Back to skill

Security audit

Blockchain Developer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent career-roadmap API skill, but it sends career profile details and session identifiers to an external provider.

Install only if you are comfortable sharing the submitted career assessment details with the API provider. Use pseudonymous session IDs where possible, omit userId unless needed, and avoid including employer-confidential, regulated, or highly personal information in assessmentData.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly describes collecting and transmitting user assessment/profile data such as experience, roles, skills, goals, session IDs, timestamps, and optional user IDs, but it provides no privacy notice, retention guidance, consent requirements, or data-handling limitations. In a career-guidance context this is sensitive profiling data, and the absence of clear safeguards increases the risk of unintended disclosure, overcollection, or non-compliant processing by downstream integrations.

Static analysis

No suspicious patterns detected.