Back to skill

Security audit

Village Carpenter Starter

Security checks for vulnerabilities and agentic risk

Overview

This is a simple instructional woodworking skill with no executable code or hidden digital behavior.

Installation appears reasonable from a security perspective. Users should still treat the carpentry instructions as practical advice, use proper physical safety precautions, and note that the declared filesystem permission is not visibly needed by the skill text.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.