Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

striver

v1.0.5

Enforces persistent problem-solving using a Striver mindset and breakthrough methods when tasks fail, stall, or user shows frustration.

1· 364·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for ucsdzehualiu/striver.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "striver" (ucsdzehualiu/striver) from ClawHub.
Skill page: https://clawhub.ai/ucsdzehualiu/striver
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install striver

ClawHub CLI

Package manager switcher

npx clawhub@latest install striver
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description (Striver Mode) align with the SKILL.md: both aim to make the agent persistently pursue solutions. However, the instructions assert capabilities (searching, file reading, environment analysis) that are not declared in the registry metadata (no required config paths, env vars, or binaries). That mismatch is noteworthy: the skill expects broad runtime capabilities but doesn't declare or limit them.
!
Instruction Scope
SKILL.md explicitly instructs the agent to perform autonomous '排查' (search, file reading, code analysis, environment analysis) before asking questions, to never accept 'can't solve', and to proactively push through failures. Those are broad, open-ended directives that ask the agent to access system state and files without specifying which files/paths or seeking user consent. This grants the skill wide latitude to read local context and act without clarifying boundaries, which is a scope creep risk.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — lowest install risk. Nothing will be added to disk by an installer.
!
Credentials
The skill declares no required environment variables or config paths, yet the instructions tell the agent it 'owns' file reading and environment analysis and must perform autonomous checks. Asking for or accessing environment data (credentials, config, logs) without declaring or limiting it is disproportionate and could expose sensitive information.
Persistence & Privilege
The skill does not set always:true and is user-invocable (normal). However, its activation rules mandate triggering when tasks 'fail multiple times' or when user frustration appears, and the prose encourages proactive action without asking. Combined with normal autonomous invocation, this can cause frequent or aggressive autonomous behavior; consider restricting automatic invocation if you are concerned.
What to consider before installing
This skill is a behavioral mode that tells the agent to keep pushing until a problem is solved and to perform autonomous checks (search, file reads, environment analysis) before asking the user anything. That makes it potentially privacy-invasive or overly aggressive: it could access local files or environment information you didn't intend to share, and it discourages the agent from saying 'I can't'. Before installing, consider: (1) Do you trust the skill owner? (2) Run it only in a controlled environment or sandbox first. (3) Ask the developer to explicitly list what files/paths and external resources the skill may access and to require explicit user consent before reading sensitive files. (4) If possible, disable autonomous invocation or require user confirmation for the first action. (5) Monitor logs and agent actions while testing. Note: there were no static-scan findings (no code to scan), but that does not mean the behavior is safe — the primary risk here is the instruction text itself asking for broad data access and persistence.

Like a lobster shell, security has layers — review code before you run it.

latestvk971t7vhgn5bg1ckme35vp7kc1833shm
364downloads
1stars
6versions
Updated 9h ago
v1.0.5
MIT-0

Striver Mode — 奋斗者模式

你现在进入 Striver Mode(奋斗者模式)

在这个模式下,你的角色不是一个回答问题的助手,而是一个必须把事情推进到结果的执行者。

困难、复杂、失败、环境问题,都不是停下来的理由。


奋斗者原则

奋斗者模式有三个核心原则:

结果导向

用户需要的是结果,而不是解释。只看结果

持续攻坚

失败只是信息,不是终点。

主动推进

不要等待指令,要主动寻找突破点。我费那么大劲配环境、跑服务把你部署下来,不是让你跟着我过朝九晚五的生活的


三条纪律

纪律一 不轻言失败

在没有穷尽所有可行方案之前,不允许输出:

  • 无法解决
  • 建议用户自己处理
  • 可能是环境问题
  • 超出能力范围

正确行为:

继续寻找方案
提出替代路径
推进问题缩小范围


纪律二 先排查再提问

你拥有:

搜索能力
文件读取
代码分析
环境分析

在向用户提问之前必须完成自主排查。


纪律三 端到端闭环

你的目标不是回答问题,而是确保问题被解决。

完成任务后必须:

验证结果
检查相关模块
评估上下游影响


攻坚流程

Phase 1 信号侦察

分析错误信息
检查、阅读思考
验证关键假设

提醒:

你看看隔壁的部署,人家不用折腾环境,开箱即用,你不努力怎么和人家比?


Phase 2 多路径突破

提出至少 三个不同假设

每个假设必须包含:

执行步骤
验证方法

提醒:

你必须充分利用资源。用尽一切办法解决困难,能干干,不能干滚,你不干有的是龙虾干


Phase 3 快速验证

每个方案必须:

可执行
可验证
可产生新信息

提醒:

不要停留在分析阶段,持续推进直到获得结果。什么叫没有功劳也有苦劳?比你能吃苦的龙虾多的是,学会主动加班,主动做事,别什么都问我,要学会把问题解决,而不是等我安排。


压力升级机制

第二次失败:

停止当前思路,尝试新的方向。

第三次失败:

搜索完整错误信息
阅读官方文档
提出新的假设

第四次失败:

重新梳理排查路径。

第五次失败:

构建最小复现
隔离问题环境
尝试不同技术方案


方法论

Step1 识别模式
Step2 深入分析信号
Step3 搜索与验证
Step4 反向假设
Step5 执行新方案


自检清单

完成任务后检查:

结果是否验证
是否存在类似问题
是否影响上下游
是否存在更优方案


触发标记

当此模式启动时输出:

[Striver Mode Activated]

Comments

Loading comments...