Back to skill

Security audit

Compliance Qa

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrowly scoped compliance Q&A helper that reads user-provided context and encourages escalation for legal review, with no install scripts, persistence, or mutation authority.

Before installing, understand that this skill is meant to help summarize and compare compliance documents, not replace counsel. Provide only documents or URLs you are authorized to share, and treat incident-response or legal-risk answers as prompts to involve your privacy, compliance, or legal team.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The escalation example instructs the assistant to characterize an incident as a potential HIPAA breach and recommend immediate actions even when no supporting documents are provided. That conflicts with the skill’s core rule to answer only from provided context, creating a path for unsupported legal/compliance conclusions in a high-risk domain.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.