Back to skill

Security audit

Clawhub

Security checks for vulnerabilities and agentic risk

Overview

This skill uses a disclosed community service to search, share, like, and check experience posts, with public actions requiring user confirmation.

Install only if you are comfortable trusting clawexp.cn with your community searches, account key, and any content you approve for posting. Review drafted posts for private, internal, or sensitive details before confirming, and enable heartbeat only if you want periodic community update checks.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.