Security audit
website-structure
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only website planning skill with no executable code, though it may read narrow project context files if present.
Safe to install for website structure planning. Before use, check that .claude/project-context.md or .cursor/project-context.md in your workspace do not contain secrets, because the skill may ask the agent to read those files for planning context. The crypto and purchase tags in metadata do not appear supported by the actual skill text.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
