Security audit
ArtzAIn Tool Gate
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed pointer to an external governance plugin that blocks or allows tool calls through the user's own CogNEXUS decision service.
Before installing, verify the npm package provenance and source, use only a Decision API key scoped for this gateway, and expect tool calls to be blocked if the decision service or configuration is unavailable.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
