Singapore Location Helper
v1.0.0🇸🇬 新加坡租房选址专家:精确到楼栋的推荐、通勤分析、避坑指南,帮你找到最适合的居住区域
⭐ 1· 339·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name/description, examples, and requested resources (PropertyGuru, LTA, URA, Google Maps, Citymapper) are coherent for a Singapore housing-location assistant. No unrelated binaries, credentials, or config paths are requested.
Instruction Scope
SKILL.md is an instruction-only skill that contains detailed checklists and recommended data sources. This scope is appropriate, but it references live web lookups (Google Maps/Street View, LTA, URA) so the agent will be expected to fetch external public data. The file also triggered a prompt-injection pattern (unicode-control-chars) — the content should be checked for hidden control characters that might alter model behavior or embed hidden instructions.
Install Mechanism
No install spec, no code files, and no downloads — lowest-risk delivery model. The skill is instruction-only, so there's nothing being written to disk by an installer.
Credentials
The skill requires no environment variables, credentials, or config paths. That matches the described functionality and is proportionate.
Persistence & Privilege
always:false and default agent-invocation settings. The skill does not request permanent presence or elevated system privileges; autonomous invocation is the platform default but does not appear combined with other high-risk requests here.
Scan Findings in Context
[unicode-control-chars] unexpected: Control/unprintable Unicode characters were detected in SKILL.md. These are not expected for a straightforward location/advice guide and can be used to hide or alter instructions (prompt injection). The rest of the content seems benign, but the presence of this pattern warrants manual inspection of the raw file for hidden characters or embedded directives.
What to consider before installing
This skill appears to do what it says (Singapore rental/location advice) and does not request credentials or install code, but the SKILL.md contains hidden/unicode control characters that could attempt to manipulate model behavior. Before installing: 1) Inspect the raw SKILL.md (or the GitHub repo) in a text editor that can show control/unicode characters and remove any unexpected invisible characters. 2) If you allow the skill to run, avoid granting it any credentials or private data (full addresses, keys, or files) until you trust the author. 3) Consider testing the skill in a sandboxed agent session first (no access to your files or secrets). 4) If you want extra assurance, contact the author or review the referenced GitHub repo to confirm there are no hidden instructions. If you detect suspicious hidden text or unclear behavior, do not enable the skill and report it to the registry.Like a lobster shell, security has layers — review code before you run it.
latestvk9744q3cq9h0v6e3esdkrx381s81sphv
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🇸🇬 Clawdis
