Back to skill

Security audit

website-structure

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only website planning skill with no executable code, though it may read narrow project context files if present.

Safe to install for website structure planning. Before use, check that .claude/project-context.md or .cursor/project-context.md in your workspace do not contain secrets, because the skill may ask the agent to read those files for planning context. The crypto and purchase tags in metadata do not appear supported by the actual skill text.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.