Security audit
ship-it
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed release-readiness audit checklist that reads project files and reports findings without making changes unless the user later asks.
Install only if you want an agent to inspect repository files for release-readiness evidence. Expect it to run searches and read relevant code, including looking for secret-shaped values, but the artifact tells the agent to report first and avoid code edits unless you explicitly approve follow-up fixes.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
