Back to skill

Security audit

Exit Waterfall

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed educational cap-table payout calculator with no evidence of hidden access, persistence, or data exfiltration.

Before installing, consider whether you are comfortable giving an agent confidential cap-table and financing data. If the agent tries to run scripts/exit_waterfall.py, confirm that script actually exists in your environment and comes from a trusted source, since it is not included in this skill package.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.