Back to skill

Security audit

Professional Web Engineering

Security checks for vulnerabilities and agentic risk

Overview

This is a broad web engineering guidance skill with no hidden scripts or data collection, though users should be aware that most detailed instructions are in Indonesian and its activation scope is wide.

Install only if you want a broad professional web/app engineering workflow. Non-Indonesian users should review the SKILL.md language carefully or request translated guidance before relying on it for deployment, security, or production decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation text is extremely broad, covering nearly every kind of software project and offering no concrete activation boundaries. In an agentic environment, this can cause the skill to be selected in inappropriate contexts, expanding its influence over planning and implementation steps where a narrower or more specialized skill should apply.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README tells the user to consult another file for the real activation criteria instead of stating them directly, which weakens safe routing and makes invocation decisions opaque. If tooling or reviewers only inspect the README, the skill may be activated without clear constraints, increasing the chance of misuse or overreach.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description is extremely broad, covering nearly all website, app, API, backend, and AI-related engineering tasks. This can cause the skill to activate in many unrelated or only partially related contexts, increasing the chance that a generic high-authority workflow overrides more specialized or safer skills and leads to unintended actions.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The skill content is written in Indonesian and frames directives as mandatory without offering user language selection or fallback behavior. In practice, this can cause misunderstanding of requirements, remediation, security constraints, or deployment steps for users who do not understand the language, which is especially risky in a broad engineering skill intended for many high-impact tasks.

Static analysis

No suspicious patterns detected.