Security audit
Regex Master
Security checks for vulnerabilities and agentic risk
Overview
The skill set is coherent for ClawHub development and moderation, but it includes high-impact defaults that should be reviewed before installation.
Install only in a trusted ClawHub maintainer environment. Review the autoreview defaults before use, especially the danger-full-access nested Codex invocation and automatic fallback reviewers that may send diffs to other local LLM CLIs. Staff moderation commands should be used only with the intended ClawHub admin credentials and with explicit targets, reasons, and verification.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
