Back to skill

Security audit

Agent Bootstrap Hardening

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only workspace hardening guide that may affect future agent behavior, but its scope is disclosed and proportionate.

Install this only if you want help reviewing and tightening agent bootstrap or memory files. Require a visible diff and rationale before edits are applied, since changes to these files can alter how future agents follow instructions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.