Back to skill

Security audit

Isocast

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed guide for an external weather-signal API with clearly described paid endpoints and no hidden code or persistence.

Use the free endpoints first and review the service terms before connecting any wallet, x402 payment client, bearer receipt, or Telegram delivery. The skill is informational and betting-adjacent, so treat the data as non-advisory and keep spending limits under your control.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.