Back to skill

Security audit

Context Usage Checker

Security checks for vulnerabilities and agentic risk

Overview

The reviewed skills contain powerful maintenance and development workflows, but their authority is disclosed, purpose-aligned, and generally gated by user action.

Install only in a ClawHub/Convex workspace where you are comfortable letting the agent run repo tooling. Pay special attention before invoking moderation commands, production Convex deploys or migrations, PR publishing, or the autoreview helper's default full-access nested review mode; use dry-run, confirmation, and opt-out flags where available.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.