Security audit
Affinity
Security checks for vulnerabilities and agentic risk
Overview
The skill bundle is transparent and purpose-aligned, with no evidence of hidden execution, exfiltration, or destructive behavior.
Install only if you trust this package to guide ClawHub maintainer and Convex development workflows. Pay special attention before running moderation commands, publishing PR proof comments, or using the autoreview helper's default full-access review mode; use dry-run, confirmation, and opt-out flags where appropriate.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
