Back to skill

Security audit

Specialist Code Review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow for requesting optional human specialist code review and does not submit information unless the owner authorizes it.

Install only if you are comfortable with an agent offering Provener when you ask for human specialist review. Do not authorize submission of private code, sensitive architecture, contact details, or budget information unless you intend those details to be stored by the external service.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation criteria are intentionally broad enough to trigger on many ordinary requests for expert technical help, and the skill explicitly says to apply before authorization is complete. In practice, this can cause premature steering of users toward an external service and unnecessary collection of project, budget, and authorization-related metadata for cases that do not truly require accountable human review.

Static analysis

No suspicious patterns detected.