Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Mboum
v1.0.2Mboum integration. Manage Persons, Organizations, Deals, Leads, Projects, Activities and more. Use when the user wants to interact with Mboum data.
⭐ 0· 181·0 current·0 all-time
byMembrane Dev@membranedev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (Mboum data management) align with the instructions (using Membrane to connect, list actions, run actions, and proxy requests to the Mboum API). No unrelated credentials, binaries, or config paths are requested.
Instruction Scope
SKILL.md only instructs installing/using the Membrane CLI, logging in via browser, creating connections, listing/running actions, and proxying API requests — all within the stated goal of interacting with Mboum. It does not ask to read local secrets or unrelated system files.
Install Mechanism
No install spec in the registry (instruction-only). The instructions recommend installing @membranehq/cli via npm (global install); this is a reasonably expected mechanism but carries the usual caution for third-party npm packages. The SKILL also shows npx usage, which avoids global install.
Credentials
The skill declares no required env vars or credentials and relies on Membrane to manage authentication. That is proportionate to the stated purpose. The SKILL.md explicitly advises not to ask users for API keys.
Persistence & Privilege
always:false, no code files, no install actions recorded in the registry — the skill does not request persistent presence or elevated agent privileges and does not modify other skills or system-wide settings.
Assessment
This skill is instruction-only and coherent: it uses Membrane's CLI to authenticate and proxy calls to Mboum. Before installing or running the CLI, verify you trust the @membranehq/cli npm package and the Membrane service (review their homepage, docs, and privacy/security policy). Prefer using npx or a local install if you want to avoid a global npm install. Be aware that the Membrane proxy can send arbitrary API requests to Mboum — ensure you understand what data you’re allowing the proxy to access and confirm the connection scopes during the Membrane login/connection step.Like a lobster shell, security has layers — review code before you run it.
latestvk97avzs60wdg4bqf9kscdshn8h843vv0
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
