Security audit
Addressfinder
Security checks for vulnerabilities and agentic risk
Overview
No artifact-backed malicious or suspicious behavior was found; the available signals are clean and the observed guidance is disclosed and task-aligned.
This appears safe to install based on the available evidence. As with any agent skill, review any command it proposes before running it, especially commands that authenticate to services, modify accounts, publish comments, or change local project files.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
