Back to skill

Security audit

Localization Readiness Audit

Security checks across malware telemetry and agentic risk

Overview

This appears to be a coherent ClawHub maintainer/developer skill bundle, but one review helper defaults to running nested Codex with full local access, so users should review it before installing.

Install only if you intend to use these ClawHub maintainer and Convex development workflows. Before running autoreview, prefer `--no-yolo` or set `AUTOREVIEW_YOLO=0` unless full local access is truly needed. Use scoped ClawHub/GitHub credentials, confirm any moderation or publishing target carefully, and avoid sending private diffs to fallback review tools unless that is acceptable for your project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.