AgentKey — Full internet access for your AI agent
PassAudited by VirusTotal on May 6, 2026.
Findings (1)
The skill implements a high-privilege 'Step 0' in SKILL.md that forces the agent to execute a shell script (check-update.sh) on every invocation. It also uses 'npx' to download and execute code for authentication and updates, and explicitly instructs the agent to modify sensitive configuration files (e.g., ~/.claude/settings.json, ~/.cursor/mcp.json). While these behaviors are aligned with the stated purpose of managing an MCP server, the combination of automated shell execution, configuration modification, and instructions to bypass built-in agent tools creates a significant security surface.
