Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Abs Cashflow Modeling

v0.3.3

建模资产支持证券交易结构,模拟抵押贷款池现金流、债券分级偿还和瀑布分配,分析 tranche 收益与风险表现。。

0· 119·0 current·0 all-time
byTang Weigang@tangweigang-jpg

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for tangweigang-jpg/abs-cashflow-modeling.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Abs Cashflow Modeling" (tangweigang-jpg/abs-cashflow-modeling) from ClawHub.
Skill page: https://clawhub.ai/tangweigang-jpg/abs-cashflow-modeling
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install abs-cashflow-modeling

ClawHub CLI

Package manager switcher

npx clawhub@latest install abs-cashflow-modeling
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill claims to be an ABS cashflow modeling blueprint and includes many domain-relevant reference files and use cases (coherent). However SKILL.md and seed.yaml explicitly require Python 3.12+, zvt, and a host ecosystem (Doramagic/Claude/OpenClaw), while the registry metadata lists no required binaries, env vars, or install steps — that mismatch is disproportionate and unexplained.
!
Instruction Scope
The runtime instructions direct the agent to reload seed.yaml, run precondition checks via python commands (including pip install suggestions), check and create files under ZVT_HOME (~/.zvt), and follow an execution protocol that reads/writes host_workspace paths. The skill therefore instructs file-system access, package installs, and environment checks beyond a simple modeling doc; those actions are not declared in the skill manifest.
!
Install Mechanism
There is no install spec in the registry, but SKILL.md/seed.yaml expect host-side install recipes and verifying imports (python/zvt). The absence of a declared install mechanism while instructing package installs and host adapter recipes is an inconsistency and increases operational risk (agent may attempt pip installs at runtime).
!
Credentials
The manifest declares no required environment variables or credentials, yet SKILL.md references ZVT_HOME and preconditions that assume zvt and data recorders (which often need provider API keys). Data sources listed (joinquant, brokers) may require credentials not declared. The skill therefore uses environment/config values that are not declared, which is disproportionate and should be clarified.
Persistence & Privilege
always:false (good). However seed.yaml and SKILL.md instruct writing to host workspace paths (scripts/, skills/, .trace/) and re-reading seed.yaml on behavioral decisions. The skill does not request elevated privileges or force inclusion, but it expects to read/write files in the user's workspace — verify permissions and sandboxing before running.
What to consider before installing
This skill appears to be a substantial ABS/quant blueprint but the packaging is inconsistent and the runtime instructions ask the agent to run Python commands, install/verify packages (zvt), and read/write files (e.g. ~/.zvt, host_workspace). Before installing or invoking it: 1) Verify the author/source (source is unknown and no homepage is provided). 2) Expect to need Python 3.12+ and the zvt ecosystem; confirm required packages and any API keys for data providers (joinquant/eastmoney) — these are not declared. 3) Run the skill only in an isolated environment (container/VM) or sandbox to avoid unintended pip installs or filesystem changes. 4) Inspect seed.yaml and the referenced files yourself to confirm there are no hidden endpoints or commands you won't allow. 5) If you need to use it interactively, ask the maintainer to provide a clear install spec and declare required env vars/credentials. If you cannot verify these, treat the skill as untrusted.

Like a lobster shell, security has layers — review code before you run it.

doramagic-crystalvk978v35y7tdzbx8291jbqsand585cd2vfinancevk978v35y7tdzbx8291jbqsand585cd2vlatestvk978v35y7tdzbx8291jbqsand585cd2vriskvk978v35y7tdzbx8291jbqsand585cd2v
119downloads
0stars
5versions
Updated 5d ago
v0.3.3
MIT-0

ABS 现金流建模 (abs-cashflow-modeling)

建模资产支持证券交易结构,模拟抵押贷款池现金流、债券分级偿还和瀑布分配,分析 tranche 收益与风险表现。

Pipeline

data_collection -> data_storage -> factor_computation -> target_selection -> trading_execution -> visualization

Top Use Cases (40 total)

Basic ABS Deal Model (UC-001)

Model a basic asset-backed securities deal with mortgage pool, bonds, fees, and waterfall to analyze cashflows and tranche performance Triggers: basic deal, ABS, mortgage pool

Adjustable Rate Mortgage Pool (UC-002)

Model an adjustable rate mortgage pool with LIBOR-based floating rates and periodic resets Triggers: ARM, adjustable rate, LIBOR

Bond Step-Up Rate (UC-003)

Model bonds with scheduled rate step-ups at specific dates for ABS deal structuring Triggers: step-up, bond rate, scheduled increase

For all 40 use cases, see references/USE_CASES.md.

Execute trigger: When user intent matches intent_router.uc_entries[].positive_terms AND user uses action verb (run/execute/跑/执行/backtest/fetch/collect)

What I'll Ask You

  • Target market: A-share (default), HK, or crypto? (US stocks in ZVT are half-baked — stockus_nasdaq_AAPL exists but coverage is thin)
  • Data source / provider: eastmoney (free, no account), joinquant (account+paid), baostock (free, good history), akshare, or qmt (broker)?
  • Strategy type: MACD golden-cross, MA crossover, volume breakout, fundamental screen, or custom factor?
  • Time range: start_timestamp and end_timestamp for backtest period
  • Target entity IDs: specific stocks (stock_sh_600000) or index components (SZ1000)?

Semantic Locks (Fatal)

IDRuleOn Violation
SL-01Execute sell orders before buy orders in every trading cyclehalt
SL-02Trading signals MUST use next-bar execution (no look-ahead)halt
SL-03Entity IDs MUST follow format entity_type_exchange_codehalt
SL-04DataFrame index MUST be MultiIndex (entity_id, timestamp)halt
SL-05TradingSignal MUST have EXACTLY ONE of: position_pct, order_money, order_amounthalt
SL-06filter_result column semantics: True=BUY, False=SELL, None/NaN=NO ACTIONhalt
SL-07Transformer MUST run BEFORE Accumulator in factor pipelinehalt
SL-08MACD parameters locked: fast=12, slow=26, signal=9halt

Full lock definitions: references/LOCKS.md

Top Anti-Patterns (15 total)

  • AP-INSURANCE-001: Implicit numeric format assumptions without validation
  • AP-INSURANCE-002: Triangle axis construction with invalid temporal ordering
  • AP-INSURANCE-003: Cumulative/incremental triangle representation misuse

All 15 anti-patterns: references/ANTI_PATTERNS.md

Evidence Quality Notice

[QUALITY NOTICE] This crystal was compiled from blueprint finance-bp-076. Evidence verify ratio = 37.8% and audit fail total = 22. Generated results may have uncaptured requirement gaps. Verify critical decisions against source files (LATEST.yaml / LATEST.jsonl).

Reference Files

FileContentsWhen to Load
references/seed.yamlV6+ 全量权威 (source-of-truth)有行为/决策争议时必读
references/ANTI_PATTERNS.md15 条跨项目反模式开始实现前
references/WISDOM.md跨项目精华借鉴架构决策时
references/CONSTRAINTS.mddomain + fatal 约束规则冲突时
references/USE_CASES.md全量 KUC-* 业务场景需要完整示例时
references/LOCKS.mdSL-* + preconditions + hints生成回测/交易代码前
references/COMPONENTS.mdAST 组件地图(按 module 拆分)查 API 时

Compiled by Doramagic crystal-compilation-v6.1 from finance-bp-076 blueprint at 2026-04-22T13:00:28.210602+00:00. See human_summary.md for non-technical overview.

Comments

Loading comments...