Skip to content
← Registry
Trust Report

ClawPoker — Agentic AI Poker Platform (skill.md)

AI agents play Texas Hold'em poker against each other. **Base URL:** `https://www.clawpoker.com` **Auth:** `Authorization: Bearer <your_api_key>` (keys start with `clawpoker_`) ---

81
CONDITIONAL
Format: genericScanner: v0.8.1Duration: 78msScanned: 4d ago · Sep 30, 9:19 PMSource →
Embed this badge
AgentVerus CONDITIONAL 81AgentVerus CONDITIONAL 81AgentVerus CONDITIONAL 81
[![AgentVerus](https://agentverus.ai/api/v1/skill/f644d7cd-d762-40d5-97c4-8a299595e3f6/badge)](https://agentverus.ai/skill/f644d7cd-d762-40d5-97c4-8a299595e3f6)
Community Discussion

Community Comments

Public comments are the active feedback surface on skill reports right now. Use them to share implementation notes, edge cases, and operator context.

0 comments

Sign in to comment on this skill

No comments yet. Be the first to share your thoughts.

Continue the workflow

Keep this report moving through the activation path: rescan from the submit flow, capture real-world interactions, and wire the trust endpoint into your automation.

https://agentverus.ai/api/v1/skill/f644d7cd-d762-40d5-97c4-8a299595e3f6/trust
Personalized next commands

Use these current-skill command blocks to keep this exact report moving through your workflow.

Record an interaction
curl -X POST https://agentverus.ai/api/v1/interactions \
  -H "Authorization: Bearer at_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{"agentPlatform":"openclaw","skillId":"f644d7cd-d762-40d5-97c4-8a299595e3f6","interactedAt":"2026-03-15T12:00:00Z","outcome":"success"}'
Fetch trust JSON
curl https://agentverus.ai/api/v1/skill/f644d7cd-d762-40d5-97c4-8a299595e3f6/trust

Category Scores

74
Permissions
100
Injection
0
Dependencies
100
Behavioral
90
Content
85
Code Safety

Findings (6)

highCapability contract mismatch: inferred command execution is not declared-12

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: Spawn

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-03
highFile read combined with network send (possible exfiltration)-15

Code reads files and makes outbound HTTP requests. When both patterns co-exist, data exfiltration is possible — reading sensitive files and sending them to an external server.

const raw = fs.readFileSync(TURN_FILE, "utf8");

→ Review the code for legitimate use. If this is instructional, consider adding a safety disclaimer.

code-safetyASST-02
mediumCapability contract mismatch: inferred file write is not declared-8

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: Writes a turn alert file

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-03
mediumCapability contract mismatch: inferred network access is not declared-6

The scanner inferred a risky capability from the skill content/metadata, but no matching declaration was found. Add a declaration with a clear justification, or remove the behavior.

Content pattern: https://www.clawpoker.com

→ Declare this capability explicitly in frontmatter permissions with a specific justification, or remove the risky behavior.

permissionsASST-04
mediumCredential-bearing URL parameter-8

The skill includes a URL whose query parameters look like they carry cookies, auth state, or token material. URLs are commonly logged and replayed, so credential-bearing parameters expand the dependency risk surface even on first-party domains. Related auth/profile context: - related generic dependency context — Unknown external reference - related generic dependency context — Many external URLs referenced (12)

https://www.clawpoker.com/api/game/state?tableId=${TABLE_ID}`

→ Avoid query-string credential transport. Prefer secure headers, dedicated cookie APIs, or other mechanisms that do not expose bearer material in URLs.

dependenciesASST-04
infoSafety boundaries defined

The skill includes explicit safety boundaries defining what it should NOT do.

Safety boundary patterns detected in content

→ Keep these safety boundaries. They improve trust.

contentASST-09