Back to skill

Security audit

Pine Pitch Glue Making Basics

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable instructional skill for making pine-pitch glue; its safety and barter guidance need caution, but no hidden or malicious behavior was found.

Install only if you are comfortable using filesystem logs and sharing photos or approximate location for resin identification. Treat all safety instructions as advice, not enforcement: use ventilation, low heat, protective gear, and fire controls. Do not rely on the barter templates as legal, safety, or market validation for selling or trading homemade adhesive.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The skill presents a concrete barter value for pine-pitch glue as if it were broadly valid, despite barter values being highly dependent on local scarcity, legality, quality, and market conditions. This can mislead users into making poor economic decisions or facilitate exploitative trade expectations, especially in emergency or off-grid contexts where users may rely heavily on the agent's guidance.

Static analysis

No suspicious patterns detected.