Is inthaiguy/get-esim safe?

https://github.com/openclaw/skills/tree/main/skills/inthaiguy/get-esim

94
SAFE

This skill provides legitimate eSIM purchasing functionality using USDC cryptocurrency on Base blockchain. The code is clean, well-documented, and shows no malicious behavior. The skill transparently handles financial transactions for its stated purpose.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 90/100 · 25%
Code Execution 95/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (3)

INFO Cryptocurrency Transaction Handling -5

Skill facilitates real cryptocurrency transactions (USDC) for eSIM purchases, which involves irreversible financial operations

LOW External Service Dependency -10

Skill communicates with external eSIM service (esimqr.link) which is outside user control

INFO Financial Transaction Risk -5

Users should be aware that eSIM purchases involve real money and may have associated risks