Back to skill

Security audit

ClawHub 技能发布指南

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned and no artifact-backed security concern was found in the supplied scan signals or available workspace evidence.

This looks safe to install based on the available evidence. As with any skill, review the instructions before use and only approve commands or external-service access that match your intended workflow.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.