Back to skill

Security audit

apaleo

Security checks for vulnerabilities and agentic risk

Overview

The skill set is mostly coherent, but its review helper grants nested AI reviewers full local authority by default, so it should be reviewed before installation.

Install only in a trusted development environment. Before using the autoreview skill, consider disabling its full-access mode with its no-yolo option and review which fallback reviewer CLIs are configured, because generated diffs may be passed to them. Moderation and PR-maintainer workflows should be used only by users who intentionally want those account, content, or public GitHub actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.