Back to skill

Security audit

Mumo

Security checks across malware telemetry and agentic risk

Overview

The artifact is a coherent set of ClawHub maintainer and Convex workflow skills with powerful but disclosed, user-directed actions and no evidence of hidden persistence or data theft.

Install only if you are doing ClawHub maintainer or Convex work and are comfortable with the agent being guided to run authenticated admin, GitHub, Convex, and review-helper commands. Review commands before confirming writes, especially bans, role changes, package transfers, production migrations, and outbound email.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.