德胧思想领袖论坛v3.0

AdvisoryAudited by VirusTotal on Apr 22, 2026.

Overview

Type: OpenClaw Skill Name: delonix-thought-leader-forum Version: 3.0.0 The skill bundle is a role-playing framework designed to simulate industry debates and strategic discussions involving AI, hospitality, and venture capital personas. The included bash script (run-discussion.sh) is a simple utility that validates the presence of persona files and prints usage instructions for the user, while the SKILL.md and persona files (e.g., musk.md, huang-renxun.md) contain instructions for the AI agent to maintain specific formatting and legal disclaimers. No evidence of data exfiltration, unauthorized execution, or malicious prompt injection was found.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

A reader could misunderstand simulated opinions as real endorsements if labels are removed or ignored.

Why it was flagged

The skill intentionally simulates views of named real people. The artifact mitigates this with repeated labeling and legal disclaimers, but users must keep those labels so outputs are not mistaken for real statements.

Skill content
所有输出必须标注【观点模拟:XXX人物名】 ... 不声称代表任何真实人物的立场、观点或言论。
Recommendation

Keep the 【观点模拟】 labels, use outputs as internal brainstorming only, and do not publish or attribute them as real statements.

What this means

Generated viewpoints may depend on searched public sources, which could be incomplete, outdated, or unreliable.

Why it was flagged

The skill may ask the agent to supplement missing background through search if available. This is aligned with the stated goal of using public information, but it introduces externally sourced context into the output.

Skill content
有没有具体的背景资料?(没有的话我会根据议题自行搜索补充)
Recommendation

Ask the agent to cite or summarize sources when search is used, and provide your own vetted background for sensitive business discussions.

What this means

Users have less independent provenance information for the skill publisher and updates.

Why it was flagged

The registry metadata does not provide a source repository or homepage, limiting provenance verification. The supplied artifacts themselves do not show suspicious install behavior.

Skill content
Source: unknown; Homepage: none
Recommendation

Install only if you trust the registry owner, and review future updates because there is no linked upstream source to compare against.