Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

gold-radar

v1.0.0

Real-time gold price monitoring and investment decision support system. Use when users ask about gold prices, gold investment analysis, market trends for pre...

0· 104·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for quiteqiang/gold-radar.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "gold-radar" (quiteqiang/gold-radar) from ClawHub.
Skill page: https://clawhub.ai/quiteqiang/gold-radar
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install gold-radar

ClawHub CLI

Package manager switcher

npx clawhub@latest install gold-radar
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The name/description match the stated purpose (gold monitoring and investment support). However, the skill's workflows refer to real-time data feeds, executing trading decisions, and a local config.json for user profile/watchlist, yet the package declares no required environment variables, no config paths, and there is no config.json in the file manifest. Real-time monitoring and automated trading would normally require API keys, broker credentials, or at least a documented integration; their absence is inconsistent with the claimed functionality.
!
Instruction Scope
SKILL.md explicitly instructs the agent to 'Check config.json' and to 'execute trading decisions' on certain alerts. It also references fetching or prioritizing multiple external data sources (Bloomberg/TradingView/SGE/Twitter) but provides no concrete endpoints, auth requirements, or limits. The instructions are vague in places (e.g., 'execute trading decisions') and direct the agent to access a local config that is not declared or supplied — scope creep and an unclear runtime surface.
Install Mechanism
There is no install specification (instruction-only), which is low-risk. However, repository files include package.json and a large package-lock.json listing dependencies (notably 'clawhub'), despite no install instructions or code files. This is inconsistent: either the skill was intended to include runnable code or the package files are leftover. The presence of a package-lock implies Node packages could be required if the author intended code to run, but no install mechanism is provided.
!
Credentials
The skill declares no required environment variables or primary credential, yet its workflows imply access to live market feeds and the ability to place trades/notifications. Those operations normally require credentials (market data APIs, broker APIs, notification/webhook endpoints). The lack of declared secrets or config paths is disproportionate to the claimed automated capabilities and increases the chance the agent will (a) attempt unsupported actions or (b) ask the user for sensitive credentials ad hoc.
Persistence & Privilege
The skill is not set to always: true and is user-invocable with normal autonomous invocation allowed. There is no install spec writing persistent components or modifying other skills. From a persistence/privilege standpoint this is standard and not elevated.
What to consider before installing
This skill's text promises real-time monitoring and even automated trading, but the package contains no runnable code or install instructions and there is no config.json or declared API/broker credentials. Before installing or enabling it: 1) Ask the publisher for the source/homepage and a clear integration plan (which APIs/brokers, required env vars, where config.json should live). 2) Do not provide broker API keys or other secrets until you confirm how and where they will be stored and used. 3) If you only want analysis (not execution), require the skill to be read-only and explicitly disable any autonomous trade execution. 4) If you plan to rely on real-time data, insist on documented, auditable data endpoints and credentials rather than ad-hoc web-scraping or asking you to paste tokens. 5) Consider declining installation until the author removes the ambiguity around executing trades, supplies the missing config, or provides a verifiable code package and homepage. If you need help formulating questions to ask the author, I can draft them.

Like a lobster shell, security has layers — review code before you run it.

latestvk9778dw7dp7qd8vfgvc0qfm3md83gwte
104downloads
0stars
1versions
Updated 1mo ago
v1.0.0
MIT-0

Gold Intelligence Monitor

Real-time gold price monitoring and investment alert system.

When to Use This Skill

This skill should be triggered when the user:

  • Asks about current gold prices or XAU/USD rates
  • Wants gold investment analysis or trading advice
  • Requests market briefings or price alerts
  • Mentions gold-related economic indicators (Fed rates, USD, inflation)
  • Needs help tracking their gold portfolio or positions

Quick Start

  1. Check config.json for user profile (currency, timezone, watchlist)
  2. Use the workflow below based on user request type

Workflows

Daily Briefing

When user asks for "daily briefing", "market update", or "what's happening with gold today":

Generate market briefing:
1. Get price trends for the past 24 hours
2. Check US Dollar Index movement
3. Review Fed officials' speeches/economic data releases
4. Provide position holding advice and risk management

Output format:

📋 Gold Market Briefing - {Date}

🎯 Market Overview:
{Summary}

💰 Price Quotes:
| Instrument | Price | Change | Key Level |
|------------|-------|--------|-----------|
| {Name} | {Price} | {Change} | {Key Level} |

📊 Technical Analysis:
- Support: {levels}
- Resistance: {levels}
- Trend: {Direction}

📅 Economic Calendar:
- {Time}: {Event} (Impact: {High/Medium/Low})

💡 Investment Recommendations:
- Holding Cost: {cost}
- Current P&L: {P&L}
- Recommended Action: {recommendation}

⚠️ Risk Warning: {level}
{Risk Description}

Price Alert

When user asks for "alert me when...", "notify me if...", or mentions price targets:

Alert Levels:

LevelTrigger ConditionsResponse
🔴 RedPrice breaks target profit/stop-loss levels, daily movement >8%, major geopolitical conflictsImmediate notification, execute trading decisions
🟡 YellowPrice breaks key round numbers, technical divergence, Fed officials' speechesPrepare to trade, closely monitor
🟢 GreenNormal price fluctuations, routine market monitoringRegular briefings

Alert output format:

🚨 [Alert Level] {Alert Type}

💰 Instrument: {Gold Type}
📈 Current Price: {Price} ({Change})
🎯 Key Level: {Breakout Level}

⚡ Recommended Actions:
1. {Action 1}
2. {Action 2}
3. {Action 3}

📊 Market Analysis:
{Brief Analysis}

🔗 Influencing Factors:
- US Dollar Index: {DXY}
- Treasury Yield: {US10Y}
- Major Events: {event}

Weekly Analysis

When user asks for "weekly outlook", "this week", or "Monday analysis":

Generate weekly outlook:
1. Review last week's gold price performance
2. This week's economic calendar (Fed meetings, NFP, etc.)
3. Technical analysis (trends, key support/resistance)
4. Next week's trading strategy recommendations

Buy/Sell Signal Check

When user asks "should I buy?", "sell now?", or "is it a good time to invest":

Buy Signals:

  • Federal Reserve rate cut expectations rise
  • Geopolitical risks escalate
  • Technical breakout (breaks consolidation range)

Sell Signals:

  • Federal Reserve rate hike expectations rise
  • Technical breakdown (breaks support level)
  • Position reaches expected profit (take profit)

Data Sources Priority

  1. Official: Shanghai Gold Exchange (SGE), World Gold Council (WGC)
  2. Market: Bloomberg/Reuters, TradingView, Kitco
  3. Macro: Federal Reserve, Non-farm payroll, CPI/PPI
  4. Sentiment: X/Twitter posts, geopolitical news, central bank reports

Configuration

Edit config.json to customize:

  • Holding cost and target price levels
  • Alert thresholds (price change percentage)
  • Gold instruments to monitor (spot, futures, ETFs)
  • Local timezone and currency

Disclaimer

This system is for reference only and does not constitute investment advice. Gold investment involves risks; invest with caution.

Comments

Loading comments...