Security audit
Agent Analytics Autoresearch
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed, review-first analytics workflow that reads analytics data and writes local experiment-planning artifacts without hidden or automatic production changes.
Install only if you are comfortable letting an agent use the Agent Analytics CLI or other supplied analytics sources for the chosen project. Use scoped analytics access where possible, review saved data snapshots for sensitive event payloads, avoid storing PII in project context, and only approve the outer experiment loop after reviewing the proposed production changes.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
