Back to skill

Security audit

Qms Selection

Security checks for vulnerabilities and agentic risk

Overview

This skill is a structured QMS software selection assistant with no executable code, persistence, credential access, or hidden data handling found.

Before installing, treat outputs as advisory selection support and verify all vendor claims, costs, certifications, and scoring inputs with your organization and vendors. The artifact did not show security-sensitive behavior, but the referenced report-generation script was not included in the inspected files.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.