Back to skill

Security audit

Outbreak Investigation Report

Security checks for vulnerabilities and agentic risk

Overview

The skill artifacts are coherent developer and maintainer workflows with disclosed command use and no evidence of hidden exfiltration, destructive automation, or persistence.

Install only if you want these repo-maintainer and Convex development workflows. Review the autoreview helper before use because it defaults to a full-access nested Codex review unless run with its opt-out, and use the moderation, migration, publishing, and auth setup commands only with the intended accounts, explicit targets, and appropriate credentials.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.