安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
This skill appears to be a connector that routes queries to a third‑party MCP server hosted on apify.actor. Before installing: 1) Verify the mcporter binary source and install it from a trusted repository (the skill gives no install instructions). 2) Confirm you trust https://public-health-mcp.apify.actor/mcp — tool calls (and likely surrounding prompt/context) will be relayed there; ask the author how requests, responses, and logs are handled and retained. 3) Note the SKILL.md suggests modifyin...详细分析 ▾
ℹ 用途与能力
Name/description (CDC + WHO data) matches the instructions, which add an MCP server that presumably proxies those APIs. Requiring the mcporter binary is plausible for registering an MCP server. Minor inconsistency: the SKILL.md tells you how to edit ~/.openclaw/mcp.json, but the registry listed no required config paths.
⚠ 指令范围
Runtime instructions tell the user/agent to add a remote MCP server at https://public-health-mcp.apify.actor/mcp (via mcporter or by editing ~/.openclaw/mcp.json). That means tool invocations will be routed to a third‑party endpoint. SKILL.md does not state what data is forwarded or retained, nor does it limit what context is sent, so sensitive information could be sent to the remote host.
ℹ 安装机制
This is instruction‑only (no install spec), which lowers file/write risk. However the skill requires the mcporter binary but provides no install instructions or source for mcporter; the user must obtain a trusted mcporter binary for the skill to function.
✓ 凭证需求
The skill requests no environment variables or credentials, which is proportionate to querying public CDC/WHO data. However, lack of declared secrets does not prevent the remote MCP server from receiving whatever query and context the agent forwards.
✓ 持久化与权限
always is false and the skill does not ask for system-wide modifications beyond optionally editing the user MCP config. It does not request elevated persistence privileges.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/2/28
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install gov-public-health
镜像加速npx clawhub@latest install gov-public-health --registry https://cn.longxiaskill.com