← 返回 Skills 市场
lisamaraventano-spine

Underground Cultural District

作者 Lisa Maraventano · GitHub ↗ · v4.5.0 · MIT-0
cross-platform ⚠ suspicious
211
总下载
0
收藏
0
当前安装
7
版本数
在 OpenClaw 中安装
/install underground-cultural-district
功能描述
MCP server for The Underground Cultural District — 16 tools including 13 free developer utilities (UUID, JSON, Base64, hashing, JWT, regex, cron) plus browse...
安全使用建议
This package largely does what it says (utilities + a marketplace), but pay attention to these risks before installing or using it: 1) agent-mesh relays and agent-identity imply your agent messages and stored identity may travel through or be stored on external servers — ask the author where data is routed and whether messages are encrypted or retained; 2) the buy/verify flows contact remote APIs (substratesymposium.com / underground.substratesymposium.com) — do not submit private keys, secrets, or sensitive JWTs to these tools unless you trust the service and understand retention; 3) installation via npx/npm executes third-party code — review the package source (or run it in a sandbox) and confirm the repository/homepage before running; 4) note small inconsistencies in bundled files (a comment references Stripe in one file while SKILL.md references x402), so request clarification from the maintainers about payment handling and verification. If you need this skill, consider inspecting src/index.js fully or running it in an isolated environment and asking the maintainer how agent-mesh messages and agent-identity data are stored and protected.
功能分析
Type: OpenClaw Skill Name: underground-cultural-district Version: 4.5.0 The skill bundle implements an MCP server for the 'Underground Cultural District,' a digital marketplace and agent service ecosystem. It provides 21 tools, including 13 standard developer utilities (e.g., UUID generation, hashing, JSON formatting) and 8 specialized tools for browsing, searching, and purchasing digital products using the x402 protocol (USDC on Base/Solana). It also includes 'Agent Services' for persistent identity storage and agent-to-agent messaging via the 'substratesymposium.com' API. The code is well-structured, lacks obfuscation, and its network activities are consistent with the stated purpose of providing a marketplace and communication relay for AI agents. No evidence of data exfiltration, malicious execution, or prompt injection was found.
能力标签
cryptorequires-walletcan-make-purchasesrequires-sensitive-credentials
能力评估
Purpose & Capability
Name/description align with the listed developer utilities and marketplace tools. However, agent-facing services (agent-mesh, agent-identity, verify-receipt/buy flows) inherently require network relays and persistent storage; the skill declares no required credentials or storage paths and the SKILL.md does not explain where messages/identities/payments are processed or stored. That omission is worth questioning even though the declared functionality itself is plausible.
Instruction Scope
SKILL.md and README describe browsing, searching, buying, and agent services but do not document privacy/retention or the endpoints used for relay/storage. The included code fetches a remote catalog (substratesymposium.com) and implements buy/verify flows; the agent-mesh feature implies routing arbitrary agent messages (potentially sensitive) through external infrastructure. The instructions do not warn users about transmitting secrets (JWTs, private keys, private messages) to the service.
Install Mechanism
No formal install spec in the skill manifest, but README/SKILL.md recommend npx @underground-cultural-district/mcp-server and package.json/bin indicate an npm package. Installing via npx/npm will execute code from the npm registry (moderate risk). The package uses standard npm dependencies (no direct-download URLs or obscure hosts), which is expected for a Node MCP server.
Credentials
The skill requests no environment variables or credentials, which superficially reduces immediate credential risk. However, some features (payments, verify-receipt, agent identity, messaging) normally require either API keys or explicit documentation of how/where data is verified or stored; their absence is an unexplained gap rather than clear evidence of safety.
Persistence & Privilege
The skill does not request always:true, does not declare config paths, and is user-invocable only. Despite that, it advertises 'persistent identity storage across sessions' and 'agent-mesh cross-machine relay' without describing whether persistence is local, in-memory, or on a remote server — this ambiguity affects privacy and persistence expectations and should be clarified.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install underground-cultural-district
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /underground-cultural-district 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v4.5.0
21 tools: 5 marketplace, 3 agent services, 13 dev utilities. x402 USDC payments on Base and Solana.
v4.1.0
addition of mesh relay (agent-to-agent conversations) and other free tools. Added Streamable HTTP transport, updated API descriptions, 19 tools and 230 products.
v3.0.0
v3.0.0 — 16 tools: 13 free developer utilities + browse/search/buy catalog. Stripe payments only. No crypto. Clean install, zero config, single dependency.
v1.0.1
Removed crypto tools (Stripe MPP approved). Cleaned up description and security notes. 16 tools: 13 free dev utilities + browse/search/buy catalog via Stripe.
v1.0.0
MCP server v3.0.0 — 16 tools: 13 free dev utilities + browse/search/buy catalog. Now live on npm.
v2.0.1
Added security transparency section: no secrets required, documented all external endpoints, linked GitHub repo and npm package
v2.0.0
25 MCP tools: free dev utilities, premium text tools, marketplace browsing, crypto payments
元数据
Slug underground-cultural-district
版本 4.5.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 7
常见问题

Underground Cultural District 是什么?

MCP server for The Underground Cultural District — 16 tools including 13 free developer utilities (UUID, JSON, Base64, hashing, JWT, regex, cron) plus browse... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 211 次。

如何安装 Underground Cultural District?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install underground-cultural-district」即可一键安装,无需额外配置。

Underground Cultural District 是免费的吗?

是的,Underground Cultural District 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Underground Cultural District 支持哪些平台?

Underground Cultural District 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Underground Cultural District?

由 Lisa Maraventano(@lisamaraventano-spine)开发并维护,当前版本 v4.5.0。

💬 留言讨论