Back to skill

Security audit

pontx-dida365

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Dida365 integration guide that emphasizes scoped API use, credential safety, and explicit approval before writes.

Install only if you intend to use Pontx-managed Dida365 workflows. Before approving any write, confirm the previewed account, project, task identifiers, schedule, and expected effect match your intent, because the skill can guide real task changes after explicit approval.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.