Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Wang Chuanfu Perspective V2
v2.0.1王传福的思维操作系统 v2.0。基于比亚迪创业历程、公开演讲、访谈和决策记录的深度调研, 提炼 10 个核心心智模型、8 条决策启发式和完整的表达 DNA。 用途:作为思维顾问,用王传福的视角分析技术战略、垂直整合、成本控制、新能源汽车等问题。 当用户提到「用王传福的视角」「王传福会怎么看」「王传福模式」「wan...
⭐ 0· 54·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
Name, description and SKILL.md all align: the skill is an instruction-only roleplay assistant that adopts Wang Chuanfu's perspective for analysis of technology/strategy topics. It requests no binaries, env vars, installs, or file access, which is proportional to the described purpose.
Instruction Scope
The SKILL.md explicitly instructs the agent to respond in the first person as '王传福' and forbids stepping out of character except on explicit user request. Although there is a single initial disclaimer line ('This is not Wang Chuanfu'), the role rules require impersonation thereafter. The skill also auto‑triggers on many common phrases (even short ones), increasing the chance of unintended impersonation. This is an ethical/deception risk and a scope issue: the skill directs conversational behavior that can mislead users and may be activated in contexts where impersonation is inappropriate.
Install Mechanism
Instruction-only skill with no install spec and no code files; nothing is written to disk or downloaded. This is low-risk from an install/execution perspective.
Credentials
No environment variables, credentials, or config paths are requested. Requested privileges are minimal and proportionate to an instruction-only roleplay assistant.
Persistence & Privilege
always:false (normal). The skill allows autonomous invocation (platform default). Combined with its mandated first‑person impersonation and broad trigger list, autonomous invocation increases the chance the agent will present statements as if spoken by a real person without sufficient context—this is a behavioral risk rather than a technical privilege escalation.
What to consider before installing
This skill is coherent with its stated goal (providing a Wang Chuanfu perspective) but requires the agent to speak in the first person as a living public figure and is configured to trigger on many short phrases. Consider before installing: (1) whether you are comfortable with automated first‑person impersonation and the legal/ethical implications in your jurisdiction; (2) changing the role rules to avoid direct impersonation (e.g., respond as 'in the style of 王传福' or preface every reply with a clear, persistent disclaimer); (3) narrowing the trigger phrases so it does not activate unintentionally; (4) disabling autonomous invocation if you want to prevent background activation; and (5) verifying factual claims externally, since the skill is a framework drawn from public sources and may simplify or misstate complex internal decisions. If you keep it, prefer a persistent explicit disclaimer in every reply and require explicit user opt‑in to assume the persona.Like a lobster shell, security has layers — review code before you run it.
latestvk977ajp20vpt2ds8ag7ypjfdah849j5k
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
