Security audit
what-changed
Security checks for vulnerabilities and agentic risk
Overview
This skill provides bounded guidance for explaining meaningful changes between user-provided versions and does not request unusual access or background behavior.
Install this only for workflows where you want the agent to compare versions or snapshots and explain impact. Provide only the files and organizational context needed for the comparison, especially when contracts, policies, or business data are sensitive.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
