Real Skill packageSource verifiedClawHub registry

Travel Planner HY

Plan requested multi-day travel itineraries, research public attractions, compare requested travel options, and export local itinerary HTML with optional public platform homepage QR codes. Use for concrete travel planning, itinerary revisions or exports; not travel small talk, calendar scheduling, b

Identity and source

Publisher attributionCryptocxfregistry owner unverified by skillvetai
Functional categorySearch, Research & Knowledgeautomatically inferred · 64% rule confidence
Package forminstruction with code22 recorded files
Canonical sourceClawHub registryclawhub:cryptocxf:travel-planner-hy
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/18/2026.claude/skills/travel-planner-hy

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/18/2026.agents/skills/travel-planner-hy

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/18/2026skills/travel-planner-hy

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @cryptocxf/travel-planner-hy
clawhub inspect @cryptocxf/travel-planner-hy --version 1.3.2

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
22 / 22 inspected as text
Checked
9/18/2026, 4:41:00 AM
Scanner
0.1.3
Policy
1.0.3
1 automated finding
highPackage contains a path commonly used for secrets.npmrc · confidence 88%.npmrc
1 High/Critical review queue entry
STATIC_SENSITIVE_FILE_IN_PACKAGEpending
Open human review queue →
4 inferred permission indicators
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
14 dependency and API indicators
  • npm: qrcode 1.5.4
  • npm: ipaddr.js 2.2.0
  • api: 169.254.169.254
  • api: 2130706433
  • api: evil.test
  • api: github.com
  • api: m.tuniu.com
  • api: registry.npmjs.org
  • api: u
  • api: www.12306.cn
  • api: www.dpm.org.cn
  • api: www.dpm.org.cn.evil.test
  • api: www.tuniu.com
  • api: www.tuniu.com.evil.test
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/18/2026, 1:49:44 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:de4af218452c5c0bd6af6fb640b516d5f63c3a1ba5f91b74c7391417b7ae16b5
Show up to 22 recorded paths
  • .gitignore
  • .npmrc
  • examples/demo-output.html
  • examples/mock-data.json
  • package-lock.json
  • package.json
  • README.md
  • references/attraction-model.md
  • references/itinerary-rules.md
  • references/output-templates.md
  • references/parameters.md
  • references/search-rules.md
  • references/url-safety.md
  • references/usage.md
  • references/validation.md
  • scripts/fetch-guide.js
  • scripts/generate-trip-page.js
  • scripts/mock-data.js
  • scripts/qrcode.js
  • scripts/safety.js
  • SKILL.md
  • tests/security.test.js

Source changelog

Version 1.3.2 (summary: Security & architectural overhaul; expanded documentation) - Fully rewrote documentation for precise capabilities, privacy, and boundaries - Replaced all external access and env handling: no API keys, no bookings/payments, local exports only - Strict new allowlist and DNS/TLS safety checks for all web resource fetches - All itinerary file exports go to output/ only; removed deprecated auto-open/browser-launch features - Added detailed usage references and security test coverage; thoroughly described permissible data flows and user data handling - Expanded command/installation instructions and file structure references