Security audit
Censys
Security checks for vulnerabilities and agentic risk
Overview
The skill set is coherent for ClawHub and Convex development work, with sensitive actions disclosed and mostly guarded by user confirmation or normal tool authentication.
Install only if you want ClawHub/Convex maintainer automation. Before using the moderation, PR publishing, or autoreview helper flows, confirm the target and command because they can affect accounts, GitHub PRs, local code review execution, or authenticated service state.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
