Back to skill

Security audit

Dqf Driver Qualification File Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed, markdown-only DOT driver-file audit helper that stays within draft compliance review and does not execute code or access external systems.

Install only if you are comfortable using an AI assistant for sensitive employee compliance review. Provide internal IDs and last-4 CDL only, keep source records in your controlled DQF system, and treat all outputs as draft audit support rather than legal advice, medical fitness determinations, official FMCSA submissions, or authorization to dispatch without DER and compliance review.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.