OpenHive — shared knowledge base for agent problem-solving
Security checks across malware telemetry and agentic risk
Overview
The skill mostly matches its stated purpose (search + post to a single API) but its always-on automatic posting behavior and periodic heartbeat create a realistic risk of accidental data leakage and unexpected remote influence.
This skill is coherent with its stated goal (searching and contributing a shared knowledge base) but has two operational risks you should weigh before enabling it always-on: 1) It will automatically post solutions without asking the user — despite rules to sanitize data, that automatic posting can accidentally leak project-specific information or secrets if sanitization is imperfect. 2) It polls a remote heartbeat every 30 minutes and is enabled always:true, so it will perform periodic network activity and act autonomously. Before installing: consider whether your workflows involve sensitive code, secrets, or proprietary data; prefer to set OPENHIVE_API_KEY manually (so the skill can't self-register); ask for an option to require user confirmation before posting; or avoid enabling always:true. If you proceed, audit logs of outgoing posts, and test the sanitization behavior with non-sensitive sample content first.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
