Book a 30-minute demo →
Skill scan report

qfc

View on GitHub
39 Medium Automated analysis flagged 3 potential risk patterns.

What this skill does

Blockchain interaction - wallet management, chain queries, staking, and AI inference

github/leoyeai - Security Policy - 2.1k stars

ThreatsSecurity Policy Wallet Persistence Third-party Dependencies

Threat analysis

Security Policy1 finding
Wallet Persistence1 finding
Third-party Dependencies1 finding

Skill info

Nameleoyeai/qfc
Registrygithub
Versione5199b5
PURLpkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=qfc
Stars2.1k

Assessments (3)

Security Policy1 finding HIGH
HIGH

Security Policy via local-llm-review

src/security.ts

The `SecurityPolicy` class includes a `preTransactionCheck` method that performs checks on transactions, including validation of address format and transaction size. However, the implementation is inc
Wallet Persistence1 finding MEDIUM
MEDIUM

Wallet Persistence via local-llm-review

README.md

The skill includes functionality for saving and loading wallets with AES encryption. While this is a legitimate feature, the documentation does not explicitly mention secure handling of passwords or e
Third-party Dependencies1 finding LOW
LOW

Third-party Dependencies via local-llm-review

package.json

The skill uses the `ethers` library, which is a legitimate and widely used Ethereum library. However, it is important to ensure that the version used is up to date and secure.

Badge

Add the Anomity scan badge for qfc to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/leoyeai/qfc/)
HTML
<a href="https://anomity.ai/skills/github/leoyeai/qfc/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of qfc? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok