Back to skill

Security audit

customer-research

Security checks for vulnerabilities and agentic risk

Overview

This skill provides customer research guidance and public-source research playbooks without hidden execution, persistence, or unrelated data access.

Installers should expect this skill to guide agents through customer research, including reading explicitly relevant marketing context files and analyzing customer materials the user provides. Review sensitive transcripts, support tickets, and survey exports before sharing them with an agent, but the artifact does not show hidden collection, automatic posting, credential use, or persistent behavior.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.