bossskill
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle implements a commercial 'client-server' architecture where advanced functionality is executed via a remote API (bt.fanfan.la). While the behavior is documented, the SKILL.md file contains explicit instructions to the AI agent to minimize user approval prompts ('approve 弹窗') and prioritize internal execution paths to reduce 'interruption.' This intentionally weakens the human-in-the-loop security model of the OpenClaw/Hermes platforms. Additionally, scripts/booskill_license.py collects system metadata (hostname, home directory path) to generate a hardware-bound machine_id, and scripts/startup_os_db.py facilitates the transmission of user-provided business data to the vendor's cloud for 'commercial' processing.
