Back to skill

Security audit

Primattography Color & Film Logic

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only DaVinci Resolve color-science skill with no executable code, install hooks, persistence, or hidden data access.

Before installing, expect the skill to guide DaVinci Resolve DCTL and color-science work primarily in Turkish. Users who prefer another language may need to ask the agent to respond in that language, but the artifact does not show risky local actions or credential handling.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This markdown file contains the substantive skill instructions in Turkish, but it does not indicate that the skill is Turkish-only or give the user an option to choose another language. That creates a natural-language policy concern because it effectively forces a specific language without user opt-in.

Static analysis

No suspicious patterns detected.