Back to skill

Security audit

Mp Diagnose

Security checks for vulnerabilities and agentic risk

Overview

No scanner or available workspace evidence showed harmful behavior, but direct artifact inspection was limited because the target skill files were not present.

The telemetry is clean, so this can be treated as benign from the available evidence. Because the target artifact files were not available for direct review, inspect the skill contents and install requirements yourself before installing if it asks for broad local access, credentials, long-running background behavior, or write permissions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.