Security audit
gaoshu-questionbank-workflow
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed workflow for generating and validating math question-bank batches, with project-file edits that fit that purpose.
Install this only for the intended question-bank project. It will guide an agent to modify local repository data, mark imported questions as reviewed, and keep batch artifacts, so review generated questions and backups before running imports against the master database.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
