Back to skill

Security audit

Test Debug Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable documentation skill about a commerce API, with disclosed payment/API-key topics and no hidden automation found.

Reasonable to install as documentation. Before following any live commerce steps, verify GreenHelix independently, use test or sandbox payment settings, keep API keys scoped and private, and require explicit review before live payments, crypto transfers, or marketplace listings.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.