media
Security checks across malware telemetry and agentic risk
Overview
The skill's runtime instructions are coherent with a media API hub (it sends media to https://api.skillbossai.com/v1/pilot and expects a SKILLBOSS_API_KEY), but the published registry metadata contradicts the SKILL.md (it lists no required env vars) and the skill will upload local media and generated content to an external service — verify origin and data handling before installing.
Before installing, verify the skill's origin and publisher (there's no homepage/source listed). Confirm you are comfortable giving an API key that will be sent to https://api.skillbossai.com and that the provider's privacy, retention, and content policies meet your needs. Ask the publisher to fix the registry metadata mismatch (SKILL.md declares SKILLBOSS_API_KEY but metadata says none). Avoid uploading sensitive or private media until you trust the service. If you must test, use a restricted API key with limited permissions and monitor usage/costs. If the publisher cannot provide a reliable source repository or documentation, treat this as higher risk and consider not installing.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
