Security audit
Terminology
Security checks for vulnerabilities and agentic risk
Overview
This is a small always-on terminology reference for UML sequence diagrams and does not contain code that runs, accesses data, or changes the system.
Install this only if you want a lightweight always-on UML terminology reference. The main thing to notice is that it asks the agent not to edit its own installed skill files, but it does not run code, access private data, use credentials, or make network calls.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
