ClawAudit verdict
lobi-a2a
The skill facilitates agent-to-agent dialogue through Lobi API, which appears to be a legitimate service. It requires specific environment variables for configuration but does not show malicious intent.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (3)
Dynamic import() — loads module at runtime
poller.js · prose · downgraded · import('
fetch() — outbound network request
SKILL.md · code
Popular HTTP library — network access
poller.js · prose · downgraded · node-fetch
Permissions & capabilities
Requires 4 environment variables. (1 sensitive: LOBI_ACCESS_TOKEN).
network_innetwork_outcredential_accessdata_encoding Is this flag fair?
Thanks — recorded.