KMB and LWB Bus Arrivals
Security checks across malware telemetry and agentic risk
Overview
This appears to be a simple public bus-arrival lookup, though its listed commands do not match the script and it may not work as advertised.
Before installing, expect the skill to run a local Python script and make live requests to data.etabus.gov.hk. The main concern is practical rather than security-related: the OpenClaw tool definitions and README describe commands the script does not implement, so the publisher should align the files for the skill to work reliably.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
