Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Macro Economic Model

v0.3.3

运行ALM资产负债管理模拟,生成组合收益、现金流报告,并通过Smith-Wilson方法校准EIOPA风险自由收益率曲线进行企业债券定价。。

0· 97·0 current·0 all-time
byTang Weigang@tangweigang-jpg

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for tangweigang-jpg/macro-economic-model.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Macro Economic Model" (tangweigang-jpg/macro-economic-model) from ClawHub.
Skill page: https://clawhub.ai/tangweigang-jpg/macro-economic-model
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install macro-economic-model

ClawHub CLI

Package manager switcher

npx clawhub@latest install macro-economic-model
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
Purpose & Capability
The name/description (ALM, EIOPA, bond pricing) are coherent with the SKILL.md contents (data pipelines, curve construction, pricing components). However SKILL.md requires Python 3.12+ and ZVT ecosystem tools (zvt, recorders, data providers), while the registry metadata lists no required binaries/dependencies — a mismatch that should be resolved before trusting automatic execution.
!
Instruction Scope
The runtime instructions direct the agent to run Python checks, run zvt recorder commands, read and re-load seed.yaml, check/touch the user's ZVT_HOME directory, and integrate with external data providers (eastmoney, joinquant, qmt). These operations access the host filesystem and may trigger network activity and package installs (pip). That scope is broader than the registry declares and includes actions (filesystem writes, pip installs, network calls to data/broker APIs) that warrant explicit user consent and further vetting.
Install Mechanism
This is instruction-only (no install spec, no code files executed by the skill itself). That limits what the skill bundle writes to disk. Nevertheless the SKILL.md expects host-side installs (Python packages like zvt) to be present or installed by the user/agent; because installs would be performed by executing host commands, they should be reviewed before running.
!
Credentials
Registry declares no required environment variables or credentials, but SKILL.md and references use ZVT_HOME, recommend data providers that typically require API keys/accounts (joinquant, qmt), and instruct precondition checks that read environment variables and touch ~/.zvt. The missing declaration of these env vars/credentials (and absence of any explanation of which credentials are needed for trading/broker actions) is disproportionate and unclear.
Persistence & Privilege
The skill does not request permanent/always-on presence (always: false) and does not declare modifications to other skills or global agent settings. Autonomous invocation is enabled by default (disable-model-invocation: false) which is normal; combine this with the above inconsistencies before allowing autonomous runs.
What to consider before installing
Before installing or running this skill: (1) Treat it as an instruction-only recipe that expects Python 3.12+ and the ZVT ecosystem (zvt, recorders); the registry did not declare these requirements — confirm and install them in a controlled environment. (2) Review seed.yaml and the referenced files locally — the SKILL.md instructs the agent to read and re-load them and to run Python commands that may install packages or touch ~/.zvt. (3) Expect network access to data providers (eastmoney, joinquant, akshare, qmt) and potential need for API credentials; do not provide sensitive broker/API keys until you confirm exactly which endpoints the skill will call. (4) Because the bundle references a LICENSE.txt that is not present and declares proprietary licensing, verify licensing and provenance before trusting outputs. (5) If you will run this on a machine with real credentials or broker access, run it first in an isolated VM/container or sandbox, and avoid enabling autonomous invocation until you have validated the skill's behavior manually.

Like a lobster shell, security has layers — review code before you run it.

doramagic-crystalvk97c06zgbn71rmqm7w5q58tar185dkwjfinancevk97c06zgbn71rmqm7w5q58tar185dkwjinsurancevk97c06zgbn71rmqm7w5q58tar185dkwjlatestvk97c06zgbn71rmqm7w5q58tar185dkwjportfoliovk97c06zgbn71rmqm7w5q58tar185dkwjriskvk97c06zgbn71rmqm7w5q58tar185dkwj
97downloads
0stars
3versions
Updated 4d ago
v0.3.3
MIT-0

宏观经济模型 (macro-economic-model)

