Security audit
Api Change Review
Security checks for vulnerabilities and agentic risk
Overview
This is a local API review checklist skill with no executable code and only clearly disclosed optional file-writing or cloud setup steps.
Reasonable to install if you want an API-change review checklist. Before using the optional Ritual Cloud path, review what the external CLI does and only approve knowledge-note writes when the captured convention is appropriate for the repository.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
