Back to skill

Security audit

Jotform

Security checks for vulnerabilities and agentic risk

Overview

The skill bundle is mostly coherent, but one review helper runs nested Codex with full filesystem access and sandbox bypass by default, so it should be reviewed before installation.

Install only if you trust the publisher and need these ClawHub/Convex maintainer workflows. Pay special attention to the autoreview helper: use its no-yolo option or equivalent safeguards if you do not want nested review runs to bypass approvals and sandboxing. For moderation, GitHub publishing, deployments, and migrations, require explicit targets and review the exact command before allowing writes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.