Gov Travel

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This skill appears to provide disclosed, read-only travel information through a remote MCP service and does not request credentials or local file access.

This skill looks safe for general use if you are comfortable connecting OpenClaw to the listed remote MCP service. Do not include sensitive personal information in travel queries unless you trust that service.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Your travel queries will be handled by the configured remote MCP service.

Why it was flagged

The setup uses a remote MCP service rather than local reviewed code. This is disclosed and central to the skill's purpose, but it means the user is trusting the hosted endpoint.

Skill content
mcporter add gov-travel --url https://immigration-travel-mcp.apify.actor/mcp --transport streamable-http
Recommendation

Install only if you trust the listed MCP endpoint and the linked project source.

What this means

Location-related travel lookup requests may be sent to the remote MCP server.

Why it was flagged

The skill communicates with a remote MCP server over streamable HTTP. The documented data appears limited to travel lookup parameters such as cities, borders, and airport codes.

Skill content
"url": "https://immigration-travel-mcp.apify.actor/mcp", "transport": "streamable-http"
Recommendation

Avoid entering sensitive personal travel details unless you are comfortable sharing them with the remote service.