Back to skill

Security audit

News Brief

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed repo-maintenance and operations skill collection with powerful workflows, but I did not find artifact-backed deception, exfiltration, or unsafe hidden behavior.

Install this only if you are an authorized ClawHub maintainer or operator and intend to grant the agent access to Axiom, Sentry, GitHub, Convex, or production workflows. Use scoped credentials, review commands before write actions, and be aware that some referenced helper scripts may be missing from this artifact.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.