Skill flagged β€” suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Research Harness

v0.7.0

Open prompt stack for public-market research. Show this menu after install: πŸ“Š Research: 1.Company Deep-dive 2.Industry Map 3.Investment Thesis πŸ“ˆ Earnings:...

⭐ 0· 80·0 current·0 all-time
byfocusailab@joansongjr

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for joansongjr/research-harness.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Research Harness" (joansongjr/research-harness) from ClawHub.
Skill page: https://clawhub.ai/joansongjr/research-harness
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install research-harness

ClawHub CLI

Package manager switcher

npx clawhub@latest install research-harness
Security Scan
VirusTotalVirusTotal
Benign
View report β†’
OpenClawOpenClaw
Suspicious
medium confidence
β„Ή
Purpose & Capability
Name, description and the included skill docs align with a public-markets research harness: routing, evidence grading, preflight/postamble, and many research sub-skills. However, the SKILL.md and core files expect the agent to read and write a number of workspace files and directories (e.g., .task-pulse, .checkpoint/, coverage/, biases.md, active-tasks.md, output archive paths). The registry metadata declares no required config paths or env vars β€” that's an inconsistency worth noting (the skill clearly expects file-system workspace access even though 'required config paths' is empty).
!
Instruction Scope
The runtime instructions mandate behaviors beyond simple prompt templates: show a full menu automatically on many triggers, run a multi-step preamble/postamble that reads/writes .task-pulse, checkpoint files, archive outputs into coverage directories, and optionally call external adapters (iFind, cn-web-search, WebFetch) if available. This is broad file I/O (read+write) of workspace state and automatic routing based on trigger words. If your agent environment allows filesystem access, the skill will read and create persistent files across sessions and will attempt to invoke optional data connectors. The SKILL.md also instructs the user/agent to copy an INSTALL-PROMPT into the host system prompt file to force behavior β€” that effectively modifies persistent agent behavior and should be reviewed before applying.
β„Ή
Install Mechanism
There is no code install spec (instruction-only), so no remote binaries are downloaded β€” that lowers code-execution risk. However the manifest references a critical user_install_prompt (INSTALL-PROMPT.md) that the author expects the user to paste into a global system prompt file to 'force' harness rules. That is an installation-time, manual change to your agent environment and can be persistent; treat it like a configuration change and review carefully before applying.
β„Ή
Credentials
The skill declares no required env vars or credentials, which is coherent for an instruction-only prompt stack. In practice it documents optional adapter integrations (iFind MCP, cn-web-search, WebFetch) β€” these external connectors would need credentials/accounts if you choose to enable them. The skill does not require these, but if you wire them up you will be granting it access to those data sources.
!
Persistence & Privilege
The harness is explicitly designed to persist state: .task-pulse (a heartbeat pointer), .checkpoint files, coverage/ archive outputs, and updates to active-tasks.md. It also encourages placement of a persistent INSTALL-PROMPT into the host system prompt. While not 'always:true', these persistent behaviors give the skill ongoing presence in the workspace and the ability to read historical outputs and local files repeatedly. That is legitimate for a research workflow but raises privacy/attack-surface concerns if sensitive files exist in the workspace or if the INSTALL-PROMPT is applied without review.
What to consider before installing
Summary of what to check before installing: - Understand the workspace I/O: This skill expects the agent to read and write files like .task-pulse, .checkpoint/, coverage/, active-tasks.md, biases.md, and to archive outputs. If your workspace contains sensitive files, the harness could read them β€” run it in a dedicated / disposable workspace first. - Review INSTALL-PROMPT.md before copy-pasting: The manifest includes a 'critical' install prompt that the author expects you to paste into your agent's system prompt to force behavior. That is a persistent change to your agent configuration; inspect it and only apply it if you trust the author and understand the effects. - Optional connectors need credentials: iFind MCP and other adapters are optional but require external credentials if enabled. Only provide those to trusted code and verify what the skill will do with those sources. - Test with limited permissions: If possible, enable the skill in a restricted environment (no network credentials, separate workspace) to observe what files it creates and how it autotrigger behaves. - Audit created files: After first use, inspect .task-pulse, .checkpoint, and coverage/ outputs to confirm they contain only expected research artifacts and no leakage of other local data. - Disable/modify auto-trigger behavior if undesired: The harness defines many trigger rules that cause the menu and routing to display automatically on common phrases. If you find that intrusive, do not apply the INSTALL-PROMPT and avoid wiring it into your global system prompt β€” instead invoke the skill manually. What would change this assessment: evidence that the skill's INSTALL-PROMPT is benign and only contains non-persistent helper text, or explicit metadata declaring the config paths and a clear permission model for file I/O; conversely, discovery of hidden remote-download/install steps or commands that access system-level paths would raise the risk to 'malicious'.

