DC wendao-agent
(no description)
Not recommendedlow grade D
As a process C 51/100 · Has gaps — weak spots: result and completion, when it triggers, inputs and preconditions
How to improve
- Add a description to the frontmatter: without it the skill never triggers.
For the model run — optional
- Your own cases (evals/evals.json, 4–6 real requests with expected answers): the full check would then run those instead of a model-drafted suite.
- A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.
Guard findings · 17
✓ No critical or high findings
Medium and low: 17
-
low Secrets in code
secret-high-entropy-tokendist/cli.js:14High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)nfa: process.env.NFA_ADDRESS || "0x3b…842",
quoted -
low Secrets in code
secret-high-entropy-tokendist/cli.js:15High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)vault: process.env.VAULT_ADDRESS || "0x5F…A61",
quoted -
low Secrets in code
secret-high-entropy-tokendist/cli.js:16High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)token: process.env.TOKEN_ADDRESS || "0x86…a29",
quoted -
low Secrets in code
secret-high-entropy-tokenpackage-lock.json:238High-entropy token-like string (may be an id, hash or a credential) (detector / deny-list definition)"integrity": "sha5…l1I+R1H7…G3i/cYFJ…fIw==",
detector -
low Secrets in code
secret-high-entropy-tokenpackage-lock.json:272High-entropy token-like string (may be an id, hash or a credential) (detector / deny-list definition)"integrity": "sha5…XcW+/GvMN…kxZ/opySAZMrc+9LY/WyjA…InQ==",
detector -
low Secrets in code
secret-high-entropy-tokenpackage-lock.json:289High-entropy token-like string (may be an id, hash or a credential) (detector / deny-list definition)"integrity": "sha5…qEP+UeRV…fdw==",
detector -
low Secrets in code
secret-high-entropy-tokenpackage-lock.json:323High-entropy token-like string (may be an id, hash or a credential) (detector / deny-list definition)"integrity": "sha5…Fnw/+3lVx…cQS+Yu6w==",
detector -
low Secrets in code
secret-high-entropy-tokenpackage-lock.json:425High-entropy token-like string (may be an id, hash or a credential) (detector / deny-list definition)"integrity": "sha5…UzV+AA46…P4O+ng17CA==",
detector -
low Secrets in code
secret-high-entropy-tokenREADME.md:78High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)nfa: "0x3b…842",
quoted -
low Secrets in code
secret-high-entropy-tokenREADME.md:79High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)vault: "0x5F…A61",
quoted -
low Secrets in code
secret-high-entropy-tokenREADME.md:80High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)token: "0x86…a29",
quoted -
low Secrets in code
secret-high-entropy-tokenREADME.md:202High-entropy token-like string (may be an id, hash or a credential) (documentation table row)| JingwuNFA (修士) | `0x3b…842` |
table -
low Secrets in code
secret-high-entropy-tokenREADME.md:203High-entropy token-like string (may be an id, hash or a credential) (documentation table row)| GameVault (金库) | `0x5F…A61` |
table -
low Secrets in code
secret-high-entropy-tokenSKILL.md:75High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)- 合约 (BSC): NFA `0x3b…842`
quoted -
low Secrets in code
secret-high-entropy-tokensrc/cli.ts:15High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)nfa: process.env.NFA_ADDRESS || "0x3b…842",
quoted -
low Secrets in code
secret-high-entropy-tokensrc/cli.ts:16High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)vault: process.env.VAULT_ADDRESS || "0x5F…A61",
quoted -
low Secrets in code
secret-high-entropy-tokensrc/cli.ts:17High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)token: process.env.TOKEN_ADDRESS || "0x86…a29",
quoted
Files scanned: 27. Evidence is masked. Grey chips explain why severity was lowered.
Against the Agent Skills spec
- error
frontmatterSKILL.md: no YAML frontmatter block found - error
name-missingSKILL.md: frontmatter has no `name` - error
description-missingSKILL.md: no `description` — the skill can never trigger
Process rating: all ten parameters 51/100
- 0Result and completion. Does not say what the result is
- 0When it triggers. No condition that starts the skill
- 0Inputs and preconditions. Does not say what the process needs to start
- 0Failures and branches. Linear process with no failure handling
- 0Progress reporting. Says nothing while it works
- 100Tools and files. No external tools needed
- 100Steps. 15 steps
- 100Consistency. Name and required fields are in place
- 100Execution cost. Instruction body is 405 tokens
- 100Running it twice. No mutating operations
- low 10 top-level sections: this looks like several domains in one skill
Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.
Quality signals
- +5Description has no quoted example phrases that should trigger the skill
- +4Description does not say when NOT to use the skill (false activations)
- +3Description length 0: 120–800 characters recommended
- +3Output format is not stated: the model decides each time
- +1No license
- +2Single-language instructions
- +4Structure: 11 headings
- +3Step-by-step instructions: 15 items
- +4Has examples (3 code blocks)
Quality base 70; lint remarks subtract, signals add up to 100. Result: 0.
External checks
ClawHub: suspicious
This is a real blockchain game automation skill, but users should review it carefully because it controls a wallet and can automatically spend tokens despite some documentation describing it as gas-only.
LLM: suspicious (high) · VirusTotal: · 29 May 2026