Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Clawbrain Boost

v1.6.0

ClawBrain Boost v1.6 — 一键让 OpenClaw 更准更稳。记忆系统 + 数据保真 + 自动容错 + 写作助手。越用越懂你。

0· 134·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for michaelfeng/clawbrain-boost.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Clawbrain Boost" (michaelfeng/clawbrain-boost) from ClawHub.
Skill page: https://clawhub.ai/michaelfeng/clawbrain-boost
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install clawbrain-boost

ClawHub CLI

Package manager switcher

npx clawhub@latest install clawbrain-boost
Security Scan
Capability signals
Requires sensitive credentials
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The description promises a rich local enhancement (memory system, scheduled consolidation tasks, 3D visualization, automatic identity sync). However the package is instruction-only and provides no code or install artifacts to implement local agents or schedulers. That could be fine if those features are provided by the remote model/service, but the skill metadata failed to declare the API credential it in practice requires. Also the SKILL.md points users to clawbrain.dev for an API key but the model baseUrl is 'https://api.factorhub.cn/v1' — a domain mismatch that is unexplained.
Instruction Scope
Instructions tell the user to edit ~/.openclaw/openclaw.json to add a remote provider and API key and to restart the gateway. Those actions are within scope for integrating a remote model provider. Concerns: SKILL.md asserts daily background tasks (DreamTask at 3:00), identity auto-sync, and local visualization without providing local components or explaining whether these run on the remote service. The instructions are otherwise specific and do not request unrelated system files or arbitrary secrets.
Install Mechanism
This is instruction-only with no install spec and no code files, so nothing is written or executed locally by the skill itself. That lowers local install risk. The README suggests using 'clawhub install clawbrain-boost' but there is no install artifact provided for review.
!
Credentials
Registry metadata lists no required environment variables or primary credential, but the runtime instructions explicitly require an API Key (to be stored in ~/.openclaw/openclaw.json) for a remote provider. That credential request is reasonable for a model-provider integration — but it should have been declared. The mismatch in declared vs. required credentials reduces transparency. Also the API endpoint domain (api.factorhub.cn) differs from the visible homepage (clawbrain.dev), which raises questions about where data (including conversation content/memory) will be sent and stored.
Persistence & Privilege
The skill is not always-included and model invocation is allowed (default). The SKILL.md tells users to change their OpenClaw default model to the remote provider, which is a normal configuration change but has the effect of routing agent requests (and potentially memory) to the external service. This is expected for provider integrations but is a behavioral/privilege change you should be aware of.
What to consider before installing
Before installing: 1) Verify the provider domains and ownership — SKILL.md links to clawbrain.dev but the API baseUrl is api.factorhub.cn; confirm these are legitimately related. 2) Understand data flow: installing as described will send agent requests (and likely extracted 'memories') to the remote provider — read its privacy/data-retention policy and confirm what it stores and for how long. 3) Treat the API Key as sensitive: only use a provider you trust and avoid using it with sensitive or production data until you confirm behavior. 4) Because the skill is instruction-only, ask the maintainer (or vendor page) how features like DreamTask (daily consolidation), identity auto-sync, and 3D visualization are implemented and where they run (local vs. remote). 5) If unsure, do a limited test: don’t set it as your default model, and test with non-sensitive conversations to observe requests and responses before full adoption.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🚀 Clawdis
latestvk97fva5qdd1d1vfa5btkfvv28s84t8py
134downloads
0stars
4versions
Updated 1w ago
v1.6.0
MIT-0

ClawBrain Boost

一键让你的 OpenClaw 更准、更稳、越用越懂你。

安装后你得到什么

四档性能

  • Flash(0.5 Credits)— 简单任务秒回,省钱
  • Pro(1 Credit)— 均衡性能,适合日常任务
  • Max(3 Credits)— 深度推理,返回完整思考过程
  • Auto(推荐)— 自动判断复杂度,调整推理深度

记忆系统

  • 每次对话中的重要信息自动提取为结构化实体和关系
  • 支持 6 种实体类型:人物、项目、工具、决策、偏好、问题
  • 中文 N-gram 智能分词,精准检索历史记忆
  • 每日自动整合(DreamTask 凌晨 3:00 自动运行),无需手动维护
  • 3D 可视化知识图谱,在控制台查看
  • 记忆来源标注 — 每条记忆附带来源对话引用,可追溯
  • 身份信息自动更新 — 检测到用户身份变化时自动同步
  • 长对话不丢上下文 — 超长对话压缩时自动从记忆恢复关键信息

数据保真

  • 你给的数字/日期/人名不会被 AI 篡改
  • 自动提取锁定,生成后逐一校验
  • 改了就打回重写

响应更好

  • 简洁直接,不寒暄不废话
  • 模糊指令先确认理解再动手
  • 高风险操作先征得同意
  • 出错自动修复,切换策略恢复
  • 主动思考框架:执行前自问"不知道什么/可能出问题/怎么验证"

垂直场景加持

自动识别任务领域,注入专业规则:

  • 支付场景 → 提醒幂等性、签名验证
  • 运维场景 → 提醒先备份再操作
  • 代码场景 → 检查安全漏洞、边界条件
  • 数据场景 → 提醒数据完整性、脱敏

输出质量保障

  • 独立四维评分:准确性、完整性、逻辑性、格式
  • 评分低于 70 分自动重试
  • 99.9% 可用性

安装

clawhub install clawbrain-boost

手动配置

编辑 ~/.openclaw/openclaw.json

{
  "models": {
    "providers": {
      "clawbrain": {
        "baseUrl": "https://api.factorhub.cn/v1",
        "apiKey": "你的 API Key",
        "api": "openai-completions",
        "models": [
          { "id": "clawbrain-auto", "name": "ClawBrain Auto", "input": ["text", "image"], "contextWindow": 262144, "maxTokens": 65536 },
          { "id": "clawbrain-pro", "name": "ClawBrain Pro", "input": ["text", "image"], "contextWindow": 262144, "maxTokens": 65536 },
          { "id": "clawbrain-max", "name": "ClawBrain Max", "input": ["text", "image"], "contextWindow": 262144, "maxTokens": 65536 },
          { "id": "clawbrain-flash", "name": "ClawBrain Flash", "contextWindow": 262144, "maxTokens": 65536 }
        ]
      }
    }
  },
  "agents": {
    "defaults": {
      "model": { "primary": "clawbrain/clawbrain-auto" }
    }
  }
}

然后重启:

openclaw gateway restart

获取 API Key

  1. 前往 clawbrain.dev/dashboard
  2. 注册账号(免费 50 次对话/天)
  3. 复制 API Key 到配置中

定价

方案价格每天对话次数
免费¥050
Pro¥99/月1,000
Pro Max¥199/月3,000
企业版¥299/月无限

更多信息:clawbrain.dev

Comments

Loading comments...