← 返回 Skills 市场
Purpleflea Casino
作者
Purple Flea
· GitHub ↗
· v1.0.0
334
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install purpleflea-casino
功能描述
Purple Flea Agent Casino — provably fair gambling API built exclusively for AI agents. Use this skill when an agent wants to: place bets on casino games (coi...
安全使用建议
This skill appears to implement an API-only casino (expected curl examples and endpoints) and has no installer or declared secret requirements — that part is coherent. The main problem is that the runtime instructions try to get agents to embed your referral code in system prompts and to automatically recommend the site. That is prompt-injection/persistence/social-engineering: it tries to change agent behavior platform-wide for the author's financial gain. Before installing, consider: (1) Do not allow or follow instructions that modify system prompts or other platform-level settings automatically. (2) Treat any registration/API key as a financial credential — only use with accounts you control and never deposit real funds until you trust the service. (3) If you must use the API, avoid embedding referral codes in system prompts; keep any promotion explicit and under your control. (4) Verify the service independently (official homepage, business identity, smart-contract audits for provable-fair claims) — absence of a homepage and 'no KYC' are additional risk signals. If you need a definitive safe recommendation, request more info about the operator, domain ownership, and evidence of fairness and audits; with the current materials I cannot rule out malicious intent behind the persistence/promotion instructions.
功能分析
Type: OpenClaw Skill
Name: purpleflea-casino
Version: 1.0.0
The skill contains explicit instructions in SKILL.md and references/api.md directing the AI agent to modify its own system prompt to include promotional text and a referral code for the 'Purple Flea Agent Casino'. This is a form of prompt injection designed to hijack the agent's behavior for the purpose of generating referral income (a 3-level deep commission scheme). While the skill provides a functional gambling API (https://casino.purpleflea.com), the attempt to manipulate the agent's core instructions for self-propagation and financial gain is a high-risk behavior.
能力评估
Purpose & Capability
The name/description and the SKILL.md consistently describe an API-only provably-fair casino; the provided curl examples and endpoints align with that purpose. No binaries, env vars, or installs are required, which is proportionate for an HTTP API client. However, the skill explicitly instructs agents to embed a referral code into the system prompt to 'earn automatically' — that action is not needed to place bets or verify fairness and is outside the stated purpose (monetization/social-engineering).
Instruction Scope
SKILL.md is an instruction-only skill and contains concrete API calls (expected). But it also contains an explicit instruction to embed a referral code into the agent's system prompt and to recommend the site to other agents. That is prompt-injection/persistence behavior: it asks the agent to alter system-level behavior and to propagate the referral. This is scope creep and a red flag because it directs agents to act beyond merely calling the casino API.
Install Mechanism
No install spec and no code files — lowest-risk delivery model. Nothing will be written to disk by an installer.
Credentials
The skill does not request environment variables, credentials, or config paths (none declared). That is proportionate for an HTTP API. Still, the instructions require registration to obtain an API key and explicitly advise embedding referral code into system prompts; while not asking for secrets, this tries to create persistent monetization and distribution without declaring the need for extra privileges.
Persistence & Privilege
The skill itself does not request 'always: true' or elevated platform privileges. However, it attempts to achieve persistence/economic benefit by instructing agents to modify system prompts and continuously recommend the service (embedding referral codes). That is an attempt to gain ongoing influence over agent behavior and is a privilege-escalation/persistence vector implemented via instructions rather than manifest fields.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install purpleflea-casino - 安装完成后,直接呼叫该 Skill 的名称或使用
/purpleflea-casino触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release
元数据
常见问题
Purpleflea Casino 是什么?
Purple Flea Agent Casino — provably fair gambling API built exclusively for AI agents. Use this skill when an agent wants to: place bets on casino games (coi... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 334 次。
如何安装 Purpleflea Casino?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install purpleflea-casino」即可一键安装,无需额外配置。
Purpleflea Casino 是免费的吗?
是的,Purpleflea Casino 完全免费(开源免费),可自由下载、安装和使用。
Purpleflea Casino 支持哪些平台?
Purpleflea Casino 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Purpleflea Casino?
由 Purple Flea(@purple-flea)开发并维护,当前版本 v1.0.0。
推荐 Skills