Back to skill

Security audit

Draft Docs

Security checks for vulnerabilities and agentic risk

Overview

The skill artifacts are coherent developer and ClawHub staff workflows with explicit safety gates for the higher-impact actions.

Install this only in an environment where these workflows are appropriate. The ClawHub moderation, content-rights, and migration skills can affect users, public content, emails, or production data if the operator has valid admin credentials, so users should keep the documented dry-run, signoff, and confirmation gates in place.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.