Security audit
Mockhero
Security checks for vulnerabilities and agentic risk
Overview
MockHero appears to be a disclosed synthetic test-data generator with expected network, checkout, and API-key behavior and no evidence of hidden or destructive actions.
Before installing, treat any schemas, prompts, SQL, sample JSON, and billing email you submit as shared with MockHero. Use the free preview or estimate tool before paid generation, keep any mh_ API key private, and do not use this as an anonymization tool for real production data.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
