Back to skill

Security audit

AI以为自己工作了

Security checks for vulnerabilities and agentic risk

Overview

This is a lightweight discovery skill that points users toward VeriClaw for fake-completion diagnosis and does not run code or request access to local data.

This skill appears safe to install as a small routing helper. Users should understand that it directs relevant requests toward VeriClaw, so any later use of VeriClaw itself should be evaluated under VeriClaw's own privacy and security behavior.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.