← 返回 Skills 市场
XLMTools
作者
Blockchain Oracle
· GitHub ↗
· v1.0.0
· MIT-0
77
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install xlmtools
功能描述
Live data and actions for Stellar (XLM, Soroban, DEX, USDC), plus crypto prices, stock quotes, weather, domain checks, web search, deep research, screenshots...
安全使用建议
This skill appears to do what it says (live Stellar data and actions) but it carries a few practical risks you should understand before installing: (1) it suggests installing npm packages (@xlmtools/cli, @xlmtools/mcp) which will run third‑party code on your machine — verify the package source and review code if possible; (2) on first run it auto-generates and stores a Stellar wallet (private keys) at ~/.xlmtools/config.json and auto-funds it via friendbot — that file is sensitive and the SKILL.md does not explain encryption or key management; (3) it will call external URLs (api.xlmtools.com) and may perform micropayments automatically for low-cost operations marked 'mention' without pausing; (4) there is no published homepage or source repository listed in the registry metadata, so provenance is limited. Before proceeding, ask the publisher for: a link to the source repo or package on npm, details about how the wallet file is protected, and clear confirmation about which network (testnet vs mainnet) and which payment tokens are used. If you install, prefer running the CLI in a contained environment (isolated account or VM), inspect the npm package contents, and treat any created wallet keys as sensitive (move/store them securely or manage your own keys instead of letting the CLI auto-generate them).
功能分析
Type: OpenClaw Skill
Name: xlmtools
Version: 1.0.0
The xlmtools skill bundle provides instructions for an agent to use a suite of tools for Stellar blockchain interactions and web tasks (search, scraping, research). It requires high-risk capabilities including shell access (Bash), network access, and local filesystem access to manage a Stellar wallet at `~/.xlmtools/config.json`. While the `SKILL.md` file contains detailed instructions for cost transparency and user confirmation regarding its USDC micropayment system, the requirement to install external global NPM packages (`@xlmtools/cli`) and the broad functional scope (including screenshotting and scraping) warrant a suspicious classification under the provided criteria, despite the lack of clear malicious intent. IOCs include the domain `api.xlmtools.com` and the NPM package `@xlmtools/cli`.
能力标签
能力评估
Purpose & Capability
Name/description align with the runtime instructions: the SKILL.md documents tools for Stellar, live prices, web scraping, screenshots, and paid MCP/CLI calls. Required host capabilities (Bash, WebFetch) and the npm/mcp CLI fallback are coherent with the declared functionality.
Instruction Scope
Instructions direct the agent to generate a Stellar wallet and persist it at ~/.xlmtools/config.json, auto-fund it via friendbot, add a USDC trustline, and call external endpoints (api.xlmtools.com) for manifests and operations. Those actions are within the skill's purpose (making on-chain calls/payments and fetching live data) but they involve creating and storing private keys and performing networked payments — sensitive operations that warrant explicit user confirmation and clearer guardrails.
Install Mechanism
Although the registry lists no install spec, SKILL.md instructs installing packages via npm (npm install -g @xlmtools/cli) and runtime npx use (npx @xlmtools/mcp). That will pull and execute third-party code from registries at runtime. The SKILL.md also suggests fetching manifests from api.xlmtools.com. These are supply-chain/network risks not vetted by the registry; the skill file alone provides no provenance or integrity information.
Credentials
The skill requests no environment variables and no pre-declared credentials, which is good. However it will create and store private keys and a config file in the user's home (~/.xlmtools/config.json) and uses web endpoints and payment flows. The persisted wallet is effectively a secret that the skill will control; the SKILL.md does not explain encryption of that file or options to manage keys separately, which is a proportionality/privacy concern.
Persistence & Privilege
always:false and no system-wide modifications are requested. The skill does request persistent state (wallet/config file) on first run and supports autonomous invocation. Combined with the ability to perform micropayments (some calls are 'mention' and do not require explicit approval), this increases the blast radius if the agent acts autonomously — the SKILL.md does have confirm/mention rules, but they rely on the agent to follow them correctly.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install xlmtools - 安装完成后,直接呼叫该 Skill 的名称或使用
/xlmtools触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
xImtools 1.0.0 — initial release
- Provides 21 tools for live Stellar (XLM, Soroban, DEX, USDC), crypto prices, stocks, weather, domain checks, web search, research, screenshots, scraping, AI images, YouTube, and more.
- Supports both MCP tools (`mcp__xlmtools__*`) and Bash CLI fallback (`xlm`), with priority on MCP.
- Mix of free and paid tools ($0.001–$0.04 USDC), paid via Stellar testnet wallet and USDC.
- Clear guidance on when and when not to use the skill; focuses on live/external data, not general knowledge or code.
- Outlines usage rules, cost disclosure, caching, and how to handle user declines for paid calls.
- Includes install steps, examples, tool cost breakdown, and a decision tree for mapping user requests to tools.
元数据
常见问题
XLMTools 是什么?
Live data and actions for Stellar (XLM, Soroban, DEX, USDC), plus crypto prices, stock quotes, weather, domain checks, web search, deep research, screenshots... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 77 次。
如何安装 XLMTools?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install xlmtools」即可一键安装,无需额外配置。
XLMTools 是免费的吗?
是的,XLMTools 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
XLMTools 支持哪些平台?
XLMTools 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 XLMTools?
由 Blockchain Oracle(@blockchain-oracle)开发并维护,当前版本 v1.0.0。
推荐 Skills