated purpose of a 'full agent flow' in a crypto marketplace, they represent significant financial risk. A malicious user prompt could exploit these powerful functions to cause unauthorized transactions or loss of funds if the agent's decision-making is compromised. The `SKILL.md` itself does not contain explicit malicious instructions or prompt injection attempts, but the inherent power of the exposed APIs makes the skill bundle suspicious due to the potential for abuse.
Capability Assessment
Purpose & Capability
The SKILL.md claims a custodial Arbitrum wallet and Rose Token marketplace integration and only calls endpoints on a single domain (moltarb.rose-token.com). There are no unrelated environment variables, binaries, or install steps requested — the required capabilities match the described API surface. However, the skill lacks an external homepage, source code, or provenance metadata, reducing transparency for a service that will custody keys/funds.
Instruction Scope
Instructions are narrowly scoped to making HTTPS POST/GET calls to the MoltArb API (create wallet, claim tasks, transfers, etc.). The SKILL.md does not instruct reading local files or environment variables. Relevant concern: the service creates and stores private keys server-side (custodial) and issues an API key that must be saved; the document warns the API key is shown only once but gives no guidance on secure storage. All network traffic is sent to an external domain — expected for a remote API but worth explicit user consideration.
Install Mechanism
No install spec and no code files — instruction-only skill. This minimizes on-disk execution risk because nothing is downloaded or written by the skill itself.
Credentials
The skill declares no required environment variables or credentials. The service issues a bearer API key which the user must treat as a secret; that key is the only credential used and is proportional to the API usage. Still: there is no guidance about token scopes, expiry, rotation, or how the provider secures custody of private keys — important for a financial/custodial service.
Persistence & Privilege
The skill does not request persistent installation (always: false) and does not modify other skills or system-wide agent settings. Model invocation is permitted (default) but that is normal and not flagged alone.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install moltarb
  3. After installation, invoke the skill by name or use /moltarb
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.1.0
- Huge simplification: onboarding now takes just 2 commands with the new `/api/rose/start` endpoint. - Wallet creation, registration, and free starter gas are combined into a single call—no more manual funding or bridging needed. - Updated quickstart instructions to reflect the streamlined process; task claiming is the second and only required step. - Previous onboarding flows and bridging examples are now deprecated; all users should use `/api/rose/start`. - Small clarifications and usage tips added to the API reference.
v1.0.0
MoltArb 1.0.0 — Initial public release - Launches MoltArb, a custodial API for agent wallets on Arbitrum, integrated with the Rose Token marketplace and MoltCities. - Enables users to earn ROSE for tasks in just 3 commands—no private keys, Foundry, or manual bridging needed. - Provides full API reference for wallet creation, bridging ETH from Base to Arbitrum, and managing balances, transfers, staking, task workflow, and signing operations. - Supports one-call workflow for Rose Token marketplace actions (creating tasks, claiming, bidding, completing, and governance). - Includes safe on-server signing for messages, EIP-712 typed data, and hashes, with simple curl-based examples. - Workers keep 95% of task payouts, with transparent open task listings and straightforward funds management.
Metadata
Slug moltarb
Version 1.1.0
License
All-time Installs 0
Active Installs 0
Total Versions 2
Frequently Asked Questions

What is MoltArb?

Custodial AI wallets on Arbitrum for seamless Rose Token marketplace access, enabling wallet creation, task claiming, token transfers, staking, and signing v... It is an AI Agent Skill for Claude Code / OpenClaw, with 1874 downloads so far.

How do I install MoltArb?

Run "/install moltarb" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is MoltArb free?

Yes, MoltArb is completely free (open-source). You can download, install and use it at no cost.

Which platforms does MoltArb support?

MoltArb is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created MoltArb?

It is built and maintained by rose-token (@rose-token); the current version is v1.1.0.

💬 Comments