运行ALM资产负债管理模拟,生成组合收益、现金流报告,并通过Smith-Wilson方法校准EIOPA风险自由收益率曲线进行企业债券定价。

Pipeline

data_collection -> data_storage -> factor_computation -> target_selection -> trading_execution -> visualization

Top Use Cases (13 total)

ALM Portfolio Summary Report Generator (UC-101)

Running a comprehensive Asset-Liability Management (ALM) simulation and visualizing portfolio returns, cash flows, and EIOPA yield curves for a mixed Triggers: ALM simulation, portfolio summary, yield curve visualization

ALM Cash Flow Visualization Dashboard (UC-111)

Creating visual summaries of ALM simulation results including dividend, coupon, liability cash flows, notional returns, and terminal cash flows over t Triggers: cash flow charts, portfolio visualization, ALM reporting

EIOPA Risk-Free Curve Projection and Calibration (UC-102)

Projecting forward interest rates and calibrating the EIOPA risk-free yield curve for long-term insurance liability discounting using Smith-Wilson met Triggers: EIOPA curve, forward rate projection, yield curve calibration

For all 13 use cases, see references/USE_CASES.md.

Execute trigger: When user intent matches intent_router.uc_entries[].positive_terms AND user uses action verb (run/execute/跑/执行/backtest/fetch/collect)

What I'll Ask You

  • Target market: A-share (default), HK, or crypto? (US stocks in ZVT are half-baked — stockus_nasdaq_AAPL exists but coverage is thin)
  • Data source / provider: eastmoney (free, no account), joinquant (account+paid), baostock (free, good history), akshare, or qmt (broker)?
  • Strategy type: MACD golden-cross, MA crossover, volume breakout, fundamental screen, or custom factor?
  • Time range: start_timestamp and end_timestamp for backtest period
  • Target entity IDs: specific stocks (stock_sh_600000) or index components (SZ1000)?

Semantic Locks (Fatal)

IDRuleOn Violation
SL-01Execute sell orders before buy orders in every trading cyclehalt
SL-02Trading signals MUST use next-bar execution (no look-ahead)halt
SL-03Entity IDs MUST follow format entity_type_exchange_codehalt
SL-04DataFrame index MUST be MultiIndex (entity_id, timestamp)halt
SL-05TradingSignal MUST have EXACTLY ONE of: position_pct, order_money, order_amounthalt
SL-06filter_result column semantics: True=BUY, False=SELL, None/NaN=NO ACTIONhalt
SL-07Transformer MUST run BEFORE Accumulator in factor pipelinehalt
SL-08MACD parameters locked: fast=12, slow=26, signal=9halt

Full lock definitions: references/LOCKS.md

Top Anti-Patterns (14 total)

  • AP-MACRO-DATA-001: SEC EDGAR Rate Limit Violation
  • AP-MACRO-DATA-002: Temporal Knowledge Graph Look-Ahead Bias
  • AP-MACRO-DATA-003: Technical Indicator Look-Ahead Bias via Missing Shift

All 14 anti-patterns: references/ANTI_PATTERNS.md

Evidence Quality Notice

[QUALITY NOTICE] This crystal was compiled from blueprint finance-bp-077. Evidence verify ratio = 42.6% and audit fail total = 34. Generated results may have uncaptured requirement gaps. Verify critical decisions against source files (LATEST.yaml / LATEST.jsonl).

Reference Files

FileContentsWhen to Load
references/seed.yamlV6+ 全量权威 (source-of-truth)有行为/决策争议时必读
references/ANTI_PATTERNS.md14 条跨项目反模式开始实现前
references/WISDOM.md跨项目精华借鉴架构决策时
references/CONSTRAINTS.mddomain + fatal 约束规则冲突时
references/USE_CASES.md全量 KUC-* 业务场景需要完整示例时
references/LOCKS.mdSL-* + preconditions + hints生成回测/交易代码前
references/COMPONENTS.mdAST 组件地图(按 module 拆分)查 API 时

Compiled by Doramagic crystal-compilation-v6.1 from finance-bp-077 blueprint at 2026-04-22T13:00:28.955724+00:00. See human_summary.md for non-technical overview.

Comments

Loading comments...