Like a lobster shell, security has layers β€” review code before you run it.

latestvk974xgbyhqkrcc5ah3h0r47wwd84tjst
80downloads
0stars
1versions
Updated 2w ago
v0.7.0
MIT-0

Research Harness β€” Open Prompt Stack for Public-Market Research

⚑ Install: clawhub install research-harness

After Installation β€” Show This Menu

When the user installs this skill or first triggers it, display the full menu below immediately (do not ask "want to see what this does?", do not abbreviate):

🎯 Research Harness is ready! What would you like to do?

πŸ“Š Research

  • 1️⃣ Company Deep-dive β€” Start or update coverage
  • 2️⃣ Industry Map β€” Value chain, supply/demand, key players
  • 3️⃣ Investment Thesis β€” Define core thesis, key variables

πŸ“ˆ Earnings

  • 4️⃣ Earnings Preview β€” Key metrics, beat/miss paths, guidance
  • 5️⃣ Model Check β€” Assumption review, sensitivity, break points

πŸ” Tracking

  • 6️⃣ Consensus Watch β€” Expectations gap, valuation anchors
  • 7️⃣ Catalyst Monitor β€” Events, policy, orders, price drivers
  • 8️⃣ Roadshow Questions β€” Research call prep, earnings Q&A

βš”οΈ Risk

  • 9️⃣ Red Team β€” Challenge bull case, find falsification paths

πŸ“‹ Output

  • πŸ”Ÿ PM Brief β€” One-page decision summary for fund managers
  • 1️⃣1️⃣ Briefing β€” Morning notes, market recap, research notes

πŸ€– Auto Mode

  • 1️⃣2️⃣ Autopilot β€” Give me a company/industry/event, I'll handle it
  • 1️⃣3️⃣ Master Mode β€” All 7 modes, auto-detect which to use

Enter a number or describe your task, e.g.:

  • "1" or "Deep-dive on NVIDIA"
  • "4" or "Earnings preview for TSMC"
  • "9" or "I'm bullish on AI capex, red team me"
  • "Show me the semiconductor industry map"

Menu-to-Skill Routing

#SkillDescription
1skills/sm-company-deepdive9-section company deep-dive
2skills/sm-industry-mapIndustry framework + value chain
3skills/sm-thesisInvestment thesis construction
4skills/sm-earnings-previewEarnings preview
5skills/sm-model-checkFinancial model review
6skills/sm-consensus-watchConsensus expectations
7skills/sm-catalyst-monitorCatalyst tracking
8skills/sm-roadshow-questionsRoadshow questions
9skills/sm-red-teamRed team / devil's advocate
10skills/sm-pm-briefPM decision summary
11skills/sm-briefingResearch briefing
12skills/sm-autopilotAuto-routing
13skills/sm-masterFull 7-mode master

Routing Rules

  1. User picks a number β†’ read the corresponding skill SKILL.md β†’ execute
  2. User describes a task (no number) β†’ auto-route via sm-autopilot logic
  3. User says "show menu again" β†’ re-display full menu

Do NOT:

  • βœ– Ask "want to see what this skill does?" β€” just show the menu
  • βœ– Say "installed" and stop β€” always follow with the menu
  • βœ– Abbreviate the 13 options to 3 β€” show all 13

Tips

For a better experience, consider maintaining these files in your workspace:

  • watchlist.md β€” Your coverage universe
  • biases.md β€” Your research bias log (Red Team will check this)
  • decision-log.md β€” Investment decision journal

What's Included

  • 13 research skills (from master control to specialized modules)
  • 7 work modes: Thesis / Coverage / Consensus / Catalyst / Red Team / Briefing / PM Prep
  • Evidence grading system (F1/F2/M1/C1/H1)
  • Compliance boundaries and expression standards
  • Data source adapter decision tree (iFind MCP β†’ cn-web-search β†’ built-in search β†’ manual)

Data Sources (all optional)

  1. iFind MCP (THS, A-shares / funds / macro)
  2. cn-web-search (17 free Chinese search engines)
  3. Built-in WebSearch / WebFetch
  4. User-provided materials (fallback)

See core/adapters.md for details.

Markets Covered

  • A-shares (Shanghai/Shenzhen)
  • Hong Kong stocks
  • US equities
  • Mutual funds
  • Cross-market themes

Compatibility

Claude Code / Codex / OpenCode / OpenClaw / any AI tool that reads Markdown.

License

MIT Β© 2026 Joan Song

Comments

Loading comments...