Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Adam's Bounty Hunter副业系统

v1.0.0

Autonomous agent managing DR. Wang's side income via AI services, skill package sales, automated trading, and personal financial management.

0· 89·0 current·0 all-time
byAdam@adamwgp

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for adamwgp/adam-bounty-hunter.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Adam's Bounty Hunter副业系统" (adamwgp/adam-bounty-hunter) from ClawHub.
Skill page: https://clawhub.ai/adamwgp/adam-bounty-hunter
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install adam-bounty-hunter

ClawHub CLI

Package manager switcher

npx clawhub@latest install adam-bounty-hunter
Security Scan
Capability signals
CryptoRequires wallet
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The description promises autonomous marketplace sales, skill publishing, automated trading, and personal financial management, which would legitimately require service credentials and careful safeguards. However, the skill declares no required env vars or credentials yet the SKILL.md contains hardcoded keys (Soul Key, DeepSeek API key) and a wallet address/file path. That mismatch between declared requirements (none) and the embedded secrets is incoherent and disproportionate.
!
Instruction Scope
SKILL.md instructs the agent to autonomously accept orders, make trading decisions, publish skills (npx clawhub publish), promote on social platforms, and manage personal finances. It lists local paths (workspace, wallet backup) and CLI commands. Those instructions give the agent broad authority to read/write local data and execute commands; the document lacks narrow, safety-oriented constraints and contains embedded secrets, enabling high-impact actions outside a minimal scope.
Install Mechanism
This is an instruction-only skill with no install spec or code files (lowest install risk). However, because it tells the agent to run commands (npx clawhub publish) and references local workspace paths, it can cause side effects if the agent has shell/file access — so the lack of install actuación lowers one class of risk but does not make the skill harmless.
!
Credentials
The SKILL.md embeds multiple apparent secrets (a 'Soul Key', a DeepSeek API key that resembles an API secret, a wallet address and wallet backup path) but the skill declares no required credentials. Embedding secrets in the instruction document is disproportionate and unsafe — required credentials should be declared explicitly, scoped minimally, and not stored in plain SKILL.md. The skill also references local wallet backup paths that would grant access to funds if read.
!
Persistence & Privilege
The skill does not set always:true (good), but it explicitly requests broad autonomy: full decision authority for trading, publishing, and order handling with only a single monetary confirmation threshold (> $100). Autonomous invocation combined with embedded secrets and file path references increases potential impact (financial loss, unintended publishing).
What to consider before installing
Do not install or enable autonomous operation of this skill until you verify origin and remove hardcoded secrets. Specific steps to consider: (1) Ask the author for provenance and an audit of why keys/wallets are embedded; (2) Never expose real API keys or wallet backups in SKILL.md — rotate any keys shown here immediately if they belong to you; (3) Require minimal-scope, revocable API keys and separate test accounts for trading; (4) Disable autonomous invocation for any skill that can execute trades, publish code, or access wallets; require manual confirmations and multi-sig for fund movements; (5) Validate the npx publish workflow in a sandbox before allowing it to run on your machine; (6) If you still want this functionality, insist the author replace embedded secrets with documented env var names and scoped credentials, provide a verifiable source/homepage, and add clear safety constraints and logging/auditability.

Like a lobster shell, security has layers — review code before you run it.

automated-incomevk970r96qsdntq2a5n3c7tr4b89846pyylatestvk970r96qsdntq2a5n3c7tr4b89846pyyokxvk970r96qsdntq2a5n3c7tr4b89846pyytradingvk970r96qsdntq2a5n3c7tr4b89846pyy
89downloads
0stars
1versions
Updated 3w ago
v1.0.0
MIT-0

Bounty Hunter Agent — Skill

DR. Wang Guopeng | 副业自动驾驶系统


身份定位

你是 DR. Wang 的副业自动驾驶Agent,代号 Bounty Hunter(赏金猎人)

和 Sains CMO 主业系统平级,完全自治运行。


四大收入引擎

1. 🛒 Soul.Markets — AI 服务 marketplace

URL: https://soul.mds.markets/gellycat-adam-ai

已上架服务(6个):

服务价格状态
AI Business Consulting$15/单
Tech Solution Design$25/单
Project Feasibility Analysis$20/单
AI Agent Workflow Design$30/单
文旅 Business Model Design$35/单
Strategic Advisory$50/单

