Back to skill

Security audit

FFHub

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide disclosed, user-directed workflow automation with no evidence of hidden persistence, data theft, or destructive behavior.

Install or use this skill only if you intend to grant it the described workflow authority. Pay particular attention before running commands that ban or unban users, change roles, publish PR artifacts, install packages, or run full-access review helpers; those actions should stay tied to explicit user requests and trusted credentials.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.