Security audit
Design Systems Index
Security checks for vulnerabilities and agentic risk
Overview
The skill bundle contains disclosed ClawHub and Convex operational workflows, including some powerful staff actions, but the instructions are scoped, gated, and purpose-aligned.
Install this only in a maintainer or staff context where ClawHub, Convex, GitHub, and reviewer CLI access are expected. Treat moderation, email, role, package transfer, and production migration commands as privileged operations: review the exact command, confirm the target and reason, and keep the built-in dry-run/signoff/audit steps in place.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
