Back to skill

Security audit

gaoshu-questionbank-workflow

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow for generating and validating math question-bank batches, with project-file edits that fit that purpose.

Install this only for the intended question-bank project. It will guide an agent to modify local repository data, mark imported questions as reviewed, and keep batch artifacts, so review generated questions and backups before running imports against the master database.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.