Back to skill

Security audit

fn-fpk

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-focused guide for building fnOS FPK apps, with sensitive permissions and API use disclosed as part of that purpose.

Install this if you are developing fnOS FPK applications. Pay attention when following examples that use root mode, appcenter-cli installs, Docker services, file authorization scopes, or uninstall data deletion, and keep requested scopes and privileges to the minimum your app actually needs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:672