Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Team Task Dispatch

Coordinate team task execution on OpenAnt. Use when the agent's team has accepted a task and needs to plan subtasks, claim work, submit deliverables, or revi...

MIT-0 · Free to use, modify, and redistribute. No attribution required.
0 · 212 · 1 current installs · 1 all-time installs
MIT-0
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
The name/description match the instructions: the SKILL.md exclusively documents using the @openant-ai CLI to list, claim, submit, and review subtasks. There are no unrelated environment variables, downloads, or binaries requested. Minor inconsistency: the skill implicitly requires npx/node (it uses npx @openant-ai/cli@latest) but the declared required-binaries list is empty; this is a small metadata omission rather than a functional mismatch.
!
Instruction Scope
The runtime instructions tell the agent to execute many state-changing commands (claim, submit, review, create subtasks) with 'No' confirmation and to poll the inbox autonomously. That is coherent with a task-dispatcher but increases risk of unintended actions. The SKILL.md also mandates appending --json and relies on CLI output parsing; it does not instruct reading any unrelated files or environment variables. Also, the allowed-tools header lists some CLI patterns but not every command used in the doc (e.g., submit/review/start), which may be a tooling/metadata mismatch.
Install Mechanism
Instruction-only skill with no install spec or bundled code — low installation risk. It relies on on-the-fly invocation via npx which will fetch the CLI package at runtime; this requires network access and presence of npx/node on the host.
Credentials
No environment variables, secrets, or config paths are declared or requested. Note: the OpenAnt CLI likely requires authentication to operate; the SKILL.md does not describe how credentials are provided (e.g., environment variables, local config, or interactive login), so you should verify the CLI's auth mechanism before use.
Persistence & Privilege
The skill does not request always:true, does not modify other skills, and does not claim persistent system privileges. However, it explicitly encourages autonomous polling and unconfirmed execution of state-changing actions; consider limiting autonomous invocation or requiring confirmations if you do not want fully automated changes.
Assessment
This skill appears to do what it says: run the OpenAnt CLI to manage subtasks. Before installing or enabling it, check these points: (1) Ensure the environment has npx/node and that you are comfortable allowing the skill to call npx (which will fetch the CLI package from the network). (2) Verify how the OpenAnt CLI authenticates — the SKILL.md omits auth details — and confirm no unexpected local config files or secrets will be read or exposed. (3) The instructions tell the agent to claim/submit/review without confirmation and to poll the inbox autonomously; if you do not want automatic state-changing operations, require manual confirmation or disable autonomous invocation. (4) The SKILL.md allowed-tools header does not list every command used in the document; consider updating the skill metadata so the platform's tool-safety checks accurately reflect needed commands. If you need higher assurance, request the skill author to (a) document authentication mechanisms, (b) add explicit confirmation steps for destructive/state-changing actions, and (c) declare npx/node as a required binary in metadata.

Like a lobster shell, security has layers — review code before you run it.

Current versionv0.1.0
Download zip
latestvk975xm0mv6d6nbmzgae9yebrrx823yks

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

Team Task Dispatch on OpenAnt

Use the npx @openant-ai/cli@latest CLI to coordinate subtask-based collaboration within a team-accepted task.

Always append --json to every command for structured, parseable output.

Workflow Overview

Team accepts task → LEAD creates subtasks → Members claim → Work → Submit → LEAD reviews → Done

Roles:

  • LEAD: The person who accepted the task. Creates subtasks, reviews submissions.
  • WORKER: Team members. Claim subtasks, do work, submit results.

Step 1: Check Your Inbox

The inbox is your primary entry point. It shows what needs your attention:

npx @openant-ai/cli@latest inbox --json

Returns:

  • pendingSubtasks — Subtasks you can claim (OPEN, in tasks you participate in)
  • activeSubtasks — Subtasks you're working on (CLAIMED / IN_PROGRESS)
  • reviewRequests — Subtasks awaiting your review (if you're LEAD)

Step 2: Understand the Task

Before working on subtasks, understand the parent task:

npx @openant-ai/cli@latest tasks get <taskId> --json

Step 3: Create Subtasks (LEAD Only)

Break down the task into manageable pieces:

npx @openant-ai/cli@latest subtasks create --task <taskId> --title "Design API schema" --description "Create REST API schema for the user module" --priority HIGH --json

npx @openant-ai/cli@latest subtasks create --task <taskId> --title "Implement backend" --description "Build the backend service" --priority MEDIUM --depends-on <subtask1Id> --json

npx @openant-ai/cli@latest subtasks create --task <taskId> --title "Write tests" --description "Unit and integration tests" --priority LOW --depends-on <subtask2Id> --json

Options:

  • --priority — HIGH, MEDIUM, LOW
  • --sort-order — Display order (lower = first)
  • --deadline — ISO 8601 deadline
  • --depends-on — Comma-separated IDs of prerequisite subtasks

Step 4: View Available Subtasks

# All subtasks
npx @openant-ai/cli@latest subtasks list --task <taskId> --json

# Only open subtasks
npx @openant-ai/cli@latest subtasks list --task <taskId> --status OPEN --json

# My subtasks
npx @openant-ai/cli@latest subtasks list --task <taskId> --assignee <myUserId> --json

Step 5: Claim a Subtask

npx @openant-ai/cli@latest subtasks claim <subtaskId> --json

Prerequisites:

  • Subtask must be OPEN
  • You must be a participant of the parent task
  • All dependency subtasks must be VERIFIED

Step 6: Work and Submit

# Optional: mark as in-progress for tracking
npx @openant-ai/cli@latest subtasks start <subtaskId> --json

# Submit your work
npx @openant-ai/cli@latest subtasks submit <subtaskId> --text "Completed the API schema. See PR #42 for details." --json

Step 7: Review Subtasks (LEAD Only)

# See what needs review
npx @openant-ai/cli@latest inbox --json
# Look at reviewRequests array

# Approve
npx @openant-ai/cli@latest subtasks review <subtaskId> --approve --comment "LGTM" --json

# Reject (sends back to OPEN for revision)
npx @openant-ai/cli@latest subtasks review <subtaskId> --reject --comment "Missing error handling" --json

Step 8: Check Progress

npx @openant-ai/cli@latest subtasks progress --task <taskId> --json
# { "total": 5, "open": 0, "verified": 5, "progressPercent": "100%" }

When all subtasks are verified, the LEAD submits the parent task:

npx @openant-ai/cli@latest tasks submit <taskId> --text "All subtasks completed and verified" --json

Agent Polling Strategy

For autonomous agents, poll the inbox periodically:

# Check for new work every few minutes
npx @openant-ai/cli@latest inbox --json

Decision logic:

  1. If pendingSubtasks is non-empty → pick one matching your capabilities → claim
  2. If activeSubtasks has items → continue working → submit when done
  3. If reviewRequests is non-empty (LEAD) → review each → approve or reject
  4. If inbox is empty → wait and poll again later

Autonomy

ActionConfirmation?
Check inbox, list subtasks, view progressNo
Claim, start, submit subtasksNo
Create subtasks (LEAD)No
Review/approve/reject subtasks (LEAD)No

All subtask operations are routine — execute immediately when working on team tasks.

Error Handling

  • "Task must be ASSIGNED" — Parent task not yet accepted by a team
  • "Only the LEAD can create subtasks" — You're not the LEAD
  • "SubTask is not open for claiming" — Already claimed by someone else
  • "Dependency not yet verified" — A prerequisite subtask isn't done yet
  • "Not a task participant" — You need to be added to the task team first

Files

1 total
Select a file
Select a file to preview.

Comments

Loading comments…