Back to skill

Security audit

Buildin CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a cautious Buildin CLI guide that asks for approval before installation, login, or remote changes and does not include hidden code.

Install only if you intend agents to operate on your Buildin workspace. Review the active Buildin account before writes, avoid pasting bearer tokens into chat, and confirm page/database/file targets before allowing create or update commands.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.