Back to skill

Security audit

ArtzAIn Tool Gate

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed pointer to an external governance plugin that blocks or allows tool calls through the user's own CogNEXUS decision service.

Before installing, verify the npm package provenance and source, use only a Decision API key scoped for this gateway, and expect tool calls to be blocked if the decision service or configuration is unavailable.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.