Back to skill

Security audit

MuHaven RWA Portfolio (rehearsal)

Security checks across malware telemetry and agentic risk

Overview

This wallet-related skill is mostly coherent and disclosed, but it needs Review because it can affect account policy and relies on sandbox protections that the artifacts say may be advisory in the current runtime.

Install only if you intend to connect this agent to your MuHaven account and broker. Prefer read-only mode first, verify you are using the legitimate @muhaven/mcp broker and endpoint, confirm whether your OpenClaw runtime enforces the declared sandbox, and treat buy, claim, and pause prompts as financial/account-control actions that should only be approved when you initiated them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
The manifest and prose frame the skill as only drafting buys and claims, yet the exposed tool subset also includes a kill-switch style `policy.pause` operation. Even if pause is safety-oriented, it is still a state-mutating control plane action that broadens the skill’s authority beyond the stated investor-facing scope and could be abused to disrupt account activity.

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The documentation says the skill 'cannot store any secret,' but the manifest explicitly declares secret storage via OS keychain for a referenced JWT. Even if the secret belongs to the broker rather than the skill process, this contradiction can mislead reviewers and users about where credentials exist and how compromise of the broader deployment could expose them.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.