Back to skill

Security audit

AI收藏夹与桌面Dock 助手

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed productivity skill for creating Command Compass cards from user-selected prompts, files, folders, shortcuts, and links.

Install this if you intend to use Command Compass to organize user-selected resources. Review generated cards before syncing or opening files, shortcuts, scripts, or links, and avoid placing private paths or sensitive content in cards that may be shared or stored remotely.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.