Security audit
ponytail-debt
Security checks for vulnerabilities and agentic risk
Overview
This skill only scans repository comments for a specific debt marker and reports the results, with file writing only if the user asks.
Install only if you are comfortable with the agent scanning repository source comments and showing matching lines in a report. It does not request credentials or network access, and it should only write a ledger file when you explicitly ask it to persist one.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
