Back to skill

Security audit

Nonviolent Communication

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Markdown communication-coaching skill with no code, external access, persistence, credential handling, or automatic actions.

This appears safe to install as a conversational writing aid. Users should still avoid sharing unnecessary sensitive personal details and should review any drafted message before sending it. The marketplace capability tags look mismatched, but the actual artifact does not implement crypto or purchase behavior.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.