Security audit
Cost Guardian by Dexter Labs
Security checks for vulnerabilities and agentic risk
Overview
The skill artifacts are coherent maintainer/developer guidance for ClawHub and Convex workflows, with sensitive actions disclosed and mostly gated by user intent.
This appears suitable for ClawHub/Convex maintainers. Before installing, be comfortable with commands that can run repo tests, contact GitHub or Convex, perform staff moderation through authenticated APIs, and run the autoreview helper with broad local access unless you use its no-yolo option.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
