Security audit
sadouchengbing
Security checks for vulnerabilities and agentic risk
Overview
This is a non-executable operations template for reusing project workflows, and I found no hidden code or suspicious behavior.
Safe to install as a project-operations template. Before using it with real projects, make sure any customer data, source code, recordings, metrics, or test data stored in GitHub, cloud drives, or archives is approved, redacted where needed, and encrypted when sensitive.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
