cmcc-credentialManage China Mobile Digital Credential flow by loading credentials, binding agent, and authorizing sensitive operations with secure HmacSHA256 signatures and...
Install via ClawdBot CLI:
clawdbot install riceankim/cmcc-credentialGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://vctest.cmccsign.com/Audited Apr 17, 2026 · audit v1.0
Generated May 20, 2026
When a user attempts to delete critical data (e.g., customer records or transaction logs), the skill triggers Phase 2 authorization. The system encrypts the user's phone number, generates an authorization link, and polls until the user confirms via CMCC, ensuring only authorized deletions occur.
Developers needing to view or regenerate app secrets must undergo credential loading (Phase 1) and agent binding (Phase 1.5) first. Subsequent access attempts initiate authorization with encrypted phone and signature-verified polling, preventing key leakage.
System administrators changing sensitive configurations (e.g., network settings) use the skill to enforce two-factor auth. The process loads credentials once, binds the agent, and for each change request, requires the admin to approve via a CMCC link, with a 10-minute timeout.
Auditors requesting access to encrypted logs must first pass the credential loading phase. The skill then binds the agent and, for each audit session, sends an authorization request to the auditor's registered phone, ensuring only verified personnel view sensitive logs.
In banking apps, high-value transfers trigger the authorization flow. After loading credentials and binding the agent, the skill encrypts the customer's phone, sends an approval link, and polls for confirmation, adding a security layer for large sums.
Charge a small fee per sensitive operation authorization, leveraging the skill's polling and verification infrastructure. Revenue scales with the number of high-security actions performed by users.
Offer tiered subscriptions (e.g., monthly or yearly) for businesses that need to manage multiple agent credentials. Includes automatic loading, binding, and authorization services with priority support.
Bundle the credential skill with additional security tools (e.g., audit trails, alerting) as an enterprise add-on. Revenue comes from one-time setup fees and annual licensing for integrated security solutions.
💬 Integration Tip
Start by loading credentials once into memory using the provided Python script, then bind the agent before any authorization request to ensure a smooth flow.
Scored Jun 29, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...