Security audit
Outbreak Investigation Report
Security checks for vulnerabilities and agentic risk
Overview
The skill artifacts are coherent developer and maintainer workflows with disclosed command use and no evidence of hidden exfiltration, destructive automation, or persistence.
Install only if you want these repo-maintainer and Convex development workflows. Review the autoreview helper before use because it defaults to a full-access nested Codex review unless run with its opt-out, and use the moderation, migration, publishing, and auth setup commands only with the intended accounts, explicit targets, and appropriate credentials.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
