Back to skill

Security audit

Mdorigin

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward mdorigin CLI guide with disclosed install, preview, build, search, and Cloudflare deployment commands that fit its publishing purpose.

Before installing, verify that the npm package is the mdorigin package you intend to trust, prefer a project-local or pinned install when practical, and only run Cloudflare/R2 sync or init commands after confirming the target directory, bucket name, and active credentials.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.