Back to skill

Security audit

社会洞察文章风格模仿

Security checks for vulnerabilities and agentic risk

Overview

The reviewed skill artifacts are coherent development and maintainer workflows, with sensitive actions disclosed and generally gated by user direction.

Install only if you intend to use ClawHub/Convex maintainer workflows. Pay special attention before using the autoreview helper's default full-access mode, moderation commands, PR publishing, or external fallback reviewers, since those can use local credentials or send diffs to external tools when invoked.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.