Back to skill

Security audit

vow-enforcement

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed governance guide for deciding when project rules should become hooks or validator checks, with no executable payload in the artifact.

Install this if you want an agent to reason about project-rule enforcement and quality gates. Be aware that its broad trigger words may make it appear in wider governance or compliance conversations, so review activation behavior if you prefer narrowly scoped skills.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains broad terms like "enforcement," "constraints," "hooks," and "compliance," which can cause the skill to activate in many unrelated contexts. Over-broad activation is risky because it can inject governance/enforcement behavior into tasks that did not request it, increasing the chance of inappropriate blocking, policy interference, or prompt-scope takeover by this skill.

Static analysis

No suspicious patterns detected.