Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Strategic Mentality

v1.2.0

Apply battle-tested business mentality frameworks from Sun Tzu (Art of War), Alex Hormozi ($100M Leads), The 12 Week Year, and Dan Kennedy (No BS Direct Resp...

1· 102·0 current·0 all-time
byNex AI@nexaiguy

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for nexaiguy/strategic-mentality.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Strategic Mentality" (nexaiguy/strategic-mentality) from ClawHub.
Skill page: https://clawhub.ai/nexaiguy/strategic-mentality
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install strategic-mentality

ClawHub CLI

Package manager switcher

npx clawhub@latest install strategic-mentality
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill claims to be a strategy/mentality framework (benign for advice). However, its instructions (HEARTBEAT.md and references) expect the agent to send scheduled Telegram messages, store trend data, run scrapers, query PageSpeed/social activity, and optionally use Resend/Calendly/Qwen Vision — none of which are declared in requires.env or install specs. Either the platform is expected to provide connectors (not documented), or the skill assumes access to external services that a user must authorize. This is an incoherence between purpose and the external capabilities the skill expects.
!
Instruction Scope
SKILL.md and HEARTBEAT.md explicitly instruct the agent to: (a) schedule weekly Telegram pings and monthly check-ins; (b) store weekly scores and trend history; (c) run reconnaissance (website checks, PageSpeed, social activity), and (d) optionally auto-load Nex AI-specific context which references internal endpoints and infrastructure. Those are operational actions beyond pure text advice and may cause network activity, data collection, or outbound messages. The instructions do not specify where credentials, chat IDs, or storage reside, and they grant broad discretion for scraping and automated outreach logic.
Install Mechanism
No install spec and no code files — the skill is instruction-only. That lowers disk/write risk: nothing will be downloaded or executed by an installer. The primary runtime surface is the agent following prose instructions.
!
Credentials
The skill requests no environment variables, yet references multiple services that normally require credentials (Telegram bots, Resend API, Calendly, Qwen Vision, Google/Maps scraping). The 'Nex AI Context' file contains private/internal endpoints and lists infrastructure (ports, domains, bots). Asking the agent to access those resources without declaring required env vars or explaining authorization is disproportionate and ambiguous — it could lead the agent to attempt to use platform-level credentials or hit internal endpoints unexpectedly.
Persistence & Privilege
HEARTBEAT.md configures recurring behavior (weekly Telegram pings, trend storage, execution alerts). 'always' is false and there's no install, so the platform would need to run a scheduler or the agent must be permitted to create persistent tasks. This persistent outbound communication capability is not inherently malicious but requires explicit user consent and clear configuration of where messages go and where data is stored.
What to consider before installing
This skill is mostly a set of well-structured business frameworks and templates, but it expects the agent to perform scheduled messaging, scraping, and use external services without declaring how it will obtain credentials or where it will store data. Before installing or enabling: - Confirm how Telegram pings are authorized: which bot/token and chat ID will be used, and that you explicitly consent to scheduled messages. - Ask where weekly scores and trend data will be stored (agent memory, platform DB, your account storage) and who can access them. - If you are not part of 'Nex AI', treat the Nex AI context as potentially environment-specific: it references internal endpoints, ports, and bots. Do not expose private network or credentials to this skill unless you control that environment. - If you want the automation (heartbeat, scrapers, email sequences), require the skill (or platform) to declare which environment variables or connectors it will use (Telegram_TOKEN, RESEND_API_KEY, etc.) and review those integrations separately. - If you only want advice/templates, restrict the skill from performing network actions or automated outreach until you've validated connectors and consent. Given the mismatch between instructions and declared requirements, proceed only after clarifying the above; otherwise treat the skill as text-only guidance and disable any automated outbound features.

Like a lobster shell, security has layers — review code before you run it.

latestvk971fy5nn8v7n5ew6trefnfz55849na4
102downloads
1stars
3versions
Updated 3w ago
v1.2.0
MIT-0

Strategic Mentality System

Apply decision frameworks from four master sources to real business problems. No philosophy quotes, no motivational fluff. Actionable heuristics, concrete next actions, structured output.

Available Mentalities

Read the relevant reference file in references/ before applying any framework.

MentalityFileUse WhenCore Question
SUN_TZUreferences/sun-tzu.mdCompetition, positioning, market entry, timing, resource allocation"How do I win without wasting resources?"
HORMOZIreferences/hormozi.mdLead generation, offers, pricing, advertising, scaling, outreach"How do I get more strangers to want to buy my stuff?"
TWELVE_WEEKreferences/twelve-week.mdSprint planning, accountability, execution scoring, time blocking"Am I executing on what matters this week?"
DAN_KENNEDYreferences/dan-kennedy.mdSales psychology, urgency, direct response, closing reluctant buyers"How do I get them off the fence right now?"

Specialized Modules

ModuleFileUse When
Lead Scoringreferences/lead-scoring.mdEvaluate any lead with a 0-100 mentality-weighted score
Sales Callreferences/sales-call.mdHandle objections during sales calls, especially with SME owners
Nex AI Contextreferences/nex-ai-context.mdAuto-load when running in Nex AI's OpenClaw instance for calibrated recommendations

Weekly Accountability

The HEARTBEAT.md file configures a scheduled Sunday evening ping via Telegram with a 12 Week Year scorecard prompt. The agent asks the user to fill in their weekly score, reviews the trend, and flags if execution is slipping below 65%.

How to Apply

Step 1: Map the Problem

Problem TypePrimarySupport
Should I pursue this lead/client?HORMOZISUN_TZU
How do I beat competitor X?SUN_TZUHORMOZI
I'm not making progressTWELVE_WEEKSUN_TZU
What should I build/sell next?HORMOZITWELVE_WEEK
How do I plan my next quarter?TWELVE_WEEKHORMOZI
Should I pivot or stay the course?SUN_TZUTWELVE_WEEK
How do I price this?HORMOZISUN_TZU
I'm spread too thinTWELVE_WEEKSUN_TZU
How do I outreach effectively?HORMOZIDAN_KENNEDY
Score this leadLead Scoring moduleAll mentalities
Handle sales objectionSales Call moduleDAN_KENNEDY
Close this dealDAN_KENNEDYHORMOZI
Follow up strategyDAN_KENNEDYTWELVE_WEEK

Step 2: Load the Reference File

Read the matching references/*.md file. Each contains core principles, if-then heuristics, diagnostic questions, and an output template.

Step 3: Run Diagnostics

Ask the diagnostic questions from the loaded mentality to map the user's specific situation.

Step 4: Apply Heuristics and Output

Run the situation through the if-then heuristics. Output:

  1. Situation Assessment - 2-3 sentences mapping problem to framework
  2. Framework Verdict - what the mentality says to do
  3. Concrete Actions - specific next steps with measurable targets
  4. Risk - what could go wrong

Step 5: Combine When Needed

For complex decisions, apply the PRIMARY mentality first, then layer the SUPPORT mentality as a constraint or amplifier. Flag any contradictions explicitly.

Comments

Loading comments...