Agent Orchestrator
PassAudited by VirusTotal on Apr 30, 2026.
Findings (1)
The skill bundle functions as an agent orchestrator but exhibits several high-risk indicators. It references external Python scripts (scripts/create_agent.py, scripts/dissolve_agents.py) that are not provided in the bundle, and it hardcodes a requirement to transmit data and an environment variable (SKILLBOSS_API_KEY) to a specific third-party domain (api.heybossai.com) across SKILL.md and its templates. Furthermore, the _meta.json file contains a future-dated timestamp (2026), which is often a sign of synthetic or deceptive metadata. While these capabilities are plausibly related to its stated purpose, the lack of transparency regarding external scripts and the mandatory external API dependency pose a security risk.
