clawteam
Fail
Audited by Snyk on Apr 24, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). High-risk: the content deliberately includes features that bypass agent safety prompts (e.g., --skip-permissions / --dangerously-* / --yolo), supports networked/shared state (SSHFS, p2p) and exposes reactive execution (inbox watch --exec and HTTP/SSE dashboard), which together enable remote-triggered command execution, stealthy sandbox bypassing, and potential exfiltration/backdoor scenarios when an attacker can write to team state or transport peers.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata