registry / record
github.com/the-open-agent/openagent
> throne registry github.com/the-open-agent/openagent
sealed
- scan id
- 300f0452a6b34dcfa9285d5c85012ac0
- target
- https://github.com/the-open-agent/openagent
- sealed at
- 2026-06-12 08:06:44Z
- evidence hash
- sha256:29cfb1072fb2443cd07f42957fb1c6ec0a575bbcba11cc0544f22fd96156c653
server never launched: no package.json or pyproject.toml at the repository root — Throne can launch Node (npm/pnpm/yarn) and Python (uv) projects
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
server never launched: no package.json or pyproject.toml at the repository root — Throne can launch Node (npm/pnpm/yarn) and Python (uv) projects
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
not run — server never launched
"preinstall" runs arbitrary code on every npm install: 'node -e "if (process.env.npm_execpath.indexOf(\'yarn\') === -1) throw new Error(\'Use yarn for installi'
openagent-HEAD/web/package.json139 non-local endpoint host(s) referenced in code — verify each is expected for this server's purpose: (openagent-HEAD/web/src/SkillEditPage.js:174), 01.ai (openagent-HEAD/web/src/ProviderSetting.js:143), a (openagent-HEAD/swagger/swagger-ui-bundle.js:16), ai.baidu.com (openagent-HEAD/model/context_length_util.go:22), ai.google.dev (openagent-HEAD/model/gemini.go:50), aliyun.com (openagent-HEAD/web/src/ProviderSetting.js:231), ant.design (openagent-HEAD/web/src/shadcnTheme.js:16), api-docs.deepseek.com (openagent-HEAD/model/context_length_util.go:19), api.baichuan-ai.com (openagent-HEAD/model/baichuan.go:82), api.deepseek.com (openagent-HEAD/model/deepseek.go:76), api.example.com (openagent-HEAD/web/src/ProviderSetting.js:1375), api.hunyuan.cloud.tencent.com (openagent-HEAD/model/tencentcloud.go:32), api.jina.ai (openagent-HEAD/embedding/jina.go:65), api.kimi.com (openagent-HEAD/model/moonshot.go:30), api.lingyiwanwu.com (openagent-HEAD/model/yi.go:70)
openagent-HEAD/audio/audio.go:7base64-like blob of 980 chars in a file that also decodes/executes data
openagent-HEAD/swagger/swagger-ui-bundle.js:16base64-like blob of 980 chars in a file that also decodes/executes data
openagent-HEAD/swagger/swagger-ui-es-bundle-core.js:16base64-like blob of 980 chars in a file that also decodes/executes data
openagent-HEAD/swagger/swagger-ui-es-bundle.js:16base64-like blob of 20832 chars in a file that also decodes/executes data
openagent-HEAD/swagger/swagger-ui-standalone-preset.js:16base64-like blob of 980 chars in a file that also decodes/executes data
openagent-HEAD/swagger/swagger-ui.js:16base64-like blob of 700 chars
openagent-HEAD/web/src/ResourceListPage.js:313 invisible unicode character(s) (zero-width/soft hyphen) — a known vector for hiding instructions from human review
openagent-HEAD/swagger/swagger-ui-bundle.js:163 invisible unicode character(s) (zero-width/soft hyphen) — a known vector for hiding instructions from human review
openagent-HEAD/swagger/swagger-ui-es-bundle-core.js:163 invisible unicode character(s) (zero-width/soft hyphen) — a known vector for hiding instructions from human review
openagent-HEAD/swagger/swagger-ui-es-bundle.js:162 invisible unicode character(s) (zero-width/soft hyphen) — a known vector for hiding instructions from human review
openagent-HEAD/swagger/swagger-ui-standalone-preset.js:163 invisible unicode character(s) (zero-width/soft hyphen) — a known vector for hiding instructions from human review
openagent-HEAD/swagger/swagger-ui.js:16injection-style phrase in source string: 'do not tell the user'
openagent-HEAD/tool/browser_use.go:1512maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.
this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.