Security audit
Skillet Reduce
Security checks for vulnerabilities and agentic risk
Overview
The available scan telemetry is clean and I found no artifact-backed evidence of unsafe or deceptive behavior.
Install only if the skill name, publisher, and displayed files match what you intended to use. The available telemetry is clean, but because the artifact contents were not present for deeper review here, treat any future request for credentials, broad local access, persistence, or destructive actions as a reason to stop and inspect the skill manually.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
