Back to skill

Security audit

LYGO Champion Council (Δ9 unified v2)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a documentation helper that reads and updates repository docs and agent instruction files, with its authority matching that stated purpose.

Install this if you want an agent to help audit and update documentation, CONTRIBUTING files, and agent instruction surfaces. Expect it to read broadly across documentation files and possibly edit docs or compatibility files when asked to apply fixes; use report-only mode if you want review without changes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.