Back to skill

Security audit

what-changed

Security checks for vulnerabilities and agentic risk

Overview

This skill provides bounded guidance for explaining meaningful changes between user-provided versions and does not request unusual access or background behavior.

Install this only for workflows where you want the agent to compare versions or snapshots and explain impact. Provide only the files and organizational context needed for the comparison, especially when contracts, policies, or business data are sensitive.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.