规划虾 Asset Planner

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This prompt-only investment planner has no code or install step, but it asks the agent to retain detailed personal financial history and give precise buy instructions, so privacy and financial-decision risks need review.

Before installing, consider whether you are comfortable uploading financial screenshots and having portfolio details remembered for future comparisons. Redact account numbers and personal identifiers, and do not treat the suggested buys or amounts as professional financial advice.

Publisher note

Pure prompt-based skill. Reads local references/knowledge-base.md only. No network access, no API keys, no binaries. Vision capability uses OpenClaw's built-in image understanding.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If platform memory is available, details about your assets, risk profile, and portfolio changes could be reused later beyond the immediate planning task.

Why it was flagged

This directs the agent to retain sensitive financial profile and portfolio history broadly, but the artifacts do not define retention limits, user consent, deletion, or session-only boundaries.

Skill content
"记住一切":用户的历史配置、风险偏好、持仓变化
Recommendation

Use only with non-sensitive or redacted screenshots unless you are comfortable with persistent financial context; the skill should make memory opt-in, scoped, and deletable.

What this means

Following the generated plan without independent review could lead to unsuitable investments or financial loss.

Why it was flagged

The skill is designed to produce very specific investment actions. That is aligned with its purpose, but users may over-trust the output in a high-stakes financial context.

Skill content
给出具体产品名、基金代码、金额、操作平台;操作步骤要具体到"在哪个App搜什么买多少"
Recommendation

Treat outputs as informational planning help, verify all products and amounts yourself, and consult a qualified professional before acting.