other
- Location
SKILL.md:174- Finding
Excessive Disclosure of Household and Critical-Grid Metadata
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a non-executable educational guide, but it teaches financial escrow and physical energy-asset control workflows without enough safety, authorization, or production-use guardrails.
Read this as a high-impact integration guide, not a drop-in production recipe. Use sandbox credentials first; do not connect production payment keys, real smart-meter data, or physical battery controllers until you have explicit owner consent, operator approval workflows, device-scoped authorization, transaction limits, idempotency, rollback/reconciliation, and local safety interlocks.
SKILL.md:174Excessive Disclosure of Household and Critical-Grid Metadata
SKILL.md:574Non-Transactional Escrow and SLA Workflow Is Described as Atomic
SKILL.md:827Safety-Critical Battery Dispatch Lacks Demonstrated Authorization and Operational Guardrails
The escrow and settlement examples show how to create escrows, execute trades, and release funds, but they do not prominently warn that using production endpoints or real API keys could lock, transfer, or dispute actual money. Because the skill references live credentials like GREENHELIX_API_KEY and STRIPE_API_KEY, a user may underestimate the financial consequences of copying the sample flow outside the sandbox.
The guide provides concrete examples for autonomous battery discharge, load shedding, and emergency island-mode actions against physical energy assets without a prominent safety warning, human-approval gate, or simulation-only constraint. In a real deployment, readers could adapt these patterns to trigger unsafe control actions that affect power availability, equipment protection, or essential services, making the omission materially dangerous even though the file is presented as educational.
No suspicious patterns detected.