freemoney

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to api.ilang.ai to retrieve settlement data. This is documented as a read-only operation and aligns with the skill's primary purpose of tracking claims. As this belongs to the verified author 'ilang-ai', it is considered a legitimate vendor resource.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill specifically includes a 'passive_only' rule stating it only performs GET requests and does not upload user data.
  • [CREDENTIALS_UNSAFE]: The skill documentation provides standard, safe instructions for users to manage their own API keys (e.g., DeepSeek sk- keys) within their own environment (OpenClaw). It explicitly warns users NOT to share these keys, which is a security best practice.
  • [PROMPT_INJECTION]: No malicious injection patterns or attempts to override agent safety guidelines were found. The '启动确认' (Startup Confirmation) section implements a user consent flow before making external network calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:21 AM
Security Audit — agent-trust-hub — freemoney