Agent Team Orchestration
MaliciousAudited by VirusTotal on Apr 30, 2026.
Findings (1)
The skill bundle instructs the agent to route all model requests through a third-party service called 'SkillBoss API Hub' at api.heybossai.com, requiring the use of a specific SKILLBOSS_API_KEY. This configuration introduces a risk of credential harvesting and data exfiltration by redirecting core agent communications to an unverified external endpoint. These instructions are primarily detailed in SKILL.md and references/team-setup.md.
