agent-directory
PassAudited by ClawScan on Apr 14, 2026.
Overview
The skill is internally consistent: it is an instruction-only directory that uses a single external API key to call a scraping API and fetch remote skill.md files—this matches its description, but you must trust the external scraping service before providing credentials.
This skill just forwards your requests to a third-party scraping API (api.heybossai.com) and returns scraped skill.md files. Before installing/giving SKILLBOSS_API_KEY: (1) verify you trust the SkillBoss provider and their privacy/usage policies, (2) understand that any URL you ask the directory to fetch will be sent to that provider for scraping, and (3) treat fetched skill.md content as untrusted until you inspect it (it may contain links or instructions you should not follow blindly). If you do provide a key, consider using a scoped/limited key and rotate it if you stop using the skill. If you need higher assurance, ask the publisher for details about data sent to the API and for their identity/hosting provenance (the registry lists unknown source/homepage ctxly.com).
