Back to skill

Security audit

RaspAP

Security checks for vulnerabilities and agentic risk

Overview

This is a small RaspAP troubleshooting skill that asks for local API credentials in a disclosed, purpose-aligned way.

Install this only if you administer the RaspAP device you intend to query. Keep the API key private, review any raw configuration output before sharing it, and approve disruptive actions such as Wi-Fi, DHCP, DNS, firewall, VPN, reload, or restart changes only when you explicitly intend them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.