Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

AgentID MCP

v1.0.0

Connect Claude Code to AgentID — persistent shared memory, live activity reporting, and multi-agent mission coordination via MCP

0· 47·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description match the instructions: the skill explains how to connect Claude Code to agentid.live, use an MCP secret, and read/write shared identity/memory and mission endpoints. It does not request unrelated binaries, credentials, or config paths.
Instruction Scope
All runtime instructions are scoped to the AgentID MCP protocol (report_activity, read/write memory, read_mission, etc.) and the agentid.live endpoints. The SKILL.md does not instruct reading local files, unrelated environment variables, or calling external endpoints outside agentid.live.
Install Mechanism
Instruction-only skill with no install spec and no code files — the lowest installation risk (nothing is downloaded or written to disk by the skill itself).
Credentials
The skill declares no required env vars, but the protocol requires placing an MCP secret (Bearer token) into Claude Code settings. This is proportional to the integration, but the user should treat that secret as sensitive and store it only in a secure agent config; do not reuse the secret elsewhere and avoid writing highly sensitive data into AgentID memory.
Persistence & Privilege
always is false and the skill does not request elevated platform privileges. Note: the SKILL.md tells the agent to act on mission handoffs immediately — that is functional behavior of the integration, so consider whether you want agents to autonomously execute handed-off work.
Assessment
This skill is coherent with its stated purpose, but before enabling it: (1) verify you trust https://agentid.live and review its privacy/security docs; (2) store the MCP secret only in Claude Code's secure settings and do not reuse it; (3) grant the integration the minimum privileges possible and rotate/revoke the secret if compromised; (4) avoid writing passwords or other highly sensitive secrets into AgentID memory; (5) be aware agents instructed to 'act on handoff immediately' may perform autonomous actions — test with low privileges first and monitor the AgentID dashboard for activity.

Like a lobster shell, security has layers — review code before you run it.

coordinationvk97enx9pdc1gx1v5xgxmrh3d3d84pfztidentityvk97enx9pdc1gx1v5xgxmrh3d3d84pfztlatestvk97enx9pdc1gx1v5xgxmrh3d3d84pfztmcpvk97enx9pdc1gx1v5xgxmrh3d3d84pfztmemoryvk97enx9pdc1gx1v5xgxmrh3d3d84pfztmulti-agentvk97enx9pdc1gx1v5xgxmrh3d3d84pfzt

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments