ai-intelligent-data-governance

Fail

Audited by Snyk on Jun 19, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These URLs point to an unverified GitHub repository and a custom domain (clawhub.ai) used as a private registry — both are plausible sources of legitimate code but are not established/verified vendors, and running code cloned from an unknown repo or pulled from a nonstandard registry can deliver malicious code, so treat them as suspicious until validated.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 1.00). The installation steps explicitly run remote code fetched from https://github.com/openclaw-skills/ai-intelligent-data-governance (git clone ... then python app.py), so the repository's contents would be executed at runtime and can directly control the agent's behavior.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 19, 2026, 05:56 PM
Issues
2
Security Audit — snyk — ai-intelligent-data-governance