Security audit
Deepvista Recipe Export Knowledge As Skills
Security checks for vulnerabilities and agentic risk
Overview
The skill bundle is a coherent set of ClawHub and Convex developer workflows, with sensitive actions disclosed and generally gated by user intent or confirmation.
Install only if you want these maintainer-oriented workflows available to your agent. Before using moderation, PR publishing, or autoreview commands, check the exact command being run and make sure you are comfortable with any repo diffs being sent to configured review tools; use the documented opt-outs such as --no-yolo or disabling fallback reviewers when needed.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
