← 返回 Skills 市场
x402 Private Search
作者
kodos-vibe
· GitHub ↗
· v1.0.0
664
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install x402-private-search
功能描述
Make paid API requests using the x402 HTTP payment protocol (USDC on Base Sepolia). Use when you need to access x402-protected services, pay for API calls wi...
安全使用建议
This skill appears to do what it claims, but it requires you to create and store an EVM private key and installs npm packages into ~/.x402-client. Before installing: (1) use a throwaway/test wallet with only the small testnet funds needed, not a mainnet or valuable key; (2) inspect the npm dependencies (@x402/* and viem) and/or run npm install in a sandbox/container if you are unsure; (3) prefer storing the key in a file with restrictive permissions (mode 600) rather than exposing it widely in your environment; (4) verify the service URL(s) you intend to call (the provided search endpoint is a Cloudflare tunnel and may be ephemeral); and (5) if you need stronger assurance, request a signed upstream source or official homepage for the x402 packages before trusting them.
功能分析
Type: OpenClaw Skill
Name: x402-private-search
Version: 1.0.0
The skill is classified as suspicious due to several vulnerabilities, despite its stated purpose appearing benign. The `SKILL.md` instructs the agent/user to store a private key in an environment variable (`X402_PRIVATE_KEY`), which is a known security risk for sensitive data. The `scripts/setup.sh` executes `npm install`, introducing a supply chain vulnerability where compromised third-party dependencies could lead to arbitrary code execution. Additionally, `scripts/x402-fetch.mjs` processes command-line arguments directly for network requests, which could pose a shell injection risk if the calling environment fails to properly sanitize or quote user-controlled input.
能力评估
Purpose & Capability
The name/description promise (x402 paid requests / paid search) matches the included code: a wallet generator, a fetch wrapper that handles 402/payment signing, and a services list. The scripts and docs are coherent with this purpose.
Instruction Scope
SKILL.md instructs the agent/user to run setup.sh, generate a wallet, store the private key (env or file), and call x402-fetch.mjs. The scripts only read a local key and sign payments; they do not attempt to read unrelated files or send arbitrary data elsewhere. The instructions do require you to keep and expose a private key to the local environment (sensitive) and to run commands from ~/.x402-client.
Install Mechanism
Installation is a local npm install (setup.sh) into ~/.x402-client which will fetch @x402/fetch, @x402/evm and viem from the npm registry. This is a common pattern but does execute network installs and writes files to your home directory; review those npm packages if you need higher assurance.
Credentials
The skill requires access to a full EVM private key (via X402_PRIVATE_KEY, X402_KEY_FILE, or --key-file). That is necessary for signing payments but is highly sensitive. Registry metadata did not declare required env vars, even though SKILL.md relies on them — a metadata/documentation mismatch you should note.
Persistence & Privilege
The skill does not request always:true or modify other skills; it installs to and operates within ~/.x402-client. That local persistence is limited in scope and expected for a CLI-style client.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install x402-private-search - 安装完成后,直接呼叫该 Skill 的名称或使用
/x402-private-search触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release: Private web search for AI agents via x402 micropayments. Zero logging, no API keys, no human signup. $0.002/query USDC on Base.
元数据
常见问题
x402 Private Search 是什么?
Make paid API requests using the x402 HTTP payment protocol (USDC on Base Sepolia). Use when you need to access x402-protected services, pay for API calls wi... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 664 次。
如何安装 x402 Private Search?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install x402-private-search」即可一键安装,无需额外配置。
x402 Private Search 是免费的吗?
是的,x402 Private Search 完全免费(开源免费),可自由下载、安装和使用。
x402 Private Search 支持哪些平台?
x402 Private Search 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 x402 Private Search?
由 kodos-vibe(@kodos-vibe)开发并维护,当前版本 v1.0.0。
推荐 Skills