Security audit
ask-the-data
Security checks for vulnerabilities and agentic risk
Overview
This skill provides straightforward instructions for answering questions from local structured data files with traceable queries, without hidden execution or unrelated data handling.
Install this if you want an agent to analyze local CSV, Excel, JSON, TSV, or Parquet data. Because it can inspect project data and may persist a local DuckDB database for repeated analysis, use it in projects where those files are appropriate for the agent to read.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
