Back to skill

Security audit

Creator Registry

Security checks for vulnerabilities and agentic risk

Overview

This skill manages creator roster records with disclosed data handling, explicit write authorization, and scoped append-only registry behavior.

Before installing, understand that this skill is meant to help maintain a creator CRM-style event log. Use it only with a trusted workspace/runtime, confirm any writes explicitly, and avoid feeding it unnecessary personal contact details or sensitive history.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.