Back to skill

Security audit

Mockhero

Security checks for vulnerabilities and agentic risk

Overview

MockHero appears to be a disclosed synthetic test-data generator with expected network, checkout, and API-key behavior and no evidence of hidden or destructive actions.

Before installing, treat any schemas, prompts, SQL, sample JSON, and billing email you submit as shared with MockHero. Use the free preview or estimate tool before paid generation, keep any mh_ API key private, and do not use this as an anonymization tool for real production data.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.