Security audit
Digital Twin Security
Security checks for vulnerabilities and agentic risk
Overview
The available skill artifacts are coherent developer workflow guides with disclosed command use and no evidence of hidden exfiltration, destructive behavior, or deceptive instructions.
Install only if you want these repo-maintenance and Convex/ClawHub workflows. Review the autoreview helper before using its default full-access nested review mode, and only run moderation, GitHub, package installation, Convex deployment, or migration commands when you understand the target and have the right account permissions.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
