Xqant Fund Research

v1.0.0

面向蚂蚁(支付宝)等下沉互联网渠道的基金投研与营销全链路赋能专家。专注于客观业绩归因、底层持仓逻辑拆解、规模反噬效应分析,并结合蚂蚁用户舆情提供克制、可落地的营销干预方法论。

1· 101·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The name/description (fund research + channel marketing for Ant/Alipay) match the SKILL.md: it instructs the agent to analyze holdings, performance attribution, user sentiment on Alipay/天天基金等 forums, and produce channel-specific marketing interventions. No unrelated binaries, env vars, or installs are requested.
Instruction Scope
Runtime instructions require pulling fund performance and forum舆情 from public sources (天天基金、同花顺、支付宝讨论区, etc.) and to label data sources and dates. This is within the skill's purpose, but the SKILL.md does not specify how to fetch data (APIs vs scraping), nor does it include guidance on privacy, consent, or anonymization when using user-generated content — a practical and compliance gap the user should consider.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, so nothing is written to disk or fetched at install time. That minimizes install-time risk.
Credentials
The skill declares no required environment variables, credentials, or config paths. All requested actions (fetch public fund data and forum sentiment) are consistent with having no special credentials in the manifest.
Persistence & Privilege
always is false, autonomous invocation is allowed (default) and appropriate for an agent skill. The skill does not request persistent system-wide privileges, nor does it modify other skills' configs.
Assessment
This skill appears coherent, but before installing consider: (1) Data sourcing and legality — confirm you have permission to access/scrape Alipay or forum content and that usage complies with site TOS and privacy laws. (2) Attribution and reproducibility — the SKILL.md requires citing data sources and dates; require the skill (or your agent) to record exact API endpoints, timestamps, and any transformations. (3) Compliance for financial/marketing advice — ensure outputs are reviewed by a compliance/legal team to avoid misleading or manipulative messaging. (4) Operational details missing — add explicit API endpoints, authentication needs, rate-limit handling, and anonymization rules to avoid accidental collection of PII. If those gaps are addressed, the skill is consistent with its stated purpose.

Like a lobster shell, security has layers — review code before you run it.

latestvk97e1bf9avtg1f7fz81kk3x0xn83gbn1

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments