Security audit
Skillet Security Sweep
Security checks for vulnerabilities and agentic risk
Overview
The reviewed artifacts are coherent ClawHub maintenance/review skills with disclosed admin and code-review capabilities, not hidden or deceptive behavior.
Install this only in a ClawHub maintainer context. Several workflows can affect users, packages, emails, or production data, so operators should keep the documented confirmation, dry-run, backup, and audit-log steps in place and avoid using staff commands casually.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
