Security audit
Taskqueue
Security checks for vulnerabilities and agentic risk
Overview
The available skill content is coherent developer and maintainer guidance, with powerful actions disclosed and tied to explicit user-directed workflows.
Install only if you intend to use these ClawHub maintainer workflows. Be especially careful with staff moderation commands and the autoreview helper: run them in the intended repo, keep credentials scoped, review commands before execution, and use the documented opt-outs when full-access review is not appropriate.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
