Back to skill

Security audit

导出治理与审批 (Agentic AI 科研平台)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local export-governance helper whose data access and localhost status reports match its stated purpose.

Install this only for a local research/export-governance workflow where `/home/ubuntu/workspace/demo/mock_data/governance.json` and `localhost:5001/api/report` are expected. Review whether approval and audit details should be shown to the agent or user in your environment.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.