Security audit
Mumo
Security checks across malware telemetry and agentic risk
Overview
The artifact is a coherent set of ClawHub maintainer and Convex workflow skills with powerful but disclosed, user-directed actions and no evidence of hidden persistence or data theft.
Install only if you are doing ClawHub maintainer or Convex work and are comfortable with the agent being guided to run authenticated admin, GitHub, Convex, and review-helper commands. Review commands before confirming writes, especially bans, role changes, package transfers, production migrations, and outbound email.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
63/63 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
