Back to skill

Security audit

skillify

Security checks for vulnerabilities and agentic risk

Overview

This skill packages proven workflows into portable skill files and does not include hidden execution, data access, or automatic installation behavior.

Install only if you want an agent to help package already-proven workflows into reusable skills. Review any generated skill before deploying it, especially because this skill is meant to create durable agent instructions, but the artifact itself does not perform automatic installation or hidden actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ae1

High
Category
analysis-evasion
Content
6. Keep `SKILL.md` concise; move deep details to one-level `references/` files.
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Static analysis

No suspicious patterns detected.