← 返回 Skills 市场
Miraix Wallet Roast
作者
richard7463
· GitHub ↗
· v1.0.1
· MIT-0
300
总下载
0
收藏
0
当前安装
2
版本数
在 OpenClaw 中安装
/install miraix-wallet-roast
功能描述
Use this skill when the user wants to analyze or roast a Solana wallet, score memecoin exposure, explain portfolio risks, generate rebalance ideas, draft a s...
安全使用建议
This skill is coherent for performing Solana wallet audits, but it calls a third‑party API (app.miraix.fun) and will transmit the wallet address you provide. Do not paste private keys or other secrets into the chat. Treat any 'commands' returned by the API as potentially unsafe: review them carefully and never run them without understanding and verifying them. If privacy is a concern, verify the Miraix domain and privacy policy before use or prefer a locally-run analysis tool.
功能分析
Type: OpenClaw Skill
Name: miraix-wallet-roast
Version: 1.0.1
The skill is classified as suspicious due to a potential shell injection vulnerability in the `SKILL.md` instructions. It directs the AI agent to execute a `curl` command against an external API (`https://app.miraix.fun/api/wallet-audit`) using a user-provided Solana wallet address as a direct parameter. While the intent appears to be a legitimate wallet analysis service, the pattern of constructing shell commands with unvalidated user input is a high-risk practice that could be exploited if the agent is tricked into processing a malicious payload as a wallet address.
能力评估
Purpose & Capability
Name, description, and runtime instructions align: the skill analyzes Solana wallets by calling Miraix public endpoints. It does not request unrelated binaries, credentials, or config paths.
Instruction Scope
Instructions are concrete (POST to https://app.miraix.fun/api/wallet-audit and include share-image URL) and constrain output to the API result. Missing: an explicit warning not to accept or forward private keys or other secrets from users. The skill also instructs to keep any actions[].command verbatim — this is fine for reporting, but callers should be warned not to execute returned commands blindly.
Install Mechanism
Instruction-only skill with no install steps and no code files — nothing is written to disk by the skill itself.
Credentials
The skill requests no environment variables, credentials, or config paths. The external API call is proportionate to the claimed purpose of wallet analysis.
Persistence & Privilege
Does not request permanent presence or elevated privileges (always:false). No modification of other skills or system settings is indicated.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install miraix-wallet-roast - 安装完成后,直接呼叫该 Skill 的名称或使用
/miraix-wallet-roast触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
Always include share card URL in wallet analysis results
v1.0.0
Initial release
元数据
常见问题
Miraix Wallet Roast 是什么?
Use this skill when the user wants to analyze or roast a Solana wallet, score memecoin exposure, explain portfolio risks, generate rebalance ideas, draft a s... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 300 次。
如何安装 Miraix Wallet Roast?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install miraix-wallet-roast」即可一键安装,无需额外配置。
Miraix Wallet Roast 是免费的吗?
是的,Miraix Wallet Roast 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Miraix Wallet Roast 支持哪些平台?
Miraix Wallet Roast 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Miraix Wallet Roast?
由 richard7463(@richard7463)开发并维护,当前版本 v1.0.1。
推荐 Skills