Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Mytaxi
v1.0.1在欧洲使用MyTaxi快速叫车、查询行程、估算费用及查看司机和到达时间,支持应用内支付。
⭐ 0· 79·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
Name/description advertise active MyTaxi functionality (ordering rides, trip lookup, payments). The skill declares no binaries, no credentials, no APIs, and contains only an informational SKILL.md that outlines a company-profile summary. A ride-booking integration would reasonably require API keys, network calls, or client binaries — none are present.
Instruction Scope
SKILL.md is narrow and safe in scope: it instructs the agent to provide a structured overview of 'mytaxi' (founding, business, market, news). It does not direct file reads, credential access, or external endpoints. However, these instructions do not implement the interactive features claimed in the description, so they are misaligned with user expectations.
Install Mechanism
Instruction-only skill with no install spec and no code files — minimal install risk. Nothing will be written to disk or downloaded by the skill as provided.
Credentials
The description implies the need for service credentials (APIs for booking/payments), but requires.env lists none. The absence of any declared credentials or config is inconsistent with the advertised live features (driver info, trip queries, payments).
Persistence & Privilege
Defaults used (always: false, agent-invocable allowed). The skill does not request persistent privileges or modify other skills; no privilege concerns from the manifest.
What to consider before installing
This skill's description promises active MyTaxi functionality (requesting rides, checking trips, estimating fares, in-app payments), but the actual runtime instructions only provide a static company overview. If you expect a tool that can book rides or access live trip/driver/payment data, this skill does not implement that and is missing the APIs/credentials required. Recommended next steps before installing: 1) Ask the author/source for clarification and for the actual integration details (APIs used, required keys). 2) Do not provide any payment or service credentials to this skill as currently specified — it does not request or use them. 3) If you only want company background summaries, this skill is low-risk; if you need live ride-hailing capability, look for a skill that declares the appropriate API access and credentials and documents endpoints and privacy practices.Like a lobster shell, security has layers — review code before you run it.
latestvk978wx0d6180p32xy3mag7h0bs84x9dg
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
