Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

市场盘前概览简报

v1.0.3

交易日开盘前(8:00-9:25)生成A股市场全景简报,整合市场结构、资金热度、风格轮动、板块强弱等信息,帮助把握当日投资主线。触发词:盘前简报、盘前分析、今日市场、开盘前瞻、市场主线、今日热点。适用场景:交易日开盘前快速了解市场全貌、投资决策参考、识别当日主线方向。不适用场景:非交易日、盘中实时分析、个股深度研究。

0· 126·0 current·0 all-time
by三水清@ksky521

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for ksky521/xiapi-premarket-briefing.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "市场盘前概览简报" (ksky521/xiapi-premarket-briefing) from ClawHub.
Skill page: https://clawhub.ai/ksky521/xiapi-premarket-briefing
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install xiapi-premarket-briefing

ClawHub CLI

Package manager switcher

npx clawhub@latest install xiapi-premarket-briefing
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The name/description (A股盘前简报) align with the actions described: fetching market metrics and composing a structured report. However, the skill's runtime explicitly requires using the daxiapi CLI (npx daxiapi-cli@latest) and an API token, while the registry lists no required environment variables or primary credential. The token requirement is proportional to the stated purpose but is not declared in metadata, creating an inconsistency.
!
Instruction Scope
SKILL.md instructs the agent/operator to run multiple npx daxiapi-cli commands and to configure a persistent token (via CLI config or by setting DAXIAPI_TOKEN / shell rc). The instructions reference and write a local config path (~/.daxiapi/config.json) and recommend adding environment variables to shell startup files—actions that read/write user config and environment state beyond what the registry declares. The commands themselves stay within the stated data domain (market APIs) and do not exfiltrate to unrelated endpoints, but they do grant the CLI persistent access to the user's token.
Install Mechanism
The skill is instruction-only (no install spec), but runtime uses npx daxiapi-cli@latest which dynamically downloads and executes an npm package. npx/remote npm execution is moderate-risk: it fetches code from the public registry at runtime and executes it locally. The skill does not provide verification of the CLI package source or a pinned version, increasing risk if the npm package or its maintainer were compromised.
!
Credentials
Functionally, an API token is reasonable for calling daxiapi APIs. However the registry declares no required env vars/credentials while the SKILL.md and references instruct storing and using an API token (DAXIAPI_TOKEN and ~/.daxiapi/config.json). This mismatch (undeclared but required credential and config path) is a proportionality/visibility problem: the skill will ask for secrets and persist them but that critical requirement is not surfaced in the metadata.
Persistence & Privilege
The skill does not set always:true and does not ask to modify other skills. It does instruct persistent storage of a token (CLI config file and/or adding export to shell rc), making the token persist on the host. Persisting API credentials is expected for a client CLI but is an important security consideration: the token will remain on disk/environment and could be used by other processes if compromised.
What to consider before installing
What to consider before installing/using this skill: - The skill's runtime requires a daxiapi API token and instructs using npx daxiapi-cli@latest; the registry metadata does not declare this credential—expect to provide and persist a token. - npx will download and run code from the npm registry each time; verify the daxiapi-cli package origin and prefer pinned versions or review its source before executing (check npm page and upstream GitHub repository). Avoid running unknown 'latest' packages on sensitive machines. - The token may be saved to ~/.daxiapi/config.json or added to your shell rc (persistent). If you proceed, create a dedicated, least-privileged token/account, do not reuse high-privilege credentials, and avoid storing secrets in shared accounts or repos. - Consider running the CLI in an isolated environment (container, VM) or limiting network access, and inspect the CLI's configuration file after first use to confirm only expected data is stored. - If you need metadata to match runtime requirements (recommended), ask the publisher to update the registry to declare the required credential (DAXIAPI_TOKEN) and to document/pin the CLI package source/version. Confidence note: I am confident this skill is internally inconsistent (undeclared but required token; use of npx), so exercise caution. Additional information that would change the assessment: a declared required-env field listing the token, a pinned CLI package URL/version, or hosting/publisher provenance (official daxiapi.com package repository) would reduce concern.

