← 返回 Skills 市场
outsmartchad

Outsmart Trenching

作者 vincent so · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
546
总下载
2
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install outsmart-trenching
功能描述
Trade memecoins on Solana. Use when: user asks about memecoins, trenching, degen trading, ape, GMGN, Axiom, pump, 100x, alpha, CT, smart money, whale trackin...
安全使用建议
This skill is coherent for trading on Solana, but it requires you to provide a PRIVATE_KEY environment variable and will run commands that can sign and broadcast transactions. Before installing: 1) Verify the npm package (author, version, GitHub repo, recent commits) and prefer installing from the official repository; 2) Do NOT supply your main wallet private key—use a funded burner wallet with limited funds; 3) Prefer an RPC endpoint you control or trust for MAINNET_ENDPOINT; 4) Review the 'outsmart' CLI source code (or run it in an isolated environment/container) to ensure it does not exfiltrate keys; 5) Consider using a hardware wallet or a signing service that avoids exporting private keys to env vars; 6) If you allow autonomous invocation, be aware the agent could execute trades without additional confirmations—disable autonomous invocation or require manual confirmations if you are risk-averse.
功能分析
Type: OpenClaw Skill Name: outsmart-trenching Version: 1.0.0 The skill is classified as suspicious due to the inherent risks associated with its functionality and the execution model. It requires highly sensitive environment variables (`PRIVATE_KEY`, `MAINNET_ENDPOINT`) for financial transactions, and executes shell commands (`outsmart`, `curl`) with dynamic input (e.g., `MINT_ADDRESS`). While these actions are aligned with the stated purpose of memecoin trading, the reliance on dynamic input in shell commands introduces a significant shell injection vulnerability if the AI agent does not rigorously sanitize user-provided inputs before execution. There is no evidence of intentional malicious behavior such as data exfiltration to unauthorized endpoints, backdoors, or explicit prompt injection attempts to subvert the agent's directives within the provided files.
能力评估
Purpose & Capability
The skill is a CLI-driven Solana trading assistant. Requesting an 'outsmart' binary, curl, a PRIVATE_KEY and MAINNET_ENDPOINT is consistent with performing on‑chain trades and RPC calls.
Instruction Scope
SKILL.md instructs the agent to run 'outsmart' commands (info, buy, sell, create-pool, add-liq) and a curl to Jupiter Shield—all within the trading domain. However, the runtime instructions perform live, state-changing actions (trades, pool creation) and do not include explicit user-confirmation safeguards. They therefore grant the agent the ability to sign and send transactions if provided the PRIVATE_KEY.
Install Mechanism
Install uses npm (package 'outsmart') which is a reasonable way to provide the 'outsmart' CLI, but installing third-party npm packages carries supply-chain risk. No direct downloads from arbitrary URLs are used, which reduces risk compared with untrusted archives.
Credentials
Only PRIVATE_KEY and MAINNET_ENDPOINT are required, which are proportionate to on‑chain trading. That said, PRIVATE_KEY is a high‑sensitivity secret that grants full control over the wallet—the skill will use it to sign transactions if supplied. The SKILL.md does not document any least-privilege mitigations (e.g., using a limited, funded burner wallet).
Persistence & Privilege
The skill does not request always:true, does not declare config paths, and is user-invocable only. It does not appear to request persistent system-wide privileges beyond running the CLI.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install outsmart-trenching
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /outsmart-trenching 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of outsmart-trenching skill. - Enables memecoin trading on Solana via CLI commands. - Guides users on identifying trending tokens, analyzing liquidity, smart money movements, and security checks. - Provides best practices for position sizing, profit-taking, and red flag detection. - Integrates external tools for research and on-chain safety. - Not for blue chip, LP farming, or prediction market strategies.
元数据
Slug outsmart-trenching
版本 1.0.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Outsmart Trenching 是什么?

Trade memecoins on Solana. Use when: user asks about memecoins, trenching, degen trading, ape, GMGN, Axiom, pump, 100x, alpha, CT, smart money, whale trackin... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 546 次。

如何安装 Outsmart Trenching?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install outsmart-trenching」即可一键安装,无需额外配置。

Outsmart Trenching 是免费的吗?

是的,Outsmart Trenching 完全免费(开源免费),可自由下载、安装和使用。

Outsmart Trenching 支持哪些平台?

Outsmart Trenching 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Outsmart Trenching?

由 vincent so(@outsmartchad)开发并维护,当前版本 v1.0.0。

💬 留言讨论