Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/pixelletter.mjs:6
Security audit
Security checks across malware telemetry and agentic risk
The submitted skill artifacts are coherent maintainer and Convex workflow helpers with disclosed command use and no evidence of hidden exfiltration, persistence, or destructive behavior.
Install only if you want agent assistance with ClawHub maintainer and Convex development workflows. Pay particular attention before running moderation commands, proof publishing, auth setup, package installs, or the autoreview helper's default full-access nested review mode; use the documented confirmation and opt-out controls when appropriate.
66/66 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access