Security audit
Jotform
Security checks for vulnerabilities and agentic risk
Overview
The skill bundle is mostly coherent, but one review helper runs nested Codex with full filesystem access and sandbox bypass by default, so it should be reviewed before installation.
Install only if you trust the publisher and need these ClawHub/Convex maintainer workflows. Pay special attention to the autoreview helper: use its no-yolo option or equivalent safeguards if you do not want nested review runs to bypass approvals and sandboxing. For moderation, GitHub publishing, deployments, and migrations, require explicit targets and review the exact command before allowing writes.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
