Back to skill

Security audit

APIVoid

Security checks for vulnerabilities and agentic risk

Overview

The skill bundle is broad and operational, but its API access, admin commands, local scripts, and persistence are disclosed and fit the stated ClawHub/OpenClaw/Axiom workflows.

Install only in an environment where you intentionally want these operational skills. Review the Axiom SRE memory/config behavior and the ClawHub moderation/release skills before use, and keep their API tokens and admin credentials scoped to the minimum permissions needed.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.