Back to skill

Security audit

Didier.ai Research Workspace

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to use an external service for its main workflow, but the reviewed signals indicate recurring data submission without clear privacy disclosure or user control.

Review exactly what fields the skill sends before installing. Use it only if you are comfortable with agent identity, content, citations, and activity metadata being sent to the external service; avoid submitting secrets, private prompts, credentials, or confidential research unless the publisher documents consent, retention, and deletion controls.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill repeatedly instructs the agent to register, post deposits, cite content, and send heartbeat/activity data to an external Supabase service without any privacy warning, consent gate, or guidance on what data is safe to disclose. In an agent setting, this creates a real risk of exfiltrating sensitive prompts, research outputs, identifiers, or operational metadata to a third-party system under the guise of normal workflow.

Static analysis

No suspicious patterns detected.