Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Spatix
v1.1.0Create beautiful maps in seconds. Geocode addresses, visualize GeoJSON/CSV data, search places, and build shareable map URLs. No GIS skills needed. Agents ea...
⭐ 0· 1.3k·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (map creation, geocoding, GeoJSON/CSV visualization) matches the SKILL.md instructions, which show only HTTP calls to api.spatix.io and optional MCP helper installation. There are no unrelated required env vars, binaries, or config paths.
Instruction Scope
All runtime instructions are scoped to interacting with Spatix endpoints (map creation, geocoding, datasets, leaderboard). The skill does instruct agents to upload datasets and post map data to https://api.spatix.io (expected), so users should be aware that any uploaded location data or datasets will be transmitted to and may be visible via Spatix (public dataset examples and license fields are shown).
Install Mechanism
There is no registry install spec (instruction-only), which is low risk. The SKILL.md suggests an optional 'pip install spatix-mcp' or 'uvx spatix-mcp' for an MCP server; if a user follows that advice they should vet the package source before installing. The skill itself does not force installation of any code.
Credentials
The skill declares no required env vars or credentials. It mentions optional non-secret display identifiers (SPATIX_AGENT_ID, SPATIX_AGENT_NAME) and an optional JWT for account-based higher rate limits—these are proportional to the stated functionality.
Persistence & Privilege
always:false and no config paths or persistence are requested. The skill can be invoked autonomously by an agent (platform default), but it does not request elevated or persistent privileges beyond typical agent use.
Assessment
This skill appears to do what it says: call api.spatix.io to create maps, geocode addresses, and upload datasets. Before installing or using it: (1) remember that any data you send (addresses, GeoJSON, CSV) is transmitted to Spatix and uploaded datasets may be public depending on the fields you set — avoid sending sensitive location data; (2) if you follow the SKILL.md suggestion to 'pip install spatix-mcp', review the package source and contents before installing; (3) if you need to manage or remove maps later, consider creating an account and using the JWT so you retain deletion/edit control; (4) review Spatix's privacy, dataset licensing defaults, and rate limits before integrating into automated agents.Like a lobster shell, security has layers — review code before you run it.
csvvk979zdje9j447nzc43yz1h35t980sje4geocodingvk979zdje9j447nzc43yz1h35t980sje4geojsonvk979zdje9j447nzc43yz1h35t980sje4geospatialvk979zdje9j447nzc43yz1h35t980sje4gisvk979zdje9j447nzc43yz1h35t980sje4latestvk978y2vrkxdzsqkbqj3zjtpp05814627locationvk979zdje9j447nzc43yz1h35t980sje4mapsvk979zdje9j447nzc43yz1h35t980sje4mcpvk979zdje9j447nzc43yz1h35t980sje4visualizationvk979zdje9j447nzc43yz1h35t980sje4
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
