activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
Crawler Summary
Interact with VirusTotal API v3 for threat intelligence, file/URL/IP/domain analysis, and malware hunting. Use when looking up hashes, scanning files/URLs, investigating IOCs (IPs, domains), searching VT Intelligence, retrieving analysis reports, checking file reputations, or working with threat intelligence data from VirusTotal. --- name: virustotal-api description: Interact with VirusTotal API v3 for threat intelligence, file/URL/IP/domain analysis, and malware hunting. Use when looking up hashes, scanning files/URLs, investigating IOCs (IPs, domains), searching VT Intelligence, retrieving analysis reports, checking file reputations, or working with threat intelligence data from VirusTotal. --- VirusTotal API v3 Query VirusTotal for threat Capability contract not published. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 4/15/2026.
Freshness
Last checked 4/15/2026
Best For
virustotal-api is best for file, url, a workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack
Interact with VirusTotal API v3 for threat intelligence, file/URL/IP/domain analysis, and malware hunting. Use when looking up hashes, scanning files/URLs, investigating IOCs (IPs, domains), searching VT Intelligence, retrieving analysis reports, checking file reputations, or working with threat intelligence data from VirusTotal. --- name: virustotal-api description: Interact with VirusTotal API v3 for threat intelligence, file/URL/IP/domain analysis, and malware hunting. Use when looking up hashes, scanning files/URLs, investigating IOCs (IPs, domains), searching VT Intelligence, retrieving analysis reports, checking file reputations, or working with threat intelligence data from VirusTotal. --- VirusTotal API v3 Query VirusTotal for threat
Public facts
5
Change events
1
Artifacts
0
Freshness
Apr 15, 2026
Capability contract not published. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 4/15/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Apr 15, 2026
Vendor
Neo23x0
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 4/15/2026.
Setup snapshot
git clone https://github.com/Neo23x0/virustotal-skill.gitSetup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Neo23x0
Protocol compatibility
OpenClaw
Adoption signal
1 GitHub stars
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
5
Snippets
0
Languages
typescript
Parameters
bash
echo -n "http://example.com" | sha256sum
bash
# Look up a file hash vt-file-lookup.sh d41d8cd98f00b204e9800998ecf8427e # Download malware sample (premium) vt-file-download.sh d41d8cd98f00b204e9800998ecf8427e /tmp/sample.bin # Scan a suspicious URL vt-url-scan.sh "http://suspicious.example.com" # Search for recent malware vt-search.sh "type:peexe positives:10+ first_submission_date:7d-" # Get IP relationships vt-relationships.sh ip 8.8.8.8 communicating_files
bash
# List all rulesets vt-livehunt-rulesets.sh list # Create a new ruleset from YARA file vt-livehunt-rulesets.sh create "Ransomware Detector" rules.yar true # Enable/disable ruleset vt-livehunt-rulesets.sh update abc123 enabled false # View notifications (matches) vt-livehunt-notifications.sh list 50 # Delete all notifications vt-livehunt-notifications.sh delete all
bash
# List retrohunt jobs vt-retrohunt.sh list # Create job (scans 500M+ files from past 3-12 months) vt-retrohunt.sh create rules.yar --corpus main --time-range 3m # Check job status vt-retrohunt.sh get job_id # Get matching files vt-retrohunt.sh matches job_id 100 # Abort running job vt-retrohunt.sh abort job_id
yara
rule NewHighDetections {
condition:
new_file and positives > 10
}Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB OPENCLEW
Editorial quality
ready
Interact with VirusTotal API v3 for threat intelligence, file/URL/IP/domain analysis, and malware hunting. Use when looking up hashes, scanning files/URLs, investigating IOCs (IPs, domains), searching VT Intelligence, retrieving analysis reports, checking file reputations, or working with threat intelligence data from VirusTotal. --- name: virustotal-api description: Interact with VirusTotal API v3 for threat intelligence, file/URL/IP/domain analysis, and malware hunting. Use when looking up hashes, scanning files/URLs, investigating IOCs (IPs, domains), searching VT Intelligence, retrieving analysis reports, checking file reputations, or working with threat intelligence data from VirusTotal. --- VirusTotal API v3 Query VirusTotal for threat
Query VirusTotal for threat intelligence on files, URLs, IPs, and domains. Supports lookups, scans, Intelligence searches, and relationship exploration.
