Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

China Stock Analysis 1.0.0

v1.0.0

Analyze Chinese stock prices (A-shares, HK stocks) and provide investment recommendations. Use when the user asks about stock analysis for Chinese companies,...

0· 30·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description match the instructions: the skill performs web searches for prices/news and produces buy/hold/sell recommendations for Chinese (and listed) stocks. Required capabilities (none) are proportionate to the stated purpose.
Instruction Scope
SKILL.md restricts runtime behavior to web searches for price/news, assembling technical/fundamental commentary, and returning a structured recommendation with a disclaimer. It does not instruct reading system files, accessing unrelated env vars, or exfiltrating data to unknown endpoints.
Install Mechanism
Instruction-only skill with no install spec or code files to write/execute — lowest install risk.
Credentials
Requires no environment variables, no credentials, and references public data sources only. The requested environment access is minimal and appropriate for the task.
Persistence & Privilege
always is false and autonomous invocation is allowed (platform default). The skill does not request elevated persistence or modify other skills/config; behavior is within normal expectations.
What to consider before installing
This skill appears to do what it says (search public finance sites and summarize price/news), and it does not request credentials or install code. However: (1) the source/homepage is missing and the registry ownerId (kn78...) does not match the ownerId inside _meta.json (kn79...), which is an unexplained provenance inconsistency; (2) because it will perform web searches, verify the agent's search tool is trustworthy and that results are coming from reputable finance sites (e.g., Eastmoney, Xueqiu, Yahoo) before relying on recommendations; (3) treat any investment recommendations as informational only (the skill includes a disclaimer but you should still verify data independently); and (4) if you need stronger guarantees, ask the publisher for provenance (who published this, a homepage or source repo, and why owner IDs differ) or prefer a skill from a known/trusted provider. If you plan to use it in production or give it autonomous access, request additional provenance or testing logs first.

Like a lobster shell, security has layers — review code before you run it.

latestvk97117vptvg1bkjrewnaen0gs98461rx

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments