Back to skill

Security audit

max-research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed deep-research workflow that may be very broad and time-consuming but does not show hidden, destructive, or deceptive behavior.

Install this only when you want exhaustive research. Expect many web searches and source fetches, including non-English sources and possibly video/PDF review. For confidential work, explicitly limit which local files and external searches the agent may use.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to use English first and mandates multiple Chinese/local-language searches, overriding user language preference and potentially causing unnecessary data transfer to external sources without user opt-in. In a research skill, this is risky because it can bias source selection, reduce accessibility, and conflict with user or organizational constraints around language, locality, or disclosure.

Static analysis

No suspicious patterns detected.