安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
This skill mostly does what it says (it provides a detailed protocol for 'thinking like X'), but it has two noteworthy red flags: (1) it instructs the model to produce explicit step-by-step chain-of-thought in responses (the 'compensation' guidance), which can reveal internal reasoning and encourage overconfident hallucination — you should disable or ignore any instruction that forces chain-of-thought to be emitted verbatim; (2) it encourages deep psychological profiling (core wounds, defense me...详细分析 ▾
ℹ 用途与能力
The skill is instruction-only and contains detailed reference layers that align with its description (mapping cognitive and psychological layers, synthesis, operational application). It does not request unrelated credentials or installs, so the declared requirements are proportionate to the stated goal.
⚠ 指令范围
SKILL.md and the reference files explicitly instruct the agent to infer deep psychological constructs (e.g., 'CORE WOUND', 'shadow profile', defense mechanisms) from available evidence and to apply them as an active reasoning lens. The model-guidance file further instructs smaller models to emit explicit step-by-step chain-of-thought before any layer output. Forcing explicit chain-of-thought in outputs and producing sensitive psychological inferences about named individuals (potentially living people) is privacy- and safety-sensitive, increases risk of hallucinated or speculative personal profiling, and may disclose internal reasoning the platform or operator prefers to keep private.
✓ 安装机制
No install spec, no code files that execute, and all content is local instruction/reference prose — the lowest risk install posture.
ℹ 凭证需求
The skill requests no environment variables or external credentials, which is proportionate. However, the instructions expect the agent to gather and grade 'primary sources' (writings, interviews, biographies), which may require web access or paywalled data not declared in the skill; the skill does not justify or request such access explicitly.
ℹ 持久化与权限
always:false and default autonomous invocation are used. The skill will keep a loaded framework active for the conversation, which is reasonable for its purpose, but it does not request permanent system-level privileges. The session persistence of a loaded framework may increase chance of repeated sensitive inferences over a conversation.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.42026/3/19
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install thinking-framework
镜像加速npx clawhub@latest install thinking-framework --registry https://cn.longxiaskill.com