User-controlled placeholder is embedded directly into generated source code.
Critical
- Code
- suspicious.generated_source_template_injection
- Location
- SKILL.md:39
Security audit
Security checks for vulnerabilities and agentic risk
The inspected skill content is repo-focused developer guidance with high-impact commands disclosed and generally gated by user intent or confirmation.
Install only if you expect repo-maintenance behavior: these skills can run local tooling, use authenticated GitHub or ClawHub moderator commands, and in one review helper default to full-access nested Codex review. Review the commands before running moderation, publishing, deploy, or proof workflows.
Detected: suspicious.generated_source_template_injection