Get a demo — 30 minutes →
Skill scan report

qwen-agent

View on GitHub
35 Medium Automated analysis flagged 2 potential risk patterns.

What this skill does

Delegate menial, well-scoped coding tasks to a Qwen-backed subagent via the `claude-9arm` command

github/thananon - Security Misconfiguration - 3.1k stars

ThreatsSecurity Misconfiguration Insecure Defaults

Threat analysis

Security Misconfiguration1 finding
Insecure Defaults1 finding

Skill info

Namethananon/qwen-agent
Registrygithub
Versiona1fc303
PURLpkg:github/thananon/9arm-skills@a1fc303?skill=qwen-agent
Stars3.1k

Assessments (2)

Security Misconfiguration1 finding HIGH
HIGH

Security Misconfiguration via local-llm-review

SKILL.md

The `claude-9arm` alias is defined as `claude --model qwen3.6-35b-a3b` routed through the 9arm gateway. This could be a misconfiguration or a potential attack vector if the '9arm' gateway is not prope
Insecure Defaults1 finding MEDIUM
MEDIUM

Insecure Defaults via local-llm-review

SKILL.md

The alias bakes in `--allowedTools '*'`, which is explicitly noted to be silently ignored by Claude Code with a warning. This could lead to unexpected behavior or security risks if the intended allowe

Badge

Add the Anomity scan badge for qwen-agent to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/thananon/qwen-agent/)
HTML
<a href="https://anomity.ai/skills/github/thananon/qwen-agent/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of qwen-agent? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok