Security audit
Dev Machine Cleanup
Security checks for vulnerabilities and agentic risk
Overview
The skill is purpose-aligned for cleanup, but it would asynchronously SSH into a development machine and delete files/Docker images without clear credential scoping, confirmation, or enforceable safeguards.
Install or invoke this only if you trust the agent to use SSH on the datax development machine. Before use, add a dry-run and explicit approval step, confirm the exact host/account/path scope, make Docker pruning optional, and ensure you can review or cancel any background cleanup run.
Static analysis
No suspicious patterns detected.
