Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Africa

v1.0.0

提供基于DeepSeek v4的非洲市场政策、法规和投资环境的智能查询与分析,支持多语言和灵活数据源配置。

0· 65·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for yezhaowang888-stack/africa.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Africa" (yezhaowang888-stack/africa) from ClawHub.
Skill page: https://clawhub.ai/yezhaowang888-stack/africa
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install africa

ClawHub CLI

Package manager switcher

npx clawhub@latest install africa
Security Scan
Capability signals
Requires sensitive credentials
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The README and SKILL.md repeatedly state the skill is 'DeepSeek v4-driven' and integrates with 惠迈/three-tier agents and external data sources, but the included code (index.js) contains only local simulated data and no calls to DeepSeek, no network requests, and no declared dependencies. This is an incoherence between advertised capabilities and actual requested/implemented resources.
Instruction Scope
Runtime instructions (SKILL.md) are limited to configuration and installation notes and recommend using environment variables for API keys. The SKILL.md does not instruct the agent to read unrelated files, exfiltrate data, or contact unexpected endpoints. However, it implies behavior (calling external APIs/DeepSeek) that is not present in the code, which is potentially misleading.
Install Mechanism
No install spec is provided (instruction-only skill), and the package includes only small JS files and a package.json with no dependencies. Installation instructions point to clawhub or npm; nothing pulls arbitrary remote blobs or runs opaque installers.
!
Credentials
The package declares no required environment variables, but README and SKILL.md show many example env var names (INVESTMENT_API_KEY, TRADE_API_KEY, etc.) and recommend storing sensitive keys in env. The skill does not actually read these variables in the shipped code. Requesting no credentials while advertising external integrations is inconsistent and could mislead users about required permissions/keys.
Persistence & Privilege
The skill is not always-enabled, does not modify other skills, and does not request system-wide config or privileges. It does not persist credentials or alter agent settings in the provided files.
What to consider before installing
This package appears to be a lightweight/local stub that advertises DeepSeek/惠迈 integration but doesn't implement any network/model calls or require credentials. Before installing or using it in production: 1) verify the package source/author (unknown owner ID); 2) inspect the published npm package contents if you install from a registry to ensure the runtime implementation matches the advertised behavior; 3) if you expect DeepSeek integration, ask the maintainer for the network/API integration code or a changelog describing when that will be added; 4) run the package in a sandboxed environment and review network activity to ensure it doesn't contact unexpected endpoints; and 5) treat any future versions that add network calls or require API keys with extra caution (verify what endpoints are called and why).

Like a lobster shell, security has layers — review code before you run it.

agent-collaborationvk97297esfgnyj8y5kga6vaw6ts85bgyhdeepseek-v4vk97297esfgnyj8y5kga6vaw6ts85bgyhefficiency-revolutionvk97297esfgnyj8y5kga6vaw6ts85bgyhglobal-policyvk97297esfgnyj8y5kga6vaw6ts85bgyhhuimai-agentsvk97297esfgnyj8y5kga6vaw6ts85bgyhlatestvk97297esfgnyj8y5kga6vaw6ts85bgyhmarket-policyvk97297esfgnyj8y5kga6vaw6ts85bgyh
65downloads
0stars
1versions
Updated 5d ago
v1.0.0
MIT-0

非洲市场政策查询Skill

🚀 概述

基于DeepSeek v4的智能政策分析系统,提供非洲市场政策、法规、投资环境的智能查询和分析。

🌟 核心亮点

  • DeepSeek v4驱动:利用最新AI模型进行智能政策分析和预测
  • 惠迈智能体协作:基于惠迈三层智能体架构,确保数据准确性和实时性
  • 多语言支持:支持中文、英文等多种语言
  • 数据源可配置:灵活配置不同数据源,适应各种业务需求

🔧 技术特性

多语言支持

  • 中文(简体)
  • 英文(美国)
  • 自动语言检测和切换

数据源配置

{
  dataSources: {
    investment: '[请替换为您的非洲投资政策数据源]',
    trade: '[请替换为您的非洲贸易法规数据源]',
    // ... 其他数据源
  }
}

📦 安装

# 通过ClawHub安装
clawhub install africa-policy-query

# 或手动安装
npm install africa-policy-query

🔒 安全使用指南

  1. 数据源配置:使用环境变量管理敏感数据源信息
  2. API密钥:不要将真实API密钥写入代码
  3. 权限控制:为数据源配置最小必要权限

支持

如有问题,请提交Issue或联系维护团队。


惠迈智能体:让全球业务变得简单

Comments

Loading comments...