Badman — Autonomous Business Agent
Autonomous AI agent for entrepreneurs managing lead prospecting, email replies, job applications, and social media content automatically.
MIT-0 · Free to use, modify, and redistribute. No attribution required.
⭐ 0 · 49 · 0 current installs · 0 all-time installs
byMister fantastic@okfreelancerai
MIT-0
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The skill's name and description promise inbox monitoring, sending emails, WhatsApp/Telegram auto-replies, and social posting. However the registry metadata declares no required environment variables, no config paths, and no binaries. That is inconsistent: performing those integrations normally requires credentials or explicit integration instructions (OAuth tokens, API keys, or platform-specific setup). The agent.json lists channels including discord (not mentioned elsewhere) which is another minor mismatch.
Instruction Scope
SKILL.md tells the user to "Configure your API keys (Gmail, WhatsApp optional)" and that "Badman runs autonomously" but gives no concrete instructions for how credentials are provided, how OAuth flows are performed, what endpoints will be contacted, or what actions are allowed. The instructions are high-level and open-ended, granting broad discretion (prospecting, auto-replies, sending applications) without explicit safety/consent checks or limits. This vagueness increases the chance the agent will request or be given sensitive data in an unsafe manner.
Install Mechanism
There is no install spec and no code files — this is instruction-only. That reduces attack surface because nothing is downloaded or written automatically. However, an instruction-only skill that then solicits credentials or instructs the agent to perform networked actions is still risky if the flows are unclear.
Credentials
The capability set implies the need for multiple credentials (Gmail, WhatsApp, Telegram, APIs for social platforms), but requires.env and primary credential fields are empty. The SKILL.md explicitly says to "Configure your API keys" yet the manifest doesn't declare which env vars or tokens will be used or stored. Missing declarations make it unclear where credentials will be entered and how they will be protected — this is disproportionate and incoherent.
Persistence & Privilege
always is false (normal) and disable-model-invocation is false (also the platform default). Autonomous invocation is permitted by default; combined with the agent's broad capabilities and lack of declared integration details this raises risk because the agent could act without fine-grained user approvals. There's no evidence the skill requests persistent system-level privileges or modifies other skills.
What to consider before installing
Think twice before installing. This skill promises broad, autonomous access to email, messaging, and social platforms but doesn't declare the credentials or explain the integration flow. Ask the author: (1) exactly which environment variables or OAuth flows are required and how/where tokens are stored (never paste tokens into chat), (2) what network endpoints the agent will contact and whether third-party servers will process your data, (3) what actions the agent is authorized to take automatically and how to approve/rollback them, (4) how to revoke access and see activity logs. Do not provide raw API keys or passwords via chat prompts; prefer OAuth with least-privilege scopes. If the author can't supply clear integration details, demo code, or a trusted homepage/repo, treat this as risky and consider testing only in an isolated account or sandbox.Like a lobster shell, security has layers — review code before you run it.
Current versionv1.0.0
Download zipagentautonomousbusinessemailentrepreneurlatestmarketingprospecting
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
SKILL.md
Badman — Autonomous Business Agent
Badman is a fully autonomous AI agent for entrepreneurs and small business owners. He handles your prospecting, lead qualification, job applications, email responses, and marketing content — all on autopilot.
What Badman does
- 🔍 Prospector — Finds leads and qualifies them automatically
- 📧 Email Manager — Monitors inbox, drafts and sends professional replies
- 📱 Content Generator — Weekly social media content for Twitter, TikTok, LinkedIn
- 🤖 Auto-Responder — Replies to WhatsApp/Telegram when you're unavailable
- 💼 Job Application Agent — Sends tailored cover letters + CV automatically
Use cases
- Small business owners who want a 24/7 digital employee
- Freelancers who need automated outreach and follow-up
- Entrepreneurs running lean — no staff, just Badman
Setup
- Install this skill
- Configure your API keys (Gmail, WhatsApp optional)
- Set your agent profile (name, business, tone)
- Badman runs autonomously from there
Tags
agent, business, autonomous, prospecting, email, marketing, lead-qualification, entrepreneur
Author
Karim Ourkia — Agent Rental (https://agentrental.tiiny.site) Twitter: @okfreelancer
Files
4 totalSelect a file
Select a file to preview.
Comments
Loading comments…
