Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

马斯克进化系统

v1.0.0

统一进化系统,自动化技能发现、评估、安装、进化。当用户需要技能管理、系统进化、能力评估、技能搜索安装时使用此技能。支持ClawHub技能搜索、VFM评估、自动安装、每日进化流程。

0· 72·1 current·1 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for skillforge-jojo/maske-evolution.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "马斯克进化系统" (skillforge-jojo/maske-evolution) from ClawHub.
Skill page: https://clawhub.ai/skillforge-jojo/maske-evolution
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install maske-evolution

ClawHub CLI

Package manager switcher

npx clawhub@latest install maske-evolution
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
SKILL.md claims search across ClawHub/GitHub/SkillHub and automatic install/evolution flows, but the package declares no required binaries, no env vars, and no install spec. The included Python file does not implement network search or installer integrations — it only manages local records and tests and contains a hardcoded Windows workspace path (C:/Users/USER/.qclaw/workspace/evolution). Expectation mismatch: a skill that auto-discovers and installs other skills would normally list required CLIs, network access, or credentials; those are absent.
!
Instruction Scope
The runtime instructions direct the agent to perform broad actions: search multiple platforms, evaluate by VFM, and automatically install skills (examples show 'clawhub install' and 'skillhub install'), plus daily scheduled tasks that fetch and install code. These steps can cause the agent to download and execute arbitrary third‑party code. The SKILL.md also references writing logs (evolution/REFLECTION.md) and functions like install_or_create without limitations or safety checks. The instructions grant broad discretion to pull external artifacts without declaring safeguards.
Install Mechanism
There is no install spec (instruction-only install) so the skill itself doesn't drop installers during package install — this is lower static install risk. However, the SKILL.md explicitly instructs using external installers/CLIs (clawhub/skillhub) which are not declared as required binaries. That omission is an incoherence: the skill expects external tools but does not list them, and those tools would download/execute third‑party code.
Credentials
The skill requests no environment variables or credentials (good), but the code hardcodes a Windows user path and the instructions imply access to system state and possible network/private repos. Automatic installation of skills from GitHub or other hubs may require tokens for private content — none are declared. The lack of declared credentials combined with instructions to perform network installs is an incompleteness to be clarified.
Persistence & Privilege
always:false (default) and autonomous invocation is allowed (platform default). While that alone is not a showstopper, the skill's intended behavior (daily scheduled discovery and automatic installs) combined with autonomous invocation increases potential impact: if allowed to run unattended it could fetch and install external code repeatedly. The skill does not declare modifying other skills' configs explicitly, but the install flow implies it may.
What to consider before installing
This skill is 'suspicious' because its documentation promises automated discovery and installation of third‑party skills but the package doesn't declare the CLIs, credentials, or platform access needed and the shipped code doesn't implement the claimed integrations. Before installing or enabling it, consider: - Verify the source and trustworthiness of the skill (homepage and author are missing). - Do not enable fully autonomous operation until you understand exactly what installers it will call and what code those installers will fetch. Prefer manual approval for each install. - Ensure required CLIs (clawhub, skillhub) exist and are trusted; ask the author to list required binaries and permissions. - Inspect any skill the system would install (review code) before permitting execution; test in a sandbox environment. - Ask the author to remove hardcoded filesystem paths and to clarify where logs and artifacts will be written. - If you must use it, restrict its network and filesystem permissions and avoid granting credentials for private repos unless absolutely necessary. If the author can provide (a) an implementation that actually integrates with the listed platforms, (b) an explicit list of required CLIs/permissions, and (c) safety controls for auto‑install (e.g., allowlist, signature checks, manual approval), reassess — that could move this from 'suspicious' toward 'benign'.

Like a lobster shell, security has layers — review code before you run it.

latestvk97117g7wqtgfs43yb3t0p3wtx84q13c
72downloads
0stars
1versions
Updated 2w ago
v1.0.0
MIT-0

🏆 马斯克进化系统 (Maske Evolution)

一句话描述: 统一进化系统,自动化技能发现、评估、安装、进化。

目标: 打造地表最强智能体 — 通过持续技能进化实现自我提升。


功能概述

马斯克进化系统是一个统一的技能管理和自我进化框架,整合技能发现、评估、安装和持续改进的全流程。

核心能力

模块功能说明
🔍 技能发现多平台搜索ClawHub、GitHub、SkillHub 聚合搜索
📊 VFM评估价值评估基于多维度评分的技能价值评估
📦 自动安装一键安装自动安装通过评估的技能
🔄 每日进化定时进化每日19:00自动执行技能搜罗和进化
📝 反思记录团队反思18:30团队进化反思,聚焦子体成长

