Back to skill

Security audit

Internal Audit Risk Control Matrix

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only internal audit drafting skill that stays aligned with creating draft risk-control matrices and does not request code execution, credentials, persistence, or hidden data movement.

Reasonable to install for drafting internal audit RCMs. Users should still limit unnecessary sensitive company details, keep outputs labeled as drafts, and have a qualified internal auditor and CAE review any matrix, sampling plan, or reliance decision before fieldwork.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.