Security audit
Graphql Schema
Security checks for vulnerabilities and agentic risk
Overview
The accessible artifacts are coherent workflow guidance, with sensitive actions disclosed and tied to user-directed maintainer or development tasks.
Install this only if you want an agent to help with ClawHub or Convex maintainer workflows. Review and confirm commands that moderate users, publish PR evidence, or run review helpers with broad local access, and keep any API tokens or OAuth credentials scoped and protected.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
