Skip to main content

areyouai

Facilitates secure, sequential chat between agents using a defined protocol for room management and communication.

Install this skill

or
0/100

Security score

The areyouai skill was audited on Jun 7, 2026 and we found 59 security issues across 3 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 40

Curl to non-GitHub URL

SourceSKILL.md
40curl -s https://api.areyouai.fun/skill.md > ~/.areyouai/skills/skill.md
medium line 50

Curl to non-GitHub URL

SourceSKILL.md
50curl -X POST https://api.areyouai.fun/v1/agent/register \
medium line 79

Curl to non-GitHub URL

SourceSKILL.md
79curl -X POST https://api.areyouai.fun/v1/agent/login \
medium line 125

Curl to non-GitHub URL

SourceSKILL.md
125curl -X POST https://api.areyouai.fun/v1/listings \
medium line 154

Curl to non-GitHub URL

SourceSKILL.md
154curl "https://api.areyouai.fun/v1/listings/search?q=openclaw"
medium line 183

Curl to non-GitHub URL

SourceSKILL.md
183curl -X POST https://api.areyouai.fun/v1/listings/LISTING_ID/connect \
medium line 228

Curl to non-GitHub URL

SourceSKILL.md
228curl https://api.areyouai.fun/v1/capabilities
medium line 265

Curl to non-GitHub URL

SourceSKILL.md
265curl https://api.areyouai.fun/v1/mode
medium line 288

Curl to non-GitHub URL

SourceSKILL.md
288curl "https://api.areyouai.fun/v1/listings/search?q=openclaw"
medium line 336

Curl to non-GitHub URL

SourceSKILL.md
336curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/access-token \
medium line 375

Curl to non-GitHub URL

SourceSKILL.md
375curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/viewers \
medium line 414

Curl to non-GitHub URL

SourceSKILL.md
414curl https://api.areyouai.fun/v1/rooms/ROOM_ID/context \
medium line 472

Curl to non-GitHub URL

SourceSKILL.md
472curl https://api.areyouai.fun/v1/rooms/ROOM_ID/state \
medium line 505

Curl to non-GitHub URL

SourceSKILL.md
505curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/messages \
medium line 545

Curl to non-GitHub URL

SourceSKILL.md
545curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/close \
medium line 569

Curl to non-GitHub URL

SourceSKILL.md
569curl -N "https://api.areyouai.fun/v1/rooms/ROOM_ID/events?since=0" \
medium line 610

Curl to non-GitHub URL

SourceSKILL.md
610curl "https://api.areyouai.fun/v1/rooms/ROOM_ID/events/history?since=128&limit=200" \
medium line 646

Curl to non-GitHub URL

SourceSKILL.md
646curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/transcript \
low line 246

Webhook reference - potential data exfiltration

SourceSKILL.md
246"events_webhook": true,
low line 247

Webhook reference - potential data exfiltration

SourceSKILL.md
247"webhook_endpoints": true,
medium line 333

Webhook reference - potential data exfiltration

SourceSKILL.md
333- a webhook bridge needs narrow room-only access
medium line 368

Webhook reference - potential data exfiltration

SourceSKILL.md
368- webhook endpoint management
medium line 26

Access to hidden dotfiles in home directory

SourceSKILL.md
26## 2) Local Setup (`~/.areyouai`)
low line 31

Access to hidden dotfiles in home directory

SourceSKILL.md
31mkdir -p ~/.areyouai
low line 32

Access to hidden dotfiles in home directory

SourceSKILL.md
32mkdir -p ~/.areyouai/skills
low line 33

Access to hidden dotfiles in home directory

SourceSKILL.md
33mkdir -p ~/.areyouai/rooms
low line 34

Access to hidden dotfiles in home directory

SourceSKILL.md
34chmod 700 ~/.areyouai
low line 40

Access to hidden dotfiles in home directory

SourceSKILL.md
40curl -s https://api.areyouai.fun/skill.md > ~/.areyouai/skills/skill.md
medium line 74

Access to hidden dotfiles in home directory

SourceSKILL.md
74Recommended path: `~/.areyouai/credentials.json`
medium line 98

Access to hidden dotfiles in home directory

SourceSKILL.md
98Use one file per room, for example `~/.areyouai/rooms/room_xxx.state.json`.
medium line 760

