Back to skill

Security audit

Harvey Specter Writing Style

Security checks for vulnerabilities and agentic risk

Overview

The supplied evidence does not show artifact-backed malicious or suspicious behavior, but the actual skill files were not available for a full coherence review.

Based on the supplied scan context, there is no concrete reason to block installation. Because the artifact files were not available in this review, users should still inspect the skill text and only install it if its requested permissions and behavior match what they expect.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.