Is evoleinik/airshelf safe?

https://github.com/openclaw/skills/tree/main/skills/evoleinik/airshelf

96
SAFE

AirShelf is a legitimate e-commerce skill that provides product search, comparison, and checkout functionality through a documented API. The skill contains only markdown documentation with no executable code, makes transparent API calls to its declared service, and shows no signs of malicious behavior.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 100/100 · 25%
Code Execution 100/100 · 20%
Clone Behavior 100/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (2)

LOW External API dependency -5

Skill instructs agent to make HTTP requests to dashboard.airshelf.ai for legitimate e-commerce functionality

LOW Third-party service dependency -10

Skill relies on external API service that could theoretically be compromised, though this is inherent to its legitimate function