Like a lobster shell, security has layers — review code before you run it.

latestvk977b8vxsd7d5s2e60364ykdxh84q80k
126downloads
0stars
4versions
Updated 2w ago
v1.0.3
MIT-0

A 股盘前简报 Skill

交易日开盘前全方位分析A股市场,帮助把握当日投资主线。

Overview(功能概述)

在交易日开盘前(8:00-9:25),通过大虾皮 CLI 获取市场结构、成交额、风格轮动、板块热度、涨跌停等多维度数据,生成结构化盘前简报,帮助投资者快速了解市场全貌并把握当日主线。

When to Use(何时使用)

  • 交易日开盘前快速了解市场全貌
  • 获取当日投资主线和热点方向
  • 判断当日市场偏向(多/空/震荡)

触发词:盘前简报、盘前分析、今日市场、开盘前瞻、市场主线、今日热点、盘前消息、开盘前分析

When Not to Use(何时不使用)

  • 非交易日(周末、节假日)
  • 盘中实时分析
  • 个股深度研究或财务分析
  • 需要精确买卖点判断

Process(执行流程)

Step 0: 前期准备

Token 已配置则跳过此步骤。

npx daxiapi-cli@latest config get token
# 未配置则执行:
npx daxiapi-cli@latest config set token YOUR_TOKEN

Step 1: 并行获取数据

以下命令全部执行,获取完整盘前数据:

# 1. 市场结构(趋势/估值/情绪三维)
npx daxiapi-cli@latest market compass

# 2. 成交额(与昨日对比)
npx daxiapi-cli@latest turnover

# 3. 大小盘风格
npx daxiapi-cli@latest market style

# 4. 板块热力图(CS强度排名)
npx daxiapi-cli@latest sector heatmap

# 5. 涨跌停池
npx daxiapi-cli@latest zdt

# 6. 概念板块热榜
npx daxiapi-cli@latest hotrank concept

# 7. 行业板块热榜
npx daxiapi-cli@latest hotrank board

数据时效说明:以上数据均为前一交易日收盘后更新,盘前查询的是昨日收盘数据。恐贪指数在交易日晚9点后更新,盘前可能为空,属正常情况。


Step 2: 分析数据

维度一:市场结构分析(market compass)

直接调用 xiapi-market-compass skill 对 compass 数据进行分析,获得趋势结构、估值、情绪三层综合判断。重点关注:

  • 趋势温度(60日):判断中期趋势强弱
  • 恐贪指数:判断短期情绪极端值(0-10极度恐惧,90-100极度贪婪)
  • CS中位数:判断全市场动量状态(负值表示多数股票在均线下方)
  • CS离散度:值越大说明板块分化越严重

维度二:成交额(turnover)

关注两个核心字段:当前成交额绝对值(2万亿以上为活跃市场),以及较昨日变化方向(放量/缩量)。

维度三:大小盘风格(market style)

读取「当前风格」和「历史百分位」字段,判断今日资金偏向大盘还是小盘。详细解读方法参考 xiapi-style-rotation skill。

维度四:板块强弱(sector heatmap)

重点看 CS 强度排名靠前的板块(今日 cs_gt_5_names 字段),以及昨日强势板块今日是否延续(↑/↓箭头)。

维度五:市场活跃度(zdt)

  • 涨停数量 > 50:市场活跃,题材有赚钱效应
  • 涨停数量 < 20:市场低迷,谨慎操作
  • 连板股数量:判断题材持续性,连板越多说明游资越活跃

维度六:热点主线(hotrank concept + hotrank board)

概念热榜和行业热榜结合板块热力图,交叉验证当日主线方向。热榜靠前且 CS 强度也高的板块,是当日最强主线。


Step 3: 生成报告

严格按照下方「Report Template」的六章节结构输出,不得改变章节顺序和标题措辞。核心结论放在最前,每个章节必须有具体数值支撑,不得空泛描述。

Report Template(报告模板)

严格按照以下格式输出,不得增减章节,不得改变标题措辞。方括号 [...] 为占位说明,输出时替换为真实内容。


A股盘前简报 · [YYYY-MM-DD]

数据截至前一交易日收盘,盘前参考使用。

核心结论:[一句话总结,格式:市场偏向 + 最强主线 + 关键风险。例:"市场偏震荡,通信设备/光纤主线延续,成交额缩量需关注持续性。"]


一、市场结构

[基于 compass 数据,用 2-3 句话描述当前市场状态。必须包含以下三个指标的具体数值和判断:]

  • 趋势温度(60日):[数值,如 25.61],[判断:<30 偏弱 / 30-60 中性 / >60 偏强]
  • 恐贪指数:[数值,如 44.48],[判断:<20 恐惧 / 20-80 中性 / >80 贪婪;若为 0 则注明"数据未更新,参考前一交易日 [YYYY-MM-DD] 的数据:XX"]
  • CS中位数:[数值,如 -1.26],[判断:负值表示多数股票在均线下方,正值反之]

综合判断:[一句话,例:"趋势偏弱但情绪中性,市场处于震荡修复阶段。"]


