Back to skill

Security audit

Infra

Security checks for vulnerabilities and agentic risk

Overview

This is a broad infrastructure guidance skill with no code, hidden access, or automatic system-changing behavior.

This skill may give advice about production infrastructure and security-sensitive systems. Review and test any recommendations yourself before applying changes to live cloud accounts, networks, IAM, secrets, or incident-response workflows.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description and body cover a very wide range of infrastructure topics, including incident response, architecture, cloud, security, and IaC, without clear activation boundaries. In an agent setting, this can cause over-broad invocation on routine conversations, increasing the chance the agent applies powerful infrastructure guidance in the wrong context or acts without sufficient scoping and user confirmation.

Static analysis

No suspicious patterns detected.