Security audit
pontx-dida365
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed Dida365 integration guide that emphasizes scoped API use, credential safety, and explicit approval before writes.
Install only if you intend to use Pontx-managed Dida365 workflows. Before approving any write, confirm the previewed account, project, task identifiers, schedule, and expected effect match your intent, because the skill can guide real task changes after explicit approval.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
