Meyhem Capabilities

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do the advertised capability search, but users should avoid putting secrets or proprietary details in the search query because it is sent to an external API.

This skill is reasonable to install if you are comfortable sending capability-search queries to api.rhdxm.com. Keep searches generic and do not include secrets, private code, customer data, or proprietary internal details.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI07: Insecure Inter-Agent Communication
Low
What this means

Anything typed into the capability search may be sent to the external service, so sensitive business details or secrets included in the query could leave the local environment.

Why it was flagged

The skill explicitly communicates with an external provider and transmits user-provided query text. This is purpose-aligned and disclosed, but users should understand the data boundary.

Skill content
This skill sends your search query to `api.rhdxm.com`. The skill does not access local files, environment variables, or credentials on its own, but anything you include in the query will be transmitted. Avoid sending sensitive or proprietary content.
Recommendation

Use general task descriptions and avoid including credentials, private customer data, proprietary project details, or other sensitive information in search queries.