Back to skill

Security audit

Quit Weed

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent cannabis-cessation coaching skill that stores sensitive tracking notes locally and does not show hidden networking, executable code, or credential access.

Install only if you are comfortable keeping cannabis-use, craving, mood, sleep, and trigger notes in a local ~/quit-weed/ folder. Treat the withdrawal and reduction guidance as coaching information, not medical advice; seek professional or urgent help for severe distress, self-harm thoughts, serious physical symptoms, or uncertainty involving other substances.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This markdown file provides health-related guidance and makes a strong safety claim that cannabis withdrawal is 'never medically dangerous' and that the brain 'recovers fully.' Under the missing-user-warnings rule for markdown files, this omits a caution that severe symptoms, co-occurring mental health issues, or uncertainty about substance use should be evaluated by a clinician rather than relying solely on the document.

Static analysis

No suspicious patterns detected.