Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

吴军 AI 趋势

v2.0.0

[何时使用]当用户需要分析 AI 趋势时;当用户问"AI 投资机会在哪里"时;当进行智能趋势分析时;当应用吴军 AI 三波浪潮理论时

0· 161·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for lj22503/wu-ai.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "吴军 AI 趋势" (lj22503/wu-ai) from ClawHub.
Skill page: https://clawhub.ai/lj22503/wu-ai
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install wu-ai

ClawHub CLI

Package manager switcher

npx clawhub@latest install wu-ai
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill claims only trend analysis and lists no required binaries/env, but scripts/analyze-ai.py attempts to invoke an external command ('uv') and a sibling skill script at a relative path ('../../skills/searxng/scripts/searxng.py'). Requiring another skill's code and an undeclared binary is not proportional to the stated purpose and is an undeclared dependency.
Instruction Scope
SKILL.md describes analysis and mentions using searxng for search results, which aligns with the script's behavior. However, the runtime instruction surface (the included Python) executes a local external script by subprocess (potentially running arbitrary code from a sibling path). The SKILL.md does not document that the skill will execute other local scripts or require the 'uv' runtime.
Install Mechanism
There is no install spec (instruction-only plus a code file). No remote downloads or archive extraction are present in the manifest, which minimizes supply-chain install risk.
Credentials
The skill declares no required environment variables or credentials, and none are obviously needed for its stated functionality. However, the script will perform network-like search operations via searxng (if available) and executes an external binary; callers should ensure no secrets or unrelated config are accessible to the executed subprocess.
Persistence & Privilege
always is false and there is no indication the skill requests elevated or persistent platform privileges. The skill does not attempt to modify other skills' configs in the provided files.
What to consider before installing
This skill appears to implement AI trend analysis, but before installing you should: 1) Verify whether your agent environment has the 'uv' binary and the sibling skill 'skills/searxng' at the referenced relative path—the Python script will call them via subprocess. 2) Inspect the referenced searxng script (../../skills/searxng/scripts/searxng.py) to confirm it’s trustworthy, since analyze-ai.py will execute it and it may perform network requests. 3) If you don't want the skill to execute other local scripts, request the author to remove or make the search step optional and to declare required binaries/dependencies in the manifest. 4) Because the script spawns subprocesses, ensure it cannot access secrets or sensitive files in your agent environment. If you can't confirm the external 'searxng' code and the 'uv' runtime, treat this package cautiously.

Like a lobster shell, security has layers — review code before you run it.

ai-trendvk976trvmn7g8jm1hqsjagkqcj1839nryintelligencevk976trvmn7g8jm1hqsjagkqcj1839nrylatestvk976trvmn7g8jm1hqsjagkqcj1839nrywavevk976trvmn7g8jm1hqsjagkqcj1839nry
161downloads
0stars
1versions
Updated 6h ago
v2.0.0
MIT-0

吴军 AI 趋势分析 🤖

基于《智能时代》《浪潮之巅》- 吴军


📋 功能描述

分析 AI 趋势和投资机会。

适用场景:

  • AI 投资机会分析
  • 智能趋势判断
  • 行业颠覆分析
  • AI 应用评估

边界条件:

  • 不替代深入研究
  • 技术预测有不确定性
  • 需配合基本面分析

🎯 AI 三波浪潮

浪潮时间特征机会
第一波2010-2020互联网 AI✅ 平台型
第二波2020-2030行业 AI✅ 垂直应用
第三波2030-2040通用 AI⚠️ 早期

🎯 AI 投资 checklist

检查项是否符合说明
有数据优势吗?✅/❌[填写]
有应用场景吗?✅/❌[填写]
有商业闭环吗?✅/❌[填写]
有技术壁垒吗?✅/❌[填写]

通过标准: 4 项都符合


⚠️ 常见错误

错误 1:忽视数据优势

问题:
• 投资没有数据的公司
• 忽视数据积累
• 忽视数据质量

解决:
✓ 投资有数据优势的公司
✓ 关注数据积累
✓ 关注数据质量

错误 2:忽视应用场景

问题:
• 投资纯技术公司
• 忽视应用场景
• 忽视商业闭环

解决:
✓ 投资有应用场景的公司
✓ 关注商业闭环
✓ 关注变现能力

错误 3:过度炒作

问题:
• 被 AI 概念炒作
• 忽视基本面
• 忽视估值

解决:
✓ 关注基本面
✓ 关注估值
✓ 理性投资

🧪 使用示例

示例:某 AI 公司分析

输入:

公司:某 AI 公司
数据:有海量数据
应用:有明确场景
商业:有收入
技术:有壁垒

输出:

AI checklist:
✓ 数据优势
✓ 应用场景
✓ 商业闭环
✓ 技术壁垒

通过:4/4 ✅

建议:重点关注

📚 核心理念

关键洞察:

  1. 数据是新的石油
  2. 应用场景是关键
  3. 商业闭环是核心
  4. 第二波浪潮是机会
  5. 理性投资不炒作

健康公式:

AI 投资 = 数据优势 × 应用场景 × 商业闭环

更新日志

  • v2.0.0 (2026-03-19): 按照 SKILL-STANDARD-v2.md 重构,添加 Front Matter、坑点章节 🤖
  • v1.0.0 (2026-03-13): 初始版本,吴军 AI 趋势分析上线 🤖

数据是新的石油。AI 改变所有行业。 🤖

Comments

Loading comments...