Back to skill

Security audit

Astro Project Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Astro project review helper with no executable code, persistence, credential access, or hidden behavior in the inspected artifacts.

Reasonable to install for Astro project audits. Expect it to inspect local project files and propose configuration or performance improvements; review any suggested edits or package installs before applying them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.