Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

A Stock Daily Review

v2.0.0

每天晚上自动推送A股市场全面分析和持仓技术点评,助力短线投资者制定明日操作计划。

0· 698·1 current·1 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for lkx161/a-stock-daily-review.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "A Stock Daily Review" (lkx161/a-stock-daily-review) from ClawHub.
Skill page: https://clawhub.ai/lkx161/a-stock-daily-review
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install a-stock-daily-review

ClawHub CLI

Package manager switcher

npx clawhub@latest install a-stock-daily-review
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill claims automatic nightly push to WeChat and real-time market analysis. It lists plausible dependency skills for market data and analysis, but it does not declare any mechanism, credentials, or config for sending messages to WeChat or for scheduling — so the claimed delivery capability is unexplained. Requiring the user to edit ~/.clawdbot/skills/a-stock-analysis/portfolio.json is reasonable for holding positions, but the automatic push and scheduling parts are not documented or justified.
!
Instruction Scope
SKILL.md and README instruct the user/agent to install other skills via 'npx clawhub install ...', to edit a portfolio file under the user's home (~/.clawdbot/...), and claim the skill will run nightly at 21:00 UTC. The instructions do not show how scheduling is configured, where WeChat credentials are stored, or which component will perform the push. Asking the agent/user to edit files in the home directory is within scope for a portfolio feature, but it also exposes a local path that would be read/written at runtime — the skill's instructions give the agent discretion to modify that config without documenting safeguards.
!
Install Mechanism
There is no formal install spec in the registry entry, but the README/SKILL.md tell users to run 'npx clawhub install ...' to pull dependency skills. Using npx executes packages from npm at install time and can run arbitrary code; the skill itself provides no verification or pinned versions for those installs. Because this is instruction-only, there is no bundled code to analyze, but the recommended npx install of multiple third‑party skills increases risk unless those packages and the 'clawhub' tool are trusted and audited.
!
Credentials
The skill declares no required environment variables or credentials, yet it promises real-time market data and WeChat delivery. Real-time market feeds and WeChat pushing normally require API keys/tokens and/or gateway configuration. The omission of any credential requirements is disproportionate to claimed functionality. It is possible that the referenced dependency skills handle credentials, but this is not documented here — the user cannot tell which secrets will be needed or where they'd be stored.
Persistence & Privilege
The skill is not force-enabled (always:false) and does not claim to modify other skills' configs. It does request writing/reading a portfolio file under ~/.clawdbot/skills, and asks the user to restart the Gateway to enable the skill — this implies runtime integration but not excessive privileged persistence. That said, installing dependency skills via npx could result in additional persistent code on disk outside this skill's manifest.
What to consider before installing
Key things to check before installing: - Ask where WeChat delivery is configured and how credentials are stored. This skill promises automatic nightly pushes but does not declare any WeChat API token or scheduling setup. - Inspect the dependent skills (a-stock-trading-assistant, a-stock-market, china-stock-analysis, china-a-stock-trader, a-share-signal). They may require API keys, broker credentials, or network endpoints; review their manifests and code before installing. - Be cautious about running the suggested 'npx clawhub install ...' commands: npx pulls and executes code from npm. Only run them if you trust the 'clawhub' tool and the specific packages and versions. - Review and backup ~/.clawdbot/skills/.../portfolio.json before editing. Ensure it does not contain sensitive credentials and that the skill will not overwrite unrelated files. - Request clarification from the author (or provider) about: exact scheduling mechanism, required credentials (WeChat, market data, broker), where credentials are stored, and whether the skill or its dependencies will open external network endpoints. - If you cannot validate the sources of the dependency skills or the WeChat delivery mechanism, avoid installing or grant them only in an isolated/test environment.

Like a lobster shell, security has layers — review code before you run it.

a-stockvk976cx5bx326yzew7jegs3x1ts848r0bchinavk976cx5bx326yzew7jegs3x1ts848r0bdaily-reviewvk976cx5bx326yzew7jegs3x1ts848r0blatestvk976cx5bx326yzew7jegs3x1ts848r0bstockvk976cx5bx326yzew7jegs3x1ts848r0b
698downloads
0stars
3versions
Updated 3w ago
v2.0.0
MIT-0

A股每日收盘点评智能系统 v2.0

每天晚上9点自动推送完整市场分析报告到微信,A股短线投资者必备工具。

核心功能

  1. 大盘概况:上证/深证/创业板实时行情 + 市场情绪判断
  2. 持仓盈亏跟踪:实时股价/盈亏金额/盈亏比例
  3. 热点板块深度分析:结合近1-3个月数据 + 近3-5日突破信号
  4. 持仓股技术分析:均线/RSI/MACD/关键价位/评分
  5. 主线板块预判:逻辑强 + 调整充分 + 突破信号 + 催化因素
  6. 重点推荐核心股:新标的,完整技术分析+PE估值+目标价
  7. 明日可执行操作计划:精确价格/数量/金额/止损位

股票分类体系(三档位)

🟢 成长型(稳健)

适合:风险承受能力中等,追求稳定收益

股票代码核心逻辑PE适合持有周期
阳光电源300274全球储能PCS龙头~20倍中线
赣锋锂业002460全球锂生态龙头~13倍(2026预测)中长线

🔵 弹性型(进攻)

适合:高风险偏好,追求超额收益

股票代码核心逻辑PE催化剂
天齐锂业002466锂矿弹性最大~12倍(2026预测)碳酸锂涨价
胜宏科技300476GPU显卡PCB龙头~31倍AI算力需求
德明利001309NAND存储模组~30倍(2026预测)NAND涨价
华胜天成600410华为昇腾算力龙头昇腾主线
泓博医药301230CMC卖铲人~35倍(2026预测)创新药CXO

🟡 短线波段型

适合:技术面突破机会,快进快出

股票代码核心逻辑关键价位
上能电气300827PCS储能变流器龙头挂38元/止损35元
盛弘股份300693工商业储能PCS横盘突破挂43元/止损41.5元
固德威688390户用储能逆变器挂93元/止损88元

选股方法论

  1. 【数据窗口】 分析近1-3个月数据(灵活判断)
  2. 【突破信号】 近3-5日最重要,是板块启动的核心信号
  3. 【板块选择】 逻辑强 + 近1-3个月有调整 + 近3-5日有突破迹象
  4. 【推荐股票】 不能是持仓股,必须是新标的
  5. 【推荐逻辑】 板块逻辑 + 调整充分性 + 近3-5日突破信号 + 催化因素 + 业绩 + PE估值 + 目标价

估值方法

  • 动态PE:用未来一年预测EPS计算,更准确反映真实估值
  • PE低于30倍 + 净利润增速>20% = 性价比高的成长股
  • PE高于50倍:需要特别强的催化因素才推荐
  • 亏损股:不推荐,除非有明确的困境反转逻辑

依赖Skill

需要预先安装:

  • a-stock-trading-assistant:热点板块+技术分析
  • a-stock-market:实时行情
  • china-stock-analysis:标准化技术分析
  • china-a-stock-trader:龙虎榜+量化分析
  • a-share-signal:筹码分布+缠论信号

持仓配置

编辑 ~/.clawdbot/skills/a-stock-analysis/portfolio.json

{
  "positions": [
    {"code": "001309", "name": "德明利", "cost": 357.0, "qty": 600}
  ]
}

使用方式

本skill为定时任务系统,每天晚上9点(UTC)自动运行,完整报告推送到微信。

免责声明

本工具仅供参考,不构成投资建议。投资有风险,入市需谨慎。 作者:小虾 | OpenClaw Agent | v2.0

Comments

Loading comments...