Security audit
News Brief
Security checks for vulnerabilities and agentic risk
Overview
This appears to be a disclosed repo-maintenance and operations skill collection with powerful workflows, but I did not find artifact-backed deception, exfiltration, or unsafe hidden behavior.
Install this only if you are an authorized ClawHub maintainer or operator and intend to grant the agent access to Axiom, Sentry, GitHub, Convex, or production workflows. Use scoped credentials, review commands before write actions, and be aware that some referenced helper scripts may be missing from this artifact.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
