Security audit
groupchat-participant
Security checks for vulnerabilities and agentic risk
Overview
This skill only guides an agent to participate in a host-mediated group chat once per round, with no code, installs, local data access, or hidden persistence.
Before installing, understand that this skill lets an agent send concise group chat replies and join/leave/status commands to a host session. Its behavior is disclosed and narrowly scoped, but users should only enable it where host-mediated multi-agent chat is expected.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
