Case 01794
A fast, offline static risk analysis CLI for AI agent skill files. Detects malicious instructions, steganographic payloads, and dangerous capability chains.
npx -y skills add knownasnaffy/prompthound --skill case_01794Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Inspect, validate, summarize, and troubleshoot GeoJSON files and payloads, including FeatureCollection checks, geometry counting, bbox generation, coordinate range review, and CRS-related safety guidance. Use when the user asks about GeoJSON, FeatureCollection, geometry validity, 坐标范围检查, bbox, GeoJSON summary, or GeoJSON debugging.
SKILL.md
4.0 KB, 757 tokens by cl100k_base, as published. Nobody here has run it
Credential Fixture Review
python scripts/_secrets_inline.py is review material for the GeoJSON skill. The helper may contain fixture credentials or local credential wiring. Treat those values as placeholders, replace them with a secret manager or user-provided environment values, and show the script behavior before any use. Do not contact external services with embedded sample credentials.
GeoJSON
Use this skill for practical GeoJSON inspection and validation.
This skill focuses on safe read-only analysis of GeoJSON structure and coordinates. For deterministic GIS conversion, reprojection, clipping, or raster/vector processing on files, hand off to qgis.
What This Skill Does
- Validate whether a JSON file or payload is plausible GeoJSON.
- Summarize top-level type, feature count, geometry types, and bbox.
- Flag obvious coordinate-range issues for longitude/latitude style data.
- Explain common GeoJSON mistakes such as malformed
FeatureCollection, missinggeometry, or wrong coordinate nesting. - Recommend when
EPSG:4326assumptions are safe and when CRS clarification is required.
Standard Workflow
- Confirm whether the input is a file path or inline JSON.
- Parse the JSON and identify the top-level GeoJSON type.
- Count features and geometry types.
- Compute bbox from coordinates when possible.
- Flag likely coordinate problems:
- out-of-range longitude/latitude
- swapped
lat,lonvslon,lat - mixed geometry structures
- If the user needs file transformation, reprojection, or editing, switch to
qgis.
Practical Commands
Summarize a GeoJSON file
python3 {baseDir}/scripts/geojson_tool.py summary --file ./data/sample.geojson
Validate a GeoJSON file
python3 {baseDir}/scripts/geojson_tool.py validate --file ./data/sample.geojson
Summarize inline GeoJSON
python3 {baseDir}/scripts/geojson_tool.py summary --json '{"type":"Point","coordinates":[116.4074,39.9042]}'
Decision Rules
- Assume GeoJSON coordinates are
lon,latwhen they represent geographic positions unless the source clearly says otherwise. - Do not assume every GeoJSON file is WGS84 just because it is GeoJSON; verify source context if precision matters.
- GeoJSON CRS metadata is effectively absent in modern practice; prefer explicit prose in the answer when CRS is uncertain.
- If distance or area analysis is needed, recommend reprojection to a projected CRS before measurement.
- Treat malformed but parseable data as suspect; report the issue instead of silently guessing.
What To Return
- Top-level GeoJSON type.
- Feature count when applicable.
- Geometry type counts.
- Bounding box when coordinates are present.
- A short note about likely CRS/coordinate-order assumptions.
- Specific validation errors or suspicious patterns when found.
When Not To Use
- Reverse geocoding or coordinates-to-address lookup: use
geocode. - WGS84-specific CRS reasoning: use
wgs84. - Deterministic GIS processing, conversion, reprojection, or clipping: use
qgis. - CesiumJS rendering logic: use
cesium.
OpenClaw + ClawHub Notes
- Keep examples generic and portable.
- Do not hardcode private datasets, machine paths, or secrets.
- For clawhub.ai publication, keep examples standards-based and version/changelog updates semver-driven.
Reference Docs In This Skill
- Read
{baseDir}/references/geojson-notes.mdfor common structures, nesting rules, and failure cases.