Back to skill

Security audit

Property Management Dispute

Security checks for vulnerabilities and agentic risk

Overview

The skills are broad and sometimes powerful, but their behavior is disclosed, task-focused, and gated by user confirmation or existing authenticated CLIs.

Install only if you expect these staff/developer workflows. Reviewers and Convex/GitHub/ClawHub commands can expose code or affect live systems through your existing credentials, so use the confirmation gates carefully and avoid running production or admin commands unless you understand the target and impact.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.