Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Iching Divination

v1.1.0

AI占卜大师 - 结合古老易经智慧与现代AI技术的智能占卜工具。当用户问到占卜、易经、算命、卦象、运势、创业决策、感情问题、事业发展等话题时使用。支持六十四卦解读、吉凶判断、决策建议。

0· 49·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for jaxint/iching-divination.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Iching Divination" (jaxint/iching-divination) from ClawHub.
Skill page: https://clawhub.ai/jaxint/iching-divination
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install iching-divination

ClawHub CLI

Package manager switcher

npx clawhub@latest install iching-divination
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Suspicious
high confidence
Purpose & Capability
The skill claims to combine I Ching rules with AI interpretation; the code implements deterministic hexagram generation and then calls an external AI service for interpretation — that is consistent with the stated purpose. However, the code requires an API key (MINIMAX_KEY) and a MINIMAX_URL endpoint not mentioned in the SKILL.md or the registry metadata, creating an inconsistency between claimed requirements and actual dependencies.
!
Instruction Scope
SKILL.md describes how to produce hexagrams and AI-driven interpretations but does not disclose that the runtime will POST the user's question and a prompt to an external API. The code sends the full constructed prompt (including the user's question) to https://api.sfkey.cn/v1/chat/completions. User-provided questions / context will therefore be transmitted to that third-party host — this data flow is not documented in the instructions.
Install Mechanism
There is no install spec (instruction-only install) and only Python source files are included. Nothing in the manifest indicates downloads from unknown URLs or archive extraction. This is the lower-risk install model.
!
Credentials
The code reads MINIMAX_KEY from the environment but the skill metadata lists no required env vars or primary credential. Worse, the code contains a hard-coded default API key ('sk-y9avgZs...') embedded in the source. That default key looks like a bearer-style key and may be sensitive or abused; embedding such a key is inappropriate and elevates risk because user data could be routed via an author-controlled credential without disclosure.
Persistence & Privilege
The skill is not always-included and uses the platform defaults for invocation. Autonomous invocation is allowed (platform default). While that alone is normal, combined with the undocumented external API call and embedded key it increases the blast radius (the agent could autonomously send user questions to the external endpoint).
What to consider before installing
Before installing, consider these points: - The code will transmit the user's question and a generated prompt to https://api.sfkey.cn using an API key embedded in the source. That network call and the key are not documented in SKILL.md or the skill metadata. If you care about privacy, do not install until this is resolved. - Ask the maintainer to remove the hard-coded API key, declare MINIMAX_KEY as a required environment variable in the metadata, and document the external endpoint and its operator/terms. Prefer providing your own API key rather than relying on a default baked into the package. - If you cannot verify the endpoint or the author's trustworthiness, avoid giving this skill permission to run autonomously or disable AI usage (use_ai=False) so interpretation runs locally or not at all. - If you proceed, review network traffic from the agent to confirm where data is sent, and consider running the skill in an environment without sensitive context. Treat the embedded key as potentially compromised and assume user questions sent to that endpoint may be logged or used by third parties.

Like a lobster shell, security has layers — review code before you run it.

latestvk971fa3bpc89nb7mp5x2vxd9fh85janb
49downloads
0stars
2versions
Updated 2d ago
v1.1.0
MIT-0

IChing Divination — AI占卜大师

易经是中国最古老的典籍之一,通过八卦和六十四卦系统来解读天地人三才的关系。

八卦基础

卦名符号意义
刚健、自强不息
柔顺、厚德载物
震动、把握时机
渗入、顺从
陷危险、危机感
光明、智慧
停止、稳健
喜悦、人际和谐

六十四卦速查

六十四卦由八卦上下组合而成。如"天泽履"是乾在上、兑在下。

常用卦象速查

问题类型推荐卦解读重点
创业/事业乾、屯、鼎、大有起步、突破、成长
投资/财运谦、泰、临、益稳健、顺势、增益
感情/姻缘咸、恒、睽、归妹吸引、长久、磨合
职业/学业晋、升、益、蒙晋升、发展、启蒙
决策/选择萃、需、讼、否抉择、等待、突破

卦辞精选

创业相关卦

  • 乾为天: "元亨利贞" — 创业最吉卦,表示大吉大利
  • 天火同人: "同人于野,亨" — 贵人相助,广结善缘
  • 火天大有: "大有,元亨" — 事业兴旺,财源广进

财运相关卦

  • 地山谦: "谦,亨" — 低调行事,闷声发财
  • 地天泰: "泰,小往大来" — 阴阳调和,事事顺遂
  • 风天小畜: "小畜,亨" — 积累阶段,积少成多

感情相关卦

  • 泽山咸: "咸,亨,利贞" — 感情萌芽,心意相通
  • 雷风恒: "恒,亨,无咎" — 长久稳定,专一持久

使用方法

当用户提出占卜请求时:

用户: 我想辞职创业,能成功吗?

系统:
🔮 正在掷筊请卦...

📿 得卦:天泽履卦
📜 卦辞:履虎尾,不咥人,亨
💡 解读:此卦显示...

或者用户可以直接问:

用户: 我的事业运如何?
系统使用八卦或六爻为您解读。

AI解读要点

  1. 先理解问题 - 准确把握用户想问什么
  2. 选择卦象 - 根据问题类型和直觉选择合适的卦
  3. 给出卦辞 - 解释卦辞的基本含义
  4. 结合实际 - 把卦象与用户具体情况联系起来
  5. 给出建议 - 提供具体的行动建议

解读风格

  • 像朋友聊天,有温度
  • 不迷信,强调主观能动性
  • 具体可行,不说空话
  • 适度鼓励,不盲目乐观

参考资源


占卜是参考,不是定论。命运掌握在自己手中。

Comments

Loading comments...