Back to skill

Security audit

Developer Onboarding Doc

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation template for developer onboarding and does not request code execution, credentials, persistence, or sensitive system access.

Before installing, be aware that the generated document may include internal service names, contacts, deployment details, and operational links; use it in a trusted workspace and avoid pasting secrets into the onboarding content.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.