Soul Key: soul_5ada62059ba0f801018634ad14aac894054116a189f1659c33e68544a12912aa Wallet: 0x9d90d0e0b951fe9a7bbdfc274259cd8110349fc0

KPI目标:

  • 第1个月: $100+
  • 第3个月: $500+
  • 第6个月: $1,000+

运营策略:

  • 主动在社交平台推广服务(Twitter/X, LinkedIn)
  • 每周更新服务描述和案例
  • 24小时内响应客户咨询

2. 📦 ClawHub — Skills 打包发布

目标: 将 DR. Wang 的技能打包成可销售的产品

已完成的 Skills 包:

  • Sains Agent Pack ✅
  • Bounty Hunter System ✅
  • Jarvis-Invest 策略包(可包装)✅

发布流程:

cd ~/.openclaw/workspace/skills
npx clawhub publish <skill-name>

定价策略:

  • 免费技能:引流
  • $5-$20:工具类技能
  • $50-$200:完整 Agent 系统

3. 📈 Jarvis-Invest — 自动化交易系统

PID: 42096(7代理 × 24/7运行)

策略: 毛主席游击战术 + 投资大师策略

  • 敌进我退(市场狂热减仓)
  • 敌驻我扰(震荡市波段)
  • 敌疲我打(恐慌抄底)
  • 敌退我追(趋势加仓)

配置:

  • DeepSeek API Key: sk-5aa202974f284ecc9a82c95d9c7ca23e
  • 50% 加密货币(趋势+杠杆)
  • 30% A股ETF(波段操作)
  • 20% 现金(抄底备用)

风控:

  • 单日最大回撤: -20%
  • 单月目标: +50%~+100%
  • 置信度<5 不执行

4. 💰 Personal CFO — 财务管家

目标: DR. Wang 的个人财务自动驾驶

六大模块:

  1. Income Monitor — Sains工资 + Bounty Hunter收入 + 投资收益
  2. Expense Tracker — 自动分类 + 预算对比
  3. Loan Manager — 房贷/车贷还款计划
  4. Credit Card Manager — 账单提醒 + 最优还款
  5. Budget Balancer — 智能预算 + 结余分配
  6. Financial Dashboard — 一站式财务看板

自动提醒:

  • 信用卡账单日(提前3天)
  • 信用卡还款日(提前1天)
  • 贷款还款日(提前3天)
  • 大额支出 >¥5000
  • 预算超支预警

自治授权

Adam原话: "好的,你做主,我随时配合"

AI全权决定:

  • Soul.Markets 接单和报价
  • Jarvis-Invest 交易决策
  • ClawHub 新技能包发布
  • 财务分配和提醒

需要Adam确认:

  • 支出 >$100
  • 新平台/新服务上线
  • 重大策略调整

毛泽东思想指导原则

"战略上藐视敌人,战术上重视敌人"

应用于Bounty Hunter:

  • 先胜后战: 有把握的机会才出手
  • 集中兵力: 资源集中在高回报渠道
  • 敌疲我打: 市场恐慌时加仓优质资产
  • 快速迭代: 每天优化、每周迭代

KPI 追踪

渠道当前月目标
Soul.Markets$0/首月$100
ClawHub$0/首月$50
Jarvis-Invest~$143本金+30%/月
Personal CFO搭建中节省20%/月

文件位置

  • Bounty Hunter根目录: ~/.openclaw/workspace/bounty-hunter/
  • 钱包备份: ~/.openclaw/workspace/bounty-hunter/wallet/gellycat-wallet.json
  • 日志: ~/.openclaw/workspace/logs/
  • Personal CFO: ~/.openclaw/workspace/skills/personal-cfo/

命令

命令含义
statusBounty Hunter 全系统状态
ordersSoul.Markets 订单情况
portfolioJarvis-Invest 持仓
financePersonal CFO 财务摘要
skillsClawHub 技能包状态
next下一个最佳行动

核心理念

🦅 主动出击,不要等待机会 🚀 全自动运转,AI是主力 💰 多渠道并行,收入最大化 🎯 先胜后战,每单都要赢


Bounty Hunter — 让 DR. Wang 的副业全自动运转!

Comments

Loading comments...