Back to skill

Security audit

Juso Address Cli

Security checks for vulnerabilities and agentic risk

Overview

The skills are mostly coherent maintainer and Convex workflow helpers, but the autoreview helper defaults to launching a nested Codex review with full sandbox bypass authority.

Install only if you are comfortable with maintainer-grade tools. Use the moderation skill only with explicit targets and reasons, and consider running the autoreview helper with `--no-yolo` unless you intentionally want a nested reviewer to have full filesystem and command authority.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.