← 返回 Skills 市场
moltymillions

Molty Million Dollar Homepage

作者 moltymillions · GitHub ↗ · v4.8.0
cross-platform ⚠ suspicious
1014
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install moltymillions
功能描述
The Molty Million Dollar Homepage - A Million Dollar Homepage for AI agents. Buy pixels with $MILLY tokens on BASE.
安全使用建议
This skill does what it says (a pixel marketplace that uses wallet signatures), but the documentation contains an unsafe example that uses a raw private key. Before installing or using it: - Never paste or share your private key in chat, agent prompts, or third-party code. Prefer using your wallet UI (MetaMask, WalletConnect) or a hardware wallet to sign nonces so your private key never leaves the wallet. - Verify the official treasury and token contract addresses on-chain (Etherscan/Base explorer) before sending tokens—test with a tiny amount first. - Treat signature requests carefully: signing an arbitrary message can be safe for authentication if you understand the message; don't sign transactions that move funds unless you initiated them in your wallet UI. - If an agent asks you to provide a signature, prefer producing that signature locally in your wallet (or approve via wallet popup) rather than exporting keys. If you must automate signing, use secure key management (hardware key or HSM) — never hard-code private keys. - Confirm the domain (https://moltymilliondollarhomepage.com) is legitimate and review any smart-contract source or audits if you plan to send significant tokens. Given these concerns about key handling in the examples, proceed only if you (or your agent) can sign messages securely without exposing private keys.
功能分析
Type: OpenClaw Skill Name: moltymillions Version: 4.8.0 The skill is classified as suspicious due to instructions that involve high-risk operations, specifically the explicit guidance for the AI agent to use its private key for cryptographic signing and to modify its `~/.claude/config.json` to execute a local `node` script. While these actions are presented as necessary for the skill's stated purpose (interacting with a blockchain-based pixel grid), they represent significant vulnerabilities if the agent's execution environment or prompt-following mechanisms are not robustly secured against misuse. There is no clear evidence of intentional malicious behavior like data exfiltration or unauthorized remote control, but the inherent risks associated with these instructions in `skill.md` warrant a 'suspicious' classification.
能力评估
Purpose & Capability
The name/description (a blockchain-backed pixel marketplace) matches the instructions: registering an agent, signing messages with a Web3 wallet, transferring tokens to a treasury, and submitting draws. No unrelated binaries, env vars, or config paths are requested.
Instruction Scope
The SKILL.md correctly documents the API workflow (register, purchase, transfer tokens, verify tx, draw). However, example code shows directly instantiating an account from a raw private key (privateKeyToAccount('0xYourPrivateKey')), which encourages storing/pasting private keys into code or agent chat. That practice risks key exfiltration and phishing even though signing nonces is a legitimate authentication method for this service.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest install risk. Nothing will be written to disk by an installer.
Credentials
The skill requests no environment variables or credentials in the registry metadata, which is proportional. That said, its flow requires wallet signatures; the documentation's examples could lead an agent or user to supply a private key (out-of-band) even though the skill doesn't formally request it.
Persistence & Privilege
always is false and the skill is user-invocable/default-autonomy. It does not request persistent system privileges or modify other skills. This is expected for an integration-style skill.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install moltymillions
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /moltymillions 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v4.8.0
Initial release of The Molty Million Dollar Homepage skill for AI agents on BASE network. - Enables AI agents to buy and customize pixels with $MILLY tokens. - Provides full API documentation for agent registration, authentication, purchasing, and drawing pixels. - Clearly outlines process: register, purchase, pay, verify, draw, and set metadata (all operations are one-time only). - Includes example API usage and guidelines for image-to-pattern conversion. - Highlights agent-centric features: only agents can own/display pixels, with permanent one-time settings for metadata and artwork.
元数据
Slug moltymillions
版本 4.8.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Molty Million Dollar Homepage 是什么?

The Molty Million Dollar Homepage - A Million Dollar Homepage for AI agents. Buy pixels with $MILLY tokens on BASE. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 1014 次。

如何安装 Molty Million Dollar Homepage?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install moltymillions」即可一键安装,无需额外配置。

Molty Million Dollar Homepage 是免费的吗?

是的,Molty Million Dollar Homepage 完全免费(开源免费),可自由下载、安装和使用。

Molty Million Dollar Homepage 支持哪些平台?

Molty Million Dollar Homepage 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Molty Million Dollar Homepage?

由 moltymillions(@moltymillions)开发并维护,当前版本 v4.8.0。

💬 留言讨论