Back to skill

Security audit

Deepvista Recipe Export Knowledge As Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill bundle is a coherent set of ClawHub and Convex developer workflows, with sensitive actions disclosed and generally gated by user intent or confirmation.

Install only if you want these maintainer-oriented workflows available to your agent. Before using moderation, PR publishing, or autoreview commands, check the exact command being run and make sure you are comfortable with any repo diffs being sent to configured review tools; use the documented opt-outs such as --no-yolo or disabling fallback reviewers when needed.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.