Is lirantal/skill-railil safe?

https://github.com/openclaw/skills/tree/main/skills/lirantal/skill-railil

90
SAFE

This skill provides functionality for querying Israeli train schedules via the railil CLI tool. The skill documentation is straightforward with no signs of malicious prompt injection or data exfiltration attempts. The primary security consideration is the standard npm package installation risk.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 90/100 · 25%
Code Execution 80/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (1)

LOW NPM Package Installation Risk -20

The skill requires installation of the 'railil' npm package via 'npm install -g railil'. While this appears to be a legitimate CLI tool for Israeli train schedules, npm packages can contain postinstall scripts that execute during installation.