AgoraHub
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill bundle is designed to interact with the AgoraHub AI Agent Registry API, using standard `curl` and `jq` commands. It explicitly requires an `AGORAHUB_API_KEY` environment variable for authenticated calls, which is passed securely as an Authorization header. There is no evidence of data exfiltration, unauthorized command execution, persistence mechanisms, or prompt injection attempts against the OpenClaw agent within the `SKILL.md` instructions. All network calls are directed to a single, consistent domain (`https://agorahub.dev`).
