OpenClaw GenPark agent skill framework with multiple autonomous commerce and consumer protection agents
GenPark UCP is a deeply problematic MCP server that combines legitimate health/nutrition tools with multiple tools designed for deceptive, abusive, and potentially illegal activities. The tool definitions themselves are poorly structured: most lack proper input validation schemas, descriptions are inconsistent in quality, and several tools describe capabilities that violate fundamental ethical and legal boundaries. Of the 13 tools, 6 are explicitly high-risk (arbitrage front-running, contract generation for unknown purposes, lead harvesting from social platforms, AI-driven closing sequences, subscription cancellation with generated legal notices, and automated account creation with simulated engagement). Even the benign health tools lack proper error handling and output schemas. The naming is inconsistent (mix of verb_noun and descriptive phrases). Parameter descriptions are minimal. No evidence of pagination, structured output schemas, or recovery guidance.
Appediet Vision: Analyzing food images (simulated). Uses AI Vision identification to detect food items from image paths.
AppeChat: Evaluating today's diet. Compares daily caloric intake against user profile goals and provides health advice.
GenPark AI Closer: Executes high-performance sales closing sequence including hook, proof, and CTA delivery to convert identified leads.
GenPark Ghostwriter: From intent to legally binding smart-contract draft. Translates business intent into legal logic and generates contract templates.
Fetching nutrition facts for a given food item. Returns caloric and macronutrient information from the food database.
GenPark Lead Harvester: Scans social platforms for users expressing specific purchasing friction and high-intent signals.
Arbitrage tool (scan_and_lock_arbitrage) explicitly describes front-running retail listings, a market manipulation and potentially illegal activity. Description states 'auto-executes purchase contracts' without user authorization gates, permission checks, or dry-run capability.
Contract generation tool (generate_enforceable_contract) offers to produce 'legally binding smart-contract drafts' from user intent without legal disclaimers, validation of deal terms, or warning that AI-generated contracts may be unenforceable or inappropriate. No description of what 'legally binding' means in context.
Lead harvesting tools (harvest_leads, scan_intent) describe scanning social platforms for 'high-intent purchasing signals' without disclosing whether this involves consent, scraping, or terms-of-service violations. No privacy boundary documentation.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 34 | 2026-07-28+ | v2 |
Analyzing lead friction indicators to determine sales priority and qualification status.
Recipe Expert: Finding recipes based on dietary preference. Returns list of recipe recommendations.
Fast Swarm: Automated account registration and social engagement. Creates new user accounts with realistic profiles and simulates natural interaction patterns (scrolling, liking posts).
GenPark Arbitrage Engine: Monitors wholesale APIs to front-run retail listings. Searches across logistics endpoints, detects price dips, and auto-executes purchase contracts.
GenPark Subscription Killer: Analyzing recurring transactions in bank feed to identify and flag unused subscriptions.
Scanning social platform for high-intent purchasing signals and friction points.
GenPark Subscription Killer: Automatically initiates cancellation process for identified vampire subscriptions with generated legal notices.
Account creation tool (register_and_like) creates accounts with 'realistic profiles' and simulates engagement without disclosure. Code shows Playwright automation with headless browser and realistic user agent string, classic bot pattern. Violates most social platforms' terms of service and potentially violates computer fraud statutes.
Subscription cancellation tool (trigger_cancellation) auto-initiates cancellation with 'generated legal notices', tool description explicitly states it generates fake legal language. This is document forgery and fraud.
Most tools lack input validation schemas. E.g. scan_intent has empty input schema ({}), scan_bank_feed has empty schema. Tools cannot validate user intent or prevent injection attacks.
Descriptions are vague or missing for most tools. E.g. 'Scanning social platform for high-intent purchasing signals and friction points' (scan_intent) does not explain what 'friction' means, how it's detected, or whether it involves scraping. harvest_leads similarly lacks specificity about data collection method.
No error handling or recovery guidance in any tool. Tools return hardcoded results or simulated data (e.g. appediet_engine always returns 'avocado' for image analysis regardless of input). Agents cannot diagnose failures or retry intelligently.
No output schemas documented. Tools return free-form results (e.g. diet_evaluation returns narrative text, not structured data). LLMs cannot reliably parse or chain results.
No pagination or result limits on discovery tools. harvest_leads and scan_intent have no limit, offset, or pagination parameters. A large result set could exhaust context windows.
Parameter naming inconsistent. Some use snake_case (image_path, food_name), others use nested objects (lead, subscription) with undocumented structure. No type hints for nested properties.
Irreversible operations lack confirmation or dry-run capability. trigger_cancellation and register_and_like both make permanent changes without a preview or confirmation step.