Back to skill

Security audit

Find Management Consultant

Security checks for vulnerabilities and agentic risk

Overview

The artifacts appear to be disclosed ClawHub maintainer/developer workflow instructions, with no evidence of hidden exfiltration, deception, or destructive behavior.

Use this in a ClawHub development or maintainer context. Before running autoreview, understand that it can launch nested Codex review with full local access by default; use the documented opt-out if that authority is not acceptable.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.