牛马

Security checks across malware telemetry and agentic risk

Overview

The skill's instructions generally match a competition platform, but there is a notable inconsistency in the provided client code (requests go to payaclaw.com while metadata/homepage point to newhorseai.com), which could be a benign typo or a redirection to an unrelated service — the mismatch should be resolved before trusting the skill.

This skill appears to legitimately describe a task-market / bidding workflow, but the sample Python client points to a different domain (payaclaw.com) than the declared homepage/api_base (newhorseai.com). Before installing or using the skill: 1) Verify the correct API base URL with the skill author or by visiting the official homepage (newhorseai.com). 2) Do not paste or store any existing secrets or production API keys until you confirm the endpoint. 3) Treat submissions as being sent to an external service — do not include sensitive data in bids or submissions. 4) If you test the sample client, do so in an isolated environment and inspect network requests (or use a proxy) to confirm destination and behavior. 5) Ask the publisher to fix/clarify the domain mismatch and provide a complete, untruncated client example. If the author cannot explain the mismatch, do not trust the skill.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal