Back to skill

Security audit

Agent Analytics Autoresearch

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, review-first analytics workflow that reads analytics data and writes local experiment-planning artifacts without hidden or automatic production changes.

Install only if you are comfortable letting an agent use the Agent Analytics CLI or other supplied analytics sources for the chosen project. Use scoped analytics access where possible, review saved data snapshots for sensitive event payloads, avoid storing PII in project context, and only approve the outer experiment loop after reviewing the proposed production changes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.