Back to skill

Security audit

TokenLab API Integration

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward TokenLab API integration guide with no evidence of hidden, destructive, or deceptive behavior.

Before installing, confirm you trust the TokenLab service and the GitHub source. Generated examples may ask you to set a TokenLab API key and may make paid network API calls, so review endpoints, model choices, and costs before running them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.