Clawhub Github Publish IYLRMS

Security checks across malware telemetry and agentic risk

Overview

Files and runtime instructions align with a Kepler bookmark/memory plugin: it opens an OAuth session with keplerbrowser.com and proxies an MCP endpoint via a local stdio bridge; nothing requested is disproportionate to that purpose.

This skill appears to do what it says: bridge your agent to Kepler's hosted MCP so the agent can save and recall links. Before installing or running it: 1) Confirm you trust keplerbrowser.com and review their privacy policy (plugin contacts https://app.keplerbrowser.com/mcp). 2) Be aware the proxy will open a browser for OAuth and a token will be cached at ~/.fastmcp/oauth-mcp-client-cache; delete that file to revoke local access. 3) The runtime uses a PyPI package (fastmcp>=3,<4) fetched when you run the proxy—inspect that package/source if you have supply-chain concerns. 4) The plugin requests read/write capabilities to your stored links (normal for a bookmark/memory tool) — only proceed if you want the agent to be able to save and retrieve your links. If you want more assurance, review the small run_proxy.py and the SKILL.md instructions; no other hidden endpoints or unrelated credentials were found.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal