Myosin Hivemind Knowledge Retrieval
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is benign. The `hivemind-search.mjs` script correctly implements environment variable resolution, explicitly restricting file system access to `~/.openclaw/.env` and `~/.openclaw/openclaw.json` to only `HIVEMIND_*` keys via a strict `ALLOWED_KEYS` set, preventing arbitrary credential exfiltration. Network calls are made to a specified API endpoint for its stated purpose. The `SKILL.md` instructions guide the AI agent on how to effectively use the knowledge base, focusing on output quality and authority, without any directives for prompt injection that would lead to unauthorized actions, data exfiltration, or subversion of the agent's core function.
