Back to skill

Security audit

ClawdBot Blog Watcher

Security checks for vulnerabilities and agentic risk

Overview

This is a simple RSS/blog monitoring skill with no executable code, install steps, credentials, persistence, or hidden behavior.

This appears safe to install for blog and RSS tasks. Because it broadly lists shell and local file tools, only allow command execution or file reads/writes when they are clearly needed for a monitoring task you requested.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.