Back to skill

Security audit

Agent Dlp

Security checks for vulnerabilities and agentic risk

Overview

This DLP skill needs review because it claims security-protection features without shipping the referenced implementation and its metadata requests unexplained wallet-related access.

Review carefully before installing. Ask the publisher to provide the missing implementation files, explain or remove the wallet capability, and document how audit logs are redacted, retained, stored, and protected. Do not rely on this package for sensitive DLP enforcement until those gaps are resolved.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation states that all operations are logged and audit logs are stored, but it provides no warning about retention, access control, redaction, or privacy implications. Because this skill processes sensitive inputs, memory contents, tool requests, and outputs, indiscriminate logging could itself become a data-leak channel containing secrets and personal data.

Static analysis

No suspicious patterns detected.