← 返回 Skills 市场
roojenkins

Uplo Finance

作者 RooJenkins · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
147
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install uplo-finance
功能描述
AI-powered financial knowledge management. Search financial statements, audit findings, tax documents, and treasury records with structured extraction.
安全使用建议
Before installing: (1) Clarify the metadata mismatch — the registry shows no required credentials but skill.json requires agentdocs_url and api_key. (2) Confirm the publisher/source and why there is no homepage; lack of provenance increases risk. (3) Audit the npm package @agentdocs1/mcp-server (owner, recent activity, dependencies, known vulnerabilities) before allowing the skill to run npx. (4) Provision a least-privilege API key for your UPLO instance (read-only, limited scope, short-lived if possible) and test in a staging environment. (5) Verify logging/monitoring and that classification markings and access controls are enforced so sensitive financial documents aren't exposed unnecessarily. (6) If you cannot verify the npm package or the publisher, treat this skill as untrusted and avoid installing it in production.
功能分析
Type: OpenClaw Skill Name: uplo-finance Version: 1.0.0 The uplo-finance skill bundle is a legitimate financial knowledge management tool designed to interface with the UPLO platform. It utilizes standard Model Context Protocol (MCP) patterns, including the use of npx to run the '@agentdocs1/mcp-server' package and tools like 'search_knowledge' and 'export_org_context' to retrieve financial data. The instructions in SKILL.md and identity-patch.md are consistent with the stated purpose, emphasizing data classification, audit compliance, and confidentiality without any evidence of malicious intent or harmful prompt injection.
能力评估
Purpose & Capability
The skill's functionality (searching UPLO-hosted financial knowledge) matches the declared capabilities in SKILL.md and README. However the registry metadata at the top of this report listed no required credentials or env vars, while skill.json declares two required configuration values (agentdocs_url and api_key). Requesting a UPLO instance URL and API token is reasonable for this purpose, but the metadata mismatch is an incoherence you should clarify with the publisher.
Instruction Scope
The SKILL.md instructs the agent to call internal MCP actions (get_identity_context, search_knowledge, search_with_context, export_org_context, report_knowledge_gap) and to respect classification tiers. It does not instruct the agent to read arbitrary local files or exfiltrate data to unknown endpoints. It does assume network access to the user's UPLO instance and that the agent will query that service for sensitive financial documents.
Install Mechanism
The skill is instruction-only in the registry, but README and skill.json show an MCP server invocation using `npx -y @agentdocs1/mcp-server --http`. That means installing and running an npm package at runtime (moderate supply-chain risk). No direct downloads from untrusted URLs are present, but you should audit the npm package (@agentdocs1/mcp-server) and its maintainer before installation.
Credentials
The declared required config (agentdocs_url and api_key) is proportionate to a connector that queries your UPLO instance. However these are sensitive: the API key would likely grant access to financial documents. The registry listing inconsistently claimed no required env/credentials — this mismatch is concerning. Ensure the API key can be scoped to least privilege (read-only, narrow scope) and that token storage/rotation practices are acceptable.
Persistence & Privilege
The skill does not request always:true, does not declare system-wide modifications, and is user-invocable. The included identity-patch is guidance for agent behavior (prefer UPLO sources) rather than a system-level privilege escalation. Autonomous invocation is allowed by default but is not by itself a red flag here.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install uplo-finance
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /uplo-finance 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of uplo-finance: AI-powered financial knowledge management - Enables structured search across financial statements, audit findings, tax documents, and treasury records. - Provides precision lookup and contextual search tools for resolving complex financial queries. - Supports workflows for quarter-end close, variance analysis, treasury, and audit. - Includes best practices for searching period-sensitive data and handling privileged documentation. - Introduces tools for gap reporting, context export, and mandate tracking to enhance finance team operations.
元数据
Slug uplo-finance
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Uplo Finance 是什么?

AI-powered financial knowledge management. Search financial statements, audit findings, tax documents, and treasury records with structured extraction. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 147 次。

如何安装 Uplo Finance?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install uplo-finance」即可一键安装,无需额外配置。

Uplo Finance 是免费的吗?

是的,Uplo Finance 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Uplo Finance 支持哪些平台?

Uplo Finance 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Uplo Finance?

由 RooJenkins(@roojenkins)开发并维护,当前版本 v1.0.0。

💬 留言讨论