Security audit
论文作者档案生成器
Security checks for vulnerabilities and agentic risk
Overview
The skill set is coherent for ClawHub maintenance, but it includes powerful moderation workflows and a review helper that defaults to running nested Codex with full sandbox bypass.
Install only in a trusted ClawHub maintainer environment. Before using autoreview, consider setting its no-yolo option or environment override to avoid full sandbox bypass, and be aware that fallback reviewers may send code diffs to external model tools. Use moderation commands only with an explicit target, reason, and confirmation because they can make persistent account or content changes.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
