Sonarr

PassAudited by VirusTotal on May 14, 2026.

Findings (1)

The skill is designed to interact with a user-configured Sonarr instance. It reads API credentials from `~/.clawdbot/credentials/sonarr/config.json` and directs all network requests via `curl` to the specified Sonarr URL. The `SKILL.md` contains benign prompt injection instructions for the agent, guiding it on how to present search results and ask for user confirmation (e.g., 'Always ask user if they want to delete files when removing!'), which are aimed at improving user experience rather than subverting the agent or performing malicious actions. There is no evidence of data exfiltration, malicious execution, persistence, or obfuscation.