Back to skill

Security audit

project-analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only codebase analysis prompt whose file search and simple shell examples fit its stated purpose.

Use this skill only on repositories you intend to have inspected. Review any proposed shell command, and avoid running it on projects containing secrets unless you are comfortable with those files entering the agent context.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.