AI Product Launch — Technical GTM for AI-Native Products
Security checks across malware telemetry and agentic risk
Overview
The skill set is mostly coherent for ClawHub and Convex maintenance, but one review helper defaults to bypassing Codex sandbox and approval controls, which is high-impact enough to require review before installation.
Install only if you trust this skill set to assist with ClawHub maintainer workflows. Before using `autoreview`, consider setting `AUTOREVIEW_YOLO=0` or passing `--no-yolo`, and confirm whether fallback LLM CLIs may receive code diffs. Use the moderation and publish workflows only with explicit targets, reasons, and account permissions you are comfortable applying.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
