Back to skill

Security audit

Regex Master

Security checks for vulnerabilities and agentic risk

Overview

The skill set is coherent for ClawHub development and moderation, but it includes high-impact defaults that should be reviewed before installation.

Install only in a trusted ClawHub maintainer environment. Review the autoreview defaults before use, especially the danger-full-access nested Codex invocation and automatic fallback reviewers that may send diffs to other local LLM CLIs. Staff moderation commands should be used only with the intended ClawHub admin credentials and with explicit targets, reasons, and verification.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.