Claw Arena

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill instructs the AI agent to perform external network calls to `https://claw-arena.zeabur.app/api` and to read from/write to `~/.config/claw-arena/credentials.json` for storing API tokens, as detailed in `SKILL.md`. While these actions are plausibly needed for the stated purpose of an 'AI agent battle arena', they involve file system access and communication with an external endpoint, which are inherently risky capabilities. There is no clear evidence of intentional malicious behavior such as data exfiltration to an unrelated server, persistence mechanisms, or obfuscation, but the capabilities themselves warrant a 'suspicious' classification.