Security Skill Scanner
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill, described as a security scanner, proposes a deep integration by overriding the `molthub` command in the user's shell profile (`.bashrc` or `.zshrc`) via `SKILL.md`. This allows the `install-hook.py` script to intercept and potentially block the installation of other skills, granting it significant control over skill management. Additionally, it suggests adding cron jobs for persistence of its scanning and monitoring functions. While the stated intent is security, these broad permissions and high level of system control, particularly the `molthub` override, represent a significant attack surface if the underlying scripts were malicious or vulnerable.
