Security audit
Agent Directory
Security checks for vulnerabilities and agentic risk
Overview
This skill is a local agent-profile directory helper with disclosed validation and index-building scripts, and no evidence of hidden network, credential, or destructive behavior.
Before installing, note that this skill is meant to help maintain local agent profile files and includes shell scripts that can read profile JSON files and rewrite the generated index. Run those scripts only in the intended workspace and review profile data before sharing it, especially if it contains internal group IDs or planning details.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
