Security audit
Localization Readiness Audit
Security checks across malware telemetry and agentic risk
Overview
This appears to be a coherent ClawHub maintainer/developer skill bundle, but one review helper defaults to running nested Codex with full local access, so users should review it before installing.
Install only if you intend to use these ClawHub maintainer and Convex development workflows. Before running autoreview, prefer `--no-yolo` or set `AUTOREVIEW_YOLO=0` unless full local access is truly needed. Use scoped ClawHub/GitHub credentials, confirm any moderation or publishing target carefully, and avoid sending private diffs to fallback review tools unless that is acceptable for your project.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
61/61 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
