Back to skill

Security audit

Project Review Council

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only project review skill whose adversarial review language is disclosed and aligned with its purpose, with no evidence of hidden execution, data access, persistence, or exfiltration.

Install this for structured project audits and decision reviews. When using the Competitor or Red Team portions, frame requests as defensive scenarios, abuse-case analysis, and mitigation planning rather than instructions to attack real third parties or systems.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 4

Medium
Confidence
98% confidence
Finding
The workflow explicitly requires the 'Competitor' role to produce an executable attack plan, which can cause the agent to generate operational offensive guidance rather than high-level risk analysis. In the context of a general project review skill, this materially increases the chance of misuse for real-world targeting, especially because the instruction is embedded as a mandatory output requirement.

Static analysis

No suspicious patterns detected.