Back to skill

Security audit

Clawhub

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed local indexing and charting workflow for public financial-expert statements, with proportionate local database and network behavior.

Install only if you are comfortable keeping supplied public-source quotes, dates, URLs, and provenance in a local SQLite database. Confirm the runtime pin before use, avoid private or sensitive source material unless you have explicit permission, and approve network use only when generating or opening interactive charts.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document instructs operators to ingest full post text and run import steps that modify a persistent SQLite database, but it does not pair those actions with a clear user-facing consent/persistence warning at the operational step where data is stored. In an agent setting, this can cause unintended retention of copyrighted, sensitive, or user-provided material and unintended database changes without an explicit confirmation boundary.

Static analysis

No suspicious patterns detected.