Hong Kong MTR Next-Train ETA | 港鐵實時到站預報
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed Hong Kong MTR train-time lookup tool that only uses public transit APIs and a local station cache.
Before installing, note that the skill contacts public Hong Kong transit-data endpoints and may refresh a station-list CSV inside its own folder. It does not need secrets or account access; keep use limited to MTR ETA queries and station-data refreshes.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
