Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
The artifacts describe ClawHub and Convex maintainer/development workflows with sensitive but disclosed actions that fit their stated purposes.
Install only if you want ClawHub/Convex maintainer automation. Review the autoreview helper before use because it defaults to full-access nested Codex review, and use the moderation and publishing workflows only with the intended authenticated accounts and explicit targets.
62/62 vendors flagged this skill as clean.