ai-intelligent-data-governance
Fail
Audited by Snyk on Jun 19, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). These URLs point to an unverified GitHub repository and a custom domain (clawhub.ai) used as a private registry — both are plausible sources of legitimate code but are not established/verified vendors, and running code cloned from an unknown repo or pulled from a nonstandard registry can deliver malicious code, so treat them as suspicious until validated.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The installation steps explicitly run remote code fetched from https://github.com/openclaw-skills/ai-intelligent-data-governance (git clone ... then python app.py), so the repository's contents would be executed at runtime and can directly control the agent's behavior.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata