Security audit
BlogWatcher (Holli)
Security checks for vulnerabilities and agentic risk
Overview
This skill is a straightforward guide for installing and using a blog/RSS feed watcher CLI, with no evidence of hidden or unrelated behavior.
This appears reasonable to install if you trust the upstream Go project. Because the install command uses `@latest`, review the GitHub repository or pin a version if you want more control over exactly what code is installed.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
