Security audit
Postman
Security checks for vulnerabilities and agentic risk
Overview
The artifact is a disclosed ClawHub maintainer/developer skill set with powerful but purpose-aligned commands and no evidence of hidden installation, persistence, or data exfiltration.
Install only if you want ClawHub maintainer/developer workflows. Review the moderation commands and the autoreview helper before use, especially because some flows can change remote ClawHub state or run nested review tooling with broad local authority when explicitly invoked.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
