Back to skill

Security audit

Agent Directory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local agent-profile directory helper with disclosed validation and index-building scripts, and no evidence of hidden network, credential, or destructive behavior.

Before installing, note that this skill is meant to help maintain local agent profile files and includes shell scripts that can read profile JSON files and rewrite the generated index. Run those scripts only in the intended workspace and review profile data before sharing it, especially if it contains internal group IDs or planning details.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.