Back to skill

Security audit

Investment Policy Statement Drafter

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only drafting skill for investment policy statements, with clear draft-only limits and no executable behavior.

Appropriate to install for IPS drafting, but do not paste SSNs, full account numbers, taxpayer IDs, DOBs, government IDs, login credentials, or other direct identifiers. Treat outputs as drafts only and route them through qualified compliance, legal, tax, and fiduciary review before client signature or implementation.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.