clawsec-clawhub-checker
Warn
Audited by Snyk on Feb 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's check_clawhub_reputation.mjs explicitly calls public ClawHub CLI commands (e.g.,
clawhub inspect --jsonandclawhub install) and the hooks/clawsec-advisory-guardian/lib/reputation.mjs integrates and parses those outputs (including VirusTotal Code Insight messages) into reputation scores and installation decisions, meaning it consumes untrusted, public third‑party content that can materially change agent behavior.
Audit Metadata