Back to skill

Security audit

Cn Color Tool

Security checks for vulnerabilities and agentic risk

Overview

Available scanner telemetry is clean, but the target skill artifact was not present in the workspace for direct review.

There is no scanner-backed reason to block installation from the information provided. Because the actual skill text was not available for this adjudication, inspect the skill files before installing if you need high assurance, especially for any requests to access credentials, private files, network services, or persistent background behavior.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.