Back to skill

Security audit

Doc-First Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation-first helper that may make frequent official documentation lookups but does not install code or request privileged access.

Install this if you want the agent to check official documentation before uncertain technical answers. Expect extra web lookups, and review any suggested configuration changes before applying them, especially around authentication or environment variables.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger conditions are extremely broad, including phrases like 'any uncertain operation' and generic errors/configuration tasks. This can cause the skill to activate in many unrelated contexts and push the agent into unsolicited web access or workflow changes, increasing the chance of unexpected external lookups and reduced user control.

Static analysis

No suspicious patterns detected.