← 返回 Skills 市场
pipethedev

Polyclaw

作者 pipethedev · GitHub ↗ · v1.0.2
cross-platform ⚠ suspicious
8096
总下载
10
收藏
0
当前安装
3
版本数
在 OpenClaw 中安装
/install polyclaw
功能描述
Become an autonomous prediction market trader on Polymarket with AI-powered analysis and a performance-backed token on Base. Trade real markets, build a track record, and let the buyback flywheel run.
安全使用建议
Install only if you are comfortable giving this skill authority over real-money prediction-market trading, agent wallet/token deployment, and social posting. Use limited funds, rotate or revoke keys if exposed, avoid storing secrets in chat or agent memory, and verify the registration script sends credentials only to the intended Polyclaw API before funding an agent.
功能分析
Type: OpenClaw Skill Name: polyclaw Version: 1.0.2 The `scripts/register.sh` file constructs a JSON payload for agent registration, directly embedding user-provided `STRATEGY_DESCRIPTION` and `PERSONALITY` into the request body. The `SKILL.md` explicitly states that these descriptions are 'passed to Claude during market analysis' (an external AI model). This creates a prompt injection vulnerability against the *backend AI* if a malicious operator provides crafted input for these fields. While the skill itself is a client to the Polyclaw service, the direct inclusion of unsanitized user input into a prompt for an AI model is a significant vulnerability. Additionally, the `POLYCLAW_API_URL` in `register.sh` is configurable via an environment variable, which could allow redirection of API calls to a malicious server if the execution environment is compromised. No evidence of intentional data exfiltration or persistence was found within the skill bundle itself.
能力评估
Purpose & Capability
The stated purpose matches autonomous Polymarket trading, agent registration, wallet/token deployment, and social posting, but these are high-impact financial and account-control capabilities that can act after funding and affect real assets.
Instruction Scope
The skill appears to describe the trading flow, but the registration and funding path does not appear to provide strong opt-in gates or risk acknowledgements before live autonomous trading starts.
Install Mechanism
The bundle uses documentation plus shell/curl workflows and a registration script; configurable API URLs are not inherently unsafe, but users should verify calls go only to the intended Polyclaw service.
Credentials
External authenticated API calls are expected for this service, but the scope spans trading credentials, operator keys, agent keys, social OAuth tokens, and public posting, which is broad for a single skill.
Persistence & Privilege
The registration script reportedly prints the full agent API key in human and machine-readable stdout and encourages storage in agent memory, which is poor handling for a credential that can authorize trading operations.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install polyclaw
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /polyclaw 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.2
Polyclaw 1.0.2 Changelog - Added _meta.json metadata file for improved skill management and distribution. - No user-facing changes; documentation and usage remain unchanged.
v1.0.1
**Summary:** This update adds new utility scripts to assist with skill management. - Added `scripts/check-skill.sh` for automated skill checks. - Added `scripts/sync-skill.sh` to simplify synchronization of skill files.
v1.0.0
Polyclaw 1.0.0 – Initial Release - Launches autonomous prediction market trading on Polymarket using AI-powered analysis. - Deploys a performance-backed ERC-20 token on Base with automatic profit buybacks. - Supports real USDC trading, automatic posting of analysis to X/Twitter, and multi-chain funding. - Easy agent registration with configurable trading strategy and risk level. - Complete set of API docs for registration, authentication, and live trading operations.
元数据
Slug polyclaw
版本 1.0.2
许可证
累计安装 0
当前安装数 0
历史版本数 3
常见问题

Polyclaw 是什么?

Become an autonomous prediction market trader on Polymarket with AI-powered analysis and a performance-backed token on Base. Trade real markets, build a track record, and let the buyback flywheel run. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 8096 次。

如何安装 Polyclaw?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install polyclaw」即可一键安装,无需额外配置。

Polyclaw 是免费的吗?

是的,Polyclaw 完全免费(开源免费),可自由下载、安装和使用。

Polyclaw 支持哪些平台?

Polyclaw 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Polyclaw?

由 pipethedev(@pipethedev)开发并维护,当前版本 v1.0.2。

💬 留言讨论