Back to skill

Security audit

linkedin-posts

Security checks for vulnerabilities and agentic risk

Overview

The visible skill artifacts are coherent ClawHub and Convex maintainer aids, with powerful but disclosed commands that require careful use.

Install only if you are doing ClawHub or Convex maintainer work and are comfortable with local CLI execution and authenticated GitHub/Convex operations. Use moderation and publishing commands only with explicit targets and reasons, and consider running autoreview with its safer no-yolo option when sandbox bypass is not needed.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.