Back to skill

Security audit

security-review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a scoped defensive security-review guide with no executable payload, persistence, or hidden data movement.

Install only if you want the agent to perform defensive security reviews over code you own or are authorized to audit. Expect it to read scoped source files and potentially run dependency-audit commands when relevant, but the artifact does not add executables or persistence.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.