Back to skill

Security audit

Addressfinder

Security checks for vulnerabilities and agentic risk

Overview

No artifact-backed malicious or suspicious behavior was found; the available signals are clean and the observed guidance is disclosed and task-aligned.

This appears safe to install based on the available evidence. As with any agent skill, review any command it proposes before running it, especially commands that authenticate to services, modify accounts, publish comments, or change local project files.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.