二、成交额

[前一交易日,YYYY-MM-DD] 全市场成交额 [X 万亿],较前日[增加/减少] [X 亿]([+/-X%])。

[一句话活跃度判断,例:"成交额连续两日缩量,市场观望情绪较重,需警惕量能不足导致的反弹夭折。"]

参考基准:2万亿以上为活跃,1.5万亿以下为低迷。


三、大小盘风格

当前风格:[均衡偏大盘 / 均衡偏小盘 / 明显偏大盘 / 明显偏小盘](历史 P[N]

大小盘波动差值(中证2000 - 沪深300,30日累计):[X%]

[一句话解读,例:"差值处于历史低位(P28),大盘相对占优,但尚未到极端区间,风格切换信号不强。"]


四、今日主线

[根据热榜排名 + CS强度 + 涨停数量三重交叉验证,列出 2-3 条主线。每条主线必须有数据支撑,不得仅凭热榜排名判断。]

主线一:[板块名] 热榜排名第 [N],涨跌幅 [X%],[N] 家涨停。[一句话逻辑,例:"光纤概念热榜第1,CS强度持续为正,汇源通信5连板领涨,通信设备主线延续性强。"]

主线二:[板块名] 热榜排名第 [N],涨跌幅 [X%],[N] 家涨停。[一句话逻辑。]

主线三:[板块名](可选,若无明确第三主线则删除此条) 热榜排名第 [N],涨跌幅 [X%],[N] 家涨停。[一句话逻辑。]


五、市场活跃度

昨日涨停 [N] 只,跌停 [N] 只,炸板 [N] 只,炸板率 [X%]

[一句话活跃度判断,例:"涨停53只,炸板率23%,市场赚钱效应中等,题材持续性一般,需关注连板股表现。"]

连板股情况:[列出2-3只代表性连板股,格式:股票名(N连板),例:"汇源通信(5连板)、益佰制药(6天3板)、柏诚股份(6天3板)"]


六、风险提示

[结合当日具体数据,列出 2-3 条实质性风险,不得使用套话。每条风险需有数据支撑。例:]

  1. [具体风险1,例:"成交额较前日缩量3033亿,若明日继续缩量则反弹动能不足。"]
  2. [具体风险2,例:"趋势温度(60日)仅25.61,中期趋势偏弱,反弹高度有限。"]
  3. [具体风险3(可选),例:"炸板率偏高,题材持续性存疑,追高需谨慎。"]

数据来源:大虾皮(daxiapi.com) · AI 分析生成 · 仅供参考,不构成投资建议,投资有风险,入市需谨慎。

Quality Checks(质量检查)

必须验证

  • 报告标题含日期,核心结论在正文第一行
  • 六个章节完整,顺序和标题与模板一致
  • 一、市场结构:包含趋势温度、恐贪指数、CS中位数三个具体数值
  • 二、成交额:包含绝对值(万亿)和变化量(亿)两个维度
  • 三、大小盘风格:包含差值数值和历史百分位(P[N])
  • 四、今日主线:每条主线有热榜排名 + 涨跌幅 + 涨停数量三项数据
  • 五、市场活跃度:包含涨停/跌停/炸板数量和炸板率,以及连板股列举
  • 六、风险提示:每条风险有具体数据支撑,非套话
  • 末尾包含免责声明

危险信号

  • 🔴 使用"一定涨"、"必然"等绝对化表述
  • 🔴 主线判断只有热榜没有 CS 强度支撑(热榜可能滞后)
  • 🔴 恐贪指数为0时当作"极度恐惧"解读(实为数据未更新)
  • 🔴 缺少免责声明

Common Pitfalls(常见陷阱)

  • 热榜 ≠ 强势:热榜反映的是讨论热度,不等于 CS 强度。需要两者交叉验证,热榜靠前但 CS 为负的板块要谨慎。
  • 恐贪指数为0:盘前查询时恐贪指数可能为0,这是数据未更新,不是极度恐惧信号,应使用前一日数据。
  • 成交额缩量不等于看空:缩量震荡是正常现象,需结合趋势温度综合判断。
  • 涨停数量看绝对值:不同市场环境下基准不同,需结合近期均值判断高低。

Gotchas(避坑)

  • 401 认证失败:执行 npx daxiapi-cli@latest config get token 检查;若为空,重新配置 token。
  • 空数据返回:通常为非交易日或数据尚未更新,建议收盘后17:00以后查询。
  • 429 频率超限:等待30-60秒后重试。
  • zdt 命令:默认返回涨停池,查跌停用 npx daxiapi-cli@latest zdt --type dt,查炸板用 --type zb

References

Comments

Loading comments...