Back to skill

Security audit

Toc Constraint

Security checks for vulnerabilities and agentic risk

Overview

This skill is a user-guided business process analysis aid and does not show hidden execution, credential use, data exfiltration, or destructive behavior.

Installers should understand that the skill may ask for operational or business-process details to build a TOC report; avoid sharing confidential business information unless that is appropriate for the agent environment.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation triggers are broad enough that the skill could be invoked during generic improvement or bottleneck discussions, even when TOC-guided constraint analysis is not the user's actual intent. In an agent system, over-broad routing can cause context drift, unnecessary collection of structured business information, and inappropriate process steering that overrides better-matched skills or the user's preferred workflow.

Static analysis

No suspicious patterns detected.