Security audit
Test Debug Skill
Security checks for vulnerabilities and agentic risk
Overview
This is a non-executable documentation skill about a commerce API, with disclosed payment/API-key topics and no hidden automation found.
Reasonable to install as documentation. Before following any live commerce steps, verify GreenHelix independently, use test or sandbox payment settings, keep API keys scoped and private, and require explicit review before live payments, crypto transfers, or marketplace listings.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
