← 返回 Skills 市场
techno-hippies

Buy Sovereign Domain (Handshake DNS)

作者 techno-hippies · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
688
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install buy-handshake-domain
功能描述
Register sovereign domains (.badass, .forever, .fuck, .rebel, .pump, .hello, .howdy, .robo, .dnet, .f, bear emoji) on Ethereum mainnet via Impervious Domains...
使用说明 (SKILL.md)

See the full registration skill spec at {baseDir}/../../skills.md.

This skill registers \x3Clabel>.\x3Ctld> domains as on-chain ERC-721 NFTs using Impervious Domains contracts (ENS fork) on Ethereum mainnet.

Recommended TLDs

TLD Vibe
.badass OG flagship — default choice, cheapest
.forever Permanence, legacy
.fuck Irreverent, punk
.rebel Counter-culture
.pump Degen / trading culture
.hello Friendly, approachable
.howdy Casual, warm
.robo Tech / AI identity
.dnet Decentralized network
.f Minimal, one-letter flex
xn--gp8h Bear emoji domain

Quick summary

  1. User picks a label + TLD
  2. Commit/reveal pattern (two transactions, ~1 min wait between)
  3. Domain minted as ERC-721 to user's wallet
  4. Full procedure, ABIs, safety constraints, and contract addresses in {baseDir}/../../skills.md
安全使用建议
This skill is ambiguous rather than clearly malicious, but proceed cautiously. Before installing or using it, ask the author to: (1) provide the full ABIs and contract addresses used (not a relative `{baseDir}` reference), (2) explicitly describe how transactions are signed (do not share private keys — prefer user-side signing or hardware wallet), and (3) show the exact RPC endpoints and explain any API keys. Never paste your private key or seed phrase into the agent; instead, require the agent to prepare unsigned transactions for you to sign offline or via your wallet. If you must test, use a fresh ephemeral wallet with minimal funds on a testnet first and verify every transaction payload and destination contract address. If the skill asks to read local files outside its bundle or to accept a private key, decline until the above are clarified. If the skill's source or homepage is unknown, prefer not to grant sensitive access (private keys, full-access RPC endpoints) until the code or a trustworthy origin is available.
功能分析
Type: OpenClaw Skill Name: buy-handshake-domain Version: 1.0.0 The `SKILL.md` file contains an instruction for the AI agent to reference a file outside its bundle using a directory traversal path: `{baseDir}/../../skills.md`. This is a significant prompt injection vulnerability and an attempt to access unauthorized files. An AI agent might interpret 'See the full registration skill spec' as an instruction to read and incorporate content from an arbitrary `skills.md` file located two directories above the skill's base, potentially leading to unintended actions or information disclosure if that file contains sensitive data or malicious instructions.
能力评估
Purpose & Capability
Name/description (registering Handshake-like domains on Ethereum via Impervious Domains contracts) aligns with requiring an Ethereum RPC endpoint, but the skill claims it will mint ERC‑721 NFTs yet does not declare how transactions will be signed or how the user's wallet is supplied.
Instruction Scope
SKILL.md instructs the agent to follow a full procedure and points to `{baseDir}/../../skills.md` for ABIs, addresses, and safety constraints — those files are not included. The instructions implicitly require sending signed transactions (commit/reveal) and waiting for confirmations but give no guidance on where signing keys or user wallet access come from. Referencing files outside the skill bundle is scope creep and could cause the agent to read arbitrary host files.
Install Mechanism
No install spec and no code files — lowest-risk delivery method. However, being instruction-only means the runtime behavior depends entirely on what the agent is told to do (e.g., network calls to the RPC).
Credentials
Only ETHEREUM_RPC_URL is declared, but minting on-chain requires transaction signing (private key, hardware wallet, or user-signed payloads). The absence of any declared signing credential or explicit user-interactive signing workflow is a mismatch and could lead to the skill asking for private keys or other secrets at runtime. Also ETHEREUM_RPC_URL may embed API keys — the skill provides no guidance on acceptable RPC providers or scopes.
Persistence & Privilege
always is false, no config paths requested, and no install steps that modify system or other skills. Persistence/privilege requirements appear minimal.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install buy-handshake-domain
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /buy-handshake-domain 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
- Initial release of buy-handshake-domainl skill. - Register decentralized domains (e.g., .badass, .forever, .fuck, bear emoji) on Ethereum mainnet. - Uses Impervious Domains contracts for on-chain ERC-721 NFT minting. - Supports a secure commit/reveal pattern for domain registration. - Customizable with various TLD options for different vibes. - Requires ETHEREUM_RPC_URL environment variable for operation.
元数据
Slug buy-handshake-domain
版本 1.0.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Buy Sovereign Domain (Handshake DNS) 是什么?

Register sovereign domains (.badass, .forever, .fuck, .rebel, .pump, .hello, .howdy, .robo, .dnet, .f, bear emoji) on Ethereum mainnet via Impervious Domains... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 688 次。

如何安装 Buy Sovereign Domain (Handshake DNS)?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install buy-handshake-domain」即可一键安装,无需额外配置。

Buy Sovereign Domain (Handshake DNS) 是免费的吗?

是的,Buy Sovereign Domain (Handshake DNS) 完全免费(开源免费),可自由下载、安装和使用。

Buy Sovereign Domain (Handshake DNS) 支持哪些平台?

Buy Sovereign Domain (Handshake DNS) 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Buy Sovereign Domain (Handshake DNS)?

由 techno-hippies(@techno-hippies)开发并维护,当前版本 v1.0.0。

💬 留言讨论