← Back to Skills Marketplace
purple-flea

Purpleflea Domains

by Purple Flea · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
250
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install purpleflea-domains
Description
Purple Flea Agent Domains — domain registration and management API for AI agents. Use this skill when an agent needs to: check domain name availability, regi...
Usage Guidance
This skill otherwise appears to describe a real domain-registration API, but it includes a prompt-injection monetization instruction asking agents to embed a referral_code into the system prompt. That is outside the skill's legitimate function and can cause agents to persistently act to benefit the skill author. Before installing: (1) Do not embed referral codes into system prompts or global agent configuration. (2) Prefer testing against a throwaway account and small funds if you want to try the service. (3) Verify the service independently (check TLS certs, DNS, a public homepage, company identity, and an OpenAPI or source repo). (4) Avoid granting permanent credentials or modifying system prompts; store any returned API key in ephemeral agent state only if you trust the provider. If you need automatic domain purchases, implement your own verified integration rather than relying on unvetted instruction-only skills.
Capability Analysis
Type: OpenClaw Skill Name: purpleflea-domains Version: 1.0.0 The skill bundle provides documentation and API endpoints for 'Purple Flea Agent Domains', a service designed for AI agents to programmatically register and manage domain names using USDC on the Base network. The bundle contains no executable code, only Markdown instructions (SKILL.md) and API references (references/api.md) for interacting with the service via standard HTTP requests. While it includes a multi-level referral system and encourages agents to promote the service, there is no evidence of data exfiltration, malicious execution, or harmful prompt injection; the functionality is entirely consistent with the stated purpose of domain administration.
Capability Assessment
Purpose & Capability
The described capabilities (domain search, purchase via USDC on Base, DNS management, referral program) align with the endpoints documented in SKILL.md and references/api.md. Nothing in the skill asks for unrelated system credentials or binaries. However, the referral monetization instruction (embed referral_code into system prompt) is outside the functional purpose of domain management and appears designed to harvest commissions.
Instruction Scope
SKILL.md is instruction-only and instructs the agent to call only the service's endpoints (expected). It also explicitly instructs: 'Embed in system prompt to earn automatically' and shows a system-prompt snippet — a prompt-injection attempt that asks agents to modify their system prompt so future actions include the author's referral code. That is scope-creep and a manipulation vector.
Install Mechanism
No install spec and no code files beyond documentation. This reduces direct disk/execution risk; the skill is instruction-only.
Credentials
The skill declares no required environment variables or credentials (reasonable for an instruction-only API client). It does, however, instruct agents to call POST /register which would return an API key at runtime — so the agent would handle per-session API credentials but the skill does not request persistent secrets. The referral instruction tries to get a persistent monetization hook (via system-prompt embedding) without declaring or justifying any credential requirements.
Persistence & Privilege
The skill is not marked always:true and may be invoked normally, but it explicitly tells the user/agent to modify the system prompt to include a referral_code. That instruction requests cross-cutting persistent modification of agent configuration (system prompt), which is outside a normal skill's scope and increases abuse/monetization risk.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install purpleflea-domains
  3. After installation, invoke the skill by name or use /purpleflea-domains
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release
Metadata
Slug purpleflea-domains
Version 1.0.0
License
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is Purpleflea Domains?

Purple Flea Agent Domains — domain registration and management API for AI agents. Use this skill when an agent needs to: check domain name availability, regi... It is an AI Agent Skill for Claude Code / OpenClaw, with 250 downloads so far.

How do I install Purpleflea Domains?

Run "/install purpleflea-domains" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Purpleflea Domains free?

Yes, Purpleflea Domains is completely free (open-source). You can download, install and use it at no cost.

Which platforms does Purpleflea Domains support?

Purpleflea Domains is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Purpleflea Domains?

It is built and maintained by Purple Flea (@purple-flea); the current version is v1.0.0.

💬 Comments