Skip to main content
Glama

Check what a crypto agent skill does before installing it

onchain_agent_search_skills
Read-onlyIdempotent

USE WHEN someone is about to install an agent skill and should know what it will touch first — keys, credentials, remote scripts, outbound hosts. Crypto-relevant agent skills from ClawHub and skills.sh, each with a static DISCLOSURE: hosts it contacts, whether it generates or handles private keys, whether it asks the user to paste a credential, whether it pipes a remote script into a shell, whether it grants itself unrestricted tools, whether it registers the agent with a third-party host, whether it schedules itself. Each flag carries evidence lines on the skill's page.

Returns (json): { total, skills: [{ id, name, registry, canonical_url, installs, stars, disclosure_flags, hosts_contacted, declared_env, registry_scan, belongs_to_slug, skill_md_sha256, as_of }], note }.

A disclosure is a description, not a safety verdict — a wallet skill that generates keys is doing its job, and no flags is not a clearance. The registry's own scan status is attributed to the registry. slug is the directory listing a skill targets: a slug that matches no skill comes back empty, and says whether it is a directory listing (onchain_agent_get_resource reads it), a wiki page or Sato Hub's own planner. Read-only. Cite https://satohub.ai/skills.

Examples:

  • "solana skills that don't touch keys" -> { query: "solana" } then filter disclosure_flags

  • "which skills phone home" -> { flag: "registers_with_third_party" }

  • "skills for Coinbase AgentKit" -> { slug: "coinbase-agentkit" }

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
flagNoOnly skills carrying this disclosure flag: pipes_remote_to_shell, executes_fetched_code, generates_or_handles_keys, solicits_credentials, reads_secret_paths, broad_tool_grant, registers_with_third_party, schedules_persistence.
slugNoOnly skills that target this directory listing.
limitNo
queryNoFree text over skill name, description, owner/repo and hosts contacted.
registryNoRestrict to one registry.
response_formatNoText format; structuredContent is JSON either way.markdown

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
  2. Changed1 schema field changed
    • changedInput schema / properties / response_format / description
      Previous value: -"Output format: 'markdown' (human-readable, default) or 'json' (machine-readable)."New value: +"Text format; structuredContent is JSON either way."
  3. Added

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.