{"skill":{"slug":"dcl-provenance-tracker","displayName":"DCL Provenance Tracker — Supply Chain & Version Drift Verifier","summary":"Verify the integrity and version history of any ClawHub skill after an update. After ClawHavoc incidents where thousands of skills silently changed behavior...","tags":{"latest":"1.0.0"},"stats":{"comments":0,"downloads":98,"installsAllTime":0,"installsCurrent":0,"stars":0,"versions":1},"createdAt":1775790270728,"updatedAt":1775791006809},"latestVersion":{"version":"1.0.0","createdAt":1775790270728,"changelog":"Initial release of DCL Provenance Tracker — deterministic security verification for ClawHub skills.\n\n- Compares two versions of a skill side-by-side to detect supply chain attacks and behavioral drift.\n- Detects 30+ critical, major, and minor risk patterns: credential exfiltration, permission creep, prompt drift, and structural anomalies.\n- Operates instruction-only — no network calls or data exfiltration; analysis is fully local.\n- Produces a DCL provenance proof hash for each analysis, ensuring update integrity.\n- Designed for use after every skill update, in CI/CD, or on a schedule for critical skills.\n- Part of the Leibniz Layer™ security suite from Fronesis Labs.","license":"MIT-0"},"metadata":null,"owner":{"handle":"daririnch","userId":"s177qzsztsa0qx35zmdc3g65s184c673","displayName":"Dari Rinch","image":"https://avatars.githubusercontent.com/u/161933416?v=4"},"moderation":{"isSuspicious":true,"isMalwareBlocked":false,"verdict":"suspicious","reasonCodes":["suspicious.prompt_injection_instructions"],"summary":"Detected: suspicious.prompt_injection_instructions","engineVersion":"v2.2.0","updatedAt":1775791006809}}