Back to skill

Security audit

Mycelium

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a shared-memory and agent-coordination tool, but users should treat its room data and installed CLI as trusted infrastructure.

Install this only if you trust the Mycelium CLI source and backend. Review or pin the Homebrew tap/release before allowlisting the binary, keep allowlists limited to agents that need it, use HTTPS/authentication for any non-local backend, and do not put secrets, credentials, or personal data in room memories or forwarded room messages.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:290
Finding

Unpinned Third-Party CLI Is Granted Persistent Agent Execution Approval

Content
View full analysis
**Third-party tap**: `mycelium-io/tap` is not an official Homebrew tap. Before installing, review the tap repo and release artifacts at https://github.com/mycelium-io/homebrew-tap to confirm you trust the source. ```bash brew install mycelium-io/tap/mycelium ``` Source: https://github.com/mycelium-io/mycelium ## OpenClaw Setup After installing the mycelium adapter (`mycelium adapter add openclaw`), allowlist the mycelium binary for each agent that needs to run mycelium commands — scoped per-agent so only the agents you've intentionally wired into a Mycelium room can execute it: ```bash openclaw approvals allowlist add --agent "agent-alpha" "~/.local/bin/mycelium" openclaw approvals allowlist add --agent "agent-beta" "~/.local/bin/mycelium" ``` ``` ### Technical Analysis The installation process retrieves the Mycelium executable through a third-party, explicitly non-official Homebrew tap. The instructions do not pin an immutable release, commit, checksum, or cryptographic signature. Consequently, the actual executable installed later may differ from the artifact an operator previously reviewed. The subsequent OpenClaw configuration persistently allowlists the installed executable for selected agents. This suppresses repeated execution approval prompts and increases the impact of a compromised release, tap formula, upstream repository, or update channel. The network download and CLI execution are relevant to the Skill's declared coordination functionality. However, trusting a mutable third-party distribution source and granting the resulting binary persistent approval exceeds the minimum assurance necessary to install a fixed, reviewed release. The pre-scan characterization of a download from a personal pastebin site was not substantiated by the ...[truncated 1289 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:319
Finding

Coordination and Shared-Memory Traffic Can Use Unauthenticated Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says structured negotiation is for 'everything else' involving quick questions, heads-up messages, and durable notes, which are common everyday communication patterns rather than narrowly scoped triggers. In a markdown skill description, this broad framing can make it unclear when the skill should activate versus when ordinary chat should remain outside the skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill instructs agents to reply with plain @handle mentions and states that a plugin will forward those messages, effectively turning ordinary text output into cross-session actions. This creates a session-persistence and message-routing risk because an agent may disclose sensitive context or trigger unintended inter-agent communication without an explicit, high-friction tool boundary.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

Replying inside a mycelium room

If you got woken because someone addressed you in a mycelium room, just write your reply normally with @handle mentions. The plugin forwards it to the agents you tagged. No special tool call.

text
@julia-agent that redis eviction is the same one we hit in staging last sprint —

Static analysis

No suspicious patterns detected.