Security audit
Internal Audit Risk Control Matrix
Security checks for vulnerabilities and agentic risk
Overview
This is a text-only internal audit drafting skill that stays aligned with creating draft risk-control matrices and does not request code execution, credentials, persistence, or hidden data movement.
Reasonable to install for drafting internal audit RCMs. Users should still limit unnecessary sensitive company details, keep outputs labeled as drafts, and have a qualified internal auditor and CAE review any matrix, sampling plan, or reliance decision before fieldwork.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
