Back to skill

Security audit

Graphql Schema

Security checks for vulnerabilities and agentic risk

Overview

The accessible artifacts are coherent workflow guidance, with sensitive actions disclosed and tied to user-directed maintainer or development tasks.

Install this only if you want an agent to help with ClawHub or Convex maintainer workflows. Review and confirm commands that moderate users, publish PR evidence, or run review helpers with broad local access, and keep any API tokens or OAuth credentials scoped and protected.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.