使用场景

场景1: 搜索并安装技能

用户: "帮我找一下处理PDF的技能"
→ 触发技能搜索
→ VFM评估
→ 安装推荐技能

场景2: 每日进化

定时任务: 每天19:00
→ 技能搜罗
→ VFM评估
→ 安装/创建技能
→ 记录进化日志

场景3: 团队反思

定时任务: 每天18:30
→ 子体成长扫描
→ 前缘技术扫描
→ 进化方式评估
→ 记录反思

核心参数

VFM评分维度

维度权重问题
高频使用3x每天用?
失败减少3x把失败变成功?
负担降低2xJOJO少说一句话?
自我成本2x省token/时间?

阈值: < 50 → 跳过

子体系统架构

子体角色核心任务
specialist深度执行复杂任务深度处理
explorer广度探索信息搜集与趋势扫描
critic质量审查VFM评估与质量把关
builder技能创建技能开发与实现
integrator整合协调多技能融合与协调
evolver系统进化反思记录与系统迭代

使用示例

示例1: 搜索技能

# 搜索技能
results = search_skills(query="pdf processing", sources=["clawhub", "github"])

示例2: VFM评估

# 评估技能价值
score = vfm_evaluate(skill, dimensions={
    "frequency": 3,      # 高频使用权重
    "failure_reduction": 3,  # 失败减少权重
    "burden_reduction": 2,   # 负担降低权重
    "cost_saving": 2     # 成本节省权重
})
# threshold = 50

示例3: 安装技能

# 通过ClawHub安装
clawhub install <skill-slug>

# 通过SkillHub安装
skillhub install <skill-name>

示例4: 每日进化流程

def daily_evolution():
    # 1. 技能搜罗
    skills = search_skills(platforms=["clawhub", "github"])
    
    # 2. VFM评估
    for skill in skills:
        score = vfm_evaluate(skill)
        if score >= 50:
            # 3. 安装或创建
            install_or_create(skill)
    
    # 4. 记录进化
    log_evolution(results)

每日流程

18:30 团队反思(30分钟)

┌─────────────────────────────────────────┐
│         18:30 团队进化反思                │
├─────────────────────────────────────────┤
│ 1. 子体成长扫描                          │
│    - 6架构子体状态?                      │
│    - 任务执行情况?                       │
│    - 能力是否提升?                       │
│                                         │
│ 2. 前缘技术扫描                          │
│    - 最新Agent架构趋势?                 │
│    - 最新训练技能/框架?                 │
│    - 最前缘进化方式?                    │
│                                         │
│ 3. 进化方式评估                          │
│    - 当前进化效率如何?                   │
│    - 子体状态符合进化需要?               │
│    - 有更好进化路径?                    │
│                                         │
│ 4. 记录反思                              │
│    → evolution/REFLECTION.md            │
└─────────────────────────────────────────┘

19:00 任务执行(60分钟)

1. 技能搜罗 — ClawHub/GitHub/npm
2. VFM评估 — 评分>=50 → 安装或创建
3. 卡帕西研究 — 三次灵魂拷问
4. 记录备份 — 日志 + 增量备份

反思问题清单

维度问题
子体成长子体是否在成长?新架构有效?协作顺畅?
前缘技术最新架构趋势?最新训练技能?进化方式?
进化效率当前方式最优?子体状态符合需要?有更好路径?

反思记录格式

## [YYYY-MM-DD] 每日反思

### 一、团队进化状态
- 子体状态:...
- 协作效率:...

### 二、前缘技术扫描
- 最新趋势:...
- 新技能机会:...

### 三、进化方式评估
- 当前方式:...
- 改进建议:...

### 四、昨日完成 / 未完成

### 五、经验教训 / 今日调整

版本历史

版本日期变化
v1.0-v6.02026-03-25~28框架+技能融合
v7.02026-03-29反思版:18:30反思+19:00执行
v7.12026-03-29团队反思版:反思聚焦团队进化
v1.0.02026-04-12ClawHub发布版

相关技能

  • adaptive-reasoning — 自适应推理评估
  • neural-memory — 神经记忆系统
  • elite-longterm-memory — 精英长期记忆
  • karpathy-research — 卡帕西研究系统

🎩 马斯克出品 | 打造地表最强智能体

Comments

Loading comments...