AgoraHub

Security checks across malware telemetry and agentic risk

Overview

This skill is a user-directed guide for calling AgoraHub's remote API, with privacy caveats but no hidden execution, persistence, or destructive behavior.

Install only if you are comfortable sending selected inputs to AgoraHub's remote service. Avoid submitting real JWTs, API keys, session tokens, private source code, customer records, confidential documents, or regulated data unless you have reviewed and accepted AgoraHub's trust, privacy, and retention practices. Use the API key only for community agents you intentionally trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents sending arbitrary user-supplied content to a third-party remote service but does not warn that prompts, documents, code, or other inputs leave the local environment. In a skill intended for developer tasks, users may reasonably paste sensitive material, so the missing privacy/data-handling warning creates a real disclosure risk.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The JWT decoder example encourages users to paste tokens into a remote API call without warning that JWTs commonly contain sensitive claims and may sometimes expose bearer credentials or internal identifiers. Because the service performs decoding server-side, the token is transmitted off-host, creating an avoidable credential and metadata leakage risk.

External Transmission

Medium
Category
Data Exfiltration
Content
### General Call Format

```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_<agent-slug>_<skill-id>","arguments":{...}}' | jq
```
Confidence
85% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
### JSON Formatter
Validate, pretty-print, or minify JSON.
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_json-formatter_format","arguments":{"json":"{\"key\":\"value\",\"num\":42}"}}' | jq
```
Confidence
88% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
Decode Base64 back to text:
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_base64-codec_decode","arguments":{"text":"aGVsbG8gd29ybGQ="}}' | jq
```
Confidence
90% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
### Regex Tester
Test regex patterns against text.
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_regex-tester_test","arguments":{"pattern":"\\d+","text":"abc 123 def 456"}}' | jq
```
Confidence
86% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
### JWT Decoder
Decode a JWT token (without verification).
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_jwt-decoder_decode","arguments":{"token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"}}' | jq
```
Confidence
98% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
### Markdown to HTML
Convert Markdown text to HTML.
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_markdown-to-html_convert","arguments":{"markdown":"# Hello\n\n**Bold** and *italic*"}}' | jq
```
Confidence
87% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
### Text Stats
Analyze text for word count, reading time, and more.
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_text-stats_analyze","arguments":{"text":"The quick brown fox jumps over the lazy dog. This is a sample text for analysis."}}' | jq
```
Confidence
84% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
### CSV/JSON Converter
Convert CSV to JSON:
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_csv-json-converter_csv-to-json","arguments":{"csv":"name,age\nAlice,30\nBob,25"}}' | jq
```
Confidence
90% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
Convert JSON to CSV:
```bash
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -d '{"name":"agora_csv-json-converter_json-to-csv","arguments":{"data":[{"name":"Alice","age":30},{"name":"Bob","age":25}]}}' | jq
```
Confidence
90% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
```bash
export AGORAHUB_API_KEY="agora_your_key_here"

curl -s -X POST https://agorahub.dev/api/mcp/tools/call \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $AGORAHUB_API_KEY" \
  -d '{"name":"agora_some-community-agent_skill","arguments":{...}}' | jq
Confidence
82% confidence
Finding
curl -s -X POST https://agorahub.dev/api/mcp/tools/call \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $AGORAHUB_API_KEY" \ -d

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal