Security audit
Browserbase
Security checks for vulnerabilities and agentic risk
Overview
This looks like a legitimate ClawHub developer skill bundle, but review is warranted because one helper defaults to running nested Codex review with full sandbox bypass privileges.
Install only if you trust this publisher and intend to use it for ClawHub repo maintenance. Before using `autoreview`, consider setting `AUTOREVIEW_YOLO=0` or passing `--no-yolo`, and be aware that fallback reviewers may receive local diffs. Use the moderation workflows only with the intended ClawHub staff account because they can ban users, change roles, unhide skills, and write audit logs.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
