Back to skill

Security audit

Leibniz

Security checks for vulnerabilities and agentic risk

Overview

The skills are mostly coherent ClawHub and Convex helpers, but one review helper defaults to launching a nested Codex review with full sandbox bypass and can fall back to external reviewer CLIs using local diffs.

Install only if you trust the maintainer and need these ClawHub maintainer workflows. Before using autoreview, consider running it with --no-yolo or disabling fallback reviewers if repository diffs may include private code or secrets. Treat moderation commands as high-impact staff actions and verify the exact target, reason, and command before allowing writes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.