The skill is vulnerable to prompt injection and can
Claims to do
Stanley Druckenmiller Workflow: > Published version: **1.1.11**
Actually does
The skill processes financial and economic data from sources like `akshare`, `FRED`, `Stooq`, `Yahoo`, and various news outlets. It synthesizes this data into structured reports (Morning Briefs, Intraday Alerts, Close Reviews, etc.) for A-share and U.S. equity markets, focusing on macro regimes, drivers, and actionable insights. It explicitly avoids direct trade recommendations and defines detailed output formats and analytical rules.
openclaw skills install luckycatl/stanley-druckenmiller-workflowDeBERTa classifier detected prompt injection (confidence: 0.99)
The skill instructs the agent to read external Markdown files (`references/core-panels-and-sources.md`, `references/a-share-tape-v1_1.md`) for 'extending or maintaining the skill'. If these files are compromised or contain malicious instructions, they could poison the agent's knowledge base or influence its behavior.
When extending or maintaining the skill, read: - `references/core-panels-and-sources.md` - `references/a-share-tape-v1_1.md`
[](https://mondoo.com/ai-agent-security/skills/clawhub/luckycatl/stanley-druckenmiller-workflow)<a href="https://mondoo.com/ai-agent-security/skills/clawhub/luckycatl/stanley-druckenmiller-workflow"><img src="https://mondoo.com/ai-agent-security/api/badge/clawhub/luckycatl/stanley-druckenmiller-workflow.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/clawhub/luckycatl/stanley-druckenmiller-workflow.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.