安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
This package mainly contains local analysis and a Markdown report generator — no network calls or credentials are requested, which is good. However: (1) SKILL.md claims a pdf_exporter and other docs/templates that are missing — ask the publisher for the missing files or an updated package before using. (2) The skill will process sensitive personal financial data; confirm how reports are stored, whether anything is sent to external services, and where PDF export (if present) writes files. (3) Ver...详细分析 ▾
ℹ 用途与能力
The name/description match the included analyzer and report generator: both compute scores and produce a Markdown report. However SKILL.md and the documented file tree refer to a pdf_exporter.py, docs, and templates that are not present in the package; the README also emphasizes PDF export and funneling users to paid services, but the shipped code only generates Markdown and inlines marketing/contact links. This mismatch (claimed PDF export + missing file) is an inconsistency.
ℹ 指令范围
Runtime instructions and code operate only on provided financial data and generate reports; there are no commands to read unrelated files, environment variables, or make network calls. Still, SKILL.md's marketing/monetization steps (collecting emails, funneling to paid products) are described but not implemented in code, and the skill does not state how it will handle/retain sensitive user financial data — a privacy scope gap.
✓ 安装机制
No install spec (instruction-only) and the Python source is included. Nothing is downloaded or executed outside the local code, so install mechanism risk is low.
✓ 凭证需求
The skill requests no environment variables, credentials, or config paths. That is proportionate to the declared functionality. Note: because the skill processes sensitive financial inputs, the absence of any declared telemetry/storage settings is notable — there is no code here that exfiltrates data, but the packaging lacks a data-handling/privacy statement.
✓ 持久化与权限
always:false and no code that modifies other skills or system settings. The skill does not request persistent privileges or autonomous always-on behavior.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.12026/3/29
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install finance-report-pro
镜像加速npx clawhub@latest install finance-report-pro --registry https://cn.longxiaskill.com