Security audit
规划模式 (Plan Mode)
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only planning skill that asks the agent to research relevant context and get user confirmation before complex work.
Safe to install for normal use. It will encourage the agent to inspect relevant project code and propose a plan before edits, so review the plan before approving changes in sensitive or production repositories.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
