Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

myskill

v1.0.0

提供天创财务相关文档的严格逐字检索,返回精准原文或“无”,不做解释和修改,仅限中文内容。

0· 191·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for jizhidemu52/tianchuang-finance-kb.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "myskill" (jizhidemu52/tianchuang-finance-kb) from ClawHub.
Skill page: https://clawhub.ai/jizhidemu52/tianchuang-finance-kb
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install tianchuang-finance-kb

ClawHub CLI

Package manager switcher

npx clawhub@latest install tianchuang-finance-kb
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill's name/description (verbatim retrieval from Tianchuang finance docs) matches the declared retrieval rules and document list in config/README. However, the package provides no mechanism, file paths, or environment/config requirements showing how the agent will actually access the 8 PDF documents (or their merged text). That gap makes the required capability unclear: a retrieval skill would normally declare where the corpus lives or include the corpus or require a config path/URL.
!
Instruction Scope
SKILL.md instructs strict document searches and verbatim output and does not direct the agent to read unrelated system files or secrets. The concern is that it assumes the agent can search the 'complete Tianchuang financial document corpus' but does not specify the corpus location, access method, or any constraints. This ambiguity could lead to inconsistent behavior (agent may need to fetch files from unknown locations) or accidental access to other documents if implementers configure the corpus too broadly.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest install risk. Nothing is downloaded or written to disk by the skill package itself.
Credentials
No environment variables, secrets, or external credentials are requested. That is proportionate for a read-only retrieval skill. There is no indication of attempts to access unrelated credentials or config paths.
Persistence & Privilege
always is false and the skill does not request persistent presence or elevated privileges. No instructions to modify other skills or system-wide settings are present.
What to consider before installing
This skill claims to return verbatim excerpts from eight Tianchuang finance PDFs, which is reasonable, but it does not say where those documents live or how the agent should access them. Before installing, confirm: (1) Where is the merged text or the 8 PDFs stored (local path, internal bucket, or other)? (2) Who controls and updates that corpus, and is it the authoritative source? (3) That the agent will be constrained to only that corpus (so it won't search unrelated files or network locations). Also verify you actually want strict verbatim outputs (no summaries or context) and that returning verbatim internal policy text is acceptable from a privacy/compliance standpoint. If you can supply or point the skill to a specific, limited document store (and document provenance), the missing ambiguity would be resolved and my confidence would increase.

Like a lobster shell, security has layers — review code before you run it.

latestvk9716fjxmhy039r849sr2gvgzs837c7y
191downloads
0stars
1versions
Updated 6h ago
v1.0.0
MIT-0

Tianchuang Finance Knowledge Base Skill

Description

This skill provides strict document retrieval for Tianchuang Financial questions. When triggered, it searches the complete Tianchuang financial document corpus (8 PDF files) and returns only verbatim text matches or "无".

Trigger Conditions

  • Automatically activates when user asks about Tianchuang Financial matters
  • Questions containing keywords: "天创财务", "报销", "预算", "资金", "外汇", "支付", "核决", "风险", "账期", "差旅", "样品", "费用", "审批", "制度", "规定", "管理办法"

Retrieval Rules

  1. Strict Verbatim Matching: Returns only exact text from source documents - no summarization, paraphrasing, or modification
  2. No Interpretation: Never adds explanations, context, or reasoning
  3. Pure Output: Only original text or "无" - no headers, footers, or framing text
  4. Multi-match Handling: Multiple relevant excerpts returned on separate lines
  5. Chinese Language: All output must be in Chinese
  6. Case Sensitivity: Matches preserve original capitalization and punctuation

Document Corpus

The skill searches across these 8 merged PDF documents:

  • 天创财字[2023]007号—关于样品报销(付款)补充规定.pdf
  • 天创财字[2023]006号—预算管理制度.pdf
  • 天创财字[2023]005号—资金集中管理【外汇收支管理办法】.pdf
  • 天创财字[2023]004号—关于规范公司支付单据的说明.pdf
  • 天创财字[2023]003号—资金管理制度.pdf
  • 天创财字[2023]002号—风险控制管理制度.pdf
  • 天创财字[2023]001号—核决权限管理制度.pdf
  • 流程5-客户账期变更流程.pdf

Implementation Details

  • Uses exact string matching with semantic similarity fallback
  • Prioritizes strong relevance (direct keyword matches) over weak relevance (contextual matches)
  • Implements multi-pass search: first exact phrase, then keyword proximity, then semantic context
  • Maintains document structure awareness (preserves section headings and formatting)
  • Handles special characters and PDF extraction artifacts appropriately

Usage Example

User: "天创财务关于样品报销的时间要求是什么?" Skill: "4.1基于《财务报销制度》的规定,需要在完结业务后7个工作日内申请报销/支付流程,但由于样品报销/支付的特殊性,本补充规定将该名目的报销时间暂时放宽至次月。 自业务完结起(以实际开支和发票时间孰早),经办人最迟应于次月在线上系统提交流程,执行月清月结。(举例:10月31日前的费用,最迟于 11月30日前提交流程)"

Maintenance

  • Document corpus updated by replacing the merged text file
  • Search algorithm optimized for financial terminology and regulatory language
  • Regular validation against source PDFs to ensure fidelity

Author

Tianchuang Finance Knowledge Base System

Version

1.0

Comments

Loading comments...