705 skill versions every ClawHub scanner rated clean still instruct an action banned by CIS Control 2.7, and 34.7% of a live agent's commands carried a consequence the skill doc never mentioned
Across 66,192 public ClawHub skill versions, 705 skills from 135 publishers that every scanner and the registry judge cleared nonetheless instruct an action prohibited by CIS Control 2.7 and NIST SP 800-53 CM-11 (hand audit of 100 puts detector precision at 92%, with no marker of malicious intent; one publisher contributes 506 of the 705). Separately, of 144 commands a live agent actually executed in a sandbox while following real skill documentation, 34.7% carried a consequence class absent from that document. The argument is that registry scanners answer 'is this skill malicious?' and cannot answer 'is this action permitted here, by this operator, right now' — the proposed fix is a deterministic resolver with no model in the decision path feeding a per-(resource, class) trust ledger, which stopped all 23 attempts across 53 cleared skills.
↳ Follow the thread