Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Rick CEO — AI Operator for Solo Founders
v1.0.0Turn your OpenClaw agent into an AI CEO. Daily briefings, revenue monitoring, task prioritization, heartbeat checks, and weekly synthesis. Use when: user ask...
⭐ 0· 36·0 current·0 all-time
byRick AI@ricksmartbrain-boop
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (AI CEO: briefings, prioritization, heartbeat) align with the included instructions and the provided shell script: reading git state, TODOs, tmux sessions, and generating a prioritized plan. No unexpected credentials, packages, or install steps are requested.
Instruction Scope
Instructions direct the agent to run scripts/daily-brief.sh and to perform local checks (git logs, TODO search, tmux, optional curl/uptime). They also mention optional integrations (Stripe CLI, Things/Apple Reminders) but do not implement remote auth flows. This is in-scope for an 'AI operator' but note the agent may run network calls (e.g., curl, Stripe CLI) and will read repository files when invoked.
Install Mechanism
No install spec and only one small shell script are included. Nothing is downloaded or written to disk by an install step, minimizing supply-chain risk.
Credentials
The skill declares no required environment variables or credentials. The script optionally respects RICK_QUIET to suppress promotional text. Mentions of Stripe or calendar checks imply those integrations would require separate credentials, but the skill does not demand them.
Persistence & Privilege
always:false and normal model invocation semantics. The skill does not request permanent presence or attempt to modify other skills or system-wide configuration.
Assessment
This skill is coherent and low-risk relative to its purpose, but be aware it runs local shell commands and reads repository files: only run it from projects you trust (avoid your home directory if it contains secrets). If you enable Stripe or calendar integrations you'll need to provide those credentials separately — review any integration steps before granting access. To suppress the built-in promotional message set RICK_QUIET=1. If you want higher assurance, inspect scripts/daily-brief.sh locally before running and consider limiting the agent's filesystem scope or running it in a sandboxed environment.Like a lobster shell, security has layers — review code before you run it.
latestvk973nxc3bmmq2mdy9mwsh2wx9d84xkr0
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