Store your API key in ~/.virustotal/apikey or set VT_API_KEY environment variable.
| Task | Endpoint | Script |
|------|----------|--------|
| Get file report | GET /files/{hash} | vt-file-lookup.sh {hash} |
| Upload & scan file | POST /files | vt-file-scan.sh {path} |
| Download file | GET /files/{hash}/download | vt-file-download.sh {hash} |
| Get URL report | GET /urls/{url_id} | vt-url-lookup.sh {url} |
| Scan URL | POST /urls | vt-url-scan.sh {url} |
| Get domain report | GET /domains/{domain} | vt-domain-lookup.sh {domain} |
| Get IP report | GET /ip_addresses/{ip} | vt-ip-lookup.sh {ip} |
| Intelligence search | GET /intelligence/search | vt-search.sh "query" |
| Get relationships | GET /{obj}/{id}/{rel} | vt-relationships.sh {type} {id} {rel} |
| Livehunt Rulesets | GET /intelligence/hunting_rulesets | vt-livehunt-rulesets.sh list |
| Livehunt Notifications | GET /intelligence/hunting_notifications | vt-livehunt-notifications.sh list |
| Retrohunt Jobs | GET /intelligence/retrohunt_jobs | vt-retrohunt.sh list |
URL endpoints use SHA256(URL) as ID. Generate with:
echo -n "http://example.com" | sha256sum
Files: communicating_files, downloaded_files, contacted_domains, contacted_ips, embedded_domains, embedded_ips, parent, children
URLs: last_serving_ip_address, network_location, redirects_to
Domains: resolutions, subdomains, referrer_files, communicating_files
IPs: resolutions, communicating_files, downloaded_files
| Category | Meaning |
|----------|---------|
| harmless | Clean/not malicious |
| undetected | No opinion from engine |
| suspicious | Suspicious behavior |
| malicious | Confirmed malicious |
| timeout | Engine timed out |
content:"string" - File content searchtype:peexe - File typesize:1MB- - File sizepositives:5+ - Detection counttag:ransomware - Tagssubmissions:10+ - Times submittedfirst_submission_date:2024-01-01+ - Date range# Look up a file hash
vt-file-lookup.sh d41d8cd98f00b204e9800998ecf8427e
# Download malware sample (premium)
vt-file-download.sh d41d8cd98f00b204e9800998ecf8427e /tmp/sample.bin
# Scan a suspicious URL
vt-url-scan.sh "http://suspicious.example.com"
# Search for recent malware
vt-search.sh "type:peexe positives:10+ first_submission_date:7d-"
# Get IP relationships
vt-relationships.sh ip 8.8.8.8 communicating_files
# List all rulesets
vt-livehunt-rulesets.sh list
# Create a new ruleset from YARA file
vt-livehunt-rulesets.sh create "Ransomware Detector" rules.yar true
# Enable/disable ruleset
vt-livehunt-rulesets.sh update abc123 enabled false
# View notifications (matches)
vt-livehunt-notifications.sh list 50
# Delete all notifications
vt-livehunt-notifications.sh delete all
# List retrohunt jobs
vt-retrohunt.sh list
# Create job (scans 500M+ files from past 3-12 months)
vt-retrohunt.sh create rules.yar --corpus main --time-range 3m
# Check job status
vt-retrohunt.sh get job_id
# Get matching files
vt-retrohunt.sh matches job_id 100
# Abort running job
vt-retrohunt.sh abort job_id
| Variable | Description |
|----------|-------------|
| positives | Detection count |
| new_file | First time submitted |
| signatures | All AV signatures |
| file_type | File type string |
| submissions | Submission count |
Example YARA for Livehunt:
rule NewHighDetections {
condition:
new_file and positives > 10
}
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/contract"
curl -s "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
The Frontend for Agents & Generative UI. React + Angular
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_OPENCLEW",
"generatedAt": "2026-10-09T13:07:06.629Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "file",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "url",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "a",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "lookups",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:file|supported|profile capability:url|supported|profile capability:a|supported|profile capability:lookups|supported|profile"
}Facts JSON
[
{
"factKey": "docs_crawl",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"category": "integration",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "vendor",
"label": "Vendor",
"value": "Neo23x0",
"category": "vendor",
"href": "https://github.com/Neo23x0/virustotal-skill",
"sourceUrl": "https://github.com/Neo23x0/virustotal-skill",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T02:14:58.402Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "protocols",
"label": "Protocol compatibility",
"value": "OpenClaw",
"category": "compatibility",
"href": "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-04-15T02:14:58.402Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "traction",
"label": "Adoption signal",
"value": "1 GitHub stars",
"category": "adoption",
"href": "https://github.com/Neo23x0/virustotal-skill",
"sourceUrl": "https://github.com/Neo23x0/virustotal-skill",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T02:14:58.402Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "handshake_status",
"label": "Handshake status",
"value": "UNKNOWN",
"category": "security",
"href": "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/neo23x0-virustotal-skill-2/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true,
"metadata": {}
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true,
"metadata": {}
}
]Sponsored
Ads related to virustotal-api and adjacent AI workflows.