Security audit
自我进化循环
Security checks for vulnerabilities and agentic risk
Overview
The skill is openly about agent self-improvement, but it asks the agent to persist task traces and modify its own skills and memory with limited user control.
Install only if you want an agent to keep cross-session records about its own failures and improvements, and to modify its skill and memory files as part of that process. Use it with clear workspace boundaries, review generated traces for sensitive data, and require confirmation before any change to core behavior files such as SKILL.md, MEMORY.md, or TOOLS.md.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
