Security audit
Agent Native Speaker
Security checks for vulnerabilities and agentic risk
Overview
This is a documentation-only teaching skill that may read local source code for architecture explanations, and that behavior is disclosed and aligned with its purpose.
Install this where it is acceptable for the agent to inspect and summarize local source code when asked about agent architecture. In private projects, avoid asking it to inspect config, secrets, memories, profiles, or databases unless you intend those details to be discussed.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
