Security audit
pontx-pinhere
Security checks for vulnerabilities and agentic risk
Overview
This skill gives safety-focused guidance for integrating Pinhere and requires previews, redaction, and explicit approval before sensitive changes.
Before installing, confirm you intend to let your agent help with Pinhere API, OAuth, browser-extension, Webhook, and issue-management workflows. The skill is written to require local previews and explicit approval before changes, but users should still check every target, credential scope, and redacted request before approving any write, token, or Webhook action.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
