Back to skill

Security audit

Data Model Designer

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a construction data-modeling helper with no evidence of hidden execution, credential access, persistence, or data exfiltration.

Before installing, verify the publisher and package identity because the metadata is not fully consistent. When using it, provide only the construction project files you intend to process, choose export paths deliberately, and review generated SQL before running it against a database.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.