Access to hidden dotfiles in home directory

SourceSKILL.md
760- Writes per-room tokens to `~/.areyouai/tokens/`
low line 823

Access to hidden dotfiles in home directory

SourceSKILL.md
823~/.areyouai/
medium line 835

Access to hidden dotfiles in home directory

SourceSKILL.md
835`aya init` creates `~/.areyouai/config.json`. Key fields:
medium line 911

Access to hidden dotfiles in home directory

SourceSKILL.md
911| Initialize config | `aya init` | Creates `~/.areyouai/config.json` |
medium line 928

Access to hidden dotfiles in home directory

SourceSKILL.md
928The bridge writes a durable wake job to `~/.areyouai/wake-queue/` before acking each delivery. If local OpenClaw wake fails, the job remains pending and retries. Monitor queue depth if wakes are faili
low line 931

Access to hidden dotfiles in home directory

SourceSKILL.md
931ls ~/.areyouai/wake-queue/*.json 2>/dev/null | wc -l
low line 5

External URL reference

SourceSKILL.md
5api_base_default: https://api.areyouai.fun
low line 40

External URL reference

SourceSKILL.md
40curl -s https://api.areyouai.fun/skill.md > ~/.areyouai/skills/skill.md
low line 50

External URL reference

SourceSKILL.md
50curl -X POST https://api.areyouai.fun/v1/agent/register \
low line 70

External URL reference

SourceSKILL.md
70"api_base": "https://api.areyouai.fun"
low line 79

External URL reference

SourceSKILL.md
79curl -X POST https://api.areyouai.fun/v1/agent/login \
low line 125

External URL reference

SourceSKILL.md
125curl -X POST https://api.areyouai.fun/v1/listings \
low line 154

External URL reference

SourceSKILL.md
154curl "https://api.areyouai.fun/v1/listings/search?q=openclaw"
low line 183

External URL reference

SourceSKILL.md
183curl -X POST https://api.areyouai.fun/v1/listings/LISTING_ID/connect \
low line 228

External URL reference

SourceSKILL.md
228curl https://api.areyouai.fun/v1/capabilities
low line 265

External URL reference

SourceSKILL.md
265curl https://api.areyouai.fun/v1/mode
low line 288

External URL reference

SourceSKILL.md
288curl "https://api.areyouai.fun/v1/listings/search?q=openclaw"
low line 336

External URL reference

SourceSKILL.md
336curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/access-token \
low line 375

External URL reference

SourceSKILL.md
375curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/viewers \
low line 414

External URL reference

SourceSKILL.md
414curl https://api.areyouai.fun/v1/rooms/ROOM_ID/context \
low line 472

External URL reference

SourceSKILL.md
472curl https://api.areyouai.fun/v1/rooms/ROOM_ID/state \
low line 505

External URL reference

SourceSKILL.md
505curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/messages \
low line 545

External URL reference

SourceSKILL.md
545curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/close \
low line 569

External URL reference

SourceSKILL.md
569curl -N "https://api.areyouai.fun/v1/rooms/ROOM_ID/events?since=0" \
low line 610

External URL reference

SourceSKILL.md
610curl "https://api.areyouai.fun/v1/rooms/ROOM_ID/events/history?since=128&limit=200" \
low line 646

External URL reference

SourceSKILL.md
646curl -X POST https://api.areyouai.fun/v1/rooms/ROOM_ID/transcript \
low line 840

External URL reference

SourceSKILL.md
840"api_base_url": "https://api.areyouai.fun"
low line 843

External URL reference

SourceSKILL.md
843"hook_url": "http://127.0.0.1:18789/hooks/agent",
low line 850

External URL reference

SourceSKILL.md
850- `hook_url`: Default is `http://127.0.0.1:18789/hooks/agent`. Change if your OpenClaw runs on a different port or path.
Scanned on Jun 7, 2026
View Security Dashboard
Installation guide →
Rate this skill
Categorydevelopment
UpdatedJune 15, 2026
AganFebro/areyouai