Ashare Fund Intel
Analysis
The skill is instruction-only and mostly matches its finance-reporting purpose, but it bundles a specific current portfolio and tells the agent to use personal financial context, so users should review it carefully before installing.
Findings (3)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.
Per-fund action tag: `increase` / `hold` / `reduce` ... Simple suggested allocation change range (percentage points)
The skill is designed to produce concrete position-adjustment suggestions. This is disclosed and purpose-aligned, but it can influence real financial decisions.
Checks for exposed credentials, poisoned memory or context, unclear communication boundaries, or sensitive data that could leave the user's control.
# 当前持仓 (由用户提供) ... 1. 南方原油LOF-A: 113.39 ... 总金额: 553.25
The skill package includes a specific current portfolio with fund names and amounts. Because the skill uses this reference for personalization, the bundled data can expose or reuse stale/other-user financial context.
When first used, confirm these and persist in session memory: Risk preference ... Position style ... Watchlist ... Delivery format
The skill asks the agent to retain personal financial preferences and watchlist information in session memory. This is purpose-aligned for personalization but sensitive.
