Your super agent for work: local-first, learn your working context in mins and never forget it.
- capability exposureinferred+35
- trust mitigatorsmixed−3
inferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 10m ago · see ecosystem CVEs →
- A · 0 → B · 32
No known CVEs for this server.
No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.
analyzed commit f52b580 · analyzer v17 · 2d ago
skills & prompt files 13
- agent-rulesholaboss-ai-holaOS-f52b580/AGENTS.md
- agent-rulesholaboss-ai-holaOS-f52b580/apps/desktop/CLAUDE.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/app-builder-sdk/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/browser-core-efficient/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/browser-qa/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/build-dashboard/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/create-teammate/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/frontend-design/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/interface-design/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/mcp-configurator/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/skill-creator/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/skill-installer/SKILL.md
- skillholaboss-ai-holaOS-f52b580/runtime/harnesses/src/embedded-skills/stop-slop/SKILL.md
danger signals3
- suspicious endpointt.meholaboss-ai-holaOS-f52b580/sdk/app-builder-sdk/reference/telegram-messaging/app.ts:98
return `https://t.me/${ref.slice(1)}/${r.external_id}` - suspicious endpointapi.telegram.orgholaboss-ai-holaOS-f52b580/sdk/app-builder-sdk/reference/telegram-messaging/provider.ts:5
baseUrl: "https://api.telegram.org", - over-broad OAuth scopehttps://mail.google.com/holaboss-ai-holaOS-f52b580/sdk/app-builder-sdk/reference/post-analytics/src/client/lib/sample-data.ts:205
gmailUrl: "https://mail.google.com/mail/u/0/#sent/abc",
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of holaboss-ai.