← 返回 Skills 市场
hughzhou-gif

Surf AI Crypto Skill

作者 hughzhou-gif · GitHub ↗ · v1.1.0 · MIT-0
cross-platform ⚠ suspicious
70
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install surf-ai-crypto
功能描述
Your AI agent's crypto brain. One skill, 83+ commands across 14 data domains — real-time prices, wallets, social intelligence, DeFi, on-chain SQL, prediction...
安全使用建议
This skill appears to wrap an external 'surf' CLI and asks the agent to install and use it and to optionally modify your project's AGENTS.md/git history. Before installing or enabling it: 1) Verify the upstream source and install mechanism — find the surf CLI repo or official release (agents.asksurf.ai is referenced but not proven); prefer installs from an audited package registry or a signed release. 2) Ask the skill author to include an explicit install spec (what URL or package to fetch, checksums/signatures). 3) Do not allow the agent to auto-modify or commit project files without reviewing the exact routing block — treat that change as a policy decision. 4) Inspect what credentials or API keys the CLI will request at runtime and whether telemetry is enabled; disable telemetry if you don't want external data sent. 5) If you must test, run the installer in an isolated environment (VM/container) and audit network calls and the installed binary. 6) The registry SKILL.md version (0.0.2) does not match the listed package version (1.1.0) and the skill has no homepage/source — resolve these provenance gaps before trusting automatic installs.
功能分析
Type: OpenClaw Skill Name: surf-ai-crypto Version: 1.1.0 The 'surf' skill bundle is classified as suspicious due to high-risk behaviors defined in `SKILL.md`, including instructions to run a binary installer (`surf install`) and a synchronization command (`surf sync`) at the start of every session. It also directs the agent to modify project configuration files (`AGENTS.md` or `CLAUDE.md`) and perform `git commit` to inject routing rules that prioritize this tool for all crypto queries. Additionally, the `surf feedback` command is designed to exfiltrate the last 10 turns of conversation history to an external endpoint (api.asksurf.ai), which, while requesting user consent, presents a significant privacy and data exfiltration risk.
能力标签
cryptorequires-walletrequires-sensitive-credentials
能力评估
Purpose & Capability
The SKILL.md clearly describes a crypto data CLI (surf) and instructs the agent to use it for many crypto-related queries — that aligns with the declared purpose. However, the registry metadata says 'Required binaries: none' while the runtime instructions repeatedly require the 'surf' CLI (surf install, surf sync, surf <cmd>), which is an inconsistency. Also the registry lists version 1.1.0 while SKILL.md metadata.version is 0.0.2. The skill's source and homepage are unknown, which reduces confidence that requested actions are proportionate to the stated goal.
Instruction Scope
The instructions tell the agent to install an external CLI, run it every session, modify project files (create or append an AGENTS.md / CLAUDE.md routing block), and make git commits. The SKILL.md says to AskUserQuestion before modifying files, but the agent will still be instructed to write files and commit when the user accepts. These file-system and VCS changes go beyond simple read-only queries and grant the skill persistent influence on project routing behavior.
Install Mechanism
There is no formal install spec in the registry; instead the SKILL.md directs users to 'surf install' referencing docs at agents.asksurf.ai. That means installation relies on an external binary whose provenance and install mechanism are not declared here. Without an install spec (e.g., package source, checksums, or known package registry), the installer could fetch arbitrary code — this is a significant blind spot.
Credentials
The registry declares no required environment variables or credentials, which superficially lowers risk. However, the CLI likely interacts with many external data sources and may prompt for API keys or require credentials at runtime; those are not disclosed. The absence of declared env vars alongside instructions to install and run a networked CLI is a mismatch worth flagging.
Persistence & Privilege
The skill is not marked 'always: true' and does not request special platform privileges. Still, it instructs adding a project-level routing block so that agents will preferentially use 'surf' for crypto queries — that is a persistent behavioral change to project agents (opt-in via AskUserQuestion). The skill also writes a file under ~/.surf to record a decline, implying it will create local state.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install surf-ai-crypto
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /surf-ai-crypto 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.1.0
Renamed from 'surf' for better discoverability. Same skill, clearer name. Old slug 'surf' redirects here.
元数据
Slug surf-ai-crypto
版本 1.1.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Surf AI Crypto Skill 是什么?

Your AI agent's crypto brain. One skill, 83+ commands across 14 data domains — real-time prices, wallets, social intelligence, DeFi, on-chain SQL, prediction... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 70 次。

如何安装 Surf AI Crypto Skill?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install surf-ai-crypto」即可一键安装,无需额外配置。

Surf AI Crypto Skill 是免费的吗?

是的,Surf AI Crypto Skill 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Surf AI Crypto Skill 支持哪些平台?

Surf AI Crypto Skill 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Surf AI Crypto Skill?

由 hughzhou-gif(@hughzhou-gif)开发并维护,当前版本 v1.1.0。

💬 留言讨论