clawdhub

Fail

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the clawdhub package from the npm registry using npm i -g clawdhub.
  • [REMOTE_CODE_EXECUTION]: The skill provides commands (clawdhub install and clawdhub update) specifically designed to download and integrate executable agent skills from an external, non-whitelisted registry located at https://clawdhub.com.
  • [COMMAND_EXECUTION]: The skill utilizes several shell commands to manage agent environment state, including authentication (clawdhub login), search, and updating local skill files based on remote registry content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 23, 2026, 09:46 AM
Security Audit — agent-trust-hub — clawdhub