Back to skill

Security audit

rdd

Security checks for vulnerabilities and agentic risk

Overview

This skill is a requirements-planning workflow that creates local planning/spec files and guides normal development steps without hidden network, credential, or persistence behavior.

Install this if you want a structured requirements-to-spec-to-code workflow. Expect it to create local planning/spec artifacts such as .rdd/items for larger tasks, unless the lighter commit-message path applies; non-Chinese users should ask the agent to work in their preferred language before relying on generated specs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill text explicitly frames the agent role and process in Chinese without offering any language negotiation or opt-in, which can override the user's preferred language and reduce transparency for users who cannot fully inspect or challenge the generated requirements/specifications. In a requirements and specification skill, forced language can materially affect correctness, consent, and reviewability because misunderstandings at this stage propagate into later implementation and verification steps.

Static analysis

No suspicious patterns detected.