Security audit
Hushh One PKM
Security checks for vulnerabilities and agentic risk
Overview
This skill gives an agent scoped instructions for accessing a user's Hussh One personal data through consent-based MCP tools, with clear limits on tokens, consent, scope, and storage.
Install this only if you intend to connect an OpenClaw agent to Hussh One PKM data. Configure the developer token through the local runtime secret mechanism, approve requests only in the Hussh One/Kai app, and keep downstream handling of decrypted personal data scoped, encrypted or masked, audited, and deletion-capable.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
