Back to skill

Security audit

Terminology

Security checks for vulnerabilities and agentic risk

Overview

This is a small always-on terminology reference for UML sequence diagrams and does not contain code that runs, accesses data, or changes the system.

Install this only if you want a lightweight always-on UML terminology reference. The main thing to notice is that it asks the agent not to edit its own installed skill files, but it does not run code, access private data, use credentials, or make network calls.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.