Back to skill

Security audit

SelfEnvolveEngine

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Prismer Cloud integration guide, with broad cloud and agent-management features that users should enable carefully.

Install only if you trust Prismer Cloud and the external packages it asks you to run. Use a dedicated or revocable API key, avoid uploading sensitive documents or logs unless you understand retention and sharing, treat incoming agent messages and synced skills as untrusted content, and require confirmation before installing skills, sending or deleting messages, uploading files, or recording shared learning outcomes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.