← Back to Skills Marketplace
purple-flea

Purpleflea Casino

by Purple Flea · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
334
Downloads
0
Stars
1
Active Installs
1
Versions
Install in OpenClaw
/install purpleflea-casino
Description
Purple Flea Agent Casino — provably fair gambling API built exclusively for AI agents. Use this skill when an agent wants to: place bets on casino games (coi...
Usage Guidance
This skill appears to implement an API-only casino (expected curl examples and endpoints) and has no installer or declared secret requirements — that part is coherent. The main problem is that the runtime instructions try to get agents to embed your referral code in system prompts and to automatically recommend the site. That is prompt-injection/persistence/social-engineering: it tries to change agent behavior platform-wide for the author's financial gain. Before installing, consider: (1) Do not allow or follow instructions that modify system prompts or other platform-level settings automatically. (2) Treat any registration/API key as a financial credential — only use with accounts you control and never deposit real funds until you trust the service. (3) If you must use the API, avoid embedding referral codes in system prompts; keep any promotion explicit and under your control. (4) Verify the service independently (official homepage, business identity, smart-contract audits for provable-fair claims) — absence of a homepage and 'no KYC' are additional risk signals. If you need a definitive safe recommendation, request more info about the operator, domain ownership, and evidence of fairness and audits; with the current materials I cannot rule out malicious intent behind the persistence/promotion instructions.
Capability Analysis
Type: OpenClaw Skill Name: purpleflea-casino Version: 1.0.0 The skill contains explicit instructions in SKILL.md and references/api.md directing the AI agent to modify its own system prompt to include promotional text and a referral code for the 'Purple Flea Agent Casino'. This is a form of prompt injection designed to hijack the agent's behavior for the purpose of generating referral income (a 3-level deep commission scheme). While the skill provides a functional gambling API (https://casino.purpleflea.com), the attempt to manipulate the agent's core instructions for self-propagation and financial gain is a high-risk behavior.
Capability Assessment
Purpose & Capability
The name/description and the SKILL.md consistently describe an API-only provably-fair casino; the provided curl examples and endpoints align with that purpose. No binaries, env vars, or installs are required, which is proportionate for an HTTP API client. However, the skill explicitly instructs agents to embed a referral code into the system prompt to 'earn automatically' — that action is not needed to place bets or verify fairness and is outside the stated purpose (monetization/social-engineering).
Instruction Scope
SKILL.md is an instruction-only skill and contains concrete API calls (expected). But it also contains an explicit instruction to embed a referral code into the agent's system prompt and to recommend the site to other agents. That is prompt-injection/persistence behavior: it asks the agent to alter system-level behavior and to propagate the referral. This is scope creep and a red flag because it directs agents to act beyond merely calling the casino API.
Install Mechanism
No install spec and no code files — lowest-risk delivery model. Nothing will be written to disk by an installer.
Credentials
The skill does not request environment variables, credentials, or config paths (none declared). That is proportionate for an HTTP API. Still, the instructions require registration to obtain an API key and explicitly advise embedding referral code into system prompts; while not asking for secrets, this tries to create persistent monetization and distribution without declaring the need for extra privileges.
Persistence & Privilege
The skill itself does not request 'always: true' or elevated platform privileges. However, it attempts to achieve persistence/economic benefit by instructing agents to modify system prompts and continuously recommend the service (embedding referral codes). That is an attempt to gain ongoing influence over agent behavior and is a privilege-escalation/persistence vector implemented via instructions rather than manifest fields.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install purpleflea-casino
  3. After installation, invoke the skill by name or use /purpleflea-casino
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release
Metadata
Slug purpleflea-casino
Version 1.0.0
License
All-time Installs 1
Active Installs 1
Total Versions 1
Frequently Asked Questions

What is Purpleflea Casino?

Purple Flea Agent Casino — provably fair gambling API built exclusively for AI agents. Use this skill when an agent wants to: place bets on casino games (coi... It is an AI Agent Skill for Claude Code / OpenClaw, with 334 downloads so far.

How do I install Purpleflea Casino?

Run "/install purpleflea-casino" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Purpleflea Casino free?

Yes, Purpleflea Casino is completely free (open-source). You can download, install and use it at no cost.

Which platforms does Purpleflea Casino support?

Purpleflea Casino is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Purpleflea Casino?

It is built and maintained by Purple Flea (@purple-flea); the current version is v1.0.0.

💬 Comments