Security audit
KaleidoSphere
Security checks for vulnerabilities and agentic risk
Overview
This skill is narrowly scoped to validating and routing bounded KaleidoSphere requests and explicitly rejects credentials, arbitrary URLs, raw data, and mutation requests.
Before installing, confirm you actually use KaleidoSphere and have a trusted host transport configured. The skill is designed to refuse arbitrary endpoints, secrets, raw rows, SQL, and apply/write/delete/deploy requests, so it should be used as a bounded advisory and validation layer rather than as authority to change BI systems directly.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
