Back to skill

Security audit

Review Elixir

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly scoped Elixir/Phoenix code-review skill that runs expected project review commands and does not include hidden scripts, persistence, credential handling, or exfiltration behavior.

Install this if you want an agent-guided Elixir/Phoenix review workflow. Before use, be aware that review and verification steps may run your project's Mix tasks and tests, so use it in repositories where you are comfortable executing the project's normal development commands.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.