Security audit
Easter
Security checks for vulnerabilities and agentic risk
Overview
The reviewed skill artifacts are coherent developer and ClawHub maintainer workflows with elevated actions disclosed and generally gated by user intent or existing authorization.
Install only if you want these maintainer and Convex development workflows available to your agent. Be especially mindful before using the ClawHub moderation skill or the autoreview helper's default full-access nested review mode; use the documented confirmation steps and opt-outs when working in sensitive environments.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
