Market Alert

v0.1.0

提供自选股盯盘、异动提醒、个股研报及开盘收盘解盘。

0· 314·2 current·2 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
The name/description and SKILL.md are consistent: a market-watch/alert/report helper. However, the SKILL.md mentions syncing with "个人账单变更" and returning transaction/export data (交易流水/对账单导出), which implies access to sensitive financial records; the skill declares no credentials, config paths, or install steps to perform that access. This is plausible (the agent can ask users to upload data), but it's a potential gap to be aware of.
Instruction Scope
SKILL.md is high-level and scoped to market data, filters, return fields, example prompts, update frequency, and a safety note. It does not instruct the agent to read arbitrary system files, environment variables, or contact third-party endpoints. No open-ended instructions that grant broad discretionary access are present.
Install Mechanism
There is no install spec and no code files; this is an instruction-only skill. That minimizes on-disk risk and there are no downloads or package installs to evaluate.
Credentials
The skill lists sensitive outputs (transaction history, statement export, tax details) but requires no environment variables or credentials. This is not necessarily problematic for an instruction-only skill (it may expect the user to provide data interactively), but users should be aware that to deliver those outputs the agent will either ask for sensitive data or need external integrations — neither of which are declared here.
Persistence & Privilege
always is false and the skill is user-invocable. It does not request persistent presence or attempt to modify other skills or system-wide settings.
Assessment
This skill appears coherent and low-risk as-is because it has no install steps and asks for no credentials. Before using it, confirm how it obtains transaction/billing data: prefer providing anonymized or sample data rather than pasting real bank credentials. If the agent asks to connect to external accounts, require explicit use of read-only, scope-limited tokens from the service provider and review any privacy/terms. If you plan to allow autonomous actions (agent invoked on its own), be cautious about granting it access to sensitive financial data or automating transfers — this skill does not declare any integration mechanism, so clarify with the publisher how sensitive data is handled.

Like a lobster shell, security has layers — review code before you run it.

latestvk97cxyf86272yvk5vgh6snqk4183cc55

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments