Security audit
project-analyzer
Security checks for vulnerabilities and agentic risk
Overview
This skill is a read-only codebase analysis prompt whose file search and simple shell examples fit its stated purpose.
Use this skill only on repositories you intend to have inspected. Review any proposed shell command, and avoid running it on projects containing secrets unless you are comfortable with those files entering the agent context.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
