Security audit
Robotaxi Tracker
Security checks across malware telemetry and agentic risk
Overview
The skill's requirements and runtime instructions are consistent with its stated purpose (scraping robotaxitracker.com and querying its public Convex backend); it performs only site and backend HTTP queries and local text processing, requests no secrets, and has no install steps.
This skill is coherent with its stated purpose: it downloads robotaxitracker.com HTML/JS into /tmp, scans the bundles for API endpoints, and issues HTTP queries to the public Convex backend(s) found there using curl/jq/rg. It does not ask for credentials. Before installing, consider: (1) the skill will make outbound HTTP requests to robotaxitracker.com and any backend host discovered in the site JS (your network/firewall policies may want to block or log this); (2) it writes temporary files to /tmp (no persistent installs); and (3) if you are in a restricted environment, verify that executing these network probes is allowed. If any of those are concerns, review the SKILL.md and run the commands manually in a controlled environment instead of enabling autonomous invocation.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
64/64 vendors flagged this skill as clean.
